Hire the Best Application Security Freelancers
in India

More than 3,000 reviews on G2
Rating is 4.5 out of 5.
4.5/5
of Upwork by G2 peer reviewers
Jeel V.

Surat, India

$16/hr
5.0
15 jobs

Hi, I’m Jeel Vekariya, a Cybersecurity Expert with 5+ years of hands-on experience helping businesses, startups, SaaS companies, and organizations identify vulnerabilities, reduce security risks, and protect their applications and infrastructure. I specialize in Vulnerability Assessment & Penetration Testing (VAPT), Ethical Hacking, Offensive Security, Application Security, API Security, Mobile Security, Network Security, Cloud Security, and Security Research. My approach is simple: Find the vulnerability → Validate the risk → Explain the impact → Recommend the fix → Retest ━━━━━━━━━━━━━━━━━━━━ WHAT I CAN HELP YOU WITH ✦ Web Application Penetration Testing ➤ OWASP Top 10 Testing ➤ Authentication & Authorization Testing ➤ IDOR / BOLA & Broken Access Control ➤ SQL Injection (SQLi) ➤ Cross-Site Scripting (XSS) ➤ CSRF & SSRF ➤ File Upload & Path Traversal ➤ Remote Code Execution (RCE) ➤ Command Injection ➤ Business Logic Vulnerabilities ➤ Session & JWT Security ➤ Security Misconfiguration ✦ API Security Testing ➤ REST API Penetration Testing ➤ GraphQL Security Testing ➤ OWASP API Security Top 10 ➤ API Authentication & Authorization ➤ OAuth & JWT Security Testing ➤ BOLA / IDOR Testing ➤ Rate Limiting & Abuse Testing ➤ API Gateway Security ➤ Business Logic Testing ✦ Mobile Application Security ➤ Android & iOS Penetration Testing ➤ Mobile API Security Testing ➤ Static & Dynamic Analysis ➤ Authentication & Authorization Testing ➤ Secure Data Storage Testing ➤ SSL/TLS Security Testing ➤ MobSF, Frida & JADX Analysis ✦ Network & Infrastructure Security ➤ Internal & External Network Penetration Testing ➤ Vulnerability Assessment ➤ Network Security Assessment ➤ Firewall Security Review ➤ Server Security Testing ➤ Linux & Windows Security Testing ➤ Active Directory Security Assessment ➤ Privilege Escalation Testing ✦ Cloud & Infrastructure Security ➤ AWS Security Assessment ➤ Microsoft Azure Security Assessment ➤ Google Cloud (GCP) Security Review ➤ IAM & Access Control Review ➤ Cloud Configuration Assessment ➤ Docker & Kubernetes Security ➤ Infrastructure Security Testing ➤ Security Hardening ✦ Application & Specialized Security ➤ Source Code Review ➤ Secure Code Review ➤ SAST / DAST ➤ Software Composition Analysis (SCA) ➤ AI & LLM Security Testing ➤ Red Team Security Assessments ➤ Security Configuration Review ➤ OSINT & Cybersecurity Research ━━━━━━━━━━━━━━━━━━━━ HOW I WORK ➤ Understand your application, infrastructure, and scope ➤ Review the attack surface and potential entry points ➤ Perform manual and automated security testing ➤ Validate vulnerabilities and reduce false positives ➤ Assess technical and business impact ➤ Provide reproducible Proof of Concept (PoC) ➤ Explain the vulnerability in clear language ➤ Provide practical remediation recommendations ➤ Retest fixes after remediation I don't simply provide automated scanner results. I focus on finding meaningful security issues and giving your team information they can actually use to fix them. ━━━━━━━━━━━━━━━━━━━━ SECURITY REPORTS & DELIVERABLES ✔ Executive Summary ✔ Detailed Technical Findings ✔ Vulnerability Description ✔ CVSS-Based Severity Rating ✔ Proof of Concept ✔ Screenshots & Evidence ✔ Steps to Reproduce ✔ Business Impact ✔ Remediation Recommendations ✔ Prioritized Findings ✔ Retesting Support My reports are designed to be useful for both developers and business stakeholders, making it easier to understand the issue, its impact, and how to resolve it. ━━━━━━━━━━━━━━━━━━━━ TOOLS & TECHNOLOGIES Web & API: Burp Suite Pro, OWASP ZAP, Postman Network: Nmap, Nessus, Metasploit, Wireshark Mobile: MobSF, Frida, JADX, Objection Cloud: AWS, Microsoft Azure, GCP Containers: Docker, Kubernetes Operating Systems: Kali Linux, Linux, Windows Server ━━━━━━━━━━━━━━━━━━━━ CORE SECURITY EXPERTISE ✔ Vulnerability Assessment & Penetration Testing ✔ Web Application Security ✔ API Security ✔ Mobile Application Security ✔ Network & Infrastructure Security ✔ Cloud Security ✔ Active Directory Security ✔ Authentication & Authorization ✔ IDOR / BOLA ✔ SQL Injection & XSS ✔ SSRF & CSRF ✔ Business Logic Testing ✔ Privilege Escalation ✔ Secure Code Review ✔ AI / LLM Security ✔ Red Teaming ✔ OWASP Security Testing ━━━━━━━━━━━━━━━━━━━━ WHY CLIENTS WORK WITH ME ➤ 5+ years of cybersecurity experience ➤ Top Rated Upwork Freelancer ➤ 100% Job Success ➤ Manual + automated security testing ➤ Clear and professional security reports ➤ Practical remediation guidance ➤ Developer-friendly findings ➤ Professional communication ➤ On-time delivery ➤ Confidential and authorized testing My goal is not only to find vulnerabilities. I want to help you understand the risk, fix the problem, and improve your overall security posture. ➔ Let's discuss your security requirements and find the vulnerabilities before attackers do.

