Hi, I’m Martin — a Principal Penetration Tester with over 13 years of hands-on experience (since 2011). I’ve delivered high-impact security assessments for clients ranging from innovative startups to global enterprises across the UK, Europe, East Asia, and the Middle East.
My expertise spans the full spectrum of offensive security, including:
• Web Application Penetration Testing
• Mobile Application Penetration Testing
• API Penetration Testing (REST, SOAP, GraphQL)
• Thick Client & Desktop Application Testing
• External & Internal Infrastructure Penetration Testing
• Cloud Security Assessments (AWS, Azure, Office 365)
• Red Team Operations & Simulated Phishing
• Wireless Assessments, IoT Security, and Embedded Hardware
• Server & Workstation Build Reviews
• Mobile Device & MDM Testing
• Network Device Security Reviews
What sets me apart is my depth of experience combined with a relentless, methodical approach. As a Tigerscheme and CREST certified penetration tester, I stay at the forefront of evolving threats and techniques. I don’t just find vulnerabilities
I provide clear, actionable insights that help organisations meaningfully strengthen their security posture.
In addition to technical excellence, I’m a strong communicator who excels at translating complex findings into clear, business-relevant language. I work closely with clients to understand their unique risk landscape and deliver tailored testing programs that align with their objectives.
I run a professional, focused penetration testing company and take great pride in the quality of our deliverables. All engagements include comprehensive, high-standard reports (example reports available upon request). I am also a Cyber Essentials and Cyber Essentials Plus Assessor and work with a recognised certification body.
Top Rated on Upwork, I’m known for consistent quality, clear communication, and delivering real value. Whether you need infrastructure testing, web/mobile application assessments, API reviews, cloud configuration audits, or full Red Team exercises.
I’m here to help you identify and mitigate risks before attackers do.
Feel free to reach out, I would be happy to discuss how I can support your security needs.
Cybersecurity Management
Information Security
Security Infrastructure
Penetration Testing
Security Analysis
Web Application Security
Vulnerability Assessment
Security Testing
Cloud Security
Security Assessment & Testing
WordPress
Certified Information Systems Security Professional
Ethical Hacking
Website Security
Web App Penetration Testing
Svitlana H.
Bexhill-on-Sea, United Kingdom
$70/hr
5.0
30 jobs
When you work with me, you keep full ownership of everything I build. A top 3% Upwork Senior Full Stack Developer, and your site is in expert hands.
I am a full stack developer, SaaS developer, and dashboard developer in the UK.
As a full stack developer I own the entire stack: PostgreSQL design, Node.js and Nest.js backend, React and Next.js frontend, REST API integrations, Stripe payments, and Vercel deployment. Need a full stack developer, SaaS developer, or dashboard developer who owns the technical side end to end? Let's talk.
My recent full stack developer work includes a SaaS platform for trades businesses, a Next.js app with job management, client records, quoting, and role-based access, and a B2B admin dashboard on PostgreSQL, Node.js, and React that a team of 20 depends on every day.
Technical consultant. Architecture. Audit.
For non-technical founders my tech stack and architecture audit with written report shows what you have, what's broken, and what to build next: vendor selection, developer estimate review, security review, and a roadmap. As a Next.js performance specialist I improve Lighthouse and Core Web Vitals, taking one client from 54 to 98 and cutting page weight from 2.4 MB to 610 KB.
SaaS developer. Multi-tenant. Production-ready.
As a SaaS developer I delivered a multi-tenant SaaS starter on Next.js with Stripe subscriptions, PostgreSQL via Neon, role-based access, billing portal, and team invites, fully documented, repo transferred on handover. I led a platform rebuild from legacy PHP and WordPress to a modern Next.js and Nest.js architecture, 40% lift in user engagement post-launch. I also build multilingual B2B platforms: Next.js with Sanity CMS, localised content and routing, editorial workflows non-technical teams actually use.
Security audit. Supabase RLS. Multi-tenant isolation.
As a technical consultant I run pre-launch security audits for SaaS founders before real customer data goes live. My audits cover Supabase Row Level Security (RLS), multi-tenant isolation, PostgreSQL policy design, authentication flows, and exposed API keys in client code. I've audited a multi-tenant property maintenance SaaS on Supabase, and on another found RLS policies that lived only in discarded migrations, never applied to the database, the silent data leak an audit catches before a breach. If you're a SaaS founder on Supabase, Next.js, or PostgreSQL and aren't certain your tenant data is isolated, that's the audit I do.
