Hello! I'm Samarth, a Cyber Security Engineer and Ethical Hacker with a passion for safeguarding digital assets and securing online environments.
I have done more than 27+ VAPT projects. With over 7 years of hands-on experience in the field, I've honed my skills working with esteemed enterprise companies such as Noreg Ltd and FedEx, where I've tackled complex security challenges head-on.
🛡️ Expertise:
- Cyber Security Solutions
- Ethical Hacking
- Network Security
- Malware Analysis
- Cryptography
- Social Engineering
- Cloud Security
- Identity and Access Management (IAM)
- Security Operations Center (SOC) Management
- Vulnerability Assessment
- Penetration Testing
- Incident Response and Digital Forensics
- Web Application Security
- Security Architecture Design
🎓 Certifications:
- Certified Information Systems Security Professional (CISSP)
- Certified Ethical Hacker (CEH)
- CompTIA Security+
- Certified Information Security Manager (CISM)
- Certified Cloud Security Professional (CCSP)
- EC-Council Certified Security Analyst (ECSA)
- Certified Offensive Security Expert (OSCE)
- Offensive Security Certified Professional (OSCP)
- Certified Information Systems Auditor (CISA)
- GIAC Penetration Tester (GPEN)
- Cisco Certified CyberOps Associate
💼 Previous Experience:
- SaveAs Ltd (Senior Information Security Consultant, Auditor) - 2006
- Noreg Ltd. (Information Security Consultant, Auditor) - 2009
- AXA Group Hungary - Information Security Professional, IT audit manager - 2012
- Vodafone Group - Technology Security Project Manager - 2014
- TES Global Solutions - Lead Information Security operation consultant and architect - 2017
- BDO UK LLP - Information Security operation consultant and engineer - 2017
- FedEx - Global Security Operation Consultant - 2018
- Royal Bank of Scotland - Cyber Security Engineer - 2019
- Security-Consultan - Principal Security, Compliance and Certification consultant - 2022
🏆 Accomplishments:
➡️Successfully Conducted Advanced Penetration Tests on High-Profile Systems
[Performed comprehensive penetration testing on critical infrastructure for clients, identifying and mitigating multiple high-risk vulnerabilities, which helped prevent potential data breaches and strengthened overall security posture.]
➡️Developed a Custom Exploit Detection System
[Designed and implemented a proprietary system for detecting zero-day exploits in real-time,
significantly enhancing the organization's ability to identify and respond to sophisticated
attacks before they could cause damage.]
➡️Led a Major Incident Response and Forensics Investigation
[Headed an incident response team during a high-profile security breach, quickly containing
the threat performing an in-depth forensic analysis that led to the identification of
the attacker's tactics, techniques, and procedures (TTPs), and the improvement of future
defense strategies.]
➡️Achieved Industry-Recognized Certifications in Cybersecurity
[Earned multiple certifications in cybersecurity and ethical hacking, including CEH, OSCP, and
CISSP, which demonstrate a commitment to professional growth and expertise in
identifying, assessing, and mitigating cyber risks.]
I'm committed to delivering top-notch security solutions tailored to your specific needs, whether you're an individual, a small business looking to fortify your defenses, or a large enterprise seeking to mitigate sophisticated cyber threats.
Let's collaborate to protect your digital assets and uphold the confidentiality, integrity, and availability of your information. Reach out to me today, and let's make your online environment secure!
Amazon Web Services
Virus Removal
Web Service
Web Services Development
XML Web Services
Management Accounting
Accounting
Amazon
Web Application
Accounting Basics
Cyber Threat Intelligence
CyberARK
CyberGrants
Cyberlink PowerDirector
Sundar Lal B.
