
Closed
Posted
Paid on delivery
Objectives • Obtain an independent, manual penetration test to validate the security of the Selcomm platform and the isolation of customer environments. • Produce a formal report (with a redactable version) to evidence security assurance to enterprise customers. Environment (context) Solution: Selcomm billing platform — dedicated (non-cloud) software; virtualised Windows + Linux/Informix Hosting: Production: NTT data centre. Access/interfaces: Per-customer dedicated VLANs; site-to-site VPN; SSL/TLS and sFTP. No wireless Target list / scope (please price individually and combined) • A — External infrastructure: internet-facing VPN endpoint(s), any public web/portal, mail gateway. • B — Web application: authenticated & unauthenticated test of the Selcomm application / customer portal. • C — Internal / segmentation: validate isolation of the dedicated per-customer VLAN (no lateral access between clients). Rules of engagement • Select Software systems only; customer systems and the far side of any VPN are out of scope. • Written authorisation from hosting providers (NTT) obtained by Select Software before testing — advise required lead time. • Agreed test window, named emergency contacts and a stop procedure. Mutual NDA before detailed scoping. Provider requirements • CREST-accredited firm; assigned testers holding OSCP and/or CREST CRT (or higher). List tester certifications. • Australian-based delivery and data residency; current PI/public liability insurance; two comparable references. Deliverables & commercials • Report: executive summary, methodology, CVSS-rated findings with evidence, prioritised remediation; plus a retest and attestation letter. • Fixed-price quote per scope (A/B/C) and combined, incl. scoping call, testing, reporting and one retest; quote validity; earliest test window.
Project ID: 40638185
64 proposals
Remote project
Active 4 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
64 freelancers are bidding on average $3,781 AUD for this job

As an experienced network engineer and cybersecurity specialist for over a decade, I have helped both small businesses and enterprise companies plan, design, and implement their network infrastructures. I come to you with in-depth knowledge and practical expertise on network administration, routing, switching, VPNs, VOIP, Wireless Networks, Security Systems as well Virtualization and System Administration. I can affirm that as a freelance professional – you get my full attention with 24/7 availability and rapid response time. My previous clients can also attest to my steadfast commitment towards timely project delivery without compromising on quality. Moreover, the fact that I have worked with numerous vendors including Cisco, Checkpoint and NTT center among others adds value to me being your one-stop solution for this task. Let's take this chance to ensure your systems' are penetration resistant; having a CREST-accredited freelancer who has certifications such as OSCP/CRT is absolutely essential for such work. Thanks for considering my candidature; looking forward to discussing further with you
$4,000 AUD in 20 days
7.3
7.3

Hi there, I read through your Selcomm platform penetration test brief and I can see exactly what you're after — a rigorous, compliance-ready security validation across your external perimeter, web application, and the critical customer VLAN segmentation that keeps your tenants isolated. That's not just a scan-and-go job; it needs documented evidence your enterprise customers can take to their own auditors. What I'll deliver: ✅ Scope A — External infrastructure assessment covering your internet-facing VPN endpoints, any public portals, and the mail gateway, with CVSS-rated findings and full remediation guidance. ✅ Scope B — Authenticated and unauthenticated web application testing of the Selcomm customer portal, probing for OWASP Top 10 and business logic flaws that could expose tenant data. ✅ Scope C — Internal segmentation validation proving your per-customer VLANs are truly isolated — no lateral movement paths between clients, documented with traffic flow testing. ✅ Fixed-price proposal broken down per scope and as a combined package, including the scoping call, testing window, formal report with redactable version, retest, and attestation letter. Skills & credentials: ✅ Network security assessment — external/internal segmentation testing ✅ Web application penetration testing — authenticated and unauthenticated flows ✅ Firewall, VPN, and VLAN isolation validation ✅ CVSS scoring, remediation roadmapping, and executive-ready reporting
$3,000 AUD in 7 days
7.0
7.0

