Two skillsets, one freelancer.
On the security side, I test web applications and servers for vulnerabilities. I identify weaknesses before attackers do, covering everything from injection flaws and authentication bypasses to misconfigurations and access control issues. After every engagement I deliver a detailed report with findings, severity levels, and remediation steps. I also handle WordPress malware removal, server hardening, and VPS setup, deployment, and troubleshooting.
On the language side, I'm a native Turkish speaker with professional English fluency. I translate and localize websites, apps, and technical content with a focus on natural tone and cultural accuracy.
What I bring to the table:
Web application penetration testing and security auditing
WordPress security, malware cleanup, and hardening
Turkish to English translation and localization
SaaS and fintech terminology expertise
Developer background (Python, Flask, JavaScript) so I understand the code behind what I translate and test
Python
Website Translation
SQLite
Web App Penetration Testing
Document Translation
Translation & Localization Software
SQL Injection Mitigation
Server Administration
Translation
Web Application Security
Web Application
Localization
Turkish to English Translation
English to Turkish Translation
Audio Transcription
Video Transcription
Emre S.
Istanbul, Turkey
$85/hr
5.0
1 jobs
Automated vulnerability scanners miss critical business logic flaws and flood reports with false positives. I deliver deep manual penetration testing, protocol-level auditing, and custom offensive tooling to identify and neutralize high-risk attack paths before real-world adversaries exploit them.
Certified Ethical Hacker (CEH v13), ISO/IEC 27001 Lead Auditor, and Top 0.55% Ranked Practitioner on Hack The Box. I help engineering teams, SaaS platforms, and enterprise infrastructures secure their applications, networks, and cloud environments against sophisticated threat actors.
CORE SECURITY SERVICES & DELIVERABLES
• Web Application & API Penetration Testing: Deep manual assessments across REST/GraphQL APIs, OAuth/JWT authentication flaws, complex business logic bypasses (IDOR/BOLA), and OWASP Top 10 vulnerabilities.
• Active Directory & Cloud Infrastructure: Domain escalation auditing, Kerberoasting/AS-REP roasting, NTLM Relay vectors, ADCS certificate misconfigurations, and hybrid Entra ID (Azure AD) attack path mapping.
• Network & Linux Infrastructure Hardening: Kernel stack tuning (sysctl), ingress traffic filtering (nftables/iptables), DDoS mitigation, and exposed surface lockdown.
• Executive & Remediation-Focused Reporting: Actionable, risk-prioritized reports formatted to NIST SP 800-115 and PTES standards—complete with CVSS v3.1 scoring, reproducible PoC chains, and regulatory alignment (GDPR, NIS2, ISO 27001).
PROPRIETARY TOOLING & CUSTOM AUTOMATION (NOEMVEX SUITE)
When off-the-shelf commercial scanners fail in non-standard or heavily fortified architectures, I build bespoke, object-oriented Python security engines to conduct precision assessments:
• APEX-PREDATOR: High-speed Active Directory auditing engine automating unauthenticated SMB signing verification, Zerologon analysis, and Kerberos ticket validation.
• WEB-ARCHITECT: Specialized client-side parser for JavaScript deobfuscation, hidden endpoint discovery, and automated PII/credential leak detection.
• CHRONOS: Reconnaissance and attack surface mapping framework utilizing Shannon Entropy algorithms for cryptographic key discovery and cloud asset hijacking validation.
VERIFIED CREDENTIALS & AUDIT STANDARDS
• EC-Council: Certified Ethical Hacker (CEH v13)
• ISO/IEC 27001: Information Security Management System (ISMS) Lead Auditor
• Cisco: Cybersecurity Defense Analyst & Endpoint Security (SOC Triage, Splunk SPL & PEAK Threat Hunting)
• Qualys Certified Specialist: VMDR, Policy Compliance, CSAM & QQL
• Rank: Top 0.55% Globally (Pro Hacker Tier) on Hack The Box
• Methodologies: NIST SP 800-115, OWASP WSTG, PTES, and OSSTMM
Available for scoped penetration tests, fixed-price security assessments, and custom offensive tool development.
Application Security
Information Security
System Administration
Penetration Testing
Web App Penetration Testing
API Testing
Ethical Hacking
Vulnerability Assessment
Network Penetration Testing
Python
OWASP
Network Security
Red Team Assessment
Microsoft Windows PowerShell
Bash
Technical Writing
Microsoft Active Directory
Cloud Engineering
AWS CodeBuild
Mustafa B.
Antalya, Turkey
$30/hr
5.0
1 jobs
I help companies identify real, exploitable security vulnerabilities in production web apps and APIs — especially in authenticated systems where flaws lead to data leaks, account takeovers, and revenue loss.
I’m an active Synack Red Team researcher, ranked Top 30 globally for critical vulnerabilities and Top 5 on Featured Targets, delivering high-impact findings on live systems with real users. My security research has also been accepted at Black Hat USA (Arsenal 2023) and DEF CON 31.
