Hire the Best Information Security Analysts

Clients rate our Information Security Analysts
Rating is 4.7 out of 5.
4.7/5
Based on 1,807 client reviews
Safi Ullah K.

Peshawar, Pakistan

$25/hr
5.0
4 jobs

Stop breaches before they happen. I am a Senior Cybersecurity Architect and Engineer specializing in building resilient defensive infrastructures, performing deep-dive offensive testing, and pioneering secure AI deployments. With 5+ years of experience bridging Red Teaming and Blue Teaming, I ensure your data remains untouchable. Whether you need a modern enterprise SOC built from scratch or a rigorous vulnerability assessment for your cloud-native pipelines, I deliver tailored, production-grade protection. Core Areas of Expertise SOC Architecture & Ops: Complete design, implementation, and optimization of your SOC. I specialize in SIEM/SOAR integration (Splunk, Microsoft Sentinel, ELK), automated EDR deployment, and building actionable Incident Response Playbooks. AI Agents Security & LLM Hardening: As autonomous workflows scale, I provide specialized AI Agents Security frameworks. I mitigate risks unique to intelligent systems, including prompt injection, data exfiltration, and insecure output handling. Compliance & Governance: Aligning your business with world-class security standards. I systematically prepare your infrastructure to satisfy strict ISO 27001, SOC2, and HIPAA compliance frameworks, turning audits into a competitive advantage. Why Work With Me? Strategic SOC Engineering: I don't just monitor alerts; I build the entire SOC data pipeline to minimize your Mean Time to Detect (MTTD) and Respond (MTTR). Cutting-Edge AI Agents Security: I implement rigorous guardrails and adversarial testing to ensure your production AI Agents Security remains completely uncompromised. Audit-Ready ISO 27001 Execution: I bridge the gap between complex technical controls and regulatory compliance, ensuring your ISO 27001 implementation is seamless and stress-free. Proactive SOC Optimization: By leveraging advanced SOC telemetry and threat intelligence, I engineer defenses that evolve faster than modern threat actors. End-to-End AI Agents Security: I provide comprehensive code reviews, data flow isolation, and API protection strictly tailored for complex AI Agents Security architectures. 🛠️ Technical Stack & Tools Offensive Security: Web App, Network, and API Penetration Testing (OWASP Top 10 focus). Tools: Kali Linux, Burp Suite, Metasploit, Wireshark, Nessus. Cloud Security: AWS Security Hub, Azure Defender, Google Cloud Armor, Infrastructure-as-Code (IaC) scanning, and Kubernetes/Docker hardening. Defensive Operations: CrowdStrike, Palo Alto Networks, Wazuh, Microsoft Sentinel. I don’t just hand over a generic PDF of vulnerabilities; I provide a concrete roadmap for remediation and hands-on support to patch the gaps. Let’s secure your perimeter, ace your ISO 27001 audit, and deploy your autonomous AI systems safely.

  • Information Security
  • Threat Detection
  • Cloud Security
  • Secure SDLC
  • Security Operation Center
  • Application Security
  • Penetration Testing
  • Bug Tracking & Reports
  • Vulnerability Assessment
MD JAHANGIR A.

Dhaka, Bangladesh

$12/hr
4.7
73 jobs

Hello, and welcome to my Upwork profile! I'm an experienced offensive cybersecurity expert with over 12 years of experience in penetration testing and cybersecurity management. My expertise lies in identifying and exploiting vulnerabilities in complex systems and networks, as well as designing and implementing security solutions that mitigate these risks. I'm well-versed in a wide range of offensive cybersecurity techniques, including: Network and Web Application Penetration Testing Mobile Application Penetration Testing Vulnerability Assessments Red Teaming Exercise Social Engineering Physical Security Testing Wireless Security Testing Cloud Security Testing API Security Testing In addition to my technical skills, I also have extensive experience managing cybersecurity teams and projects. I'm well-versed in industry standards such as ISO 27001, NIST, and PCI-DSS, and I can provide guidance on compliance requirements as well as best practices for cybersecurity management. I'm a self-motivated and detail-oriented professional who takes pride in delivering high-quality results on every project I work on. I'm also a clear and effective communicator with experience presenting technical findings to both technical and non-technical audiences. If you're looking for an experienced offensive cybersecurity expert to help secure your organization's assets, look no further. I'm confident in my ability to provide top-notch cybersecurity services that will help you identify and mitigate the risks facing your organization. Contact me today to learn more about how I can help!

