I will perform professional pentest and vulnerability assessment
Cybersecurity Consultant
About this Gig
I'm a Cybersecurity Consultant with hands-on experience in penetration testing. I hold industry-recognized certifications including OSCP, OSEP, BSCP, and CREST CRT. (Happy to provide verification for certifications mentioned)
What I offer:
- Web Application Penetration Testing (OWASP Top 10: SQLi, XSS, auth flaws, business logic issues)
- Network Security Assessments (vulnerabilities, misconfigurations, exposed services)
- Detailed Report with PoC steps, risk ratings, and remediation guidance
Why work with me:
- Real-world experience testing critical information infrastructure (CII) and enterprise environments
- Clear, risk-based reports with reproducible Proof-of-Concept steps and remediation guidance
- Collaborative approach I work with your team to validate fixes and retest vulnerabilities
Message me before ordering if you'd like to discuss scope!
FAQ
What will I receive at the end of the engagement?
You'll receive a detailed report including identified vulnerabilities, risk ratings, reproducible Proof-of-Concept (PoC) steps, and remediation recommendations tailored to your environment.
Do you offer a retest after I fix the vulnerabilities?
Yes! Once you've applied fixes based on the recommendations in my report, I'll retest the previously identified vulnerabilities to confirm they've been properly remediated. This helps ensure your fixes actually close the security gaps before you consider the engagement complete.
Do I need to provide anything before we start?
Yes! Fortesting, I'll need the target URL(s), and scope details (e.g., specific pages, features, or IPs to test). For authenticated testing, I'll also need test account credentials.
Is this testing safe for my production environment?
I recommend testing on a staging/UAT environment where possible to avoid any risk of downtime. If testing must be done on production, I'll take precautions to minimize disruption, but some risk is inherent to live-environment testing.
What tools/methodology do you use?
I use industry-standard tools such as Burp Suite, Nessus, and the Kali Linux toolset, following recognized methodologies (e.g., OWASP Testing Guide) to ensure comprehensive results.
Do you sign an NDA or have a formal authorization process?
Yes! I'm happy to sign your company's NDA if you have one. I also require a written authorization letter confirming you own or have permission to test the target systems before testing begins.
