Hire the Best Certified Information Systems Auditors

More than 3,000 reviews on G2
Rating is 4.5 out of 5.
4.5/5
of Upwork by G2 peer reviewers
Attila H.

Dublin, Ireland

$135/hr
4.9
445 jobs

๐—ฌ๐—ผ๐˜‚ ๐—ณ๐—ผ๐—ฐ๐˜‚๐˜€ ๐—ผ๐—ป ๐˜†๐—ผ๐˜‚๐—ฟ ๐—•๐—จ๐—ฆ๐—œ๐—ก๐—˜๐—ฆ๐—ฆ, and leave the rest to me! Sell to Disney, Amazon, Pfizer, Uber, Siemens, Google, PWC, L'Orรฉal, Bank of America, etc, and unlock business opportunities and growth (๐Ÿ’ฒmillions) by being secure and compliant by working together. 150+ certifications and attestations for SOC 2, ISO 27001, CMMC, GDPR, and HIPAA projects on Upwork. I now focus on aligning AI innovation with frameworks like ISO 42001, the EU AI Act, and NIST AI RMF. CEO selling to Morgan Stanley: ๐Ÿฅ‚"The certification is enabling us to strike a deal with a Fortune 100 client." CEO selling to Philips: ๐Ÿพ "We have achieved the ISO 27001:2022 certification in record time." CEO selling to Pepsi:๐ŸŽ‰ "Attila supported the growth of our business into Fortune 100 accounts." COO selling to Fannie Mae:๐Ÿ‘ "We achieved a successful SOC 2 Type II attestation with no exceptions." One-stop shop for all your needs: security questionnaires, AI compliance, privacy assessments, risk assessments, policies, and technical implementation, including AV, EDR, endpoint device management, and secure configuration, DLP, cloud hardening (AWS, Azure, GCP), vulnerability scans, and penetration testing with continuous security operation! As the founder of ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜†-๐—ฐ๐—ผ๐—ป๐˜€๐˜‚๐—น๐˜๐—ฎ๐—ป๐˜.๐—ฐ๐—ผ๐—บ I know that in the B2B space, you need Security, Privacy, and Compliance to sell to Enterprises! Sleep well overnight because you know you are in good hands with the ๐Ÿฅ‡ Upwork virtual CISO, Security, Privacy, and Compliance consultant (1 M+ earnings, 20+ years of enterprise experience)! ๐Ÿ’ญSecuring your business, passing security assessments by clients or prospects, and achieving a security certification ๐™จ๐™๐™ค๐™ช๐™ก๐™™ ๐™ฃ๐™ค๐™ฉ ๐™—๐™š ๐™– ๐™˜๐™ช๐™ข๐™—๐™š๐™ง๐™จ๐™ค๐™ข๐™š ๐™–๐™ฃ๐™™ ๐™ฅ๐™–๐™ž๐™ฃ๐™›๐™ช๐™ก ๐™š๐™ญ๐™š๐™ง๐™˜๐™ž๐™จ๐™š. ๐Ÿ‘Œ All you need to do is ping me on Upwork, bring your problem, and after a 15-minute scoping call, I will provide you with a detailed Scope of Work, including pricing! Specializing in business-to-business clients, providing ๐Ÿ’ธmoney-back guaranteed๐Ÿ’ธ ISO 27001, ISO 42001, SOC 2, EU AI Act, GDPR, HIPAA, PCI-DSS, CMMC, and FedRAMP projects and affordable virtual CISO (vCISO) services. --> If you donโ€™t get certified, all my fees will be refunded! <-- ๐™’๐™š ๐™–๐™ง๐™š ๐™– ๐™œ๐™ค๐™ค๐™™ ๐™ข๐™–๐™ฉ๐™˜๐™ ๐™ž๐™› ๐™ฎ๐™ค๐™ช ๐™–๐™ง๐™š: ๐Ÿค” Want to understand the ๐™–๐™˜๐™ฉ๐™ช๐™–๐™ก ๐™˜๐™ค๐™จ๐™ฉ for implementation and maintenance of the security controls? ๐Ÿ˜ขBusy developing your product or business and not having time and resources to be consumed by compliance efforts and endless meetings, halting your production for months. ๐Ÿค”Already purchased a DIY compliance tool (Drata, Vanta, Thoropass/HeyLaika, Sprinto, Tugboat Logic, SecureFrame, Strike Graph, Audit Board, Trust Cloud, and so on) but ๐™™๐™ค๐™ฃโ€™๐™ฉ ๐™ ๐™ฃ๐™ค๐™ฌ ๐™ฉ๐™๐™š ๐™ฃ๐™š๐™ญ๐™ฉ ๐™จ๐™ฉ๐™š๐™ฅ ๐™ค๐™ง ๐™™๐™ค๐™ฃโ€™๐™ฉ ๐™๐™–๐™ซ๐™š ๐™ฉ๐™ž๐™ข๐™š. ๐Ÿ˜ขYou quickly need quick security or privacy awareness training, cloud security posture assessment (AWS, GCP, Azure), endpoint security (MS 365 - Intune, Jumpcloud, Google Workspace), or penetration testing? ๐Ÿ’ชFacing challenges with the security and privacy implications of AI products? ๐Ÿ’ชWant continuous access to a certified, credible security, compliance, and privacy professional to manage your security framework? -> Continuous virtual CISO (vCISO / fractional CISO) service with affordable weekly/monthly payments! ๐Ÿ˜ŸNeed world-class, battle-proof security and privacy policies, and you need it quickly? These are the ones that have passed audits by KPMG, Deloitte, E&Y, Pepsi, Uber, Verizon, Philips, Facebook, and many others. Working with me, you will: โ— Stop struggling with compliance requirements, security questionnaires, or useless document templates. โ— Make the first steps on the journey to selling Enterprises โ— Receive a turnkey, Enterprise-grade security operation framework ensuring long-term effectiveness โ— Work with an experienced senior team (architects, pen testers, endpoint engineers, developers, auditors, consultants) that regularly helps clients score Enterprise accounts. My stats are: โœ…Saved tens of thousands $$$$$ for clients, advising them on the right security tools, solutions, and approach โœ…#1 in Information Security and IT compliance categories (1 M+ earned) โœ…Supporting all time zones โœ…Long-term engagements โœ…Professional certifications (CISA, CISSP, ISO 27001 IA) QUALITY over QUANTITY is our ethos. Excellent quality, on time, always. Security questionnaire and vendor assessment tools: CyberGRX, Panorays, KY3P (S&P, PWC), RSM, CyberVadis, SIG, SIG Lite, CAIQ, VAS, HECVAT, OneTrust, Graphite Connect, Centrl, Whistic, Process Unity Security/Compliance frameworks: ISO 27001, SOC 2, FedRAMP, NIST 800-53, NIST 800-171, NIST CSF, TISAX, HIPAA, HITRUST CSF, GDPR, NERC, ISO 27017, ISO 27018, CMMC, CMMI, TX-RAMP, StateRAMP, AZ-RAMP, NY DFS 23 / NYCRR Part 500, PCI-DSS, FFIEC, C5, ENISA, Center of Information Security (CIS) CSAT, IRAP, PIPEDA, ISO 42001, NIST AI RMF, EU AI Act