  • Penetration Testing
  • Digital Forensics
  • Security Assessment & Testing
  • Firewall
  • Information Security Consultation
  • Vulnerability Assessment
  • Network Security
  • Elearning
  • Security Analysis
  • Articulate Storyline
  • Cloud Security Framework
  • IT Service Management
  • Security Infrastructure
  • Information Security Audit
Md N.

Comilla, Bangladesh

$12/hr
4.9
107 jobs

✅Malware removal from ⦿ Wordpress ⦿ Shopify ⦿ PrestaShop ⦿ Wix ⦿ Magento ⦿ Squarespace ⦿ PHP ✅WordPress Design: ⦿ Wordpress Expert ⦿ Wordpress Designer ⦿ Wordpress Elementor Pro ⦿ Website Optimizaton ⦿ CMS ⦿ Shopify ⦿ Customer Wordpress Website ⦿ Ecommerce ⦿ Divi Theme ⦿ Premium Plugins ✅Fix Google Ads Disapproved for Malicious Software ✅Penetration testing and Vulnerability Assessment. ✅Cloudflare Setup and DDoS Security. ✅ Wordpress Migration I'm a full-time freelancer as a Cyber Security Specialist, Malware Analyst, and Penetration Tester. I can remove malware, delete viruses, do penetration tests, do vulnerability assessments, and remove malicious (Plugins, Themes, and Software). remove the Google warning from your website. I've 5 years of experience as a website security specialist in Ignite tech solutions. Also, I'm a freelancer on Fiverr and Upwork. I've got a level two badge on Fiverr. ✅Service I will provide: 0) Penetration testing and Vulnerability Assessment. 1) WordPress Malware Removal and Security. 2) Shopify Malware Removal and Security. 3) Cloudflare Setup and DDoS Security. 4) Website Backup and Migration from old host/server/domain to new host/server/domain. 5) Google Ads Disapproved for malicious software. ✅Wordpress service: ⦿Remove Malware. ⦿Penetration Testing / Vulnerability Testing ⦿Wordpress Malware removal. ⦿Website Security. ⦿Clean Server / Server Maintenence / cPanel / WHM Panel ⦿Delete Virus / Virus Removal ⦿Remove Google blacklist/ Red screen. ⦿Remove Japanese or Chinese search results. ⦿Security patch installation ⦿Remove malware ⦿Fix the hosting site suspended ⦿Delete junk or virus script ⦿Add SSL Certificate / Setup Cloudflare ⦿Database error / Remove malware from the database ⦿Fix emails problem / Emails not coming ⦿Spam emails coming / Unwanted emails coming ⦿Critical and Fatal Error ⦿Remove the PHP backdoor ⦿Blacklist Removal, McAfee blacklist ⦿WordPress version update ⦿Install Cloudflare SSL ⦿Fix Login Issue / Broken dashboard ⦿Remove website redirect URL / Fix redirecting issues ⦿Internal 404 or 505 Error ⦿Remove the PHP shell ⦿Unwanted / Bulk email coming ⦿White/Empty Screen ⦿Error Establishing Database Connection ⦿Theme/Plugin Broken ⦿Improve website security ⦿Corrupt .htaccess file ⦿Solve PHP memory limit ⦿Core files issues ⦿Upload size problem ⦿Forgot Username/password ✅Backup and Migration Service: I will backup WordPress sites, duplicate, clone, copy, host migration, WordPress migration, Transfer, move websites, and domain migration any WordPress website for personal and business. ⦿Database Backup and Transfer ⦿Change primary addon domain/domain/subdomain ⦿Move WP from root domain/subdomain/addon domain to main ⦿Old host to another new host ⦿Clone and duplicate the WordPress website ⦿Update WordPress version/theme/plugin ✅Penetration Test and Vulnerability Service: I will perform penetration and vulnerability tests with the VAPT report ⦿According to a security report, about 90% of websites are vulnerable to malicious attacks. ⦿A website is an essential part of your Business. The thing is how secure is your website? ⦿I will perform an advanced deep scan and penetration testing on your web application with a professional report which includes all vulnerabilities. ⦿Let me help you in making your website secure against hackers: ⦿Vulnerability Checklist: ⦿ Web attack vulnerabilities.[Input Validation, Code Execution, Bypass Authentication, SQL Injection, CSRF, LFI, Cross-site Scripting, Uploader Issues, Remote Code Execution, Buffer Overflow, Session Hijacking] ⦿ Information Gathering [Server Info, Open Port] ⦿ Authorization Testing [HTTP Header] ⦿ Data Validation Testing [XSS] ⦿ Denial of Service Testing [DDos Test] ⦿ Security Testing ✅Cloudflare service: ⦿Fix A Record, CNAME Record ⦿Fix NS, MX record ⦿Cloudflare setup ⦿Email Routing ⦿Configure Emails ⦿Add SSL ⦿Cloudflare SSL ⦿Cloudflare error fix ⦿Free SSL ⦿DDOS protection from Hackers ⦿setup DNS ⦿Website Security ⦿Enable green padlock ⦿Improve Website speed ⦿Setup firewall Errors I will fix: Mail Delivery Issue 500 internal server error 502 bad gateway or error 504 gateway timeout 503 service is temporarily unavailable 520: web server returns an unknown error 521 web server is down 522: connection timed out 524: a timeout occurred 525: SSL handshake failed 526: invalid SSL certificate Cloudflare Benefits: ⦿Minification ⦿HTTP/2 Protocol ⦿DNS Security ⦿Cloud WAF ⦿Image Optimization ⦿Browser Caching ⦿WebSockets ⦿Load Balancing ⦿Optimized Network Routing ✅I can work with any CMS like: ⦿Magento, OpenCart, Drupal, Joomla, Prestashop, WordPress, SHOPIFY, LARAVEL, SQUARESPACE, WIX, WOOCOMMERCE, BigCommerce, Blogger, Hubspot CMS, Typo3, Weebly, Webflow, CMS Hub. ✅Why Me: ⦿I will provide a Professional Report ⦿Give you technical support ⦿Quality Work