What I do (manual, attacker-minded testing)
- Broken access control (IDOR, privilege escalation, cross-account access)
- Authentication & authorization flaws
- Business-logic vulnerabilities (payments, checkout, refunds, entitlements)
- High-impact web & API issues (SQL Injection, SSRF, XSS, race conditions)
What you get
- Clear, professional reports with step-by-step reproduction
- Impact analysis focused on real-world risk
- Actionable remediation guidance
- Optional retesting to confirm fixes
- Direct developer support to explain root causes and prevent regressions
No scanner dumps. No noise.
Only manually verified vulnerabilities that can be reproduced, exploited, and fixed.
If you’re looking for security testing that reflects how attackers actually break applications — not checkbox compliance — let’s talk.
Web App Penetration Testing
Web Application Security
Penetration Testing
Secure SDLC
Bug Bounty
Vulnerability Assessment
SQL Injection Mitigation
Cross-Site Scripting Mitigation
WordPress Security
CI/CD
John E.
Ankara, Turkey
$40/hr
5.0
10 jobs
I'm a cyber-security engineer who has experience in both red team and blue team. I can help you with cyber security architecture, penetration testing, static code analysis, network and Active Directory hardening. I'm also an experienced ctf player.
Computer Engineer BSc, MSc | Offensive Security Engineer | CTF Player |
OSCP | CREST CRT | OSWP | C-AI/MLPen | eDFP | PIPA |
Application Security
Penetration Testing
Web App Penetration Testing
Network Penetration Testing
Security Assessment & Testing
Web Application Security
Security Operation Center
Security Analysis
Digital Forensics
Incident Response Plan
Network Engineering
Computer Network
Architectural Design
Information Security
Computing & Networking
Utku Eren B.
Izmir, Turkey
$5/hr
5.0
4 jobs
I am a Software Engineer with frontend and backend project experience, problem-solving skills, and a proven track record of meaningful contributions. I focus on testing, bugs, vulnerabilities, and updates, and I am also a cybersecurity expert.
What can I do for you?
-I can build landing pages for your company or project and assist with publishing.
-I can test your project, report the problems, and solve these issues.
-I can design websites for your company or project.
-I can test your website and create reports on potential security vulnerabilities.
Communication is the most important aspect of my work, ensuring we can produce the most suitable solution for you. Let's keep in touch...
GitHub
Front-End Development
HTML5
CSS
Bootstrap
JavaScript
Tailwind CSS
React
jQuery
UX & UI Design
Python
Back-End Development
Ethical Hacking
Information Analysis
Cybersecurity Tool
Ehtisham F.
Izmir, Turkey
$35/hr
4.9
54 jobs
I’m a Penetration Tester specializing in Web Applications, APIs, and SaaS Security. I manually find vulnerabilities that automated scanners often miss including IDOR/BOLA, broken authentication, authorization flaws, business logic vulnerabilities, SSRF, SQLi, XSS, and tenant-isolation issues.
CRTO & CPTS certified | 5+ years offensive security | 49 completed projects
I test web applications and APIs built with modern SaaS stacks, including **REST, GraphQL, OAuth, JWT, AWS, Supabase, and PostgreSQL**.
My testing can include:
• Web application penetration testing
• API security testing (REST/GraphQL)
• SaaS & multi-tenant security
• Authentication & authorization testing
• Business logic vulnerability testing
• Cloud/backend security reviews
• Internal network & Active Directory pentesting
• Retesting after remediation
You won't receive a report full of scanner output. I manually validate vulnerabilities, provide reproducible PoCs, explain the real-world impact, and give developers clear steps to fix them.
Reports include CVSS severity, technical evidence, remediation guidance, and executive summaries** where needed. Testing can be aligned with OWASP, PTES, and NIST SP 800-115, with reporting suitable for security programs such as SOC 2 and ISO 27001.
If you're launching a product, preparing for an audit, or want to know whether your application can actually withstand an attacker, I can test it from an attacker's perspective.
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a Application Security Freelancer in Turkey on Upwork?
You can hire a Application Security Freelancer in Turkey on Upwork in four simple steps:
Create a job post tailored to your Application Security Freelancer project scope. We'll walk you through the process step by step.
Browse top Application Security Freelancer talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top Application Security Freelancer profiles and interview.
Hire the right Application Security Freelancer for your project from Upwork, the world's largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a Application Security Freelancer?
Rates charged by Application Security Freelancers on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a Application Security Freelancer in Turkey on Upwork?
As the world's work marketplace, we connect highly-skilled freelance Application Security Freelancers and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Application Security Freelancer team you need to succeed.
Can I hire a Application Security Freelancer in Turkey within 24 hours on Upwork?
Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Application Security Freelancer proposals within 24 hours of posting a job description.
Find more freelancers
Top cities for Application Security Freelancers in Turkey