  • Application Security
  • Penetration Testing
  • Vulnerability Assessment
  • Ethical Hacking
  • Web Application Security
  • Mobile App Testing
  • API Testing
  • Network Penetration Testing
  • Cloud Security
  • Cyber Threat Intelligence
  • Red Team Assessment
  • WordPress Security
  • Information Security
  • Web App Penetration Testing
  • Cybersecurity Management
Adarsh K.

Mumbai, India

$31/hr
4.9
101 jobs

TOP RATED Freelancer | 10+ Years of Experience | Your Trusted Compliance Partner 75+ clients served all with 5 * ratings The best Consultant if you are using Vanta, Drata, Scrut or Secureframe They call me "Mr. Compliance- and for good reason. While you focus on growing your business, I take care of everything compliance-related, ensuring you meet industry standards and win more deals with confidence. Whether it's SOC 2, ISO 27001, HIPAA, PCI DSS, CMMC, or FedRAMP, I make compliance effortless so you can unlock new opportunities without the hassle. Why Clients Trust Me: - Seamless Compliance: I simplify audits, security assessments, and certifications—no stress, no delays. - Growth-Driven Compliance: Compliance isn’t just a checkbox; it’s a competitive advantage. I help shorten sales cycles by getting you audit-ready fast. - End-to-End Support: From policies to risk assessments, vendor due diligence, and security questionnaires—I handle it all. - vCISO Services: Need expert guidance but not ready for a full-time CISO? I offer affordable virtual CISO (vCISO) solutions tailored to your business. - Security Strategy & TPRM: Managing third-party risks? Struggling with cloud or endpoint security? I’ve got you covered. - Maximizing Compliance Tools: Already using Vanta, Drata, Hyperproof, or Scrut but unsure what’s next? Let’s optimize your investment. Proactive, not reactive. I don’t just tick boxes—I future-proof your security and compliance programs. ** Tools & Frameworks: 🔹 Tools Expertise: JIRA, Vanta, Hyperproof, Drata, ServiceNow, AWS, Confluence, Archer, Scrut Automation 🔹 Compliance Frameworks: ISO 27001, SOC 2, FedRAMP, NIST, HIPAA, PCI-DSS, CMMC, TPRM, and more 📢 Ready to Make Compliance Work for You? Click "Invite" to connect, and let's build a stronger, more secure, and audit-ready business together. ⚠️ Note: If you're not fully committed to compliance or tend to be unresponsive, I may not be the right fit. I prioritize working with businesses serious about security and compliance success.