  • SOC 2
  • Information Security Consultation
  • AI Security
  • Information Security
  • Certified Information Systems Security Professional
  • SOC 2 Report
  • GDPR
  • Governance, Risk & Compliance Software
  • IT Compliance Audit
  • Penetration Testing
  • Information Security Audit
  • AI Compliance
  • AI Governance
  • AI Policy
  • ISO 27001
Ali H.

Manama, Bahrain

$20/hr
4.9
176 jobs

Trusted Advisor ๐Ÿฅ‡ ๐Ÿš€ Get Audit-Ready in 6 Weeks โ€” Guaranteed. Confused by compliance? I translate complex regulations into simple, actionable steps. Whether you need to win enterprise trust with ISO 27001 or unblock sales with a SOC 2 report, I provide the fastest, most cost-effective path to certification. Why hire a consultant when you can hire a Strategic Partner? As the Founder of Axipro, Iโ€™ve led over 100 successful certifications in the last year alone. We don't just "give advice"โ€”we handle the heavy lifting. ๐Ÿ›  THE GRC TOOL EXPERT Are you struggling with your automated GRC platform? I am an official partner and power user of: โœ… Drata (Gold Partner) โœ… Vanta (Expert Implementation) โœ… Secureframe, Thoropass, Sprinto, Scrut, & more. I can help you get your progress running in record time and even provide discounted subscription rates through our MSSP partnership. ๐Ÿ›ก ONE-STOP COMPLIANCE SHOP - Policies & Procedures: Custom-tailored, audit-ready documentation. - Risk Management: Deep-dive assessments that protect your business. - Security Questionnaires: Get them off your desk and submitted in hours, not weeks. - Vulnerability Assessment and Penetration Testings: Remediation recommendations and detailed reports to improve security posture - CPA Attestation: We have in-house CPAs to sign off on your SOC 2 Type 1 & 2 reports. ๐ŸŒ GLOBAL STANDARDS COVERED ISO 27001, 9001, 14001, 45001, 27701, 27017, 27018, 42001 (AI) | SOC 2 Type 1 & 2 | HIPAA | PCI DSS | GDPR | FedRAMP | NIST CSF | CMMC | TISAX | HITRUST | SAMA NCA โญ WHAT CLIENTS ARE SAYING "Ali is a lifesaver. He got us SOC 2 certified through Vanta and saved us months of work." โ€” Founder, Druxia (USA) "Knowledgeable, professional, and incredibly responsive. Ali got us across the line with Drata for ISO 27001." โ€” Founder, Tilt Legal (AUS) ๐Ÿ’Ž THE AXIPRO ADVANTAGE 10+ Years Experience: Lead Engineer & Auditor minds

  • SOC 2
  • ISO 27001
  • IT Compliance Audit
  • HIPAA
  • SOC 2 Report
  • PCI DSS
  • AI Compliance
  • Data Privacy
  • GDPR
  • Governance, Risk Management & Compliance
  • Penetration Testing
  • Information Security Consultation
  • AI Governance
  • AI Security
  • CMMC
  • ISO 14001
Aryan G.

Jaipur, India

$10/hr
4.4
12 jobs

Accounting & Audit Professional | US, UK, Canada & Australia | QuickBooks, Xero, Zoho, Bill.Com, CCH, CaseWare, Advance Flow With over 5 years of progressive experience in accounting, bookkeeping, and auditing, I have successfully managed end-to-end financial operations for 30+ clients across the US, Canada, and Australia. My expertise spans a broad range of services, including bookkepping, accounts payable/receivable, bank reconciliations, payroll management, general ledger maintenance, invoicing, financial reporting, Quickbooks Cleanup and internal control testings. In the audit domain, Iโ€™ve led financial statement audits, Single audits, employee benefit plan (EBP) audits, and state compliance audits. I manage complete audit lifecycles from planning and risk assessment to substantive testing, controls evaluation, and final report issuance. Iโ€™m well-versed in audit analytics using tools like IDEA and Datasnipper, and in secure documentation workflows through Suralink. Academically, I hold an MBA in Finance from Amity University and am actively pursuing the US CPA. I bring strong technical acumen, attention to detail, confidentiality, and the ability to meet tight deadlinesโ€”all while delivering high-quality outcomes that support strategic decision-making and business growth. โœ… Core Services โ€ข Bank & Credit Card Reconciliations โ€ข A/P & A/R Management โ€ข Payroll & Tax Filings (Superannuation, HMRC, GST) โ€ข Monthly Reporting โ€“ P&L, Balance Sheet, Cash Flow โ€ข Budgeting, Forecasting & Variance Analysis โ€ข Financial Statement Preparation โ€ข Cleanup / Catch-up Projects โ€ข QuickBooks & Xero Setup and Maintenance โ€ข Journal Entries & Ledger Management โ€ข Internal Audit Support & Financial Controls ๐Ÿ’ก Software Expertise โ€ข QuickBooks Online & Desktop โ€ข Xero โ€ข SAP, NetSuite, Wave, Zoho Books, SAGE โ€ข Bill.com, Stripe โ€ข Excel, Google Sheets, Trello, Slack, Zoom โ€ข Caseware, CCH Engagement and Advance Flow