Your Selcomm platform sits behind NTT infrastructure with per-customer VLANs, but without a CREST-accredited pentest, you cannot prove isolation to enterprise buyers. One misconfigured VLAN rule exposes every customer's billing data. Quick questions - what is your current patch cadence for the Windows/Linux stack, and have you documented the VPN cipher suites in use? And does NTT require 14 or 30 days' notice for authorised testing? Here is the architectural approach: - PENETRATION TESTING: Execute OWASP Top 10 validation on the customer portal plus authenticated session hijacking attempts against SSL/TLS endpoints. - NETWORK SEGMENTATION: Deploy VLAN hopping techniques and ARP poisoning to verify no lateral movement between customer environments. - COMPLIANCE REPORTING: Deliver CVSS 3.1-rated findings with CREST attestation letter formatted for SOC2/ISO27001 auditor handoff. I've led 8 CREST-scoped assessments for SaaS platforms processing financial data, including one that uncovered a critical VLAN misconfiguration before production launch. Let's schedule a 20-minute scoping call to confirm NTT's authorisation timeline and lock your test window.
$3,600 AUD in 30 days
5.6
5.6

You're building Compliance Wired Network Testing, where the real delivery risk is usually in the workflow details, not just the feature list. I have handled similar systems where the important part was turning a broad brief into a reliable working version. My approach would be to first isolate the highest-risk workflow in the brief, then deliver a small working milestone that proves the architecture before expanding the rest. For this project, I would focus especially on: - core workflow risks and acceptance criteria - integration points and edge cases - milestone planning and handover clarity If helpful, I can outline the first milestone around the riskiest part of the build before we start. Best, Dr. Syafiq
$4,000 AUD in 21 days
5.8
5.8

Hello, I can deliver an independent manual penetration test covering your external infrastructure web application and VLAN segmentation. My approach includes active reconnaissance against your NTT data centre VPN endpoints and manual OWASP testing of the Selcomm portal. I can perform internal segmentation testing to verify complete isolation between customer VLANs and ensure no lateral movement is possible. My team holds CREST CRT and OSCP certifications with Australian delivery and data residency. Following testing I can deliver a full CVSS rated report an executive summary an attestation letter for enterprise customers and a complimentary retest. 1) What is the total number of public IP addresses and web application roles in scope? 2) What lead time does NTT data centre require for written authorization before testing? 3) What is your target start date for the testing window? Thanks, Bharat
$4,000 AUD in 7 days
5.4
5.4

I can help you obtain a defensible security assurance package that holds up to enterprise customer scrutiny, not just a test report. My approach prioritises efficient, outcome-driven testing. We start with a focused scoping call to align on your rules of engagement and NTT's authorisation lead time. Testing is then structured to directly address your key risks: external perimeter resilience (A), application-layer vulnerabilities (B), and the critical validation of per-customer VLAN isolation to prevent lateral movement (C). The final deliverable is tailored for its dual purpose: a technical report with prioritised, CVSS-rated remediation for your engineers, and a redactable executive version designed to evidence assurance to clients. We include a retest and attestation letter to close the loop, ensuring the final state is verified and documented.
$3,000 AUD in 7 days
5.5
5.5

✋ Hi There!!! ✋ The Goal of the project:- DELIVER AN INDEPENDENT, MANUAL AND COMPLIANCE-READY PENETRATION TEST OF SELCOMM WITH VERIFIED NETWORK SEGMENTATION AND ACTIONABLE SECURITY FINDINGS. 1. Test external infrastructure including VPN, web portals and mail gateway. 2. Perform authenticated and unauthenticated web application security testing. 3. Validate dedicated VLAN isolation and prevent lateral customer access. 4. Provide CVSS-rated findings, evidence, remediation priorities and executive reporting. 5. Include one retest and attestation letter with a redactable final report. Relevant security testing projects have involved network segmentation, Linux and Windows environments, VPNs, web applications, compliance reporting and remediation validation. <-- Questions --> 1. Which scopes A, B and C should be quoted individually? 2. What earliest approved testing window is available? Looking forward to chat with you for make a deal Best Regards Elisha Mariam!
$3,000 AUD in 11 days
4.6
4.6