  • Application Security
  • Information Security
  • Risk Assessment
  • NIST Cybersecurity Framework
  • Jira
  • ISO 27001
  • SOC 2
  • CMMC
  • SOC 2 Report
  • Governance, Risk Management & Compliance
  • Application Audit
  • Sarbanes-Oxley Act
  • NIST SP 800-53
  • Mobility Work CMMS
Sandeep S.

Delhi, India

$15/hr
5.0
165 jobs

Web Penetration Testing(OWASP Top 10 methodology) | Network Penetration testing | OWASP API Security | Mobile Vulnerability Assessment(iOS and Android) | Source Code Reviews(.Net, Java, PHP) | Vulnerability Assessment and Penetration Testing | SIEM team (Cloud(AWS and Azure) Security, File Integrity Monitoring and Event Monitoring, Endpoint Security and Encryption, Data Loss Prevention, Network Access Control, Threat Monitoring (Email Traffic and Malware Analysis), Privileged Access and Identity Management) Have 7+ years of experience in both black box and white box testing penetration testing. Perform VAPT (Vulnerability Assessment and Penetration Testing) services for web applications, networks, mobile; source code reviews; malware analysis; server hardening; and security analysis etc. Conduct penetration testing in a systematic approach. Follow the standard methodology of the industry like OWASP Testing Guide v4(OTGv4); SANS top 25; NIST SP 800-115; PCI DSS to perform penetration testing so that client can concentrate on their professions without worrying about security threats. Web Application Testing: Do web application penetration testing with the latest methodology like OWASP Top-10, SANS Top-25. Perform both manual and automated penetration testing for vulnerabilities like Injection flaws(such as SQL, NoSQL, OS, and LDAP injection etc),Broken Authentication, Sensitive Data Exposure,XML External Entities (XXE), Broken Access Control,Security Misconfiguration, Cross-site scripting(XSS), Insecure Deserialization, Using Components with Known Vulnerabilities,Insufficient Logging & Monitoring. Also, perform source code reviews for many technologies like Java, NET, PHP etc. Approach for Manual Web-Application Penetration Testing: Conduct manual testing with following controls: * Configuration and Deployment Management Testing * Identity Management Testing * Authentication Testing * Authorization Testing * Session Management Testing * Input Validation Testing * Testing for Error Handling * Testing for weak Cryptography * Business Logic Testing * Client Side Testing Tools that use for Automated Web Penetration Testing: Acunetix, Burp-Suite, Netsparker, Nexpose, Nikto, IBM AppScan, HP fortify, W3af etc. Network penetration testing: Provide both external and internal network Penetration Testing so that your Network Infrastructure is secured from the real world attacks. Do both manual and automated network penetration testing. Approach for Manual Network Penetration Testing: Manually check for IDS/IPS, Server, Networks switch, Network Router, VPN, Firewalls, Anti-virus, Password etc. Tools that use for automated network penetration testing: OpenVas, Wireshark, Nessus, Metasploit, Armitage, Scapy etc. Mobile Application Penetration Testing: Perform mobile applications application penetration testing with the latest OWASP methodology(MSTG). Performed both manual and automated penetration testing for vulnerabilities like Weak Server Side Controls, Insecure Data Storage, Insufficient Transport Layer Protection, Unintended Data Leakage, Poor Authorization and Authentication, Broken Cryptography, Client Side Injection, Security Decisions Via Untrusted Inputs, Improper Session Handling, Lack of Binary Protections. Tools: Burp-Suite, HP fortify, Dex2Jar, Apktool, framework-res.apk, iNalyzer. Source Code Reviews: Perform source code reviews for both front and back-end languages. Perform source code reviews standard methodology like OWASP top 10. Do manual and automated source code reviews for various web based security vulnerabilities like SQL injection, Cross site scripting (XSS), CSRF, RFI,LFI, Authentication bypass etc. Tools: CheckMarx, IBM Appscan source for analysis, Microfocus HP Fortify. Security Analysis and Server Hardening: Regularly check and maintain your systems, servers to ensure that they comply with the standards. Do hardening application checks the item automatically on a daily basis and monitors all critical networks and server components. We support various frameworks like CIS benchmarking for Desktops & Web Browsers, Mobile Devices, Network Devices, Servers – Operating Systems, Virtualization Platforms & Cloud etc. Social Engineering: Have experience in social engineering vectors: Vishing, Phishing, Smishing, Impersonation. Used the following social engineering cycle to conduct social engineering: Gather Information: Here Information gathered from company websites, social media and other publications. Plan Attack: Next step is outline how intends to execute the attack Acquire Tools: After planning, next include computer programs that an attacker will use when launching the attack. Attack: Exploit the weaknesses in the target system. Use acquired knowledge: Information gathered during the social engineering tactics is used in attacks such as password guessing. Tools: SET(Kali-Linux); GetGoPhish