  • Financial Audit
  • Intuit QuickBooks
  • Accounts Receivable
  • Accounts Payable
  • Financial Statement
  • Microsoft Office
  • Cash Flow Statement
  • Accounts Receivable Management
  • Accounts Payable Management
  • Xero
  • Balance Sheet
  • Zoho Projects
  • Accounting
  • Bookkeeping
  • QuickBooks Online
Saif Ur R.

Lahore, Pakistan

$20/hr
4.9
501 jobs

๐Ÿ†๐ŸŽ–๏ธ Top Rated Plus Upwork Freelancer ๐Ÿ‘‹ Hi, Iโ€™m Saif Ur Rehman, Certified ISO & HSE Consultant and Qualified Engineer with a strong reputation for delivering high-impact compliance solutions, Audit-ready documentation, and tailored ISO Management systems across diverse companies. With a passion for excellence and a deep understanding of International Standards, I help businesses achieve operational efficiency, regulatory compliance, and sustainable growth through expertly crafted ISO, HSE, WHS, and risk management framework all documentation. ๐Ÿ“Œ My Services ๐Ÿ“„ ISO Documentation, Gap Analysis, Implementation & Certification โœ… Manuals | Policies | QAQC docs | ITPs & ITCs | SOPs with templates | Flowcharts | Audit Checklists โœ… Internal/External Audits | Risk Registers | Gap Assessments โœ… Full IMS & ISMS compliance: QHSE + Information Security Management System ๐Ÿ›ก๏ธ HSE, ESG & Risk Management โœ… JSA | SWMS | RAMS | SDS | Incident Statistics โœ… Method Statements | HSE Plans | Technical Training | NDIS Compliance documentation โœ… WHS / OSHA / NEBOSH / GradIOSH-Compliant Support ๐Ÿ“ Technical & Research Writing โœ… Bidding Documents | Reports | Research Papers | Thesis ๐ŸŽ“ Certifications & Expertise โœ… ISO 9001:2015 (Quality Management System - QMS) โœ… ISO 27001:2022 (Information Security & Cyber Security - ISMS) โœ… ISO 14001:2015 (Environmental Management System - EMS) โœ… ISO 45001:2018 (Occupational Health & Safety - OHS) โœ… ISO 13485:2016 Medical Devices QMS โœ… ISO 22301:2019 (Business Continuity Management System - BCMS) โœ… ISO 17025:2017 (Laboratory Management System - LMS) โœ… ISO 22000:2018 (Food Safety Management System - FSMS & HACCP Plans) โœ… ISO 31000:2018 (Risk Management) โœ… ISO 50001:2018 (Energy Management System โ€“ EnMS) โœ… ISO 41001:2018 (Facility Management System - FMS) โœ… ISO 20000:2018 (IT Service Management System โ€“ ITSMS) โœ… ISO 42001: 2023 (Artificial Intelligence Management System โ€“ AIMS) โœ… ISO 20121:2024 (Event Sustainability Management System - ESMS โœ… ISO 26000, 26030:2019 & 14064 GHG โœ… NVQ Level 6 GradIOSH Occupational Health & Safety โœ… NEBOSH International General Certificate (IGC) โœ… Occupational Safety & Health (OSHA) โœ… cGMP & FDA 21 CFR Part 820 & 111 โœ… SOC 2 & HIPAA ๐Ÿ”ท Partnering with top certification bodies like ASIB, UKAF, UKAS, UAF, IAS, JAS-ANZ, and IAF. I help organisations achieve compliance, streamline operations, and meet global standards for long-term success. ๐Ÿš€ Why Choose Me? โœจ Top Rated Plus โ€“ Trusted by global International clients โฑ๏ธ Fast delivery โ€“ On-time & detail-focused ๐Ÿ“ˆ Quality-driven โ€“ Customized & audit-ready documents ๐ŸŒ Industry-experienced โ€“ Engineering, Manufacturing, IT, Pharma ๐Ÿ“ฉ Letโ€™s Collaborate! I can perform quality projects. Feel free to contact me for more details. SAIF UR REHMAN