Backend developer. Nest.js. PostgreSQL. Data pipelines.
As a backend developer I build production Nest.js and Node.js APIs on PostgreSQL with TypeScript end to end. Recent backend work: a Nest.js and PostgreSQL backend for a raffle SaaS platform with JWT authentication, OAuth providers, password recovery, and a clean REST API layer for a Next.js and React frontend. I engineered a web scraping and data aggregation engine: Nest.js cron pipelines with adapters for multiple third-party sites, anomaly detection, stale-data cleanup, and webhook alerting, thousands of records refreshed daily on Railway, Prisma, and Neon. On the same platform I moved 4,563 hotlinked images onto Cloudflare R2 with content-hash deduplication and three generated sizes per asset, cutting card weight roughly seven times. Every endpoint authenticated, every role enforced, every query isolation-aware.
Dashboard developer. AI features. Data that changes decisions.
As a dashboard developer with a KendoReact commercial licence I build enterprise-grade interfaces standard React developers can't replicate: advanced data grids, real-time charts, complex forms under load. My portfolio includes a marketing analytics dashboard with AI insights that cut campaign review time by 60% for a British agency, and a SaaS analytics dashboard with Chart.js and PDF export that replaced weekly manual reporting. I integrate LLM APIs (Anthropic Claude, OpenAI) into production apps: AI insights, content pipelines, and matching features, keys secured server-side.
Integrations. Authentication. Infrastructure.
OAuth integration and API authentication: credential flows for Google, GitHub, and custom providers using NextAuth, Nest.js, and JWT. Google Tag Manager with GA4 and Meta Pixel across complex Next.js apps, GDPR cookie consent and Consent Mode included.
Stripe. Payments. Automation.
I built a Stripe internal payment interface with role-based access on Next.js: PaymentIntent flow, full audit log, zero card data stored. I delivered Stripe subscription billing with webhooks handling upgrades, downgrades, and failed payment recovery. I wire Stripe with Make, GoHighLevel, and Google Sheets so every transaction triggers the right email, CRM tag, and notification.
Next.js · React · Node.js · Nest.js · PostgreSQL · Supabase · TypeScript · JavaScript · REST API · Stripe · Kendo UI · Sanity · Prisma · Claude API · OpenAI · Make · GoHighLevel · Vercel · Railway · NextAuth · JWT · OAuth · RLS · Chart.js · GA4 · Meta Pixel
React
Next.js
Node.js
TypeScript
JavaScript
PostgreSQL
SQL
Dashboard
Data Visualization
Data Analytics
Supabase
API
Software Development
Web Development
PHP
HTML5
CSS
MongoDB
Redux
Vue.js
Ijaz T.
London, United Kingdom
$20/hr
5.0
2 jobs
That vulnerability your scanner flagged last? It already missed three others.
Automated tools were built for speed, not depth. They catch surface-level issues and hand you a report full of findings that look thorough but leave the real risks untouched. Business logic flaws, broken access controls and chained API vulnerabilities are not things a scanner reasons though they require someone who thinks like an attacker and understands how applications are actually built.
With 15 years of web application penetration testing experience and both OSCP and OSWE certifications, the vulnerabilities that matter most are exactly what gets found here.
✅ OSCP and OSWE certified with 15 years of hands-on web application penetration testing
✅ API security testing across REST, GraphQL, BOLA, JWT and OAuth attack surfaces
✅ Full OWASP Top 10 coverage using real working exploits, not recycled scan output
✅ Business logic flaws, auth bypasses and access control gaps that no scanner will catch
✅ SaaS, fintech and startup clients across the US, UK, Europe and Australia
✅ Virtual CISO support for SaaS, fintech and AI companies without a full-time security hire
✅ ISO 27001 implementation and ISMS structuring to pass audits and satisfy enterprise buyers
✅ Security questionnaires handled end-to-end so compliance never stalls a deal
✅ Audit-ready policies, procedures and control frameworks beyond checkbox compliance
✅ Hands-on GRC platform work across Vanta, Drata, Secureframe and Thoropass
Certifications:
✅ Offensive Security Certified Professional (OSCP)
✅ Certified Ethical Hacker (CEH)
✅ eLearnSecurity Junior Penetration Tester (eJPT)
✅ GIAC Penetration Tester (GPEN)
✅ Offensive Security Web Expert (OSWE)
✅ GIAC Web Application Penetration Tester (GWAPT)
✅ Certified AppSec Practitioner (CAP)
✅ AWS Certified Security – Specialty
✅ Microsoft Certified: Azure Security Engineer Associate
Here's the thing: most penetration testing engagements produce the same report. Same ten findings, same scanner, same template. That is not useful to a development team trying to fix real problems, and it is not useful to a business trying to understand real risk. The vulnerabilities that lead to actual breaches live inside application logic, API design and access control architecture. Finding them requires manual testing, genuine attack thinking and an understanding of where developers cut corners under deadline pressure.
