Hire the Best Certified Information Systems Security Professionals

More than 3,000 reviews on G2
Rating is 4.5 out of 5.
4.5/5
of Upwork by G2 peer reviewers
Yasir K.

Lahore, Pakistan

$35/hr
5.0
2 jobs

𝐆𝐫𝐞𝐞𝐭𝐢𝐧𝐠𝐬! I am Yasir Khan, a seasoned Information Security Manager with over 20 years of experience in cybersecurity, IT infrastructure, and project management. My expertise spans across developing robust security strategies, managing large-scale security projects, and ensuring the alignment of security measures with business objectives. Throughout my career, I have successfully led initiatives to safeguard organizational assets and data, from risk assessment and incident response to compliance and secure architecture design. My technical acumen is complemented by a proven track record in leading cross-functional teams and driving projects that deliver secure and reliable IT solutions. 𝐖𝐡𝐚𝐭 𝐈 𝐎𝐟𝐟𝐞𝐫: Comprehensive Cybersecurity Solutions: Expertise in deploying and managing FirePower Firewall, Intrusion Prevention Systems (IPS), SIEM (IBM QRadar, Microsoft Sentinel), Intelligent Threat Hunting, Endpoint Security (XDR), and DLP best practices. Network & Infrastructure Management: Extensive experience with LAN/WAN Routing & Switching, VPN Technologies, and Cisco Hardware. Proficient in network security, secure data transit, and cloud architecture. Cloud Computing Expertise: Proficient in AWS Management, including EC2, S3, RDS, Lambda, and VPC. Skilled in cloud migration, secure architecture design, and optimizing cloud infrastructure for performance and security. DevOps & Systems Administration: Skilled in deploying applications, server monitoring, and automating workflows with tools like Ansible, Grafana, Jenkins CI/CD, and GitHub. Experienced in managing Linux and Windows Server environments. Leadership & Project Management: Proven leadership in incident management, IT support, team coordination, and vendor management. Adept at ensuring project delivery aligns with business goals and maintaining high standards of security and compliance. 𝐂𝐞𝐫𝐭𝐢𝐟𝐢𝐜𝐚𝐭𝐢𝐨𝐧𝐬: Certified Information Security Manager (CISM) Amazon Web Services Certified Solutions Architect – Professional (AWS-SAP) Cisco Certified Network Professional (CCNP Routing & Switching) Microsoft Certified System Engineer (MCSE) Microsoft Unified Communications – Lync 𝐓𝐫𝐚𝐢𝐧𝐢𝐧𝐠 & 𝐒𝐩𝐞𝐜𝐢𝐚𝐥𝐢𝐳𝐚𝐭𝐢𝐨𝐧𝐬: Certified Information Security Systems Professional (CISSP) Cisco Advanced Security, Routing & Switching, and Unified Communications Linux RedHat System Administration and Advanced Security Whether you need to enhance your organization's security posture, manage IT infrastructure projects, or implement secure cloud solutions, I am here to help. Let's collaborate to protect and optimize your IT environment. Feel free to reach out to discuss your project requirements or ask any questions. #CyberSecurity #NetworkSecurity #CloudSecurity #AWS #Cisco #VPN #SIEM #ThreatHunting #XDR #FirewallManagement #IncidentResponse #DevOps #ProjectManagement #ITSupport #TeamLeadership

  • Information Security
  • Vulnerability Assessment
  • Infrastructure Management
  • Extreme Networks
  • Policy Writing
  • Ethical Hacking
  • Security Patch Installation
  • Network Architecture
  • Network Design
  • Network Penetration Testing
  • Network Monitoring
Eric L.

