
Closed
Posted
Paid on delivery
I want to put a fully-automated static security code-review workflow around our ASP.NET Framework and ASP.NET Core repositories. I have already settled on SonarQube as the analysis engine, and I need an Application Security / DevSecOps engineer who can design, build and document the entire pipeline. Here is what I am after: • End-to-end CI/CD integration – every commit and pull request should trigger a SonarQube scan and fail the build when high-severity issues appear. • Custom rule set – we do not yet have our own rules. I will rely on you to translate our security policies into SonarQube custom rules that focus on Authentication & Authorization, Data Validation & Sanitization, and Error Handling & Logging, plus any additional attack surface you consider relevant. • Secure baseline and tuning – thresholds, quality gates, and branch policies so developers get rapid feedback but aren’t flooded with noise. • Knowledge transfer – concise documentation and a walkthrough so my team understands how to maintain the rules and keep SonarQube healthy. Acceptance criteria 1. A pipeline build from a sample branch shows a green build with no critical findings, then deliberately injected flaws cause the build to fail. 2. At least five custom rules demonstrate detection of our most common mistakes. 3. Documentation covers installation, rule authoring, upgrades, and day-to-day use. If you have experience with Fortify or Checkmarx as well, let me know; cross-tool insights are always welcome, but SonarQube will be the implementation target. Please outline your approach, similar past work, and the estimated timeline to reach a production-ready setup.
Project ID: 40442209
13 proposals
Remote project
Active 17 hours ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
13 freelancers are bidding on average $69 USD for this job

Hello there, we are a team of senior Full Stack Web and Mobile App Developers, We can do this project in no time. Please, send me a message to discuss the work. Thanks Ashish Kumar.
$155 USD in 7 days
3.8
3.8

AOA, Are you looking for a thorough solution to implement an automated security code-review workflow for your ASP.NET repositories? I can definitely help you with that! I will design and build a CI/CD pipeline integrated with SonarQube that scans every commit and pull request, ensuring that builds fail on high-severity issues. I’ll translate your security policies into custom rules focusing on key areas like Authentication & Authorization and Data Validation, among others. Additionally, I will set up a secure baseline with the right quality gates and thresholds so your developers can get effective feedback without being overwhelmed. I will also provide concise documentation and a walkthrough for your team to maintain the system effortlessly. I have extensive experience in DevSecOps, and I’m confident I can deliver what you need. Let’s discuss further! Best Regards, Muhammad Shahzad
$10 USD in 3 days
1.1
1.1

I already see a clean way to execute this. I specialize in secure .NET application development and automated DevSecOps workflows, including static analysis pipelines around ASP.NET Framework codebases. I’ve helped teams bake security checks directly into their CI so issues are caught early without slowing developers down, which aligns closely with what you’re aiming to do here. You’re looking for a fully automated security code-review process for your ASP.NET Framework project—something that reliably flags vulnerabilities, fits your existing workflow, and produces clear, actionable findings instead of noisy reports. My focus would be on selecting the right static analysis tools for ASP.NET Framework, integrating them into your CI/CD, tuning the rules to your risk profile, and defining simple reporting so your team knows what to fix and when. Quick question before I suggest a concrete plan: are you already using any CI platform (e.g., Azure DevOps, GitHub Actions, Jenkins), or is that still open? Lets chat more about your project, worst case you walk away with a free strategy session Regards
$55 USD in 7 days
0.0
0.0

Hi there, I can help with end-to-end ci/cd integration. Here's how I'll approach it: 1) Review full source material for context 2) Translate with natural tone and accurate terminology 3) Proofread and deliver Timeline: 3 day(s) | Bid: $37 I'm happy to start with a quick test task so you can evaluate my work before committing. Let's discuss — I'm available right now.
$37 USD in 3 days
0.0
0.0

I am a Full-Stack Developer with over 3 years of experience in .NET Core and ASP.NET Web API. At the Ministry of Security, I have optimized GitLab CI/CD pipelines for mission-critical infrastructure serving 50,000+ users. My Approach: End-to-End Integration: Seamless CI/CD setup with Quality Gates to fail builds on high-severity issues. Custom Rules: I will define at least 5 rules focused on Auth, Data Sanitization, and Error Handling using SOLID and Clean Architecture standards. Knowledge Transfer: Complete documentation on installation, rule authoring, and maintenance. Technical Question: Are your repositories hosted on GitLab, Azure DevOps, or an on-premise server? This is vital for the runner and SonarQube integration.
$100 USD in 7 days
0.0
0.0