Bengaluru, India
$28/hr
5.0
2 jobs
I'm Sundar Lal, a CISSP | CPENT | CEH-certified penetration tester and ethical hacker with 5+ years of professional experience securing web applications, mobile apps, APIs, networks, and cloud infrastructure. Previously worked as Cloud Security Engineer at MyGate, Associate Security Engineer at Tekion, and Mobile Security Researcher at Clypeum AI — giving me real-world attacker context that most freelancers lack.
Why hire me over other testers? My bug bounty track record proves I find what automated scanners miss. I've discovered critical IDOR, Authentication Bypass, SQL Injection, XSS, and CSRF vulnerabilities in Fortune 500 companies. That mindset is what I bring to every client engagement.
🔐 Penetration Testing and Security Services:
✅ Web Application Penetration Testing (Black Box / White Box / Grey Box)
✅ Mobile App Security Testing — Android and iOS (DAST and SAST)
✅ API Security Testing — REST, SOAP, GraphQL
✅ Network Penetration Testing and Vulnerability Assessment
✅ Reverse Engineering — Android/iOS APKs, obfuscation bypass, API extraction
✅ Cloud Security Audits (AWS)
✅ Red Teaming and Ethical Hacking
✅ Malware / Ransomware Analysis and Incident Response
📋 What you receive:
✔ A detailed professional penetration testing report with PoC screenshots, CVSS scores, and step-by-step remediation
✔ Assessments aligned with OWASP, NIST, CREST, and PTES standards
✔ Free re-test after fixes — to confirm vulnerabilities are actually patched
✔ Clear communication throughout, not just a report at the end
🛠️ Tools I work with:
Burp Suite Pro · Acunetix Pro · Nessus · Metasploit · Nmap · SQLMap · Wireshark · JADX-GUI · Apktool · FRIDA · MobSF · OWASP ZAP · Postman · Splunk
📩 Ready to secure your application? Message me with your scope and I'll respond within a few hours with a clear plan.
Ethical Hacking
Penetration Testing
Vulnerability Assessment
Information Security
Code Review
Security Analysis
Cloud Security
Website Security
Web App Penetration Testing
Security Assessment & Testing
Network Security
Malware Removal
WordPress Malware Removal
WordPress Bug Fix
Malware Website
Anmol T.
Noida, India
$10/hr
5.0
2 jobs
🚨 If your application, SaaS platform, or cloud environment has never undergone a professional security assessment, you may have unknown vulnerabilities that attackers can exploit.
I’m a Certified Penetration Tester and Ethical Hacker providing Vulnerability Assessment and Penetration testing (VAPT) services for web applications, APIs, cloud infrastructure, mobile apps, SaaS platforms, and network environments. My goal is not just to find vulnerabilities — but to help you understand real security risks and fix them effectively.
I perform manual penetration testing supported by professional security tools to identify exploitable weaknesses such as authentication flaws, privilege escalation paths, injection vulnerabilities, and business logic issues.
You will receive a clear and actionable security report that helps developers resolve issues and allows management to understand the real business impact.
🎯 My Services
- Vulnerability Assessment & Penetration Testing (VAPT)
- Web Application Penetration Testing (OWASP Top 10)
- API Penetration Testing (REST, GraphQL, authentication flaws, IDOR, injection)
- Cloud Infrastructure Security (AWS, Azure — misconfigurations, IAM, exposed services)
- Network Penetration Testing (internal & external)
- Mobile Application Security (Android & iOS)
- SaaS Platform Security & Penetration Testing (multi-tenant logic, RBAC, privilege escalation)
- CMS Security (WordPress, Laravel, custom apps)
- Retesting after remediation
📋 What You Will Receive
A clear, structured security report designed for both technical teams and business stakeholders, including:
• Executive summary for management and decision-makers
• Detailed vulnerability findings with severity ratings
• CVSS scoring and risk prioritization
• Proof-of-concept evidence (screenshots, request/response captures)
• Business impact explanation for each issue
• Step-by-step remediation guidance for developers
• Retesting validation after fixes are applied
• Reporting that can support ISO 27001 and SOC 2 compliance preparation
🏆 Certifications
- Certified Ethical Hacker Practical — EC-Council
- eLearnSecurity Junior Penetration Tester (eJPT) — INE
- Certified API Penetration Tester — APISec University
- IBM Cybersecurity Analyst
- Cisco Verified Ethical Hacker
- ISO 27001:2022 Lead Auditor
🛠️ Tools I work with
Burp Suite Pro, OWASP ZAP, Nmap, Nessus, Metasploit, MobSF, Wireshark, Postman, and custom Python/Bash scripts and so on.
