Hello! I'm Samarth, a Cyber Security Engineer and Ethical Hacker with a passion for safeguarding digital assets and securing online environments.
I have done more than 27+ VAPT projects. With over 7 years of hands-on experience in the field, I've honed my skills working with esteemed enterprise companies such as Noreg Ltd and FedEx, where I've tackled complex security challenges head-on.
🛡️ Expertise:
- Cyber Security Solutions
- Ethical Hacking
- Network Security
- Malware Analysis
- Cryptography
- Social Engineering
- Cloud Security
- Identity and Access Management (IAM)
- Security Operations Center (SOC) Management
- Vulnerability Assessment
- Penetration Testing
- Incident Response and Digital Forensics
- Web Application Security
- Security Architecture Design
🎓 Certifications:
- Certified Information Systems Security Professional (CISSP)
- Certified Ethical Hacker (CEH)
- CompTIA Security+
- Certified Information Security Manager (CISM)
- Certified Cloud Security Professional (CCSP)
- EC-Council Certified Security Analyst (ECSA)
- Certified Offensive Security Expert (OSCE)
- Offensive Security Certified Professional (OSCP)
- Certified Information Systems Auditor (CISA)
- GIAC Penetration Tester (GPEN)
- Cisco Certified CyberOps Associate
đź’Ľ Previous Experience:
- SaveAs Ltd (Senior Information Security Consultant, Auditor) - 2006
- Noreg Ltd. (Information Security Consultant, Auditor) - 2009
- AXA Group Hungary - Information Security Professional, IT audit manager - 2012
- Vodafone Group - Technology Security Project Manager - 2014
- TES Global Solutions - Lead Information Security operation consultant and architect - 2017
- BDO UK LLP - Information Security operation consultant and engineer - 2017
- FedEx - Global Security Operation Consultant - 2018
- Royal Bank of Scotland - Cyber Security Engineer - 2019
- Security-Consultan - Principal Security, Compliance and Certification consultant - 2022
🏆 Accomplishments:
➡️Successfully Conducted Advanced Penetration Tests on High-Profile Systems
[Performed comprehensive penetration testing on critical infrastructure for clients, identifying and mitigating multiple high-risk vulnerabilities, which helped prevent potential data breaches and strengthened overall security posture.]
➡️Developed a Custom Exploit Detection System
[Designed and implemented a proprietary system for detecting zero-day exploits in real-time,
significantly enhancing the organization's ability to identify and respond to sophisticated
attacks before they could cause damage.]
➡️Led a Major Incident Response and Forensics Investigation
[Headed an incident response team during a high-profile security breach, quickly containing
the threat performing an in-depth forensic analysis that led to the identification of
the attacker's tactics, techniques, and procedures (TTPs), and the improvement of future
defense strategies.]
➡️Achieved Industry-Recognized Certifications in Cybersecurity
[Earned multiple certifications in cybersecurity and ethical hacking, including CEH, OSCP, and
CISSP, which demonstrate a commitment to professional growth and expertise in
identifying, assessing, and mitigating cyber risks.]
I'm committed to delivering top-notch security solutions tailored to your specific needs, whether you're an individual, a small business looking to fortify your defenses, or a large enterprise seeking to mitigate sophisticated cyber threats.
Let's collaborate to protect your digital assets and uphold the confidentiality, integrity, and availability of your information. Reach out to me today, and let's make your online environment secure!
TOP RATED Freelancer | 10+ Years of Experience | Your Trusted Compliance Partner
75+ clients served all with 5 * ratings
The best Consultant if you are using Vanta, Drata, Scrut or Secureframe
They call me "Mr. Compliance- and for good reason.
While you focus on growing your business, I take care of everything compliance-related, ensuring you meet industry standards and win more deals with confidence. Whether it's SOC 2, ISO 27001, HIPAA, PCI DSS, CMMC, or FedRAMP, I make compliance effortless so you can unlock new opportunities without the hassle.
