Hire the Best Application Security Freelancers
in the United States

Clients rate our Application Security professionals
Rating is 4.6 out of 5.
4.6/5
Based on 218 client reviews
Michael H.

Baltimore, Maryland

$125/hr
5.0
115 jobs

Stop relying on automated scans. I find the vulnerabilities they miss. I’m a senior penetration tester and vulnerability researcher with deep experience across enterprise networks, web apps / APIs and cloud platforms. Most testers just run automated tools and hand you a generic report. I simulate how an attacker actually thinks, perform thorough testing, and deliver professional, tailored reporting suitable not just for your own remediation efforts but also for audit / compliance. Benefits of manual testing: - Chaining multiple low/medium findings to show more significant impact - Breaking multi-tenant isolation - Bypassing auth controls (JWT, OAuth, misconfigurations) - Identifying cost-amplification / abuse vectors (e.g., billing attacks in serverless environments) - ZERO false positives (and wasted time trying to remediate non-issues) - REAL severity scoring (not just CVSS or ratings with no connection to actual impact/risk for your systems and data) What I Deliver - Manual, attacker-style testing (not just scans) - Clear, prioritized findings with real business impact - Proof-of-concept exploits where it matters - Practical remediation guidance your devs can use immediately - Optional retesting to verify fixes Common Engagements - SaaS / multi-tenant application security testing - API and authentication testing (JWT, OAuth, session flaws) - Cloud security reviews (GCP, AWS, Azure, O365) - DevOps security reviews (Gitlab/hub, BitBucket, etc.) - Pre-SOC2 / investor readiness assessments - High-intensity black-box pentests Why Clients Hire Me - I go beyond the scan—I find what others miss - I understand both offense and architecture - I communicate clearly with both engineers and leadership - I’ve worked on MANY real-world, high-impact systems I also help organizations: - Investigate breaches - Contain active threats - Recover compromised systems (Note: I do not assist with social media account recovery.)

  • Security Analysis
  • Security Engineering
  • Web Application Security
  • Ethical Hacking
  • Penetration Testing
  • Certified Information Systems Security Professional
  • Security Assessment & Testing
  • OWASP
  • White Box Testing
  • Network Security
  • Security Infrastructure
  • Vulnerability Assessment
  • Web App Penetration Testing
  • Network Penetration Testing
  • Incident Management
Ameen K.

Booth, Texas

$65/hr
5.0
17 jobs

I'm a USA based consultant with 10+ years experience in penetration testing. I’ve led and executed over 500 assessments across diverse environments—web applications, internal/external networks, red/purple teams, cloud infrastructures, social engineering, mobile platforms, and even physical security. I’ve had the privilege of consulting for some of the biggest Fortune 500 companies, including PayPal, Berkshire Hathaway, TikTok, Meta, Tesla, Saudi Aramco, and more, delivering actionable insights to strengthen their security postures. Additionally, I spent over 9 months working alongside leading financial and social media companies, optimizing and expanding network infrastructures with 100,000+ devices, ensuring streamlined and secure operations at scale. Whether you're a small business or an enterprise, I bring proven expertise to identify vulnerabilities, mitigate risks, and secure what matters most. Let’s build a stronger, more resilient security framework together! 🔢 My stats are: ✅ Saved tens of thousands of dollars for Forbes 500 clients by identifying critical vulnerabilities ✅ Professional certifications (OSCP, GCPN,Security+) ✅ Top 10 in HackTheBox Team Global Rank ✅ Won 2022 DEF CON 30 CTF Competition ✅ Supporting all time zones ✅ Long-term engagements ✅ USA based ✅ Active LLC ✅ Active Liability insurance 🔢Core Competencies: 1. Network Penetration Testing 2. Web Application Penetration Testing 3. Social Engineering (Phishing, Vishing) 4. Cloud (Azure/AWS ) Penetration Testing 5. Security Training 6. Defensive Solution Configurations/Reviews (Security Engineering) 7. Malware Analysis 8. Cyber Risk Analysis 9. API Penetration Testing 10. Mobile Penetration Testing 11. External Network Penetration Testing 12. Vulnerability Assessment Testing ✅I love finding vulnerabilities. Whether those vulnerabilities exist in your firewall configuration, your employee training, or under your security fence, I will identify, triage, and alert you of threats before an attacker turns them into the next front page news story. 🔢Working with me, you will: ✅ Customized approach: I understand that every client's needs are unique, and I tailor my approach to meet your specific requirements. This ensures that you get the most comprehensive and effective security testing possible. ✅ Timely delivery: I understand that time is of the essence when it comes to security testing, and I always deliver my reports on time, without compromising on quality. ✅ Complete manual testing for your application and immediate notification if any high-impact issues are found. ✅ Unlimited retesting for the fixed issues and unlimited revisions ✅ Able to find critical bug classes that are often missed by automated pentests. 🔢NOTE: If you want to see my past reports I have done with previous clients know that reports contains sensitive information, NDA is signed for most of them especially from Gov & Forbes 500 clients. Disclosing information like that is breach of client privacy. However, I can share sample report with sensitive information hidden. Skills: Penetration Testing: Extensive experience conducting penetration tests, red team exercises, and purple team engagements across various platforms, including but not limited to, web applications, APIs, wireless, physical, network infrastructure, cloud environments (AWS & Azure), and other devices. Security Tools: Proficient in utilizing a wide range of security tools such as Burp Suite, Metasploit, C2 frameworks, Mythic, Sliver, bloodhound, etc. for penetration tests and red team operations. Defensive and Monitoring Technologies: Familiarity with defensive and monitoring technologies, including Intrusion Prevention Systems (IPS), Intrusion Detection Systems (IDS), Web Application Firewalls (WAF), and Security Information and Event Management (SIEM) solutions. Programming and Scripting: Proficient in scripting languages such as Python and Bash. Skilled in modifying and executing exploits and proof-of-concepts (POCs) to evade defensive countermeasures and emulate threat actor tactics, techniques, and procedures (TTPs). Cybersecurity Compliance: Familiar with security compliance requirements and industry standards, including MITRE ATT&CK, Cyber Kill Chain, HIPAA, NIST Cybersecurity Framework, and OWASP. Communication and Collaboration: Excellent communication and reporting skills to effectively communicate technical issues to both technical and non-technical stakeholders. Proven ability to work independently and collaboratively in a team environment.