Web Application Penetration Testing
Testing covers the full attack surface authentication, session management, input validation, business logic, access control and injection vulnerabilities mapped across the complete OWASP Top 10. Burp Suite Professional, OWASP ZAP, Nuclei, ffuf, SQLmap and XSStrike are used alongside deep manual testing to find chained vulnerabilities and logic flaws that no automated tool reaches on its own.
Scope covers single-page applications in React, Angular and Vue, backend platforms including PHP, Node.js, Python, Java and .NET, and extends into microservices and cloud-native environments across AWS, Azure and GCP.
API Security Testing
Every REST and GraphQL endpoint gets tested for broken object-level authorisation, excessive data exposure, broken function-level authorisation, mass assignment, JWT vulnerabilities, OAuth misconfigurations and rate-limiting bypasses. Testing covers both technical weaknesses and business logic abuse, not just surface HTTP checks that any scanner can run.
GraphQL engagements go further into introspection abuse, batching attacks, nested query exploitation and field-level authorisation gaps.
Application Security Audit and Vulnerability Assessment
Every audit combines manual penetration testing with SAST via Semgrep, SCA via Snyk and container scanning via Trivy to deliver a full picture of code-level, dependency and infrastructure risk. Findings are prioritised by real exploitability and business impact, not by CVSS score alone.
Compliance-Aligned Testing
Audit work maps directly to OWASP ASVS, SOC 2, GDPR and NIST CSF requirements — useful for SaaS companies approaching enterprise sales, startups preparing for investor due diligence and platforms handling regulated or sensitive user data.
All findings are documented with detailed technical evidence, including proof-of-concept exploitation steps, affected endpoints, request/response analysis, and attack flow breakdowns where applicable. The reporting structure is designed to support engineering teams in reproducing and fixing issues efficiently, with clear mapping to OWASP Top 10 and relevant security controls. Each vulnerability includes prioritized remediation guidance, validation notes
Send a message to discuss scope. A short conversation is all it takes to get started.
Application Security
Penetration Testing
Web App Penetration Testing
Vulnerability Assessment
Website Security
WordPress Security
Malware Removal
WordPress Malware Removal
Ethical Hacking
Network Penetration Testing
Network Security
Application Audit
Security Analysis
Security Assertion Markup Language
Security Assessment & Testing
Security Testing
Cloud Security Framework
NIST Cybersecurity Framework
Kubernetes
Cloud Security
Creston V.
Wembley, United Kingdom
$75/hr
4.9
27 jobs
Microsoft 365 Architecture Expert!
Microsoft Certified: Cybersecurity Architect Expert
E-Learn Certified Professional Penetration Tester
Dedicated and ambitious Cyber Security Solutions Architect with a extensive experience in information security principles and industry leading best security practices with over 10 years of experience in the corporate world.
I have helped companies achieve compliancy & audited for Cyber Security Frameworks such as ISO 27001, SOC 2, Cyber Essentials Plus, GDPR and many more by carefully planning based on budget, current Infrastructure assessment, Security testings and remediation efforts.
Proficient in conducting risk assessments, penetrations testing, implementing security controls, and assisting in incident response. Skilled in utilizing cybersecurity tools and technologies to detect and mitigate threats. Committed to learning and expanding knowledge in the field to contribute to the organization's security objectives. Strong teamwork and communication skills, with a passion for maintaining a secure and resilient IT environment.