Whether you're preparing for a security review, compliance audit, or investor due diligence, I can help you understand your attack surface and security risks.
📩 Send me your scope or asset list and I’ll help you determine the best testing approach.
Penetration Testing
Information Security
Web Application Security
Web App Penetration Testing
John M.
Bengaluru, India
$89/hr
5.0
48 jobs
🔢 As an Upwork Top 1% Expert Vetted 👑 OSCP+, Certified Ethical Hacker and an Experienced Penetration Tester with 10+ years of experience Penetration Testing Web SaaS and Mobile based applications and networks, every flaw tells a story; I write the ending and specialize in helping my clients strengthen their cybersecurity defenses.
An average Cybersecurity Incident in your business can you cost you anywhere between $120,000+ to $1.24+ million and even a 10%+ reduction in risk can save your business nearly $124,000+ and hiring a full time in-house team can cost you $100,000+ per employee per year. That is why you need an expert like me to protect your business and reduce your business risk.
What makes me stand out from other freelancers is the fact that I am also a Cybersecurity Architect, capable of architecting solutions to enhance the security of your organisation and preserving the security and integrity of your data.
I have always been passionate about solving technical problems for my clients through Pen Testing and I don't rest till I get to the root of the problem and solve it.
What I can offer?
I can help you secure your business by providing the following services:
✅ Web/Mobile Application Penetration Testing,
✅ Secure Source Code Analysis,
✅ Network Penetration Testing,
✅ Secure Architecture Review,
✅ API Security Testing,
✅ SOC 2, ISO 27001, PCI DSS, AMAZON SP and Compliance-Oriented Penetration Test Reports
✅ Secure Code Review,
✅ CASA Assessment,
✅ Red Team Assessment,
✅ Phishing Simulations & Assessment.
Why Choose Me?
🧑🏼💼 Client-Centric Approach: Your security is my top priority. I work closely with your team to understand your objectives and deliver tailored services that align with your business goals. Trust and transparency are the cornerstones of my practice, and I am committed to helping you navigate the complex landscape of cybersecurity with confidence and achieve compliance.
📐 Comprehensive Security Assessments: I conduct detailed SOC Type 2 / ISO compliant evaluations to identify vulnerabilities in your network, applications, and infrastructure.
✂️ Tailored Solutions: Every organization is unique. I customize my approach to meet your specific security needs and industry standards.
🎬 Actionable Recommendations: Post-assessment, I provide clear, concise, and practical remediation steps to address identified vulnerabilities.
🔁 Ongoing Support: Cybersecurity is an ongoing process. I offer continuous support and re-assessment to ensure your defenses remain robust against evolving threats
🌏 Holistic Approach: I don't just patch vulnerabilities; I architect comprehensive security solutions that align with business goals. My focus extends beyond the technical to encompass risk management and organizational resilience.
🗨️ Collaborative Communicator: I bridge the gap between technical jargon and business language, fostering understanding across teams. Effective communication is key to successful security implementation.
🏫 Continuous Learning: The threat landscape evolves, and so do I. Whether it's a new attack vector or an emerging technology, count me in. Learning is my superpower.
🙋♂️ Key Skills:
✔️ Penetration Testing & Vulnerability Assessment: I thrive on dissecting systems, identifying weaknesses, and recommending robust solutions. Armed with tools like Kali Linux, Metasploit, Nmap, and Wireshark, I delve into web applications, networks, and APIs. But here's the twist—I don't stop at discovery; I offer a free retest after remediation to ensure vulnerabilities stay sealed.
