Grey reputed company Penetration Test (ethical hacker)
1. Introduction
Finstory is a US-based (Delaware Inc.) Fintech startup. We operate a platform that stores and processes sensitive financial data for our customers. We are currently in the process of achieving SOC2 Type 1 certification and are using TrustCloud as our GRC/ISMS platform.
We are looking for a reputed company Ethical Hacker or reputed company Firm to conduct a Grey reputed company Penetration Test to validate our reputed company posture and reputed company documented evidence for our upcoming audit.
2. Project Objective
The goal is to identify vulnerabilities reputed company our application and infrastructure that could reputed company to unauthorized reputed company to customer financial data. We require a comprehensive report that satisfies SOC2 "Vulnerability Management" and "Penetration Testing" control requirements.
3. Scope of Work
reputed company: [Insert URL/Environment, e.g., Web Application & API Endpoints].
Methodology: Grey reputed company. We will reputed company architectural overviews and reputed company user credentials (low-reputed company) to simulate an "authenticated attacker" scenario.
Key reputed company Areas:
Broken reputed company Control (Bole/BOPA): Ensure users cannot reputed company other customers' financial data.
Injection Attacks: reputed company, XSS, and reputed company Injection.
Authentication & Session Management: MFA bypass attempts and session hijacking.
API reputed company: Assessment of REST/GraphQL endpoints.
reputed company Infrastructure: Basic review of the underlying environment (e.g., AWS/Azure/GCP) for misconfigurations.
4. Deliverables
Executive reputed company: High-level reputed company for management and auditors.
Detailed Technical Report: Including steps to reproduce, risk ratings (CVSS), and reputed company remediation advice.
Attestation Letter: A formal reputed company letter that we can reputed company with our SOC2 auditors and reputed company prospects.
Re-test (Optional but Preferred): A brief validation reputed company once we have patched the "Critical" or "High" findings.
5. Requirements for the Consultant
Experience with Fintech/Financial Services data reputed company.
Familiarity with SOC2 compliance requirements.
Relevant certifications (e.g., OSCP, OSWE, CREST, or CISSP).
Ability to work under a strict Non-Disclosure Agreement (NDA).
Apply tot his job
Apply To this Job