Back to positions

Security Penetration Tester for Healthcare SaaS Platform

Remote role Full-time Open position

We're building a multi-tenant healthcare SaaS platform (B2B) for appointment scheduling with an AI-powered voice agent. We're looking for a penetration tester to validate our security posture before onboarding our first pilot clinic. Tech stack: Cloudflare, Supabase, Clerk, Railway, Twilio The engagement is split into 3 phases: Phase 1 (pre-launch, priority): External attack surface review. Validate that all publicly exposed endpoints are properly secured before going live. Phase 2: Internal platform security. Tenant isolation, RBAC enforcement, role escalation, API authorization. Phase 3: AI/voice agent security. Prompt injection, call flow manipulation, abuse scenarios. Deliverables per phase: Written report with findings ranked by severity Proof of concept for each finding Remediation recommendations Retest of critical/high findings after our fixes Budget: $1,500 - $2,200 for the full 3-phase engagement. We know this is a startup budget. We're looking for someone early in their career or willing to work with an early-stage product, with the understanding that this becomes an ongoing paid relationship as we scale (periodic reassessments, new feature reviews). Methodology: We expect testing aligned with OWASP Top 10 / OWASP ASVS. If you follow a different framework, let us know in your proposal. Timeline: We're ready to start Phase 1 within 2-3 weeks of signing an NDA. In your proposal, please mention: Which of the technologies in our stack you've pentested before, and which would be new A brief example of a similar engagement (SaaS, multi-tenant, or healthcare) Your estimated timeline per phase Your availability Full architecture details, staging access, and role credentials will be shared after NDA signing. Languages: English or Romanian. Apply tot his job Apply To this Job

Further positions

Lead Mainframe Security Admin

Remote role Full-time

Staff Threat Intelligence Manager

Remote role Full-time

Software QA Engineer, Web and API Test Automation (Remote)

Remote role Full-time

Remote Senior QA Engineer

Remote role Full-time

Senior Threat Researcher, Ransomware Affiliates (US Remote, selected states)

Remote role Full-time

QA Engineer II - Remote. Evergreen

Remote role Full-time

API Automation Tester

Remote role Full-time

Automation Test Engineer - Remote

Remote role Full-time

Product Manager (ex-founder or ex-product engineer)

Remote role Full-time

Amazon Product Launch Lead (Fractional Contractor)

Remote role Full-time

Patient Care Coordinator II (Medical Assistant), Theragnostic Clinic – Full Time, Days (08HR)

Remote role Full-time

IP Facility Coder

Remote role Full-time

Help Desk Technician III / Remote (Salem, OR ), 6 months Contract

Remote role Full-time

Experienced Part-Time Customer Experience Representative – Remote Work from Home Opportunity at arenaflex

Remote role Full-time

Staff Software Engineer – Secondary Driving System

Remote role Full-time

Bilingual Customer Service Representative – Multilingual Remote Support Specialist for Global Customer Experience at arenaflex

Remote role Full-time

Associate Director, Field Sales - CPESG Enablon

Remote role Full-time

UI / UX Developer

Remote role Full-time

Remote Customer Advocate Phone Specialist – arenaflex – Arizona‑Based Inbound Healthcare Support & Service Excellence

Remote role Full-time

Data Entry Support Specialist - Geographic Information Systems (GIS) - Remote Contract Position

Remote role Full-time