  • Information Security
  • Malware Removal
  • WordPress Website Design
  • Penetration Testing
  • Vulnerability Assessment
  • Network Security
  • CMS Development
  • WordPress Malware Removal
  • Virus Removal
  • Cloudflare
  • SSL
  • Ethical Hacking
  • cPanel
  • WordPress Bug Fix
  • WordPress Security
Vitalii R.

Kyiv, Ukraine

$25/hr
5.0
2 jobs

Hi! I'm a Cybersecurity Engineer with hands-on experience in vulnerability assessments, cloud security reviews, and compliance evidence gathering. My main responcibility is to make clients understand and improve their security posture. I work across the full assessment lifecycle: scanning exposed services, reviewing configurations, validating findings, and delivering clear, actionable remediation reports that your clients can actually use. I'm comfortable operating under NDA and have supported multiple audit during my experience in fintech sector, so I understand the discipline and documentation standards that consulting engagements demand. What I can do: - Conduct vulnerability assessments using Burpsuite Scanner, OpenVAS, Nmap, Acunetix from scoping through validated findings - Review exposed services, firewall configurations, and network infrastructure for security gaps - Perform Microsoft 365 security reviews - Azure security posture analysis aligned with CIS benchmarks and Microsoft Secure Score - Gather and structure technical evidence for compliance projects (PCI DSS, ISO 27001) - Produce detailed, structured remediation reports tailored to any environments Relevant experience: - Conducted web penetration tests using OpenVAS, Burp Suite, OWASP ZAP, and Metasploit - Provided technical evidence and documentation support for internal audits and certifications - Performed risk assessments and security hardening for infrastructure and information systems - Wrote security policies, remediation playbooks, and technical process documentation Understanding of frameworks & certificates: PCI DSS ISO 27001 CIS Benchmarks Tech stack: OS : Linux (Red Hat, Ubuntu), Windows (desktop & server), macOS VM : VMware, VBox SIEM : ELK/Wazuh, ArcSight, Splunk Cloud : Azure, Entra ID, Defender Network : Fortinet IPS&Firewall, Check Point Firewall, F5 WAF Anti-DDoS : Radware, Arbor EDR : Elastic Agent, Trellix PAM : CyberArk NDR : Vectra Vulnerability Detection : Nmap, Metasploit, Burp Suite + Scanner, OWASP ZAP, OpenVAS, Harvester, Sublister, Maltego

  • Information Security
  • Computer Network
  • Computing & Networking
  • Network Engineering
  • System Administration
  • Compliance
  • Penetration Testing
  • Incident Management
  • Cybersecurity Monitoring
  • Virus Removal
  • Security Assessment & Testing
  • Website Security
Muhammad Ahmad B.