HI, KINDLY READ THROUGH MY PROPOSAL I will deliver an independent, manual penetration test of the Selcomm platform focused on validating security controls and strict isolation of customer environments, followed by a formal report suitable for enterprise customers. MY APPROACH ✅ Phase 1: Scoping call, NDA, written authorisation coordination with NTT, and finalisation of test window + emergency contacts. ✅ Phase 2: Manual testing of the agreed scopes (external infrastructure, web application, and internal VLAN segmentation) under strict rules of engagement. ✅ Phase 3: Delivery of full report (executive summary, CVSS findings, evidence, prioritised remediation), redactable version, one retest and attestation letter. RELEVANT PROJECTS - Industrial and billing-platform penetration tests covering external, web-app and network-segmentation scopes. - Experience producing enterprise-ready reports with clear remediation guidance and retest attestation. DELIVERABLES - Full penetration test report + redactable version - Prioritised findings with CVSS ratings and evidence - One free retest and formal attestation letter QUESTIONS 1. Preferred earliest test window and required lead time for NTT authorisation? 2. Any existing documentation (architecture diagrams, VLAN scheme, VPN details) you can share under NDA? 3. Do you require the report in a specific template or branding? Ready to schedule the scoping call and proceed under mutual NDA as soon as you confirm.
$3,000 AUD in 3 days
5.4
5.4

Hi, Aashiq (Ash) here from Cape Town, South Africa. This project instantly caught my eye, so I had to reach out. I see you’re looking for an independent manual penetration test to validate the security of the Selcomm platform and ensure customer environment isolation. That's crucial for maintaining trust with your enterprise customers. I’ve helped businesses bolster their security posture through thorough penetration testing and detailed reporting. My experience includes working with dedicated software environments and producing actionable insights that lead to enhanced security measures. I’d be happy to share samples of successful projects upon request. Based on what you mentioned, here is how we would approach the project: - Conduct external infrastructure testing, including VPN endpoints and public portals. - Perform authenticated and unauthenticated tests on the Selcomm application. - Validate VLAN isolation to ensure no lateral access between clients. You can count on clear communication throughout the process, delivering a user-focused solution optimized for performance, using the latest security technologies. Best Regards, Aashiq
$4,500 AUD in 7 days
4.7
4.7

Hello! We can provide an independent security testing engagement for this platform and network scope. 1. Which scope should we price first: A, B, C, or the combined option? 2. Do you already have the written authorisation and preferred test window? — About us We are dZENcode – a full-cycle IT company for digital product development: from design and programming to integrations and post-release support. We build projects from scratch and also work on existing solutions that need further development, improvements, or technical support. You can find detailed information about our services and rates on our official website: https://dzencode.com. Please review it – after that, we can discuss the details and agree on the next step. ⚠️ After clarifying all details, we will define the scope, the suitable cooperation format – task-based, outsourcing, or outstaffing – and the final cost. Projects are guaranteed to reach release with us: • 10+ years providing IT services; • 90+ in-house specialists; • 250+ public reviews since 2015; • We support products under SLA after launch; • We work under NDA and a company contract!
$4,000 AUD in 7 days
4.3
4.3

Hello there, we are a team of senior Pen testing experts. I am interested in your project. Please, send me a message to discuss the work and finish in no time. Thanks Ashish and team.
$4,000 AUD in 7 days
3.8
3.8

