Security Penetration Tester for Healthcare SaaS Platform

Remote Full-time
We're building a multi-tenant healthcare SaaS platform (B2B) for appointment scheduling with an AI-powered voice agent. We're looking for a penetration tester to validate our security posture before onboarding our first pilot clinic.

Tech stack: Cloudflare, Supabase, Clerk, Railway, Twilio

The engagement is split into 3 phases:

Phase 1 (pre-launch, priority): External attack surface review. Validate that all publicly exposed endpoints are properly secured before going live.

Phase 2: Internal platform security. Tenant isolation, RBAC enforcement, role escalation, API authorization.

Phase 3: AI/voice agent security. Prompt injection, call flow manipulation, abuse scenarios.

Deliverables per phase:

Written report with findings ranked by severity

Proof of concept for each finding

Remediation recommendations

Retest of critical/high findings after our fixes

Budget: $1,500 - $2,200 for the full 3-phase engagement. We know this is a startup budget. We're looking for someone early in their career or willing to work with an early-stage product, with the understanding that this becomes an ongoing paid relationship as we scale (periodic reassessments, new feature reviews).

Methodology: We expect testing aligned with OWASP Top 10 / OWASP ASVS. If you follow a different framework, let us know in your proposal.

Timeline: We're ready to start Phase 1 within 2-3 weeks of signing an NDA.

In your proposal, please mention:

Which of the technologies in our stack you've pentested before, and which would be new

A brief example of a similar engagement (SaaS, multi-tenant, or healthcare)

Your estimated timeline per phase

Your availability

Full architecture details, staging access, and role credentials will be shared after NDA signing.

Languages: English or Romanian.

Apply tot his job

Apply To this Job
Apply Now →

Similar Jobs

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote

USPS Office Helper

Remote

Coca Cola High-Paying Part Time Writing Jobs From Home

Remote

Remote Cybersecurity Management Officer

Remote

[Remote] Business Analyst

Remote

Head of Brand - Driving Business Growth through Innovative Brand Strategy and Leadership at Unlock

Remote

WCG Clinical Sr. Director, Product Management – IRB (Remote) in Princeton, New Jersey

Remote

Vaco – RPG Programming Support Engineer (Hybrid) – Fort Wayne, IN

Remote

**Experienced Remote 2nd Shift Customer Care Agent - Phone, Chat, and Email Support with a Leading Online Lighting Retailer**

Remote

ATT Customer Support Service Jobs – Work From Home

Remote

Hiring Now: Overnight Remote Acute Care Psychiatrist

Remote

[Remote/WFM] Remote Delta Air Lines Careers Entry Levell

Remote
← Back