Application Security
System Security
Security Engineering
VPN
Cloud Security Framework
User Identity Management
Microsoft Active Directory
Office 365
Enterprise Architecture
Virtualization
Insurance & Risk Management
Malware Detection
Security Management
Threat Detection
Data Protection
Rafay B.
London, United Kingdom
$100/hr
4.9
83 jobs
I am a globally acclaimed Cyber security consultant and Internet Security Specialist with a proven track record in security engineering and discovering Critical Zero Day Security Issues in a significant number of Web Applications, Products and Browsers which have helped protecting Privacy and Security of millions of users globally. My research on Cyber Security has been featured in BBC, Forbes, WSJ, Tech Crunch and many International media outlets. My mission is to fortify your digital defenses by harnessing the power of cutting-edge AI/ML technologies.
I currently hold the following educational degrees and certifications:
✅ Masters in Cyber-Security and Forensics
✅ Certified Information Systems Security Professional (CISSP)
✅ Certified Information Security Auditor (CISA)
✅ Offensive Security Certified Professional (OSCP)
✅ CREST Practitioner Security Analyst (CPSA)
✅ Offensive Security Web Expert (OSWE)
✅Offensive Security Wireless Professional (OSWP)
Security/Compliance Frameworks:
ISO 27001, SOC2, PCI-DSS, HIPAA, NY DFS 23/ NYCRR Part 500, NIST, CIS, GDPR, HIPAA, FedRAMP, NIST 800-53, NIST 800-171, NIS2, DORA
Services I Offer:
Penetration Testing
Vulnerability Assessment
PCI-DSS SAQ Filing + ASV
PCI compliance assessment
Cloud Security (AWS, Azure and GCP)
Red Teaming Assessment
Threat Modelling
Security Architecture Review
Web 3.0 Wallet Security
Smart Contract Audits
Cloudflare WAF Protection
DDOS Protection Expert
Bot Protection Expert
Cyber Essentials
Cyber Essentials Plus
Cybersecurity Management
Penetration Testing
NIST Cybersecurity Framework
Web App Penetration Testing
Web Application Audit
Cloud Security
ISO 27001
GDPR Compliance Review
PCI DSS
NIST SP 800-53
SOC 2
WordPress Security
Network Security
Firewall
Website Security
Michael-Calum G.
Kings Hill, United Kingdom
$65/hr
5.0
2 jobs
Automated tools are necessary, but they aren't sufficient. To truly secure your application, you need a human tester who understands business logic and complex exploit chains.
I am a certified offensive security specialist focusing on Web Application and API penetration testing. I provide the manual verification required for SOC2, ISO 27001, and HIPAA compliance, ensuring your team doesn't waste time chasing false positives.
Core Competencies:
Manual Exploitation: Identifying logic flaws, privilege escalation, and IDORs that scanners cannot find.
Detailed Remediation: I speak your developers' language. My reports include reproduction steps (PoC) and code-level mitigation advice.
Compliance: Structured testing methodologies aligned with industry standards.
Certifications:
OSCP (Offensive Security Certified Professional)
CREST Registered Penetration Tester
BSCP (Burp Suite Certified Practitioner)
If you need a clear, actionable security assessment without the jargon, let's connect.
Web App Penetration Testing
Vulnerability Assessment
Web Application Security
Network Security
Ethical Hacking
Information Security
Metasploit
OWASP
Linux
Python
Technical Writing
Security Assessment & Testing
API
Nessus
C++
How it works
Post a job for freePost a job
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a Application Security Freelancer in the United Kingdom on Upwork?
You can hire a Application Security Freelancer in the United Kingdom on Upwork in four simple steps:
Create a job post tailored to your Application Security Freelancer project scope. We'll walk you through the process step by step.
Browse top Application Security Freelancer talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top Application Security Freelancer profiles and interview.
Hire the right Application Security Freelancer for your project from Upwork, the world's largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a Application Security Freelancer?
Rates charged by Application Security Freelancers on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a Application Security Freelancer in the United Kingdom on Upwork?
As the world's work marketplace, we connect highly-skilled freelance Application Security Freelancers and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Application Security Freelancer team you need to succeed.
Can I hire a Application Security Freelancer in the United Kingdom within 24 hours on Upwork?
Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Application Security Freelancer proposals within 24 hours of posting a job description.
Find more freelancers
Top cities for Application Security Freelancers in the United Kingdom