Islamabad, Pakistan

$10/hr
5.0
6 jobs

I’m Muhammad Ahmad Bilal, a CISSP-certified Security Architect and Information Security Manager who works at the intersection of security engineering, threat detection, and AI. For the past 9+ years I’ve been designing and running security programs at government scale, protecting critical national applications, large user bases, and high-value data across the public sector. I specialise in turning noisy, complex environments into predictable, defensible systems. That’s included building ML-driven APT detection using TensorFlow and PyTorch, modernising SIEM/SOAR stacks to cut detection and response times by around 40%, and embedding security into the SDLC so vulnerabilities are caught before they ever reach production. I’ve led Zero Trust initiatives, redesigned IAM around least privilege, and driven end-to-end implementations of governance, risk, and compliance programmes aligned with standards like ISO 27001, NIST, PCI, GDPR, and HIPAA. I’m also an educator by choice. As a Lecturer at NUST, I’ve taught Computer and Network Security, Cryptography, Operating Systems, and Data Structures, and supervised 20+ research projects in cybersecurity and machine learning. My academic work includes publications on: - Deep learning–based intrusion detection for IoT - Protocol-aware IDS using datasets such as UNSW-NB15 and Bot-IoT - Federated learning with explainable AI for malicious traffic detection and cellular traffic prediction What I do best: - Design security architectures for large, heterogeneous environments that can actually be operated and maintained by real teams. - Build and tune detection & response: SIEM, EDR, and SOAR use cases, threat hunting workflows, and playbooks that reduce noise while catching what matters. - Integrate security into delivery through secure SDLC practices, code review guidelines, and automation that supports developers instead of blocking them. - Make compliance meaningful, mapping real technical and process controls to standards and regulations so they translate into measurable risk reduction. - Develop people and teams, mentoring analysts and engineers so security becomes an organisational capability, not a one-team bottleneck. In simple terms, my work is about building security systems—technical, procedural, and human—that don’t fall apart the moment something real happens.

  • Information Security
  • Compliance
  • Cyber Threat Intelligence
  • Cybersecurity Management
  • Cybersecurity Monitoring
  • NIST Cybersecurity Framework
  • Cryptography
  • SOC 1
  • SOC 2
  • SOC 3
  • ISO 27001
  • Information Security Audit
  • Information Security Consultation
  • Certified Information Systems Security Professional
  • Information Security Governance
Stephen K.

Nairobi, Kenya

$100/hr
4.8
166 jobs

I help clients recover critical data, investigate cyber incidents, and understand what happened across computers, mobile devices, cloud accounts, email accounts, and online activity. My work focuses on digital forensics, data recovery, cyber breach investigation, OSINT, malware-related analysis, and incident response. Clients usually come to me when they need clear answers after a hack, data loss, account compromise, suspicious activity, deleted files, insider risk, or an online investigation. What I can help with: • Data recovery from computers, drives, mobile devices, and storage media • Digital forensic investigation of devices, files, accounts, logs, and user activity • Cyber breach investigation to identify what happened, how it happened, and what evidence is available • Email, cloud, and account compromise review • Malware, suspicious file, and unauthorized access analysis • OSINT and online identity investigation • Clear technical reports that explain findings in plain language • Practical next steps to secure systems and prevent repeat incidents I approach every investigation carefully, ethically, and confidentially. My goal is to preserve evidence, recover what is recoverable, explain the facts clearly, and help you make informed decisions. Tools I use: I use tools such as Autopsy, FTK Imager, R-Studio, Disk Drill, R-Drive Image, dd, xmount, Volatility, Registry Explorer, RegRipper, Wireshark, tcpdump, Zeek, Magnet AXIOM, Cellebrite UFED, ADB, email header analysis tools, browser artifact tools, log analysis tools, file recovery tools, and Linux forensic tools. I can also review disk images, memory dumps, mobile backups, cloud exports, email files, screenshots, logs, and other available evidence provided by the client. Data recovery note: Data recovery depends on the condition of the device, the storage type, the file system, and whether the data has been overwritten. For SSDs, recovery may be limited or impossible if TRIM or garbage collection has already cleared the deleted data. I always assess the situation first and explain what can realistically be recovered before proceeding. I approach every investigation carefully, ethically, and confidentially. My goal is to preserve evidence, recover what can be recovered, explain the facts clearly, and help you make informed decisions. I do not promise impossible recovery or unsupported conclusions. I provide clear findings based on the available evidence, the condition of the device or data, and the artifacts that can be verified. If you need help understanding a digital incident, recovering important data, or reviewing evidence, I can help you move from uncertainty to clear findings.

