Web Application Security Assessment & Compliance Expert Needed

Remote, USA Full-time
We are seeking an experienced Web Application Security & Compliance Specialist to conduct a comprehensive security assessment of our web application environment. The engagement requires both technical security testing and compliance alignment with globally recognized cybersecurity and data protection frameworks. This role is critical and OWASP Top 10 coverage is a mandatory baseline. ________________________________________ Scope of Work The selected consultant will be responsible for the following: 1. Web Application Security Assessment •Perform a full security review aligned with OWASP Top 10 (mandatory) • Identify vulnerabilities including (but not limited to): o Injection attacks (SQL, XSS, command injection) o Broken authentication and authorization o Session management flaws o Security misconfigurations o Insecure APIs o Sensitive data exposure • Conduct both automated and manual testing • Validate findings with proof-of-concept where applicable ________________________________________ 2. Standards & Framework Alignment Assess and map the application and supporting processes against: • ISO/IEC o Access control o Logging & monitoring o Secure configuration o Risk management controls • NIST Cybersecurity Framework o Identify o Protect o Detect o Respond o Recover • Data Protection & Privacy Regulations o GDPR (EU) o Kenya Data Protection Act o India IT Act & DPDP Act o Review consent, data retention, access control, and breach readiness ________________________________________ 3. Deliverables The consultant must provide: • Detailed security assessment report • Vulnerability severity classification (Critical / High / Medium / Low) • Clear remediation recommendations • Compliance gap analysis against each framework • Executive-ready summary for management / audit • Optional re-test after remediation (preferred) ________________________________________ Required Skills & Experience • Proven experience in web application penetration testing • Strong hands-on knowledge of OWASP Top 10 • Demonstrated experience with ISO audits or implementations • Working knowledge of NIST Cybersecurity Framework • Experience with PCI-DSS assessments (where applicable) • Solid understanding of GDPR and regional data protection laws • Familiarity with modern web architectures (APIs, cloud, SPA frameworks) • Ability to clearly document findings for both technical and non-technical stakeholders ________________________________________ Nice to Have • Relevant certifications (OSCP, CEH, CISSP, CISA, ISO 27001 LA/LI) • Experience securing ERP, finance, payroll, or compliance-heavy systems • Cloud security experience (Azure / AWS / GCP) ________________________________________ Engagement Details • Project Type: Security assessment & compliance review • Duration: Short-term / milestone-based • Budget: Open (please propose based on scope) • Start: Immediate Apply tot his job
Apply Now

Similar Jobs

[Remote] Assistant Director, Cyber GRC

Remote, USA Full-time

Cybersecurity Engineer III

Remote, USA Full-time

Cybersecurity Engineer II

Remote, USA Full-time

Forensic and Incident Response Engineer

Remote, USA Full-time

Cybersecurity Incident Response Manager

Remote, USA Full-time

Cybersecurity Incident Handler San Antonio, TX

Remote, USA Full-time

Cybersecurity Practice Manager - Network and Edge Security | Remote, USA

Remote, USA Full-time

Manager Cybersecurity (Remote Available)

Remote, USA Full-time

Deputy Director of Cybersecurity Operations

Remote, USA Full-time

Aspiring Mammoth

Remote, USA Full-time

**Experienced Online Chat Support Representative – Automotive Industry Expertise**

Remote, USA Full-time

Lecturers, Part-Time, Temporary, Online Learning

Remote, USA Full-time

Experienced Healthcare Customer Service Representative for Remote Government Client Support

Remote, USA Full-time

Experienced Homesite Customer Service Representative for Remote Insurance Support and Client Relationship Management

Remote, USA Full-time

Entry-Level Data Entry Clerk for Remote Full-Time Position with Opportunities for Growth and Professional Development at blithequark

Remote, USA Full-time

Digital Project Manager

Remote, USA Full-time

Experienced Manager, Customer Insights and Retail Media Network Development - Driving Business Growth through Data-Driven Strategies and Client Partnerships at blithequark

Remote, USA Full-time

Salesforce Adminstrator

Remote, USA Full-time

Lead Analyst – SAP Master Data Governance & Management – Remote Opportunity with a Global Leader in Innovative Solutions

Remote, USA Full-time

Senior Platform Engineer

Remote, USA Full-time
Back to Home