HighCraft.io is hiring a remote, part-time contract Application Security Engineer to manually assess a healthcare platform's web applications and APIs (initial 40-60 hour assessment, then ongoing reviews). The work centers on OWASP-based web/API security testing, validating vulnerabilities, and remediation guidance; Burp Suite is the key tool, with .NET, Azure, and healthcare experience as pluses.
HighCraft is looking for an Application Security Engineer to assess a healthcare platform for practitioners and patients. This is an ongoing remote, part-time contract, starting with a security assessment estimated at 40–60 hours. You will then provide security reviews and support as new features and integrations are developed. What you will do Perform manual security assessments of web applications and APIs. Identify and validate vulnerabilities in authentication, access controls, business logic and data handling. Review security-sensitive changes and third-party integrations. Document findings with clear evidence, reproduction steps and practical remediation guidance. Work with developers to resolve security issues and retest fixes. What we are looking for Hands-on experience independently testing authenticated web applications and APIs. Practical understanding of OWASP web and API security, authentication, authorization and multi-tenant applications. Ability to investigate and validate findings manually using HTTP requests and application behavior. Clear technical reporting and practical remediation guidance. Upper-Intermediate English (B2), with the ability to discuss findings with developers. Experience with Burp Suite, .NET, Azure or healthcare systems is a plus. To apply Please include: Your relevant web/API security testing experience. Your expected hourly rate. Your weekly availability and earliest start date. A brief, anonymized example of a security issue you identified and how you documented it.