Hire the Best Application Security Freelancers
in Turkey

More than 3,000 reviews on G2
Rating is 4.5 out of 5.
4.5/5
of Upwork by G2 peer reviewers
Ali Hamza B.

Istanbul, Turkey

$15/hr
5.0
9 jobs

Two skillsets, one freelancer. On the security side, I test web applications and servers for vulnerabilities. I identify weaknesses before attackers do, covering everything from injection flaws and authentication bypasses to misconfigurations and access control issues. After every engagement I deliver a detailed report with findings, severity levels, and remediation steps. I also handle WordPress malware removal, server hardening, and VPS setup, deployment, and troubleshooting. On the language side, I'm a native Turkish speaker with professional English fluency. I translate and localize websites, apps, and technical content with a focus on natural tone and cultural accuracy. What I bring to the table: Web application penetration testing and security auditing WordPress security, malware cleanup, and hardening Turkish to English translation and localization SaaS and fintech terminology expertise Developer background (Python, Flask, JavaScript) so I understand the code behind what I translate and test

  • Python
  • Website Translation
  • SQLite
  • Web App Penetration Testing
  • Document Translation
  • Translation & Localization Software
  • SQL Injection Mitigation
  • Server Administration
  • Translation
  • Web Application Security
  • Web Application
  • Localization
  • Turkish to English Translation
  • English to Turkish Translation
  • Audio Transcription
  • Video Transcription
Emre S.

Istanbul, Turkey

$85/hr
5.0
1 jobs

Automated vulnerability scanners miss critical business logic flaws and flood reports with false positives. I deliver deep manual penetration testing, protocol-level auditing, and custom offensive tooling to identify and neutralize high-risk attack paths before real-world adversaries exploit them. Certified Ethical Hacker (CEH v13), ISO/IEC 27001 Lead Auditor, and Top 0.55% Ranked Practitioner on Hack The Box. I help engineering teams, SaaS platforms, and enterprise infrastructures secure their applications, networks, and cloud environments against sophisticated threat actors. CORE SECURITY SERVICES & DELIVERABLES • Web Application & API Penetration Testing: Deep manual assessments across REST/GraphQL APIs, OAuth/JWT authentication flaws, complex business logic bypasses (IDOR/BOLA), and OWASP Top 10 vulnerabilities. • Active Directory & Cloud Infrastructure: Domain escalation auditing, Kerberoasting/AS-REP roasting, NTLM Relay vectors, ADCS certificate misconfigurations, and hybrid Entra ID (Azure AD) attack path mapping. • Network & Linux Infrastructure Hardening: Kernel stack tuning (sysctl), ingress traffic filtering (nftables/iptables), DDoS mitigation, and exposed surface lockdown. • Executive & Remediation-Focused Reporting: Actionable, risk-prioritized reports formatted to NIST SP 800-115 and PTES standards—complete with CVSS v3.1 scoring, reproducible PoC chains, and regulatory alignment (GDPR, NIS2, ISO 27001). PROPRIETARY TOOLING & CUSTOM AUTOMATION (NOEMVEX SUITE) When off-the-shelf commercial scanners fail in non-standard or heavily fortified architectures, I build bespoke, object-oriented Python security engines to conduct precision assessments: • APEX-PREDATOR: High-speed Active Directory auditing engine automating unauthenticated SMB signing verification, Zerologon analysis, and Kerberos ticket validation. • WEB-ARCHITECT: Specialized client-side parser for JavaScript deobfuscation, hidden endpoint discovery, and automated PII/credential leak detection. • CHRONOS: Reconnaissance and attack surface mapping framework utilizing Shannon Entropy algorithms for cryptographic key discovery and cloud asset hijacking validation. VERIFIED CREDENTIALS & AUDIT STANDARDS • EC-Council: Certified Ethical Hacker (CEH v13) • ISO/IEC 27001: Information Security Management System (ISMS) Lead Auditor • Cisco: Cybersecurity Defense Analyst & Endpoint Security (SOC Triage, Splunk SPL & PEAK Threat Hunting) • Qualys Certified Specialist: VMDR, Policy Compliance, CSAM & QQL • Rank: Top 0.55% Globally (Pro Hacker Tier) on Hack The Box • Methodologies: NIST SP 800-115, OWASP WSTG, PTES, and OSSTMM Available for scoped penetration tests, fixed-price security assessments, and custom offensive tool development.

  • Application Security
  • Information Security
  • System Administration
  • Penetration Testing
  • Web App Penetration Testing
  • API Testing
  • Ethical Hacking
  • Vulnerability Assessment
  • Network Penetration Testing
  • Python
  • OWASP
  • Network Security
  • Red Team Assessment
  • Microsoft Windows PowerShell
  • Bash
  • Technical Writing
  • Microsoft Active Directory
  • Cloud Engineering
  • AWS CodeBuild
Mustafa B.

Antalya, Turkey

$30/hr
5.0
1 jobs

I help companies identify real, exploitable security vulnerabilities in production web apps and APIs — especially in authenticated systems where flaws lead to data leaks, account takeovers, and revenue loss. I’m an active Synack Red Team researcher, ranked Top 30 globally for critical vulnerabilities and Top 5 on Featured Targets, delivering high-impact findings on live systems with real users. My security research has also been accepted at Black Hat USA (Arsenal 2023) and DEF CON 31. What I do (manual, attacker-minded testing) - Broken access control (IDOR, privilege escalation, cross-account access) - Authentication & authorization flaws - Business-logic vulnerabilities (payments, checkout, refunds, entitlements) - High-impact web & API issues (SQL Injection, SSRF, XSS, race conditions) What you get - Clear, professional reports with step-by-step reproduction - Impact analysis focused on real-world risk - Actionable remediation guidance - Optional retesting to confirm fixes - Direct developer support to explain root causes and prevent regressions No scanner dumps. No noise. Only manually verified vulnerabilities that can be reproduced, exploited, and fixed. If you’re looking for security testing that reflects how attackers actually break applications — not checkbox compliance — let’s talk.