  • Information Security
  • Risk Assessment
  • Internal Auditing
  • Workplace Safety & Health
  • Quality, Health, Safety & Environment Management
  • Quality Management System
  • Chemical Engineering
  • Quality Assurance
  • ISO 14001
  • ISO 9001
  • ISO 27001
  • Cybersecurity Management
  • Information Security Consultation
  • Environmental, Health & Safety Software
  • Management Consulting
  • AI Compliance
  • Quality Audit
  • Information Security Awareness
  • Safety Engineering
Hamza F.

Rawalpindi, Pakistan

$25/hr
4.7
13 jobs

Experienced professional with extensive expertise of Big4 (Deloitte and PwC) in accounting, assurance, and governance, risk, and compliance. Worked across diverse regions, including Saudi Arabia, UAE, China, and Pakistan, with a strong focus on telecom and technology sectors. Successfully collaborated with leading organizations such as STC, e&, Mobily, and China Mobile, providing tailored solutions that drive operational excellence and compliance. 1. Extensive experience of IFRS/US GAAP implementation, finance digital/ AI transformation, climate finance and bookkeeping services. 2. Demonstrated success in internal audits across finance, commercial operations, and network operations, focusing on compliance, operational efficiency, and policy and process standardisation. 3. Adept at conducting Internal Control Reviews (ICR), quality audits, annual risk assessments, and financial reporting audits to ensure accuracy and reliability. 4. Skilled in designing and improving policies and processes as part of management consulting engagements, delivering enhanced controls and risk mitigation strategies.

  • Financial Audit
  • Bookkeeping
  • Internal Control
  • Intuit QuickBooks
  • Financial Reporting
  • Microsoft Office
  • Policy Writing
  • Financial Analysis
  • International Financial Reporting Standards
  • Business Continuity Plan
  • Financial Planning
  • Governance, Risk Management & Compliance
  • Environmental, Social & Corporate Governance
  • Digital Transformation
  • AI Consulting
Luca F.

