I will perform manual security assessment of application and API
Senior Application Security and Penetration Testing Consultant
About this Gig
Professional Web Application and API Penetration Testing focused on real, exploitable risk not automated scanner output.
Testing covers authentication and session security, authorization and IDOR, injection flaws, XSS, SSRF, file upload issues, API weaknesses, security misconfiguration, and business logic vulnerabilities the flaws no scanner finds.
Every finding is manually validated, severity-rated with CVSS, and supported by evidence and reproduction steps.
Certifications:
- OSCP Offensive Security Certified Professional
- OSWE Offensive Security Web Expert
- eWPTXv2 Web App Penetration Tester eXtreme
- CRTP Certified Red Team Professional
- RTO Red Team Operator
You receive:
- Executive summary
- Scope and methodology
- Detailed findings with severity ratings
- Technical evidence and reproduction steps
- Remediation guidance
- Retesting where included in your package
Message me before ordering if your scope covers more than one application, many API endpoints, multiple user roles, cloud infrastructure, source code, or complex business workflows I will send a custom offer.
My Portfolio
FAQ
Do you use automated scanners or perform manual testing?
Testing is primarily manual and supported by appropriate security tools. Automated scanning may assist coverage, but findings are manually validated before being reported.
What do you need before starting?
I typically need the authorized target URL/API, testing credentials where applicable, API documentation such as Swagger/Postman collections, the number of user roles, and any scope restrictions.
Will I receive a professional penetration testing report?
Yes. Depending on the selected package, the report includes scope, methodology, validated vulnerabilities, severity ratings, evidence, reproduction steps, and remediation recommendations.
Do you provide retesting after vulnerabilities are fixed?
Yes. Retesting is included in the Premium package or can be added separately/custom-quoted for other engagements.
Can you test authenticated applications and APIs?
Yes. Authenticated testing is supported and is recommended for applications where important functionality is available only after login.
Can I use the report for compliance or customer security reviews?
The report can support internal remediation, vendor/customer security discussions, and security assurance activities. However, it should not be represented as a formal certification or compliance attestation unless specifically agreed.
How are findings prioritized?
Each finding gets a CVSS v3.1 base score with the full vector published, so you can verify it independently. Severity is then adjusted for your business context where CVSS under- or over-states real impact. Findings are ordered by what to fix first.