  • Information Security
  • Compliance
  • Penetration Testing
  • Network Penetration Testing
  • Web App Penetration Testing
  • Cloud Security
  • Security Testing
  • NIST Cybersecurity Framework
  • Red Team Assessment
  • OWASP
Ashley H.

Greensburg, Pennsylvania

$40/hr
5.0
124 jobs

Working on a project? Trying to reach a goal? Let’s put a plan in place to get you there! We will build customized project goals and establish regular check ins to keep you accountable on your journey. Rates vary per project needs. Short term and long term projects from fitness to career goals accepted. Schedule a consultation today.

  • Human Resource Management
  • Administrative Support
  • Academic Writing
  • Data Entry
  • Proofreading
  • Article Writing
  • Copy Editing
  • Resume Writing
Christian P.

Portland, Oregon

$125/hr
5.0
8 jobs

Get it done right, closing attack paths, incident response, securing identity and cloud infrastructure, building detection/response programs. My specialties include: Incident Response & Threat Detection • 5+ years running IR (CrowdStrike EDR and NG-SIEM, SentinelOne, Defender for Endpoint, Microsoft Sentinel) • Rapid triage, scoping, containment, and root-cause analysis • Building high-fidelity detection logic + tuning noisy SIEMs • Automating repetitive analysis with SOAR/SIEM workflows Web Application & WordPress Security • Full compromise triage and cleanup of hacked WordPress sites • Removing injected malware, backdoors, malicious redirects, and spam payloads • Hardening themes/plugins, locking down admin access, and securing hosting • Continuous monitoring, WAF tuning, and patching workflows for long-term stability Security Engineering & Architecture • Designing scalable, resilient security controls across cloud and endpoint • Engineering detection pipelines, log architectures, and event normalization • Building Zero Trust patterns (network segmentation, identity-first access) • Integrating security tooling (EDR, SIEM, CSPM, SSPM, SAST/DAST) into dev and ops workflows Cloud & Identity Security (AWS • Azure • M365/Entra) • Hardening cloud tenants, IAM/Entra configurations, Conditional Access • Closing privilege-escalation paths and identity misconfigurations • Securing CI/CD, supply chain, and containerized workloads SOC Enablement & Security Program Uplift • Building SOC playbooks, IR runbooks, and triage workflows • Training SOC Tier 1–2 analysts to handle alerts confidently • Designing processes for detection review, alerting quality, and escalation Red/Purple Teaming & Attack Path Analysis • End-to-end assessments with clear PoCs, screenshots, and remediation • Threat modeling, external surface analysis, OSINT investigations • Purple-team sessions with your engineers to validate defensive coverage

  • Digital Forensics
  • Incident Response Readiness Assessment
  • Red Team Assessment
  • Vulnerability Assessment
  • CrowdStrike
  • Incident Response Plan
  • Cybersecurity Monitoring
  • NIST Cybersecurity Framework
  • Cyber Threat Intelligence
  • Threat Detection
  • Malware Removal
  • WordPress Malware Removal
  • System Administration
  • Microsoft Active Directory
Igor K.