✔️ Network Security: I've designed and implemented secure network architectures, ensuring data confidentiality, integrity, and availability. Firewalls, intrusion detection systems, and VPNs—my toolkit covers it all.
✔️ Cloud Security: Proficient in securing cloud environments especially Amazon Web Services (AWS) & Oracle Cloud Infrastructure (OCI). I stress-test cloud deployments ensuring they withstand real-world attacks.
✔️ Secure Coding Practices: I advocate for secure coding principles using tools like SonarQube and collaborate with development teams to build resilient applications. Prevention beats cure, every time.
⛏️Tools I Use
☑️ Penetration Testing: Nmap, Metasploit, Burp Suite Professional, Wireshark, SQLmap, Kali Linux
☑️ Programming & Scripting Skills: Python, Bash, PowerShell, JavaScript, Java and C#
☑️ Security Frameworks & Standards: OWASP, NIST, CASA, CIA Triad, PCI-DSS
🫱🏽🫲🏽 Let's Connect: Ready to enhance your business/organization's security? Let's chat! Reach out to me here on Upwork, and let's build a safer digital future together.
🟢 Press '...' button and then ‘Send Message’ button in the top right-hand corner ✉️
🚫 No hacking service - I do not provide any hacking services, and I will not engage in any activities that involve gaining unauthorized access to any accounts, systems, or social media platforms. Requests for such services will be declined.
Penetration Testing
Vulnerability Assessment
Network Penetration Testing
Security Testing
Security Assessment & Testing
Information Security
Application Security
Web Application Security
Network Security
System Security
Web App Penetration Testing
Website Security
Black Box Testing
OWASP
Risk Assessment
ISO 27001
SOC 2
SOC 2 Report
PCI DSS
IT Compliance Audit
Chatak V.
Pune, India
$9/hr
5.0
21 jobs
Cybersecurity expert, offering expertise to help protect companies, organizations, and agencies from malicious attacks. I am experienced in working with Fortune 800 brands, multinational companies, government, military, and intelligence agencies.
🛡️As a Certified Penetration Tester, I search for weaknesses, business logic mistakes, and weak end-points, among other things, in the following areas:
➜ Web Application Security (WebApp Pentesting)
➜ Website Security
➜ Mobile Apps
➜ Web Assets
➜ Network
➜ Server
➜ Any internet-connected product or device.
🎯 Types of Cyber Security Services:
➜ Penetration Testing (External & Internal)
➜ Vulnerability Assessment
➜ Gap Analysis
➜ Internet Security
➜ Security Analysis
➜ Web Testing
➜ Network Security
➜ 24x7 Monitoring, Managed SOC
➜ Digital Forensics
➜ Risk Assessment
➜ Black Box Penetration Testing
➜ Red Teaming Operations
📟 In the security assessment, I will conduct a thorough security check and cover the following topics:
➜ Web Application vulnerabilities (SQLi, XSS, CSRF, unpatched software libraries, OWASP, etc.).
➜ Open ports on your hosting server.
➜ Exposed Credentials for your domain across the dark web.
➜ Email security issues that affect your email deliverability.
➜ SSL Certificate security issues (detect misconfigurations).
➜ Exposed subdomains.
➜ IP address information and malware infections on your website.
➜ Domain name information and security issues (domain expiry date, name servers, etc.).
🌟 I will offer you a complete pentesting report on vulnerabilities that I will create using a set of methods and manual approaches that I have built publically accessible scripts, and professional automated techniques.
🌟 The pentesting report will include a detailed explanation of how to reproduce vulnerabilities and remediation/patch/fix procedures.
👨🏼💻Since 2013, I've been compromising and pentesting online systems, and I have professional knowledge in the following areas:
➜ Web Application Pentesting.
