Linux VPS Hardening & Security Audit

Employer
Dmytro
Project parameters
Type of cooperationOne-time project
SectionAdministration
Prepaymentwithout prepayment
Payment methodsCash, Bank transfer
Acceptance of requestsfrom today, 05:53 until Aug 26, 2026
Project description
Securing production servers is not a one-time task but a systematic process that requires methodical coverage of every attack surface. Our three Ubuntu 22.04 VPS servers host PHP applications, MySQL databases, and Nginx web serving — a standard LEMP stack, but one that carries significant risk when not properly hardened. We have been operating these servers with default or near-default security configurations, and an internal review flagged that we are exposed on multiple fronts: SSH is accessible on port 22 with password authentication, firewall rules are minimal, there is no automated intrusion prevention, and SSL certificates are renewed manually.
We need a DevOps engineer with proven experience in Linux production environments to conduct a thorough security audit and implement all hardening measures in a documented, reversible way. Every change must be tested for impact on running applications before being applied to production, and all modifications must be comprehensively documented so our team understands what was done and why. The engagement should conclude with a security report in PDF format summarising all findings, actions taken, and any residual risks, plus a working monitoring setup that alerts us if the security posture changes.
Scope of work:
— SSH hardening: key-only authentication, custom port, login restrictions, fail2ban
— UFW/iptables firewall rules with documented ruleset
— Fail2ban configuration for SSH, Nginx, and PHP-FPM
— Let's Encrypt SSL with automated certificate renewal
— Nginx hardening: security headers, TLS 1.2+ enforcement, HSTS, CSP
— MySQL security audit and hardening: user privileges, bind-address, encryption at rest
— Logwatch and email alerting for anomalous activity
— ClamAV antivirus and rootkit scanner setup
— Cron-based health monitoring with uptime alerts
Deliverables: all changes applied and documented, PDF security report with findings, monitoring dashboard (Netdata or equivalent).
We need a DevOps engineer with proven experience in Linux production environments to conduct a thorough security audit and implement all hardening measures in a documented, reversible way. Every change must be tested for impact on running applications before being applied to production, and all modifications must be comprehensively documented so our team understands what was done and why. The engagement should conclude with a security report in PDF format summarising all findings, actions taken, and any residual risks, plus a working monitoring setup that alerts us if the security posture changes.
Scope of work:
— SSH hardening: key-only authentication, custom port, login restrictions, fail2ban
— UFW/iptables firewall rules with documented ruleset
— Fail2ban configuration for SSH, Nginx, and PHP-FPM
— Let's Encrypt SSL with automated certificate renewal
— Nginx hardening: security headers, TLS 1.2+ enforcement, HSTS, CSP
— MySQL security audit and hardening: user privileges, bind-address, encryption at rest
— Logwatch and email alerting for anomalous activity
— ClamAV antivirus and rootkit scanner setup
— Cron-based health monitoring with uptime alerts
Deliverables: all changes applied and documented, PDF security report with findings, monitoring dashboard (Netdata or equivalent).