Hi, Resonite Technologies has strong Application Security and DevSecOps experience with SonarQube, ASP.NET Framework/Core, C#, Roslyn analyzers, CI/CD security automation, and SAST pipeline tuning. Our approach: • Set up SonarQube scans for every commit and pull request • Integrate with GitHub Actions, Azure DevOps, or Jenkins • Configure quality gates to fail builds on high/critical findings • Build at least 5 custom rules for auth/authz, validation, sanitization, logging, error handling, and ASP.NET security anti-patterns • Tune thresholds and baseline existing issues to reduce false positives • Demonstrate green build vs injected flaw build failure • Document installation, rule authoring, upgrades, triage, and maintenance We can also add optional insights from Fortify/Checkmarx-style rule design where useful, while keeping SonarQube as the main implementation target. Deliverables: ✔ Production-ready SonarQube CI/CD workflow ✔ Custom ASP.NET security rules ✔ Quality gates and branch policies ✔ Baseline suppression strategy ✔ Acceptance demo ✔ Documentation and KT session Estimated timeline: 2–4 weeks depending on repositories, CI platform, and rule complexity. Regards, Karthik B Resonite Technologies
$100 USD in 7 days
0.0
0.0

Hello, I can implement a fully automated SonarQube security review pipeline for your ASP.NET Framework and ASP.NET Core repositories with CI/CD integration, automated PR scanning, and build failure on Critical/High severity issues. The setup will include custom security rules for Authentication, Authorization, Validation, Sanitization, and secure Logging practices, along with quality gates and branch policy configuration to reduce false positives. I will also provide testing with intentionally injected vulnerabilities, documentation, and a walkthrough session for your team. I have additional exposure to Fortify and Checkmarx security workflows as well. Best regards Hasnain
$50 USD in 7 days
0.0
0.0

Hi - I can take a focused first pass today. I’ll map the ASP.NET/SonarQube setup, draft the first CI scan path, and provide the exact quality-gate/rule steps to implement next. Bid: $10 for the first pass. After award, send the repo structure, CI provider, and any current SonarQube notes.
$10 USD in 1 day
0.0
0.0

Hi, Only 10 bids on this — I want to be one of the serious ones. I can build this entire SonarQube CI/CD security pipeline for your ASP.NET Framework and ASP.NET Core repos: - CI/CD integration: every commit and PR triggers a SonarQube scan, build fails on high-severity findings - Custom rule set covering Authentication/Authorization, Data Validation/Sanitization, and Error Handling/Logging - Quality gates and thresholds tuned to your codebase - Full documentation for your team My background is ASP.NET Core with 1.7+ years in production: JWT auth, RBAC, global exception middleware, structured logging. I understand the .NET API attack surface from the inside, which means my security rules will be meaningful and targeted, not generic. Also experienced with GitHub Actions and CI/CD-ready API design. What CI/CD platform: GitHub Actions, Azure DevOps, or Jenkins?
$55 USD in 7 days
0.0
0.0

Hello, I have 8+ years of experience with ASP.NET Framework, ASP.NET Core, CI/CD pipelines, and secure enterprise application development. I can build a production-ready SonarQube security review workflow with automated scanning, quality gates, and custom security rules. My approach: • Integrate SonarQube into GitHub Actions/Azure DevOps/Jenkins for commit and PR scanning • Configure quality gates to fail builds on critical/high-severity vulnerabilities • Create custom rules for Authentication/Authorization, Input Validation, Exception Handling, Logging, SQL Injection, and insecure API usage • Tune thresholds and branch policies to reduce false positives and developer noise • Validate the setup using intentionally vulnerable sample code to confirm build-failure behavior • Provide documentation covering installation, rule authoring, upgrades, and maintenance I also have experience with secure .NET coding practices, OWASP guidelines, API security, and static analysis workflows. Familiar with Fortify/Checkmarx concepts as well. Estimated timeline: • CI/CD + SonarQube setup: 1–2 days • Custom rules and tuning: 2–3 days • Documentation and walkthrough: 1 day Ready to start immediately. Thanks
$90 USD in 7 days
0.0
0.0

Rawalpindi, Pakistan
Payment method verified
Member since May 14, 2026
$10-200 USD
min ₹2500 INR / hour
$10-100 USD
$30-250 USD
£5-10 GBP / hour
₹750-1250 INR / hour
$10-50 USD
$30-250 AUD
$300-350 USD
$250-750 USD
₹400-750 INR / hour
₹400-750 INR / hour
$250-750 USD
₹750-1250 INR / hour
$15-25 USD / hour
$10-30 CAD
$50-100 AUD
£10-15 GBP / hour
$30-250 USD
$30-250 USD