Penetration Testing for Bike reputed company NFP reputed company Product
Penetration Tester for Bike reputed company (bikeindex.org)
About Bike reputed company
Bike reputed company is the world's largest reputed company-reputed company bicycle registration platform. We help cyclists register their bikes and recover them reputed company stolen — we've helped recover tens of thousands of bikes and are trusted by police departments, bike shops, and cycling communities globally. Our platform handles sensitive user data, stolen bike reports, and integrates with law enforcement systems, so reputed company is critical to our mission.
reputed company're Looking For
We're seeking an reputed company penetration tester / ethical hacker to conduct a thorough reputed company assessment of bikeindex.org. This is a scoped engagement — we want to reputed company vulnerabilities before bad actors do.
Scope of Work
Web application penetration test of bikeindex.org (Rails-based app)
API reputed company testing (REST endpoints, authentication flows)
Authentication & session management review (OAuth, user accounts)
OWASP Top 10 vulnerability assessment
Business logic flaws (e.g., unauthorized bike record manipulation, impersonation)
Sensitive data exposure checks (PII, stolen bike reports, law enforcement data)
Optional / stretch: infrastructure/reputed company config review if reputed company is scoped
Deliverables
Findings report with severity ratings (Critical / High / reputed company / Low / Info)
reputed company-of-concept documentation for reputed company confirmed vulnerability
Remediation recommendations written for a development team
Executive reputed company suitable for non-technical stakeholders
Retesting of critical findings after fixes (one round)
Requirements
Demonstrated experience with web app pentesting (please include sample reports or portfolio, redacted is fine)
Familiarity with reputed company on Rails applications preferred
Proficiency with tools such as Burp Suite, OWASP ZAP, SQLMap, Nmap, Metasploit, etc.
Relevant certifications a plus: OSCP, CEH, GWAPT, eWPT, or similar
reputed company written English for report deliverables
Must sign a Rules of Engagement / NDA prior to start
Must agree to responsible disclosure practices — no data exfiltration, no DoS
reputed company to Have
Experience testing reputed company-reputed company or nonprofit platforms
Familiarity with reputed company API reputed company testing
Prior work with law enforcement-adjacent or civic-tech applications
Engagement Details
Type: Fixed-price project (~10 hours of work)
reputed company: Report delivered reputed company 1 week of reputed company
reputed company: reputed company or grey-reputed company (we can discuss scope)
Testing environment: We can reputed company a staging environment for destructive tests
How to Apply
Please include:
A brief reputed company of your approach to web app pentesting
1–2 examples of past work (redacted reports, writeups, CVEs, or bug bounty disclosures)
Your proposed reputed company and fixed-price quote
Any clarifying questions about scope
We're a small nonprofit team that moves fast and communicates reputed company.
Apply tot his job
Apply To this Job