Stop relying on automated scans. I find the vulnerabilities they miss.
I’m a senior penetration tester and vulnerability researcher with deep experience across enterprise networks, web apps / APIs and cloud platforms.
Most testers just run automated tools and hand you a generic report. I simulate how an attacker actually thinks, perform thorough testing, and deliver professional, tailored reporting suitable not just for your own remediation efforts but also for audit / compliance.
Benefits of manual testing:
- Chaining multiple low/medium findings to show more significant impact
- Breaking multi-tenant isolation
- Bypassing auth controls (JWT, OAuth, misconfigurations)
- Identifying cost-amplification / abuse vectors (e.g., billing attacks in serverless environments)
- ZERO false positives (and wasted time trying to remediate non-issues)
- REAL severity scoring (not just CVSS or ratings with no connection to actual impact/risk for your systems and data)
What I Deliver
- Manual, attacker-style testing (not just scans)
- Clear, prioritized findings with real business impact
- Proof-of-concept exploits where it matters
- Practical remediation guidance your devs can use immediately
- Optional retesting to verify fixes
Common Engagements
- SaaS / multi-tenant application security testing
- API and authentication testing (JWT, OAuth, session flaws)
- Cloud security reviews (GCP, AWS, Azure, O365)
- DevOps security reviews (Gitlab/hub, BitBucket, etc.)
- Pre-SOC2 / investor readiness assessments
- High-intensity black-box pentests
Why Clients Hire Me
- I go beyond the scan—I find what others miss
- I understand both offense and architecture
- I communicate clearly with both engineers and leadership
- I’ve worked on MANY real-world, high-impact systems
I also help organizations:
- Investigate breaches
- Contain active threats
- Recover compromised systems
(Note: I do not assist with social media account recovery.)
Security Analysis
Security Engineering
Web Application Security
Ethical Hacking
Penetration Testing
Certified Information Systems Security Professional
Security Assessment & Testing
OWASP
White Box Testing
Network Security
Security Infrastructure
Vulnerability Assessment
Web App Penetration Testing
Network Penetration Testing
Incident Management
Ameen K.
Booth, Texas
$65/hr
5.0
17 jobs
I'm a USA based consultant with 10+ years experience in penetration testing. I’ve led and executed over 500 assessments across diverse environments—web applications, internal/external networks, red/purple teams, cloud infrastructures, social engineering, mobile platforms, and even physical security.
I’ve had the privilege of consulting for some of the biggest Fortune 500 companies, including PayPal, Berkshire Hathaway, TikTok, Meta, Tesla, Saudi Aramco, and more, delivering actionable insights to strengthen their security postures.
Additionally, I spent over 9 months working alongside leading financial and social media companies, optimizing and expanding network infrastructures with 100,000+ devices, ensuring streamlined and secure operations at scale.
Whether you're a small business or an enterprise, I bring proven expertise to identify vulnerabilities, mitigate risks, and secure what matters most. Let’s build a stronger, more resilient security framework together!
🔢 My stats are:
✅ Saved tens of thousands of dollars for Forbes 500 clients by identifying critical vulnerabilities
✅ Professional certifications (OSCP, GCPN,Security+)
✅ Top 10 in HackTheBox Team Global Rank
✅ Won 2022 DEF CON 30 CTF Competition
✅ Supporting all time zones
✅ Long-term engagements
✅ USA based
✅ Active LLC
✅ Active Liability insurance
🔢Core Competencies:
1. Network Penetration Testing
2. Web Application Penetration Testing
3. Social Engineering (Phishing, Vishing)
4. Cloud (Azure/AWS ) Penetration Testing
5. Security Training
6. Defensive Solution Configurations/Reviews (Security Engineering)
7. Malware Analysis
8. Cyber Risk Analysis
9. API Penetration Testing
10. Mobile Penetration Testing
11. External Network Penetration Testing
12. Vulnerability Assessment Testing
✅I love finding vulnerabilities. Whether those vulnerabilities exist in your firewall configuration, your employee training, or under your security fence, I will identify, triage, and alert you of threats before an attacker turns them into the next front page news story.
🔢Working with me, you will:
✅ Customized approach: I understand that every client's needs are unique, and I tailor my approach to meet your specific requirements. This ensures that you get the most comprehensive and effective security testing possible.
✅ Timely delivery: I understand that time is of the essence when it comes to security testing, and I always deliver my reports on time, without compromising on quality.
✅ Complete manual testing for your application and immediate notification if any high-impact issues are found.
✅ Unlimited retesting for the fixed issues and unlimited revisions
✅ Able to find critical bug classes that are often missed by automated pentests.