Hi, This engagement should be delivered under a tightly controlled, evidence-led penetration-testing methodology with explicit authorization, agreed source IPs, emergency contacts, stop conditions, and customer/third-party exclusions. Scope A would cover externally exposed VPN, portal, TLS, mail, and sFTP surfaces. Scope B would test authenticated and unauthenticated application behavior, access controls, session handling, business logic, and tenant boundaries. Scope C would validate VLAN segmentation using approved test hosts and non-destructive lateral-movement checks, without touching customer systems or the VPN far side. Reporting will include methodology, reproducible evidence, CVSS ratings with business context, remediation priorities, an executive summary, a redactable customer version, one controlled retest, and an attestation letter. All working data and reports will remain in Australia under encrypted, access-controlled storage. Relevant examples can be shared privately where client permissions allow. Regards, Houssame
$4,000 AUD in 7 days
4.0
4.0

My name is Shujaat and I am a seasoned professional with a deep understanding of C# programming and Linux. Although my expertise lies in WordPress, Magento and Shopify development, my proficiency in these web environments, which possess parallels to your dedicated (non-cloud) software Platform - Selcomm, strengthens my ability to perforbrate your task effectively. My Magento experience particularly, aligns with your project's security needs as it demands substantial protocol management and protection. I habitually deliver precise and well-functioning websites- which I shall apply to validate the security of your platform. Not only am I familiar with VPN endpoints, public webs/portals, mail gateways; but also well-read on using SSL/TLS and sFTP for secure access. My expertise in testing, reporting, scoping makes me thoroughly CREST-accredited for this job. Being Australian-based ensures data residency and easy communication which is vital for project coordination. In addition to complying with necessary legal formalities like having the current PI/public liability insurance, I have two references that speak of my exceptional quality deliverables.
$4,000 AUD in 7 days
3.8
3.8

As an experienced PhD researcher and senior Machine Learning engineer, I possess a unique combination of technical knowledge and writing skills necessary for this compliance wired network testing project. My ten years' experience working with major organizations such as Unilever Pakistan and State Bank of Pakistan in developing AI-powered systems for surveillance and automated workflows ensures I can provide a distinctive perspective in the security assurance testing of your Selcomm platform. Apart from my technical skills, being a reputable academician means that my research approaches are thorough, well-documented, and adhere to the highest standards. I have written extensive academic and technical papers on complex topics like Artificial Intelligence, Data Science, and Predictive Analytics – which will be essential in crafting the comprehensive report you require as a deliverable. I am also proficient in using Linux – an environment prominently featured relevant to your project scope. My track record demonstrates my effectiveness at meeting deadlines, delivering high-quality work, and adhering to the highest level of professionalism. Given my technical skills, robust writing aptitude, and ability to think critically – my service would be instrumental in validating the security of the Selcomm platform and the isolation of customer environments for you. I am excited to bring this valuable skill set to your project.
$3,000 AUD in 15 days
2.6
2.6

Hello. I’d be glad to support Selcomm with an independent penetration testing engagement focused on validating platform security, customer environment isolation, and producing enterprise-ready security evidence. I understand this requires a structured security assessment rather than an automated scan. I can approach the engagement with a clear methodology covering external exposure, authenticated application testing, and internal segmentation validation while respecting the defined rules of engagement and scope boundaries. The assessment would include reviewing attack surfaces, testing authentication and authorization controls, identifying vulnerabilities, validating VLAN/customer isolation, and documenting findings with evidence, risk ratings, remediation guidance, and a clear executive summary suitable for enterprise stakeholders. I can provide a professional deliverable package including the full technical report, a redacted version where required, remediation recommendations, retest validation, and attestation documentation. Before starting, I would align on scope, access requirements, test windows, emergency contacts, NDA requirements, and any hosting-provider approvals needed to ensure testing is safe and controlled. Thanks.
$3,800 AUD in 25 days
2.3
2.3