Why Clients Trust Me:
- Seamless Compliance: I simplify audits, security assessments, and certifications—no stress, no delays.
- Growth-Driven Compliance: Compliance isn’t just a checkbox; it’s a competitive advantage. I help shorten sales cycles by getting you audit-ready fast.
- End-to-End Support: From policies to risk assessments, vendor due diligence, and security questionnaires—I handle it all.
- vCISO Services: Need expert guidance but not ready for a full-time CISO? I offer affordable virtual CISO (vCISO) solutions tailored to your business.
- Security Strategy & TPRM: Managing third-party risks? Struggling with cloud or endpoint security? I’ve got you covered.
- Maximizing Compliance Tools: Already using Vanta, Drata, Hyperproof, or Scrut but unsure what’s next? Let’s optimize your investment.
Proactive, not reactive. I don’t just tick boxes—I future-proof your security and compliance programs.
** Tools & Frameworks:
🔹 Tools Expertise: JIRA, Vanta, Hyperproof, Drata, ServiceNow, AWS, Confluence, Archer, Scrut Automation
🔹 Compliance Frameworks: ISO 27001, SOC 2, FedRAMP, NIST, HIPAA, PCI-DSS, CMMC, TPRM, and more
📢 Ready to Make Compliance Work for You?
Click "Invite" to connect, and let's build a stronger, more secure, and audit-ready business together.
⚠️ Note: If you're not fully committed to compliance or tend to be unresponsive, I may not be the right fit. I prioritize working with businesses serious about security and compliance success.
Information Security
Application Security
Risk Assessment
NIST Cybersecurity Framework
Jira
ISO 27001
SOC 2
CMMC
SOC 2 Report
Governance, Risk Management & Compliance
Application Audit
Sarbanes-Oxley Act
NIST SP 800-53
Mobility Work CMMS
Shubham K.
New Delhi, India
$25/hr
5.0
8 jobs
CISM-certified Cyber Security Consultant with 9 years of experience implementing and managing comprehensive security solutions. Expertise in endpoint protection, SIEM solution, cloud security and penetration testing. I have a strong ability to assess, mitigate, and respond to complex security threats.
I am experienced in leading security projects, creating tailored policies, and providing expert guidance to organizations of all sizes.
Experienced in working with global teams across time zones, cultures, and languages
AREAS OF EXPERTISE
* Endpoint Protection
* Threat hunting
* SOC Architecture and Implementation
* Cloud Security
* Azure and Microsoft 365 Security
* Vulnerability Assessment and Penetration Testing (VAPT)
Information Security
System Security
Vulnerability Assessment
Penetration Testing
Incident Response Plan
Cloud Security Framework
Cloud Security
Microsoft Endpoint Manager
Incident Management
manmeet S.
Chandigarh, India
$38/hr
5.0
45 jobs
Microsoft Azure/365 Platform Consultant has more than 24 years of serving customers using
Microsoft technologies including Azure Infra and Security, Defender for Cloud, AD Assessment,
Sentinel, Purview, Compliance, MS365, AWS, Google.