  • Information Security
  • Digital Forensics
  • Network Analysis
  • Ethical Hacking
  • System Security
  • Cyber Threat Intelligence
  • Security Assessment & Testing
  • Security Testing
  • Cybersecurity Monitoring
  • Network Security
  • Data Recovery
  • Recover Data Recovery Software
  • Cybersecurity Tool
  • Penetration Testing
  • Information Security Audit
  • Incident Management
  • Incident Response Readiness Assessment
  • Email Spoofing Detection
  • Data Breach Mitigation

How it works

Post a job for freePost a job

Tell us what you need. Create your own job post or generate one with AI then filter talent matches.

Hire top talent fast

Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.

Collaborate easily

Use Upwork to chat or video call, share files, and track project progress right from the app.

Payment simplified

Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.

Don't just take our word for it

Information Security Analysts Hiring FAQs

What is an information security analyst?

With the scale and complexity of networked environments growing every year, the need for seasoned information security analysts has become more prevalent. Upwork provides access to information security talent adept at overseeing and managing risk in the areas of network security, cyber security, and endpoint security.

How do you hire an information security analyst?

You can source information security analysts on Upwork by following these three steps:

  • Write a project description. You’ll want to determine your scope of work and the skills and requirements you are looking for in an information security analyst.
  • Post it on Upwork. Once you’ve written a project description, post it to Upwork. Simply follow the prompts to help you input the information you collected to scope out your project.
  • Shortlist and interview information security analysts. Once the proposals start coming in, create a shortlist of the professionals you want to interview. 

Of these three steps, your project description is where you will determine your scope of work and the specific type of information security analyst you need to complete your project.  

How much does it cost to hire an information security analyst?

Rates can vary due to many factors, including expertise and experience, location, and market conditions.

  • An experienced information security analyst may command higher fees but also work faster, have more-specialized areas of expertise, and deliver higher-quality work.
  • A contractor who is still in the process of building a client base may price their information security analyst services more competitively. 

Which one is right for you will depend on the specifics of your project. 

How do you write an information security analyst job post?

Your job post is your chance to describe your project scope, budget, and talent needs. Although you don’t need a full job description as you would when hiring an employee, aim to provide enough detail for a contractor to know if they’re the right fit for the project.

Job post title

Create a simple title that describes exactly what you’re looking for. The idea is to target the keywords that your ideal candidate is likely to type into a job search bar to find your project. Here are some sample information security analyst job post titles:

  • Need marketing manager with experience in information data security
  • Cyber security analyst needed to oversee corporate governance project
  • Database analyst with security experience needed for financial institution

Project description

An effective information security analyst job post should include: 

  • Scope of work: From developing security policies to implementing network security strategies, list all the deliverables you’ll need. 
  • Project length: Your job post should indicate whether this is a smaller or larger project. 
  • Background: If you prefer experience with certain industries, software, or environments, mention this here. 
  • Budget: Set a budget and note your preference for hourly rates vs. fixed-price contracts.

Information security analyst job responsibilities

Here are some examples of information security analyst job responsibilities:

  • Help manage the enterprise information security infrastructure for a software development company
  • Support vulnerability review, management, and remediation efforts
  • Create the incident response plan and implement the business continuity plan 

Information security analyst job requirements and qualifications

Be sure to include any requirements and qualifications you’re looking for in an Information security analyst. Here are some examples:

  • Bachelor’s degree in IS or related field 
  • Minimum 5 years experience in vulnerability scanning and remediation
  • Excellent knowledge of Microsoft Windows and virtualization technologies