Full Time

Senior Blockchain Security Auditor & Penetration Tester - Upwork - Anywhere

Upwork

Anywhere
Posted 10 days ago

We are seeking an experienced Blockchain Security Auditor / Penetration Tester to conduct a comprehensive security assessment of a proprietary distributed cryptographic security platform.

This engagement requires a senior-level security professional capable of performing deep manual review and adversarial penetration testing of a blockchain-integrated cryptographic system.

Scope of Work (High-Level)

The selected expert will perform a full-spectrum security assessment including:

• Smart Contract Security Review

Logic vulnerabilities

Access control issues

State manipulation risks

Transaction-level attacks

• Cryptographic Implementation Review

Secure key handling practices

Entropy and randomness validation

Hashing and derivation review

Secure memory handling practices

• Backend & API Penetration Testing

Authentication/authorization testing

Injection vulnerabilities

Session handling review

Rate limiting & abuse testing

• Infrastructure & Network Review

Node exposure analysis

Cloud configuration review

TLS and transport security validation

Misconfiguration detection

• Adversarial Simulation

Attempted unauthorized access

Privilege escalation attempts

Data extraction attempts

System resilience under attack

Deliverables

A comprehensive written audit report including:

Executive Summary

Detailed Technical Findings

Risk Severity Classification

Proof-of-Concept Evidence (if applicable)

Remediation Recommendations

Overall Security Posture Assessment

The report should be suitable for internal stakeholders and future enterprise review.

Requirements

Proven blockchain security audit experience

Prior smart contract audits (please share examples)

Demonstrated penetration testing background

Ability to produce structured professional audit reports

Senior-level experience only

Automated scan-only submissions will not be considered.

Confidentiality

Shortlisted candidates will be required to sign a Non-Disclosure Agreement before receiving arch