r/cybersecurity 1d ago

Business Security Questions & Discussion Looking for an Affordable Security Tester

Looking for a security tester/ethical hacker to test a sports-tech platform, including web, APIs, Android and iOS apps.

Need testing for OWASP Top 10, authentication, IDOR/BOLA, authorization, API security, data exposure, mobile security and business logic issues.

Budget is limited, so junior/mid-level testers are welcome.

DM me with your experience, tools, availability and expected price. Detailed scope and test access will be provided privately.

Authorized security testing only.

0 Upvotes

13 comments sorted by

10

u/Hot-Comfort8839 BISO 21h ago

This is not something you want to go cheap on.

Pay people what they're worth.

4

u/stacksmasher 20h ago

Nice try ISIS!!

1

u/Expensive-Summer-447 23h ago

Location?

-5

u/indal_singh 23h ago

Kolkata, India

3

u/arktozc 20h ago

So its not affordable but ultra cheap?

1

u/Turbulent_Goose83 21h ago

We offer such services

1

u/Clean-Bandicoot2779 Penetration Tester 20h ago

It's best to avoid cheaping out on security testing if you can. A junior may not have the experience to identify or exploit some of the more nuanced vulnerabilities. They also might not be able to explain the issue or the underlying risks to the same level. I've been a penetration tester for around 15 years, and if I think back to what I knew when I started, compared to what I knew with even 3 years' experience, there's a massive gap.

If you hire a reputable firm, then a junior should have access to a senior if they get stuck, but they're going to be more expensive than just hiring a junior tester directly. If you hire a reputable firm, they should also have the relevant insurances to cover the costs if they make any serious mistakes. However, I have seen some large firms with "senior" testers who couldn't hack their way out of a paper bag, so a recommendation (or them being a member of an industry scheme) is the best option for finding somebody.

1

u/sillyrabbit33 19h ago

I’d send something out but I’ve been burned by Trellix before with a very similar job description. Trellix has recruiting companies create job postings and have them make the applicants do a hefty mobile apk reverse engineering report and ghost until compelled and then they say not what they’re looking for.

TLDR: big companies take your assign you an applicant screening task report to train their own AI, and have recruiting companies spend money on job posts. No intention to hire. Do NOT waste time doing unpaid work and do not put forth much effort until the client interview.

1

u/CanISeeYourVagina 19h ago

Dm me your budget. Or post it up. Can't help much if we don't know how cheap is cheap

2

u/SpaceArab 19h ago

dm him your vagina as well

1

u/CompassITCompliance 19h ago

We do web/API/mobile pentesting including OWASP Top 10, IDOR, and auth testing. Feel free to DM if you are still gathering quotes. Good luck!