San Diego, California

$90/hr
4.9
540 jobs

Senior WordPress Developer. Reliable and responsive. Result-oriented work. On time. "Top Rated Plus" Upwork premium freelancer, member of an Upwork PRO group. 14+ years skill in full-stack web site development (prototype, graphic design, front-end, back-end, SEO). Back end experience: PHP (WordPress, Laravel), C# (ASP .NET MVC, Web API, Entity Framework, Orchard, Kooboo, Umbraco). Front end experience: HTML5 / CSS3, SASS, LESS, Bootstrap 5, Html5 animation, JS, jQuery, AJAX, Json, Rest API, Angular 1-2-4, React.js, Vue.js, Node.js, Three.js. Other experience: Windows/Unix Server administration, Git, Azure, AWS and cloud solutions. In terms of WordPress can provide: ✔️ custom theme design or theme/template modification; ✔️ responsive HTML (will pass Google mobile-friendly test, work on any device and OS); ✔️ retina display support; ✔️ HTML5 animation if needed; ✔️ WordPress/Woo back end; ✔️ WordPress multisite and membership, BuddyPress, bbPress; ✔️ custom plugin development; ✔️ 3rd-party services and payment systems API integration; ✔️ SEO, make AMP compliant, setup CDN (Cloudflare); ✔️ support; ✔️ warranty. Great experience with: ✔️ e-commerce; ✔️ payment systems integration (PP, Stripe, Authorize.net and similar); ✔️ Google Maps API (custom design, clusters, routing, radius, speed/time/distances calculation, etc.); ✔️ responsive CRM and dashboards, high-traffic web-projects; ✔️ experience with Microsoft Power BI. Keep the warranty, always available, fast response and turnaround. === TAGS === WordPress Developer ; WordPress expert ; Fullstack developer.

  • WordPress
  • WooCommerce
  • PHP
  • WordPress Plugin
  • WordPress Development
  • Elementor
  • WordPress Theme
  • WordPress Security
  • WordPress Multisite
  • WordPress Customization
  • Web Design
  • CSS
  • JavaScript
  • HTML
  • Vue.js
Thomas W.

Colorado Springs, Colorado

$125/hr
5.0
6 jobs

"Top Rated Plus" cybersecurity consultant and published author with 25+ years of experience specializing in penetration testing. Clients hire me when they need senior-level testing that includes clear scoping, reporting that drives remediation, and efficient execution. I’ve led red team and penetration testing work for Fortune 100 enterprises, government agencies, and startups. My assessments are designed to simulate realistic attacker behavior, prioritize what matters most, and produce results that are easy for technical teams to reproduce and fix. Areas of expertise: * Web application testing (OWASP Top 10, authentication/session flaws, access control, input validation, SSRF, IDOR, RCE) * API testing (token/session handling, authorization boundaries, input validation, business logic, fuzzing where appropriate) * Internal and external network testing (Windows, Linux, hybrid) with segmentation and control validation * Active Directory testing (enumeration, privilege escalation simulation, attack path validation) * AWS and Azure security reviews (misconfigurations, IAM privilege analysis, exposure discovery, logging and monitoring validation) * Compliance-aligned testing and guidance (PCI DSS, HIPAA, CIS, NIST and more) What you can expect: * Strong communication, documented scope, and no surprises * Findings prioritized by real-world impact, not just scanner output * Executive summary plus actionable remediation steps your team can use immediately * Optional live debrief and remediation testing Certifications: CISSP, CCSP, ISSMP, AWS Security Specialty, AWS Solutions Architect, CCNP Security, and more. Published author of multiple penetration testing books and a frequent security conference speaker.

  • Application Security
  • Penetration Testing
  • Network Security
  • Network Penetration Testing
  • Cloud Security
  • Cybersecurity Management
  • Red Team Assessment
  • OWASP
  • Security Assessment & Testing
  • Certified Information Systems Security Professional
  • Kali Linux
  • Ethical Hacking
  • Web Testing
  • Vulnerability Assessment
  • Information Security

How it works

Post a job for freePost a job

Tell us what you need. Create your own job post or generate one with AI then filter talent matches.

Hire top talent fast

Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.

Collaborate easily

Use Upwork to chat or video call, share files, and track project progress right from the app.

Payment simplified

Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.

Don't just take our word for it

How do I hire a Application Security Freelancer in the United States on Upwork?

You can hire a Application Security Freelancer in the United States on Upwork in four simple steps:

  • Create a job post tailored to your Application Security Freelancer project scope. We'll walk you through the process step by step.
  • Browse top Application Security Freelancer talent on Upwork and invite them to your project.
  • Once the proposals start flowing in, create a shortlist of top Application Security Freelancer profiles and interview.
  • Hire the right Application Security Freelancer for your project from Upwork, the world's largest work marketplace.

At Upwork, we believe talent staffing should be easy.

How much does it cost to hire a Application Security Freelancer?

Rates charged by Application Security Freelancers on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.

Why hire a Application Security Freelancer in the United States on Upwork?

As the world's work marketplace, we connect highly-skilled freelance Application Security Freelancers and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Application Security Freelancer team you need to succeed.

Can I hire a Application Security Freelancer in the United States within 24 hours on Upwork?

Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Application Security Freelancer proposals within 24 hours of posting a job description.