🔢NOTE: If you want to see my past reports I have done with previous clients know that reports contains sensitive information, NDA is signed for most of them especially from Gov & Forbes 500 clients. Disclosing information like that is breach of client privacy. However, I can share sample report with sensitive information hidden.
Skills:
Penetration Testing: Extensive experience conducting penetration tests, red team exercises, and purple team engagements across various platforms, including but not limited to, web applications, APIs, wireless, physical, network infrastructure, cloud environments (AWS & Azure), and other devices.
Security Tools: Proficient in utilizing a wide range of security tools such as Burp Suite, Metasploit, C2 frameworks, Mythic, Sliver, bloodhound, etc. for penetration tests and red team operations.
Defensive and Monitoring Technologies: Familiarity with defensive and monitoring technologies, including Intrusion Prevention Systems (IPS), Intrusion Detection Systems (IDS), Web Application Firewalls (WAF), and Security Information and Event Management (SIEM) solutions.
Programming and Scripting: Proficient in scripting languages such as Python and Bash. Skilled in modifying and executing exploits and proof-of-concepts (POCs) to evade defensive countermeasures and emulate threat actor tactics, techniques, and procedures (TTPs).
Cybersecurity Compliance: Familiar with security compliance requirements and industry standards, including MITRE ATT&CK, Cyber Kill Chain, HIPAA, NIST Cybersecurity Framework, and OWASP.
Communication and Collaboration: Excellent communication and reporting skills to effectively communicate technical issues to both technical and non-technical stakeholders. Proven ability to work independently and collaboratively in a team environment.
Information Security
Compliance
Penetration Testing
Network Penetration Testing
Web App Penetration Testing
Cloud Security
Security Testing
NIST Cybersecurity Framework
Red Team Assessment
OWASP
Ashley H.
Greensburg, Pennsylvania
$40/hr
5.0
124 jobs
Working on a project? Trying to reach a goal?
Let’s put a plan in place to get you there!
We will build customized project goals and establish regular check ins to keep you accountable on your journey.
Rates vary per project needs. Short term and long term projects from fitness to career goals accepted. Schedule a consultation today.
Human Resource Management
Administrative Support
Academic Writing
Data Entry
Proofreading
Article Writing
Copy Editing
Resume Writing
Christian P.
Portland, Oregon
$125/hr
5.0
8 jobs
Get it done right, closing attack paths, incident response, securing identity and cloud infrastructure, building detection/response programs.
My specialties include:
Incident Response & Threat Detection
• 5+ years running IR (CrowdStrike EDR and NG-SIEM, SentinelOne, Defender for Endpoint, Microsoft Sentinel)
• Rapid triage, scoping, containment, and root-cause analysis
• Building high-fidelity detection logic + tuning noisy SIEMs
• Automating repetitive analysis with SOAR/SIEM workflows
Web Application & WordPress Security
• Full compromise triage and cleanup of hacked WordPress sites
• Removing injected malware, backdoors, malicious redirects, and spam payloads
• Hardening themes/plugins, locking down admin access, and securing hosting
• Continuous monitoring, WAF tuning, and patching workflows for long-term stability
Security Engineering & Architecture
• Designing scalable, resilient security controls across cloud and endpoint
• Engineering detection pipelines, log architectures, and event normalization
• Building Zero Trust patterns (network segmentation, identity-first access)
• Integrating security tooling (EDR, SIEM, CSPM, SSPM, SAST/DAST) into dev and ops workflows
Cloud & Identity Security (AWS • Azure • M365/Entra)
• Hardening cloud tenants, IAM/Entra configurations, Conditional Access
• Closing privilege-escalation paths and identity misconfigurations
• Securing CI/CD, supply chain, and containerized workloads
SOC Enablement & Security Program Uplift
• Building SOC playbooks, IR runbooks, and triage workflows
• Training SOC Tier 1–2 analysts to handle alerts confidently
• Designing processes for detection review, alerting quality, and escalation
Red/Purple Teaming & Attack Path Analysis
• End-to-end assessments with clear PoCs, screenshots, and remediation
• Threat modeling, external surface analysis, OSINT investigations
• Purple-team sessions with your engineers to validate defensive coverage
Digital Forensics
Incident Response Readiness Assessment
Red Team Assessment
Vulnerability Assessment
CrowdStrike
Incident Response Plan
Cybersecurity Monitoring
NIST Cybersecurity Framework
Cyber Threat Intelligence
Threat Detection
Malware Removal
WordPress Malware Removal
System Administration
Microsoft Active Directory
Igor K.
San Diego, California
$90/hr
4.9
540 jobs
Senior WordPress Developer. Reliable and responsive. Result-oriented work. On time.