Thank you for the detailed scope and governance requirements. We can support the independent manual penetration test for the Selcomm platform across the three stated areas: external infrastructure, web application, and internal segmentation/isolation validation. We will align the engagement to your rules of engagement, including written authorisation from NTT, agreed test windows, named emergency contacts, and stop procedures. We can also structure reporting to include an executive summary, methodology, CVSS-rated findings with evidence, prioritised remediation guidance, a retest, and an attestation letter, with a redactable version for enterprise assurance. We understand the need for CREST-accredited delivery, OSCP and/or CREST CRT-qualified testers, Australian-based execution and data residency, PI/public liability insurance, and comparable references. We can provide the required compliance evidence as part of formal scoping. A scoping call will allow us to confirm boundaries, confirm the earliest practical test window, and prepare a fixed-price quote for each scope item and the combined engagement, including one retest and reporting.
$4,400 AUD in 30 days
2.4
2.4

Hi, I’m a security-focused QA professional with 3+ years of experience in software testing, security validation, authentication, authorization, API testing, and access-control assessment. I also hold the relevant security certifications required for this engagement. I can conduct an independent manual assessment of the Selcomm platform across the proposed A, B, and C scopes, with particular focus on external attack surface, authenticated/unauthenticated application security, session management, authorization, and customer-environment/VLAN isolation. I’ll work strictly within the agreed Rules of Engagement, including written authorization, defined testing windows, emergency contacts, stop procedures, and NDA requirements. Deliverables will include: • Executive summary and methodology • Detailed findings with evidence and CVSS severity • Reproduction steps and remediation recommendations • Redactable report suitable for enterprise customers • Retesting of remediated findings • Final attestation letter I can provide tester certification details, relevant references, insurance information, and a fixed-price quote for A, B, C individually and as a combined engagement after reviewing the detailed scope. Available to discuss the scoping call and earliest testing window. Best regards, Zain Ul Hassan
$4,000 AUD in 7 days
1.9
1.9

Greetings! I can conduct a manual penetration test for your Selcomm platform with external infrastructure, web application, and internal segmentation testing, producing a formal report with evidence and remediation guidance. I am CREST-accredited with OSCP and CREST CRT certifications. I am Australian-based and can provide references and a fixed-price quote. Let me know your preferred test window and I will begin. Thanks, Revival
$3,000 AUD in 30 days
1.6
1.6

A manual penetration test for the Selcomm billing platform, focused strictly on software systems, can deliver exactly the security assurance enterprise customers require. I’ll validate external entry points (internet-facing VPN/web/mail gateways), perform authenticated and unauthenticated web application testing of the Selcomm customer portal, and verify per-customer VLAN segmentation to prevent lateral movement between dedicated environments. You’ll receive a formal, CREST-style report with an executive summary, clear methodology, and CVSS-rated findings backed by evidence. Remediation guidance will be prioritised, with a scheduled retest and a security attestation letter suitable for customer review. I’ll also ensure the scope respects your rules of engagement (customer systems and the far side of VPN out of scope) and supports NTT data-center delivery with the required authorisations, NDA, defined test window, and stop procedure, fiercely thorough, charm-in-command.
$3,000 AUD in 3 days
0.0
0.0

Hello, I have seen your are looking penetration testing expert working in Network Security, Compliance and Security Auditing I am having 7 years of experienced as penetration testing expert and I will work according to your features list. Please share more details of your project in chat. Looking forward to your response Thanks
$4,500 AUD in 7 days
0.0
0.0

Sydney, Australia
Payment method verified
Member since May 26, 2011
$250-750 AUD
$100-500 USD
$8-15 AUD / hour
$250-750 AUD
$250-750 AUD
$250-750 USD
₹600-1500 INR
$30-250 CAD
$10-30 USD
₹12500-37500 INR
$30-250 USD
$30-40 USD
$250-750 USD
₹75000-150000 INR
$25-50 CAD / hour
$30-250 USD
₹600-1500 INR
$250-750 CAD
$10-30 USD
$10-30 USD
$250-750 USD
$250-750 USD
$25-50 USD / hour
₹400-750 INR / hour
$10-13 USD / hour