➜ Red Teaming
➜ Mobile Application Assessments (Android & iOS)
🌟 We will discuss specific recommendations for your further actions and support you in the further procedure even after the review.
Ethical Hacking
Penetration Testing
Vulnerability Assessment
Security Testing
Web App Penetration Testing
Kali Linux
Website Security
Information Security
Application Security
OWASP
White Box Testing
Black Box Testing
Web Application Security
Information Security Audit
Internet Security
Virus Removal
Amit S.
Delhi, India
$12/hr
4.9
41 jobs
Hi, I am Amit Singh and having 10+ years of significant and well-diversified experience in Cybersecurity domains, including ⭐Web Application penetration testing (SaaS, Cloud etc.)⭐Network Penetration testing(Servers, Active Directory, IoT etc.)⭐Web API pen-testing ⭐Mobile penetration testing (android & iOS)⭐Web 3.0 DApps & Smart Contract pen-testing (Blockchain technology)⭐ Source Code Review etc.
🏆Top Rated Profile on Upwork
✅I have performed penetration tests & vulnerability assessments and delivered professional reports to companies all over the world in accordance with:
☑️ Offensive Security (OSCP) standards
☑️ OWASP Top 10 Vulnerability
☑️ OWASP API Security Top 10 Vulnerability
☑️ OWASP Mobile Security Top 10 Vulnerability
☑️ Application Security Verification Standard 4.0 (ASVS 4.0)
☑️ CWE Top 25 Most Dangerous Software Errors
☑️ ISO 27001 Penetration Testing
☑️ Payment Card Industry Data Security Standard (PCI DSS)
☑️ General Data Protection Regulation (GDPR)
☑️ Common Vulnerability Scoring System (CVSS)
☑️ Open Source Security Testing Methodology Manual (OSSTMM)
✅ Cybersecurity Certifications:-
☑️ Certified eLearnSecurity Web application penetration tester (eWPT)
☑️ Certified API Security Professional( CASP)
☑️Certified Ethical hacker(CEH)
✅ The deliverable will be a professional Penetration Testing/Vulnerability Assessment report which includes:
☑️ Executive Summary
☑️ Assessment Methodology
☑️ Type of Tests
☑️Risk Level Classifications
☑️ Result Summary
☑️ Table of Findings
☑️ Detailed Findings. Each finds listed within the report will contain a CVSS score, Issue Description, Proof of Concept, Remediation, and Reference sections.
✅ Tool List (Acunetix, Nessus, BurpSuite Professional, Nmap, Netsparker, Metasploit Framework, OpenVAS, Mimikatz, SQLmap, Nikto, checkmax and Zaproxy etc.
Note-For more info lets connect over the chat section. Thanks
Ethical Hacking
Penetration Testing
Vulnerability Assessment
Security Testing
Network Security
Web Application Security
Network Penetration Testing
Internet Security
Information Security Audit
Website Security
API Testing
OWASP
Code Review
Web App Penetration Testing
Security Assessment & Testing
How it works
Post a job for freePost a job
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a Certified Ethical Hacker in India on Upwork?
You can hire a Certified Ethical Hacker in India on Upwork in four simple steps:
Create a job post tailored to your Certified Ethical Hacker project scope. We'll walk you through the process step by step.
Browse top Certified Ethical Hacker talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top Certified Ethical Hacker profiles and interview.
Hire the right Certified Ethical Hacker for your project from Upwork, the world's largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a Certified Ethical Hacker?
Rates charged by Certified Ethical Hackers on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a Certified Ethical Hacker in India on Upwork?
As the world's work marketplace, we connect highly-skilled freelance Certified Ethical Hackers and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Certified Ethical Hacker team you need to succeed.
Can I hire a Certified Ethical Hacker in India within 24 hours on Upwork?
Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Certified Ethical Hacker proposals within 24 hours of posting a job description.