I will perform web app pentesting and manual owasp top 10 security audit
About this Gig
Professional Web Application Penetration Testing
I'm an Information Security professional with 15+ years in the financial sector, specialized in offensive web security and GRC. I've completed 100% of the PortSwigger Web Security Academy labs (270/270, including Expert level) and hold CISM, CISA and CRISC certifications.
I test your web application the way a real attacker would safely, ethically and with your authorization and give you a report your developers can actually act on.
What I test for:
- OWASP Top 10 (injection, XSS, SSRF, access control, etc.)
- Authentication & session management flaws
- Business logic vulnerabilities (Premium)
- API security REST & GraphQL (Premium)
- Attack surface & parameter/endpoint discovery (Standard & Premium)
You always get:
- Findings ranked by severity (CVSS)
- Clear proof-of-concept for each issue
- Actionable recomendations to mitigate de vulnerability
️Testing is performed only on applications you own or are explicitly authorized to test. Written authorization is required before any work begins.
Age range:
Middle-aged
Education:
Higher education
Testing platform:
Website testing
Device:
PC
•
Linux
Language:
English
•
Spanish
My Portfolio
FAQ
Is this legal?
Yes. I only test applications you own or are authorized to test, and I require written authorization before starting.
Will testing break my site?
I use non-destructive techniques by default.
Which package do I need?
Basic for a quick health check, Standard for a real manual pentest, Premium if you have APIs, complex business logic or need an executive report.
Do you provide a retest?
Yes, retesting of fixes is included in the Premium package.

