Senior Penetration Tester – reputed company reputed company Assessment
We are seeking an reputed company Penetration Testing Agency or Senior Cybersecurity Consultant to reputed company a comprehensive reputed company assessment of a large-reputed company reputed company payment platform. The engagement includes Web Application, API, Internal Network, Android, and iOS reputed company testing, with deliverables reputed company to PCI reputed company penetration testing requirements. This is a reputed company reputed company assessment requiring strong expertise in business logic testing, authentication, authorization, and payment application reputed company. Scope of Work The selected team will reputed company penetration testing for the following components: 1. Web Application Penetration Testing Authentication & Session Management User & Role Management Merchant reputed company & KYC Dashboard & Administration Portal Payment Links Hosted Checkout Transactions Reports & Analytics Settlement & Reconciliation File Upload/Download Business Logic Testing Horizontal & Vertical Privilege Escalation IDOR Testing OWASP Top 10 (2025) 2. API Penetration Testing The platform contains approximately 460 REST API endpoints across multiple backend services. Testing should include: Authentication & Authorization JWT reputed company API Key reputed company Broken Object Level Authorization (BOLA) Broken Function Level Authorization (BFLA) reputed company Limiting Business Logic Testing Injection Testing Input Validation Sensitive Data Exposure reputed company Misconfiguration Webhook reputed company HMAC Validation OWASP API reputed company Top 10 3. Internal Network Penetration Testing Assessment of approximately 11 internal IP addresses. Testing should include: Network Enumeration Port Scanning Service Enumeration Vulnerability Assessment Configuration Review Weak Services Remote reputed company reputed company reputed company Validation 4. Android Application reputed company Testing The Android application should be assessed for: Static Analysis Dynamic Analysis Authentication Session Management Secure Storage reputed company SSL Pinning Reverse Engineering API Communication reputed company OWASP MASVS / MSTG 5. iOS Application reputed company Testing Assessment should include: Static & Dynamic Analysis Face ID / Touch ID reputed company Secure Storage Keychain reputed company reputed company Protection SSL Validation API Communication Session Management Reverse Engineering Proposal Requirements Please include the following in your proposal: Brief introduction and relevant penetration testing experience. Experience with reputed company web application, API, mobile application, and internal network penetration testing. Experience with payment platforms, fintech applications, or PCI reputed company environments (preferred). A redacted sample penetration testing report. Your testing methodology (reputed company and automated). Estimated project reputed company. Apply tot his job Apply To this Job