> DOUHighCraft.io
Security Engineer
format:Remotetype:Part-time
penetration testingapplication securityapi testingowasp asvs
burp suite.netazure
> full description
HighCraft is looking for an Application Security Engineer to assess a healthcare platform for practitioners and patients.
This is an ongoing remote, part-time contract, starting with a security assessment estimated at 40–60 hours. You will then provide security reviews and support as new features and integrations are developed.
What you will do
- Perform manual security assessments of web applications and APIs.
- Identify and validate vulnerabilities in authentication, access controls, business logic and data handling.
- Review security-sensitive changes and third-party integrations.
- Document findings with clear evidence, reproduction steps and practical remediation guidance.
- Work with developers to resolve security issues and retest fixes.
What we are looking for
- Hands-on experience independently testing authenticated web applications and APIs.
- Practical understanding of OWASP web and API security, authentication, authorization and multi-tenant applications.
- Ability to investigate and validate findings manually using HTTP requests and application behavior.
- Clear technical reporting and practical remediation guidance.
- Upper-Intermediate English (B2), with the ability to discuss findings with developers.
Experience with Burp Suite, .NET, Azure or healthcare systems is a plus.
To apply
Please include:
- Your relevant web/API security testing experience.
- Your expected hourly rate.
- Your weekly availability and earliest start date.
- A brief, anonymized example of a security issue you identified and how you documented it.