  • Network Security
  • Vulnerability Assessment
  • Penetration Testing
  • Information Security
  • Internet Security
  • Security Analysis
  • Software QA
  • Network Penetration Testing
  • Website Security
  • Web Application Security
  • Information Security Audit
  • Web Testing
Steffin S.

Kozhikode, India

$30/hr
4.8
208 jobs

Need a Web Application or API penetration test that goes beyond automated scanner output? I’m an OSCP, OSEP, OSWP and CREST CPSA-certified Penetration Tester with 100% Job Success, Top Rated status, 190+ completed Upwork engagements and experience delivering 400+ penetration tests and security assessments. I help SaaS companies, startups, e-commerce platforms and enterprise teams identify real, exploitable security weaknesses before product launches, major releases and compliance reviews. My approach is manual-first. I investigate vulnerabilities that automated scanners often miss, including authentication weaknesses, authorization bypasses, IDOR/BOLA, privilege escalation, tenant-isolation failures, business-logic flaws, race condition flaws and chained attack scenarios. CORE SERVICES • Web Application Penetration Testing • API Security Testing • Mobile Application Penetration Testing • External and Internal Network Penetration Testing • Active Directory and Infrastructure Assessments • Thick Client Application Testing • Security Retesting and Remediation Verification WHAT YOU RECEIVE • A professional executive and technical report • Reproducible proof-of-concept evidence • Risk ratings and CVSS scoring where applicable • Clear business-impact explanations • Developer-focused remediation guidance • Retesting after fixes are implemented Reports can support SOC 2, ISO 27001, PCI DSS, Amazon SP-API, vendor-security reviews and internal audits. Redacted Web Application and API penetration-testing report samples are available upon request. Send me your application type, number of user roles, approximate API endpoints or hosts, testing environment and preferred timeline. I will help you define the appropriate scope, methodology and deliverables.

  • Application Security
  • Information Security
  • Penetration Testing
  • Network Security
  • Security Assessment & Testing
  • Security Testing
  • Vulnerability Assessment
  • System Security
  • Web App Penetration Testing
  • Website Security
  • Web Application Security
  • Black Box Testing
  • Network Penetration Testing
  • OWASP
  • Risk Assessment
John M.