North Wilkesboro, North Carolina

$50/hr
5.0
41 jobs

Eric Lunsford - Cybersecurity Assessor | Compliance Consultant | vCISO Certification - CCA | CCP | RPA | RP | SSCP | Pentest+ | Project+ | Sec+ | Net+ | A+| ECS I am Eric Lunsford, a cybersecurity professional with over 20 years of experience in management and leadership roles across the military and private IT sectors. I specialize in Cybersecurity, Governance & Compliance, Risk Management, and Secure Infrastructure Design. As a CMMC Certified Assessor (CCA), Certified CMMC Professional (CCP), Registered Practitioner Advanced (RPA), and Registered Practitioner (RP), I provide both formal CMMC/NIST 800-171 assessments and consulting services tailored to the unique needs of organizations within the Department of Defense (DoD) Defense Industrial Base (DIB) as well as Federal and Local Agencies. I hold certifications and credentials from the U.S. Army, ISC², CompTIA, Cisco, and EC-Council with specialization in Network Management, Cybersecurity, Encryption, and Information Assurance. I have provided regulatory and compliance assistance to over 100+ DoD supply chain organizations, helping companies strengthen their Supplier Performance Risk Score (SPRS), protect Federal Contract Information (FCI), secure Controlled Unclassified Information (CUI), and harden their networks and device configurations against threats. Specialties • Cybersecurity Auditing & Assessments (CMMC L1–L3, NIST 800-171, NIST 800-53) • Governance, Risk, and Compliance (GRC) documentation and program development • Network & Device Configuration Management aligned with DoD STIGs and CIS benchmarks • Virtual CISO (vCISO) Services for strategic security and compliance oversight • Policy & Procedure Development for security, privacy, and IT operations • AI & Emerging Technology Integration for compliance and security automation Frameworks & Compliance Expertise • NIST 800-53 – Federal systems • FedRAMP, StateRAMP, TX-RAMP – Federal/State cloud systems • NIST 800-171 – Contractor systems handling CUI • CMMC L1, L2, L3 – DoD contractor readiness and assessments • ISO/IEC 27000, 27001, 27002 – Information Security Management Systems • SOX – Financial reporting compliance • SOC 2 Type II – Service organization security controls • PCI-DSS – Payment card industry compliance • PHI, PII, Privacy Regulations – HIPAA and data protection requirements Project Deliverables & Capabilities Compliance Deliverables: • System Security Plans (SSP) • Plans of Action and Milestones (POA&M) • Risk Management Plans & Assessments • Incident Response Plans & Processes • Change & Configuration Management Plans • Gap Analyses & Remediation Plans • Security Policies, Procedures, Processes, Checklists, and Matrixes Technical Deliverables: • Secure Network & Topology Flow Diagrams • Scope Boundary Definitions • Encryption & Data Protection Programs • Endpoint Management & Mobile Device Management • System Testing Metrics, Storage, Backup, and Archiving solutions Consulting & Training: • GAP Assessments with remediation roadmaps • Policy development and compliance readiness coaching • Education & training for executives, HR, IT Admins, and staff • Full lifecycle compliance project management • Evidence collection, attestations, and audit preparation Professional Experience Throughout my career, I have served as: • Virtual Chief Information Security Officer (vCISO) – Advising executive teams on compliance and risk strategies • Senior Security Engineer – Implementing secure infrastructures and advanced encryption standards • Secure Infrastructure Specialist – Designing DoD-compliant architectures • Project Manager – Leading compliance, remediation, and IT modernization efforts • Security Operations Center (SOC) Analyst – Monitoring, detecting, and responding to threats Why Work With Me? I provide end-to-end cybersecurity and compliance services—from initial gap analysis and roadmap development to full assessments and audits. My approach is hands-on, practical, and tailored to each organization’s environment, ensuring not only compliance but also stronger overall security. Whether you need a CMMC assessment, NIST 800-171 consulting, ISO 27001 program build, or a vCISO to lead your security strategy, I bring the experience, certifications, and proven track record to help your organization succeed. Contact me with any questions or project requests. Let’s build your compliance roadmap and strengthen your cybersecurity posture. Eric Lunsford

  • Cybersecurity Management
  • Information Security Consultation
  • FedRAMP
  • ISO 27001
  • Incident Response Plan
  • IT Compliance Audit
  • NIST SP 800-53
  • SOC 2 Report
  • Security Policies & Procedures Documentation
  • Risk Assessment
  • Security Infrastructure
  • Certified Information Systems Security Professional
Michael C.