  • Web App Penetration Testing
  • Web Application Security
  • Penetration Testing
  • Secure SDLC
  • Bug Bounty
  • Vulnerability Assessment
  • SQL Injection Mitigation
  • Cross-Site Scripting Mitigation
  • WordPress Security
  • CI/CD
John E.

Ankara, Turkey

$40/hr
5.0
10 jobs

I'm a cyber-security engineer who has experience in both red team and blue team. I can help you with cyber security architecture, penetration testing, static code analysis, network and Active Directory hardening. I'm also an experienced ctf player. Computer Engineer BSc, MSc | Offensive Security Engineer | CTF Player | OSCP | CREST CRT | OSWP | C-AI/MLPen | eDFP | PIPA |

  • Application Security
  • Penetration Testing
  • Web App Penetration Testing
  • Network Penetration Testing
  • Security Assessment & Testing
  • Web Application Security
  • Security Operation Center
  • Security Analysis
  • Digital Forensics
  • Incident Response Plan
  • Network Engineering
  • Computer Network
  • Architectural Design
  • Information Security
  • Computing & Networking
Utku Eren B.

Izmir, Turkey

$5/hr
5.0
4 jobs

I am a Software Engineer with frontend and backend project experience, problem-solving skills, and a proven track record of meaningful contributions. I focus on testing, bugs, vulnerabilities, and updates, and I am also a cybersecurity expert. What can I do for you? -I can build landing pages for your company or project and assist with publishing. -I can test your project, report the problems, and solve these issues. -I can design websites for your company or project. -I can test your website and create reports on potential security vulnerabilities. Communication is the most important aspect of my work, ensuring we can produce the most suitable solution for you. Let's keep in touch...

  • GitHub
  • Front-End Development
  • HTML5
  • CSS
  • Bootstrap
  • JavaScript
  • Tailwind CSS
  • React
  • jQuery
  • UX & UI Design
  • Python
  • Back-End Development
  • Ethical Hacking
  • Information Analysis
  • Cybersecurity Tool
Ehtisham F.

Izmir, Turkey

$35/hr
4.9
54 jobs

I’m a Penetration Tester specializing in Web Applications, APIs, and SaaS Security. I manually find vulnerabilities that automated scanners often miss including IDOR/BOLA, broken authentication, authorization flaws, business logic vulnerabilities, SSRF, SQLi, XSS, and tenant-isolation issues. CRTO & CPTS certified | 5+ years offensive security | 49 completed projects I test web applications and APIs built with modern SaaS stacks, including **REST, GraphQL, OAuth, JWT, AWS, Supabase, and PostgreSQL**. My testing can include: • Web application penetration testing • API security testing (REST/GraphQL) • SaaS & multi-tenant security • Authentication & authorization testing • Business logic vulnerability testing • Cloud/backend security reviews • Internal network & Active Directory pentesting • Retesting after remediation You won't receive a report full of scanner output. I manually validate vulnerabilities, provide reproducible PoCs, explain the real-world impact, and give developers clear steps to fix them. Reports include CVSS severity, technical evidence, remediation guidance, and executive summaries** where needed. Testing can be aligned with OWASP, PTES, and NIST SP 800-115, with reporting suitable for security programs such as SOC 2 and ISO 27001. If you're launching a product, preparing for an audit, or want to know whether your application can actually withstand an attacker, I can test it from an attacker's perspective.

  • Application Security
  • Penetration Testing
  • Vulnerability Assessment
  • System Security
  • Ethical Hacking
  • Web Application Security
  • Kali Linux
  • Network Security
  • Website Security
  • Web App Penetration Testing
  • OWASP
  • Information Security
  • Security Analysis
  • Security Assessment & Testing
  • Cybersecurity Management

How it works

Post a job for freePost a job

Tell us what you need. Create your own job post or generate one with AI then filter talent matches.

Hire top talent fast

Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.

Collaborate easily

Use Upwork to chat or video call, share files, and track project progress right from the app.

Payment simplified

Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.

Don't just take our word for it

How do I hire a Application Security Freelancer in Turkey on Upwork?

You can hire a Application Security Freelancer in Turkey on Upwork in four simple steps:

  • Create a job post tailored to your Application Security Freelancer project scope. We'll walk you through the process step by step.
  • Browse top Application Security Freelancer talent on Upwork and invite them to your project.
  • Once the proposals start flowing in, create a shortlist of top Application Security Freelancer profiles and interview.
  • Hire the right Application Security Freelancer for your project from Upwork, the world's largest work marketplace.

At Upwork, we believe talent staffing should be easy.

How much does it cost to hire a Application Security Freelancer?

Rates charged by Application Security Freelancers on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.

Why hire a Application Security Freelancer in Turkey on Upwork?

As the world's work marketplace, we connect highly-skilled freelance Application Security Freelancers and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Application Security Freelancer team you need to succeed.

Can I hire a Application Security Freelancer in Turkey within 24 hours on Upwork?

Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Application Security Freelancer proposals within 24 hours of posting a job description.