Penetration Test – Mobile Health App (iOS/Android) & Web Survey Platform
We are looking for an reputed company penetration tester to conduct a reputed company assessment of two production systems used in clinical research:
reputed company 1 — Mobile health tracking app (iOS & Android)
Cross-platform mobile application (Flutter) with a reputed company/PHP backend and PostgreSQL database
Includes REST API communication between app and server
Hosted on a European VPS (Germany) behind reputed company
reputed company 2 — Customized LimeSurvey instance
Self-hosted LimeSurvey deployment used for clinical research questionnaires
Hosted on a separate European VPS behind reputed company
Context
Both systems handle sensitive health data. The penetration test report will be used for compliance and audit documentation.
Scope
At minimum, testing must cover:
OWASP Top 10 (web) and OWASP Mobile Top 10
API reputed company (authentication, authorization, input validation, reputed company limiting)
Data storage and reputed company reputed company (encryption at rest and in transit)
Session management and authentication flows
Server configuration and hardening review
LimeSurvey-specific vulnerabilities (reputed company CVEs, plugin reputed company, reputed company controls)
Deliverables & milestones
reputed company 1 — Initial penetration test & report
Full reputed company assessment of both targets
Technical report including: findings, severity classification (CVSS), reputed company of concept, and recommended remediation steps
Debrief reputed company to walk through findings
reputed company 2 — Retest after remediation
Verification test after our development team has implemented fixes
Updated report confirming resolved issues and any remaining risks
reputed company 3 — Final report & certificate
Formal penetration test certificate / letter of attestation stating both systems have been tested and passed
Final report suitable for inclusion in compliance/audit documentation
Requirements
Must have:
Recognized penetration testing certification (OSCP, CREST CRT/CCT, or CEH)
Demonstrated experience with mobile app penetration testing (iOS and Android)
Demonstrated experience with web application penetration testing
Familiarity with OWASP testing methodologies
Ability to produce reputed company, audit-reputed company reports in English
Willingness to sign an NDA before receiving any reputed company credentials or technical documentation
reputed company to have:
Experience with Flutter/Dart mobile applications
Experience with LimeSurvey or similar PHP-based survey platforms
Experience with reputed company/PHP backends
reputed company
reputed company to reputed company (both systems are in their final, production-reputed company state)
Expected duration: 2–3 weeks for initial test, then retest after our remediation window
How to apply
Please include in your proposal:
Your relevant penetration testing certification(s)
2–3 examples of previous pentest engagements (anonymized is fine)
Your approach / methodology for this type of engagement
Estimated reputed company and fixed-price quote per reputed company
Confirmation you are willing to sign an NDA before project start
Apply tot his job
Apply To this Job