Canyon, Texas

$150/hr
5.0
3 jobs

I help organizations build, strengthen, and mature cybersecurity governance, risk, and compliance (GRC) programs that stand up to real-world operational and audit scrutiny. As an Information Security professional with experience supporting defense contractors, manufacturers, federal environments, and commercial organizations, I specialize in translating complex security and compliance requirements into practical, sustainable business processes. Whether your organization is pursuing SOC 2, ISO/IEC 27001, NIST Cybersecurity Framework (CSF), NIST SP 800-53, NIST SP 800-171, or CMMC assessment readiness, my focus is helping you reduce risk while building programs that remain effective long after an assessment is complete. My expertise includes: • Governance, Risk, and Compliance (GRC) program development and maturation • SOC 2 and ISO/IEC 27001 readiness assessments • NIST Cybersecurity Framework (CSF) implementation • NIST SP 800-53 and NIST SP 800-171 compliance • CMMC Level 1 and Level 2 assessment readiness • Risk assessments and security gap analyses • Security policies, standards, procedures, SSPs, and POA&Ms • Control mapping and evidence development • Virtual CISO (vCISO) advisory services • Microsoft 365 Commercial and GCC High security governance Throughout my career, I've worked as a Business Information Security Officer (BISO), cybersecurity consultant, and assessor, partnering with executive leadership to improve security maturity, prepare organizations for external assessments, and implement governance processes aligned with business objectives. My approach is practical, execution-focused, and rooted in real-world operational experience. I don't recommend unnecessary complexity or expensive rebuilds when existing programs can be strengthened through sound governance, risk management, and well-designed security controls. I work collaboratively with leadership, IT, compliance, and operational teams to create solutions that are technically sound, operationally achievable, and auditor defensible. If your organization needs help with: • Preparing for a SOC 2, ISO 27001, NIST, or CMMC assessment • Performing a cybersecurity risk or gap assessment • Developing security documentation and governance processes • Building or improving an Information Security Program • Establishing a practical GRC roadmap • Aligning security controls with regulatory or contractual requirements • Executive cybersecurity strategy and vCISO guidance I'd welcome the opportunity to discuss your objectives and help you build a security and compliance program that delivers measurable business value.

  • Information Security
  • Risk Management
  • Risk Assessment
  • Cybersecurity Management
  • Compliance
  • NIST Cybersecurity Framework
  • NIST SP 800-53
  • CMMC
  • SOC 2
  • ISO 27001
  • Security Policies & Procedures Documentation
  • Internal Auditing
  • Microsoft Intune
  • Microsoft Endpoint Manager
Zeeshan H.

Islamabad, Pakistan

$25/hr
4.9
8 jobs

I'm a cybersecurity professional with 7+ years of experience in website and web application security, incident response, SOC operations, and security monitoring for enterprise environments. I work directly with servers, web apps, logs, alerts, and detection rules to deliver practical fixes, not generic checklists. Whether you need a hacked website cleaned, an app tested before launch, or a full SOC built, I'll tell you plainly what's broken and what to do about it. SERVICES ========== Website Security Audit --------------------------- -Full scan for common vulnerabilities (OWASP Top risks) -Outdated software, plugin, and misconfiguration checks -Admin panel exposure review -File and directory permission checks -Basic database exposure review -SSL and security header validation → Deliverable: risk report (Critical/High/Medium/Low) + plain-English fix list Hacked Website Recovery ------------------------------- -Identify how the attacker gained access -Remove malware, backdoors, and injected scripts -Clean infected files and restore safe versions -Secure admin access (password reset, session invalidation) -Patch the vulnerability used in the attack → Deliverable: clean restored website + root cause explanation + prevention checklist Website Protection & Hardening -------------------------------------- -Disable unnecessary access points and services -Configure firewall and security rules -Protect forms from spam and bots -Implement rate limiting and login protection -Secure file upload functionality -DDoS and abuse mitigation guidance → Deliverable: hardened configuration + reduced attack surface + before/after summary Secure Login & Access Control ------------------------------------- -Enforce strong password policies -Configure multi-factor authentication (MFA) -Admin panel restriction (IP / role-based) -Session security (timeouts, token handling) -Brute-force protection (lockouts, throttling) → Deliverable: secure login system with reduced unauthorized-access risk Web Application Security Testing (OWASP Top 10) ------------------------------------------------------------ -Injection testing (SQL, command, etc.) -Authentication and session bypass testing -Input validation testing -API endpoint security checks -Business logic abuse scenarios → Deliverable: detailed vulnerability report + proof of concept (screenshots/evidence) + prioritized fixes Incident Response & Log Investigation --------------------------------------------- -Breach investigation -Server compromise analysis -Malware analysis support -Log-based attack reconstruction -Suspicious activity investigation -Root cause analysis -Post-incident technical reporting SIEM & Detection Engineering ------------------------------------ -SIEM setup and configuration -Log source integration -Custom detection rule development -Alert tuning and false positive reduction -Alert fatigue reduction -MITRE ATT&CK mapping -Dashboard creation SOC Setup, Architecture & Compliance ----------------------------------------------- -SOC setup for startups / lightweight SOC design -Log retention strategy -Incident response policy design -Security monitoring framework -SOC 2 logging requirements support -ISO 27001 monitoring controls -Security gap analysis -Detection maturity assessment