"Top Rated Plus" Upwork premium freelancer, member of an Upwork PRO group.
14+ years skill in full-stack web site development (prototype, graphic design, front-end, back-end, SEO).
Back end experience: PHP (WordPress, Laravel), C# (ASP .NET MVC, Web API, Entity Framework, Orchard, Kooboo, Umbraco).
Front end experience: HTML5 / CSS3, SASS, LESS, Bootstrap 5, Html5 animation, JS, jQuery, AJAX, Json, Rest API, Angular 1-2-4, React.js, Vue.js, Node.js, Three.js.
Other experience: Windows/Unix Server administration, Git, Azure, AWS and cloud solutions.
In terms of WordPress can provide:
✔️ custom theme design or theme/template modification;
✔️ responsive HTML (will pass Google mobile-friendly test, work on any device and OS);
✔️ retina display support;
✔️ HTML5 animation if needed;
✔️ WordPress/Woo back end;
✔️ WordPress multisite and membership, BuddyPress, bbPress;
✔️ custom plugin development;
✔️ 3rd-party services and payment systems API integration;
✔️ SEO, make AMP compliant, setup CDN (Cloudflare);
✔️ support;
✔️ warranty.
Great experience with:
✔️ e-commerce;
✔️ payment systems integration (PP, Stripe, Authorize.net and similar);
✔️ Google Maps API (custom design, clusters, routing, radius, speed/time/distances calculation, etc.);
✔️ responsive CRM and dashboards, high-traffic web-projects;
✔️ experience with Microsoft Power BI.
Keep the warranty, always available, fast response and turnaround.
=== TAGS ===
WordPress Developer ; WordPress expert ; Fullstack developer.
WordPress
WooCommerce
PHP
WordPress Plugin
WordPress Development
Elementor
WordPress Theme
WordPress Security
WordPress Multisite
WordPress Customization
Web Design
CSS
JavaScript
HTML
Vue.js
Thomas W.
Colorado Springs, Colorado
$125/hr
5.0
6 jobs
"Top Rated Plus" cybersecurity consultant and published author with 25+ years of experience specializing in penetration testing. Clients hire me when they need senior-level testing that includes clear scoping, reporting that drives remediation, and efficient execution.
I’ve led red team and penetration testing work for Fortune 100 enterprises, government agencies, and startups. My assessments are designed to simulate realistic attacker behavior, prioritize what matters most, and produce results that are easy for technical teams to reproduce and fix.
Areas of expertise:
* Web application testing (OWASP Top 10, authentication/session flaws, access control, input validation, SSRF, IDOR, RCE)
* API testing (token/session handling, authorization boundaries, input validation, business logic, fuzzing where appropriate)
* Internal and external network testing (Windows, Linux, hybrid) with segmentation and control validation
* Active Directory testing (enumeration, privilege escalation simulation, attack path validation)
* AWS and Azure security reviews (misconfigurations, IAM privilege analysis, exposure discovery, logging and monitoring validation)
* Compliance-aligned testing and guidance (PCI DSS, HIPAA, CIS, NIST and more)
What you can expect:
* Strong communication, documented scope, and no surprises
* Findings prioritized by real-world impact, not just scanner output
* Executive summary plus actionable remediation steps your team can use immediately
* Optional live debrief and remediation testing
Certifications: CISSP, CCSP, ISSMP, AWS Security Specialty, AWS Solutions Architect, CCNP Security, and more. Published author of multiple penetration testing books and a frequent security conference speaker.
Application Security
Penetration Testing
Network Security
Network Penetration Testing
Cloud Security
Cybersecurity Management
Red Team Assessment
OWASP
Security Assessment & Testing
Certified Information Systems Security Professional
Kali Linux
Ethical Hacking
Web Testing
Vulnerability Assessment
Information Security
How it works
Post a job for freePost a job
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a Application Security Freelancer in the United States on Upwork?
You can hire a Application Security Freelancer in the United States on Upwork in four simple steps:
Create a job post tailored to your Application Security Freelancer project scope. We'll walk you through the process step by step.
Browse top Application Security Freelancer talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top Application Security Freelancer profiles and interview.
Hire the right Application Security Freelancer for your project from Upwork, the world's largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a Application Security Freelancer?
Rates charged by Application Security Freelancers on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a Application Security Freelancer in the United States on Upwork?
As the world's work marketplace, we connect highly-skilled freelance Application Security Freelancers and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Application Security Freelancer team you need to succeed.
Can I hire a Application Security Freelancer in the United States within 24 hours on Upwork?
Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Application Security Freelancer proposals within 24 hours of posting a job description.
Find more freelancers
Top states for Application Security Freelancers in the United States