Bengaluru, India

$89/hr
5.0
48 jobs

🔢 As an Upwork Top 1% Expert Vetted 👑 OSCP+, Certified Ethical Hacker and an Experienced Penetration Tester with 10+ years of experience Penetration Testing Web SaaS and Mobile based applications and networks, every flaw tells a story; I write the ending and specialize in helping my clients strengthen their cybersecurity defenses. An average Cybersecurity Incident in your business can you cost you anywhere between $120,000+ to $1.24+ million and even a 10%+ reduction in risk can save your business nearly $124,000+ and hiring a full time in-house team can cost you $100,000+ per employee per year. That is why you need an expert like me to protect your business and reduce your business risk. What makes me stand out from other freelancers is the fact that I am also a Cybersecurity Architect, capable of architecting solutions to enhance the security of your organisation and preserving the security and integrity of your data. I have always been passionate about solving technical problems for my clients through Pen Testing and I don't rest till I get to the root of the problem and solve it. What I can offer? I can help you secure your business by providing the following services: ✅ Web/Mobile Application Penetration Testing, ✅ Secure Source Code Analysis, ✅ Network Penetration Testing, ✅ Secure Architecture Review, ✅ API Security Testing,    ✅ SOC 2, ISO 27001, PCI DSS, AMAZON SP and Compliance-Oriented Penetration Test Reports ✅ Secure Code Review, ✅ CASA Assessment, ✅ Red Team Assessment, ✅ Phishing Simulations & Assessment. Why Choose Me? 🧑🏼‍💼 Client-Centric Approach: Your security is my top priority. I work closely with your team to understand your objectives and deliver tailored services that align with your business goals. Trust and transparency are the cornerstones of my practice, and I am committed to helping you navigate the complex landscape of cybersecurity with confidence and achieve compliance. 📐 Comprehensive Security Assessments: I conduct detailed SOC Type 2 / ISO compliant evaluations to identify vulnerabilities in your network, applications, and infrastructure. ✂️ Tailored Solutions: Every organization is unique. I customize my approach to meet your specific security needs and industry standards. 🎬 Actionable Recommendations: Post-assessment, I provide clear, concise, and practical remediation steps to address identified vulnerabilities. 🔁 Ongoing Support: Cybersecurity is an ongoing process. I offer continuous support and re-assessment to ensure your defenses remain robust against evolving threats 🌏 Holistic Approach: I don't just patch vulnerabilities; I architect comprehensive security solutions that align with business goals. My focus extends beyond the technical to encompass risk management and organizational resilience. 🗨️ Collaborative Communicator: I bridge the gap between technical jargon and business language, fostering understanding across teams. Effective communication is key to successful security implementation. 🏫 Continuous Learning: The threat landscape evolves, and so do I. Whether it's a new attack vector or an emerging technology, count me in. Learning is my superpower. 🙋‍♂️ Key Skills: ✔️ Penetration Testing & Vulnerability Assessment: I thrive on dissecting systems, identifying weaknesses, and recommending robust solutions. Armed with tools like Kali Linux, Metasploit, Nmap, and Wireshark, I delve into web applications, networks, and APIs. But here's the twist—I don't stop at discovery; I offer a free retest after remediation to ensure vulnerabilities stay sealed. ✔️ Network Security: I've designed and implemented secure network architectures, ensuring data confidentiality, integrity, and availability. Firewalls, intrusion detection systems, and VPNs—my toolkit covers it all. ✔️ Cloud Security: Proficient in securing cloud environments especially Amazon Web Services (AWS) & Oracle Cloud Infrastructure (OCI). I stress-test cloud deployments ensuring they withstand real-world attacks. ✔️ Secure Coding Practices: I advocate for secure coding principles using tools like SonarQube and collaborate with development teams to build resilient applications. Prevention beats cure, every time. ⛏️Tools I Use ☑️ Penetration Testing: Nmap, Metasploit, Burp Suite Professional, Wireshark, SQLmap, Kali Linux ☑️ Programming & Scripting Skills: Python, Bash, PowerShell, JavaScript, Java and C# ☑️ Security Frameworks & Standards: OWASP, NIST, CASA, CIA Triad, PCI-DSS 🫱🏽‍🫲🏽 Let's Connect: Ready to enhance your business/organization's security? Let's chat! Reach out to me here on Upwork, and let's build a safer digital future together. 🟢 Press '...' button and then ‘Send Message’ button in the top right-hand corner ✉️ 🚫 No hacking service - I do not provide any hacking services, and I will not engage in any activities that involve gaining unauthorized access to any accounts, systems, or social media platforms. Requests for such services will be declined.

  • Application Security
  • Penetration Testing
  • Network Penetration Testing
  • Security Testing
  • Security Assessment & Testing
  • Vulnerability Assessment
  • Information Security
  • Web Application Security
  • Network Security
  • System Security
  • Web App Penetration Testing
  • Website Security
  • Black Box Testing
  • OWASP
  • Risk Assessment
  • ISO 27001
  • SOC 2
  • SOC 2 Report
  • PCI DSS
  • IT Compliance Audit
Kunal N.