  • Information Security
  • Network Security
  • Web Application Security
  • Web Application Firewall
  • Network Monitoring
  • Security Infrastructure
  • Security Operation Center
  • Academic Research
  • Security Analysis
  • Threat Detection
  • Malware Removal
  • Digital Forensics
  • Elasticsearch
Muhammad Khuram A.

Melbourne, Australia

$30/hr
5.0
4 jobs

Information Security & GRC Specialist | Cybersecurity Product Manager | Risk & Compliance Consultant I am an experienced Cybersecurity and GRC professional with a proven track record in designing, implementing, and managing security frameworks, compliance programs, and risk management strategies across public and private sectors. With a strong technical foundation and a Master’s degree in Information Security, I bridge the gap between governance, compliance, and hands-on technical security. What I Offer: ✅ Governance, Risk & Compliance (GRC): Policy, procedure, and control development aligned with ISO, NIST, SOC2, GDPR, PCI-DSS, Cyber Essentails, Essential 8, NZISM, NCA, SAMA, etc. Internal audits, control testing, and evidence collection for compliance readiness Risk assessments, vendor due diligence, and enterprise risk register management Awareness training programs development ✅ Cybersecurity Consulting & Technical Expertise: Vulnerability assessment & penetration testing (Metasploit, Nessus, BurpSuite) Security operations & monitoring (SIEM, IDS/IPS, NGFW, WAF) Cloud security (AWS, Azure) and virtual environments (VMware, vSphere) Malware analysis, intrusion detection, and incident response ✅ Product Management for GRC Platforms: Lead product roadmaps for compliance, risk, vendor, and policy management modules SME in embedding international best practices (ISO 27001, NIST, COSO, etc.) into product features Experience working closely with developers, QA teams, and stakeholders to deliver secure, user-friendly, and compliance-driven platforms Skilled in customer-facing demos, stakeholder engagement, and executive-level presentations Certifications & Credentials: Certified Information Security Manager CISM - ISACA ISO/IEC 27001 Lead Implementer – PECB International Certificate in Enterprise Risk Management – IRM UK Certified in Cyber Security (CC) – (ISC)² GRC Professional – OneTrust HCIA Security – Huawei | CCNA Security – Cisco Plus certifications in Threat Intelligence, Python, and Network/Endpoint Security Why Work With Me? I combine strategic GRC expertise with deep technical cybersecurity knowledge—rare in the industry. Whether you need end-to-end compliance implementation, risk assessments, vendor security reviews, or product strategy for GRC and cyber security platforms, I can deliver with professionalism, accuracy, and a solutions-focused mindset. Let’s work together to strengthen your organization’s security posture, streamline compliance, and build trust with stakeholders.

  • Information Security
  • Penetration Testing
  • Vulnerability Assessment
  • Network Security
  • Cybersecurity Management
  • Information Security Audit
  • Information Security Awareness
  • Research Documentation
  • Internet Security
  • Network Engineering
Corey M. B.