Valdagno, Italy

$60/hr
5.0
71 jobs

OSCP & CEH-certified Penetration Tester with 8+ years of hands-on experience in Web, Mobile (iOS/Android), API, and Cloud security testing. 65+ projects delivered, 100% Job Success Score, Top Rated on Upwork. I help SaaS companies, healthcare platforms, FinTech, E-commerce and EdTech startups find real, exploitable vulnerabilities before attackers do, through manual penetration testing that goes far beyond automated scans. โ€” What makes my testing different โ€” I focus on real exploitation, not theoretical findings. Automated scanners miss business logic flaws, broken access control, and chained vulnerabilities. My OSCP-trained approach simulates how a motivated attacker would actually compromise your application, then documents the path so your developers can fix it for good. Every engagement includes a free retest after remediation, so you know the fix worked. โ€” Core services โ€” โ€ข Web Application Penetration Testing (OWASP WSTG v4.2 methodology) โ€ข Mobile App Security Testing for iOS & Android (OWASP MASVS / MASTG) โ€ข API Security Testing โ€” REST, GraphQL, OWASP API Top 10 โ€ข Cloud Security Reviews โ€” AWS / GCP / Azure misconfiguration testing โ€ข Source Code Security Review (PHP, Node.js, Python) โ€ข AI / LLM Security โ€” Prompt Injection, Data Leakage, OWASP LLM Top 10 โ€ข WordPress & PHP Application Hardening โ€ข WAF Bypass Testing & Detection Engineering โ€” Tools & methodologies โ€” Burp Suite Professional, Frida, Nmap, sqlmap, Metasploit, OWASP ZAP, Nuclei, Genymotion, MobSF, OWASP WSTG, OWASP MASVS, MITRE ATT&CK, NIST SP 800-115. โ€” Industries I've worked with โ€” Healthcare & medical devices (compliance-grade pentest + documentation), EdTech mobile platforms (iOS app dynamic analysis with Frida, Keychain audit), SaaS startups (full-stack web + API testing), e-commerce (WAF bypass, payment flow security). โ€” Compliance support โ€” GDPR, PCI-DSS, ISO 27001, SOC 2, HIPAA โ€” I provide the technical evidence and remediation documentation auditors expect. โ€” How I work โ€” 1. Send me your application URL or scope description, I'll review it and respond within 24 hours 2. Fixed-price or hourly proposal with clear deliverables, no surprises 3. Manual testing with detailed PoC for every finding 4. Executive summary + technical report (CVSS-scored, remediation-ready) 5. Free retest after your team applies the fixes โ€” Certifications โ€” โ€ข OSCP โ€” Offensive Security Certified Professional โ€ข CEH โ€” Certified Ethical Hacker โ€ข MSc in Information Systems & Network Security โ€” University of Milan Send me your application URL or a brief scope description, and within 24 hours you'll get a focused assessment and a clear, fixed-price estimate.

  • Penetration Testing
  • Security Testing
  • Vulnerability Assessment
  • Web Application Security
  • Web App Penetration Testing
  • Security Assessment & Testing
  • Cloud Security
  • Black Box Testing
  • Cybersecurity Management
  • Information Security Awareness
  • Kali Linux
  • Network Penetration Testing
  • OWASP
  • Risk Assessment
  • Information Security
  • WordPress Security
  • Bug Bounty

How it works

Post a job for free Post a job

Tell us what you need. Create your own job post or generate one with AI then filter talent matches.

Hire top talent fast

Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.

Collaborate easily

Use Upwork to chat or video call, share files, and track project progress right from the app.

Payment simplified

Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.

Don't just take our word for it

How do I hire a Certified Information Systems Auditor on Upwork?

You can hire a Certified Information Systems Auditor on Upwork in four simple steps:

  • Create a job post tailored to your Certified Information Systems Auditor project scope. Weโ€™ll walk you through the process step by step.
  • Browse top Certified Information Systems Auditor talent on Upwork and invite them to your project.
  • Once the proposals start flowing in, create a shortlist of top Certified Information Systems Auditor profiles and interview.
  • Hire the right Certified Information Systems Auditor for your project from Upwork, the worldโ€™s largest work marketplace.

At Upwork, we believe talent staffing should be easy.

How much does it cost to hire a Certified Information Systems Auditor?

Rates charged by Certified Information Systems Auditors on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.

Why hire a Certified Information Systems Auditor on Upwork?

As the worldโ€™s work marketplace, we connect highly-skilled freelance Certified Information Systems Auditors and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Certified Information Systems Auditor team you need to succeed.

Can I hire a Certified Information Systems Auditor within 24 hours on Upwork?

Depending on availability and the quality of your job post, itโ€™s entirely possible to sign up for Upwork and receive Certified Information Systems Auditor proposals within 24 hours of posting a job description.