Pune, India

$20/hr
5.0
6 jobs

🌐 Top 10 % on Upwork 📅 11+ Years of Experience | ✅ Penetration Tester | 🌐 80+ projects outside Upwork | 🚀 Quick Response Time | 🕒 On-Time Delivery | 🛡️ Post Contract Support I help SaaS companies, and enterprises identify critical security vulnerabilities before they become costly breaches, compliance issues, or business disruptions. As an Application Security Consultant and Penetration Tester, I specialize in uncovering real-world security weaknesses across web applications, APIs, network infrastructure, cloud environments, and modern technology platforms. My goal is not only to identify vulnerabilities but also to help organizations understand their security risks, prioritize remediation efforts, and strengthen their overall security posture. I have worked on security assessments involving enterprise applications, banking platforms, healthcare systems, cloud infrastructures, and business-critical applications. My experience includes identifying authentication flaws, access control weaknesses, business logic vulnerabilities, network misconfigurations, cloud security gaps, API security issues, and attack paths that automated scanners frequently miss. Core Security Services • Web Application Penetration Testing (OWASP Top 10 & Business Logic Testing) • API Security Testing (REST & GraphQL) • Network & Infrastructure Security Testing • Cloud Security Assessments (AWS) • Red Team Operations & Adversary Simulation • AI / LLM Security Testing • Vulnerability Assessment & Risk Analysis • Security Architecture Review • Email Security Implementation (SPF, DKIM & DMARC) What You Can Expect • Comprehensive Manual Security Testing • Detailed Vulnerability Reports • Proof-of-Concept Validation • Risk-Based Prioritization • Clear Remediation Guidance • Remediation Validation & Retesting • Executive and Technical Reporting Tools & Technologies • Burp Suite Professional • Nmap • Metasploit Framework • Nessus • OWASP ZAP • Wireshark • SQLMap • AWS Security Tools • Kali Linux Long-Term Security Partnership Many organizations engage me beyond a single penetration test. I work with clients on recurring security assessments, monthly security reviews, remediation verification, secure development guidance, and continuous security improvement initiatives. Whether you need a one-time security assessment or a long-term security partner, I focus on delivering actionable security insights that help protect your applications, infrastructure, customers, and reputation. If you are looking for a security professional who can think like an attacker and provide practical, business-focused security recommendations, I would be happy to discuss your project.

  • Application Security
  • Penetration Testing
  • Web Application Security
  • Vulnerability Assessment
  • Ethical Hacking
  • OWASP
  • API Testing
  • Network Penetration Testing
  • Metasploit
  • Cloud Security
  • Cybersecurity Tool
  • Security Testing
  • Network Security
  • Red Team Assessment
  • Information Security

How it works

Post a job for freePost a job

Tell us what you need. Create your own job post or generate one with AI then filter talent matches.

Hire top talent fast

Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.

Collaborate easily

Use Upwork to chat or video call, share files, and track project progress right from the app.

Payment simplified

Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.

Don't just take our word for it

How do I hire a Application Security Freelancer in India on Upwork?

You can hire a Application Security Freelancer in India on Upwork in four simple steps:

  • Create a job post tailored to your Application Security Freelancer project scope. We'll walk you through the process step by step.
  • Browse top Application Security Freelancer talent on Upwork and invite them to your project.
  • Once the proposals start flowing in, create a shortlist of top Application Security Freelancer profiles and interview.
  • Hire the right Application Security Freelancer for your project from Upwork, the world's largest work marketplace.

At Upwork, we believe talent staffing should be easy.

How much does it cost to hire a Application Security Freelancer?

Rates charged by Application Security Freelancers on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.

Why hire a Application Security Freelancer in India on Upwork?

As the world's work marketplace, we connect highly-skilled freelance Application Security Freelancers and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Application Security Freelancer team you need to succeed.

Can I hire a Application Security Freelancer in India within 24 hours on Upwork?

Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Application Security Freelancer proposals within 24 hours of posting a job description.