Arlington, Virginia

$111/hr
4.3
95 jobs

I’ve worked in the field as a Sr. Network, Security, and Systems Architect / Engineer for 20+ years. I troubleshoot complex WAN/LAN issues across almost any network vendor, design secure architectures, and administer Windows and Linux server environments for everything from single-office small businesses to large enterprises with international footprints. In recent years, a major focus of my work has been AI/LLM security and ISO 42001. I’ve helped design, build, and secure AI/LLM technologies, including data protection, access control, governance, and monitoring around AI systems. I also build AI/LLM solutions for operations and security teams—using LLMs to accelerate investigations, summarize and analyze logs, enhance SOC workflows, and improve day-to-day decision-making. I treat AI and LLM components as first-class assets in the security architecture, aligned with ISO 42001 and existing GRC frameworks rather than as disconnected experimental tools. My core strength is combining deep technical engineering with compliance-grade security. I have extensive experience with PCI-DSS, HITRUST/HIPAA, NIST, ISO 27001/27002, SOC1/2 Compliance and related frameworks. I’ve performed assessments and audits of existing environments and then designed the network, system, and security controls needed to actually comply: segmentation, firewalls, IAM, logging, monitoring, backup/DR, and incident response. I am the former CISO for a large organization in Washington, DC and now provide fractional CIO/CISO services. I help small and medium-sized businesses achieve enterprise-level security postures on realistic budgets. As a fractional leader, I work with executives to build end-to-end security and IT strategies so they can meet due diligence requirements, reduce breach risk, protect IP, and preserve reputation and revenue. Certifications & Skills (highlights) CISSP, CCSFP (PCI-DSS, HIPAA/HITRUST, Privacy/PII, ISO 27001, CERT-RMM) AI/LLM Security and operational efficiencies using Artificial Intelligence technologies ISO 27001 Implementer; experience with ISO 42001 and AI/LLM governance Cisco networking and security (CCNA R&S, CCNA Security) MySQL / MSSQL DBA; Linux and Windows Server engineering (AD, SQL, Exchange) Engineered high-volume LAMP (+Java) e-commerce platforms and 1500-node mixed Linux/Windows networks Global Firewall Engineer and WAF (Cisco, Palo Alto, Fortinet/Fortigate AWS and Azure design, security, and administration; Apache hardening and Mod-Security VMware/vSphere and Citrix virtualization for Dev/QA and auto-provisioned infrastructure Scripting and automation for system administration, plus performance tuning and optimizations for systems, databases and applications

  • Information Security
  • Microsoft Azure
  • Linux System Administration
  • Penetration Testing
  • Firewall
  • MySQL
  • Apache Administration
  • Cisco Router
  • Windows Administration
  • Network Security
  • Certified Information Systems Security Professional
  • ISO 27001
  • Vulnerability Assessment

How it works

Post a job for freePost a job

Tell us what you need. Create your own job post or generate one with AI then filter talent matches.

Hire top talent fast

Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.

Collaborate easily

Use Upwork to chat or video call, share files, and track project progress right from the app.

Payment simplified

Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.

Don't just take our word for it

What does a Certified Information systems Security professional do?

A Certified Information systems Security professional designs, implements, and manages an organization’s cybersecurity program to protect information assets. This role applies security and risk management practices across the entire enterprise environment rather than focusing on a single tool or isolated system. The professional evaluates assets throughout their lifecycle to identify vulnerabilities and enforce protective controls. They lead security initiatives by integrating engineering, assessment, testing, and operations into a cohesive defense strategy.

  • The specialist architects secure network and system infrastructures that align with business objectives and regulatory requirements. They configure firewalls, intrusion detection systems, and access control lists to restrict unauthorized entry. This work involves selecting hardware and software solutions that meet specific security standards while maintaining operational performance. The professional documents these architectural decisions to guide future upgrades and maintenance tasks.
  • This role conducts regular risk assessments to identify potential threats to data integrity and availability. They analyze system logs and security alerts to detect anomalies that indicate a breach or attempted intrusion. Upon finding a vulnerability, the professional develops remediation plans and coordinates with IT teams to apply patches or configuration changes. They also perform penetration testing to validate the strength of existing security measures before attackers can exploit weaknesses.
  • The expert establishes and enforces security policies that govern how employees handle sensitive information. They train staff on best practices for password management, phishing recognition, and safe data handling to reduce human error. This responsibility includes auditing user access rights so only authorized personnel can view critical systems. The professional updates these policies regularly to address emerging threats and changes in compliance laws.

How to hire a Certified Information systems Security professional on Upwork

Step 1: Post a job

Specify your security requirements to attract qualified candidates. Use the Job Post Generator powered by Uma™, Upwork's Mindful AI to draft a precise description. Describe your needs in a few sentences and Uma drafts a job post for the role. You can write a new post, update a saved draft, or reuse an existing post.

  • Specify which of the eight CISSP domains matter most, such as security architecture or risk management.
  • List required experience with system security controls and information asset protection.
  • State if the freelancer must lead your cybersecurity program or support engineering teams.

Step 2: Evaluate candidates

Look for proof of designing and managing information security programs that meet industry standards. Uma can run instant video interviews and build shortlists with side-by-side comparisons.

  • Verify active CISSP certification from (ISC)² and check work history for relevant projects.
  • Review portfolios for documented security assessments and implemented risk management practices.
  • Check for experience securing information assets across their full lifecycle.

Step 3: Interview your top choices

Discuss how candidates apply security principles to your specific environment. Interviews can be scheduled and conducted within Upwork Messages with an immediate transcript and summary after each one.

  • Ask how they evaluate threats and secure systems against current vulnerabilities.
  • Request examples of leading security operations or supporting software security activities.
  • Clarify their approach to compliance and organizational risk mitigation strategies.

Step 4: Agree on scope and begin work

Set clear milestones for security program implementation or assessment tasks. Use Upwork Messages and the contract workroom for communication and project management, plus identity verification, payment protection, hourly tracking, and project funds for security.

  • Define deliverables like security policy drafts or system hardening reports.
  • Agree on tools for vulnerability scanning and access control configuration.
  • Establish reporting frequency for ongoing security monitoring and incident response.

Upwork is not affiliated with and does not sponsor or endorse any of the tools or services discussed in this article. These tools and services are provided only as potential options, and each reader and company should take the time needed to adequately analyze and determine the tools or services that would best fit their specific needs and situation.

The rates and information provided in this article are based on current data and industry sources available at the time of publication. Freelance rates can vary depending on factors such as experience, location, project scope, and market conditions. Readers are encouraged to conduct their own research to confirm current rates and trends, as this information may change over time.

How much does hiring a Certified Information systems Security professional cost?

$500-$2,500 per project is a typical range for focused Certified Information systems Security professional work. Final pricing depends on scope, technical complexity, required integrations, source-material quality, revision needs, and the freelancer's experience level.

Security policy review

$500-$1,200/project

Entry-level to mid-level
  • Identified weaknesses in current security policies
  • Actionable steps to align with industry standards
  • Written summary of findings and proposed fixes

Risk assessment

$1,200-$3,000/project

Mid-level
  • Cataloged critical information assets and data flows
  • Mapped potential threats to specific assets
  • Prioritized list of risks with mitigation strategies

Security architecture design

$3,000-$6,000/project

Mid-level to senior-level
  • Visual map of secure network and system layout
  • Defined security controls for each system layer
  • Step-by-step instructions for deploying the design

Compliance audit preparation

$6,000-$9,500/project

Senior-level
  • Compiled required documents and logs for auditors
  • Verified effectiveness of existing security controls
  • Formal documentation of compliance status and gaps

Incident response planning

$9,500-$15,000/project

Expert-level
  • Detailed procedures for handling security incidents
  • Protocols for internal and external stakeholder notifications
  • Guides and scenarios for team incident response drills

Frequently asked questions

Is hiring a Certified Information systems Security professional worth it?

For most businesses, yes: hiring a Certified Information systems Security professional is worthwhile. This credential validates deep knowledge across eight security domains, which helps you trust the freelancer to design and manage your cybersecurity program. You gain a partner who applies proven risk management practices rather than guessing at solutions.

How do I evaluate Certified Information systems Security professional candidates?

Verify the candidate holds an active CISSP certification from (ISC)² and ask for specific examples of how they applied security controls in past projects. Look for a freelancer who describes designing or implementing a security program that reduced risk across your specific environment, rather than just listing general tools.

What tasks does a Certified Information systems Security professional handle?

A Certified Information systems Security professional designs and manages your organization’s information security program. They evaluate assets, apply risk management practices, and support engineering and operations activities to secure your systems.

When should I hire a Certified Information systems Security professional?

Hire this specialist when you need to build or overhaul your cybersecurity strategy and require leadership-level expertise. They are best suited for roles that involve managing security programs and evaluating risks across your entire infrastructure.