Assisting for CMMC, HIPAA and NIST;
Microsoft Certifications:
âś” Microsoft Certified: Azure Solutions Architect Expert
âś” Microsoft Certified: Identity and Access Administrator Associate
âś” Microsoft Certified: Azure Security Engineer Associate
âś” Microsoft Certified: Cybersecurity Architect Expert
âś” Microsoft Certified: Information Protection and Compliance Administrator Associate
âś” Microsoft Certified: Security Operations Analyst Associate
âś” Microsoft 365 Certified: Administrator Expert
âś” Microsoft Certified: Azure for SAP Workloads Specialty
Other Certifications and Trainings:
✔ Certified Information Systems Security Professional (CISSP) – ISC2
✔ Certified in Cyber Security (CC) – ISC2
âś” ISO/IEC 22301:2019 Business Continuity Lead Auditor
âś” ISO/IEC 27001:2022 Information Security Lead Auditor
âś” ISO/IEC 27701:2019 Privacy Information Lead Auditor
✔ Trained in “Certified Information Security Manager” (CISM)
✔ Trained in “Certified Information Systems Auditor” (CISA)
Azure Cloud Security Skills:
• Microsoft Azure Security Services
• M365 Environment Security
• Microsoft Defender Suite (Cloud, Identity, Office 365)
• Microsoft 365 Copilot Enablement
• Cloud Adoption and Migration
• Identity and Access Management (IAM)
• Cloud Security Posture Management (CSPM)
• Security Information and Event Management (SIEM)
• Cloud Access Security Broker (CASB)
• VPN, Segmentation, WAF, Access Control
• Encryption Technologies
• SOAR Concepts and Toolsets
• Microsoft 365 Copilot Enablement & Prompt Engineering
• Microsoft Copilot Studio (Custom Agent & Workflow Design)
• Microsoft Purview & Copilot Data Governance
Core Competencies:
• Threat and Vulnerability Management
• Penetration Testing & Red Teaming
• System Hardening & Compliance
• Application and API Security
• Third-Party Risk Management
• Team Leadership & Mentorship
• Security Frameworks (NIST, ISO 27001, OWASP)
• Cloud and Container Security (AWS, Azure, Kubernetes)
• DevSecOps Integration
• Persona-Based AI Training & Instructional Design
• AI Adoption Roadmaps & Change Management
• Cross-Functional Business Process Mapping (Legal, Finance, Operations)
Thank you for your time and consideration.
Yours truly,
Manmeet Singh
System Administration
Configuration Management
Amazon EC2
VMware Administration
Windows Administration
DevOps
Microsoft SQL Server Administration
Cloud Computing
Information Security Consultation
Microsoft Azure
Binesh S.
Chennai, India
$50/hr
4.8
143 jobs
Profile Summary
Seasoned Information Security Professional with 22+ years of experience across, Application Security, VAPT, Cloud Security, Email Security and Risk Governance. I specialize in designing secure, compliant and automated environments that protect enterprise assets from the code level to the cloud. From hardening AI infrastructure to mastering email deliverability, I ensure every layer of the digital stack is resilient.
Offensive Security: VAPT, Red Teaming, and OWASP Top 10 mitigation.
Infrastructure: Expert-level Linux/Windows migration and AI model pipeline security.
Governance: Certified (CISSP, CISA, CISM, CRISC, CGEIT) leader in ISO 27001, PCI DSS, and NIST frameworks.
Network Security Architecture:
Design and implementation of firewalls (NGFW), IPS/IDS, VPNs, VLAN segmentation, and zero-trust models for enterprise and data center environments.
Expertise in deep-packet inspection, application-layer filtering, and threat intelligence integration to detect, prevent, and respond to advanced threats.
MFA, SSO, JML workflows, passwordless authentication, IDOR, privilege escalation and governance-driven IAM programmes
Code security, data protection, and vulnerability management standards
Threat modeling and risk rating using STRIDE/DREAD or CVSS
SonicWall TZ 500, 600, SOHOW
Plesk & WHM Panel expert, Tomcat, Apache, Ngnix & IIS
Database Security hardening MySQL, Mariadb, MSSQL & Oracle
HTTP Security Header, Server Side include, XXE, XSLT, CSRF. PKI, SSL TLS 1.2 &1.3 http 1.1, http2, http3
Network Security IPv6/IPv4, ZTNA
CrowdStrike/ Sentinel/ Trend Micro Endpoint Security,
Microsoft Purview & Symantec DLP Solution
SIEM - QRadar, DNIF Google Chronicle & Mandiant SOAR
Regular risk assessments and control validation
AppSec risk register maintenance
Shift Everywhere Security
SAST, DAST, IAST, RAP, and SCA tools (Nessus, Qualys Guard, SonarQube, Fortify, Checkmarx, Veracode, Burp Suite, OWASP ZAP, MobSF, Postman)
Image vulnerability scanning (Trivy, Clair)
DNS Security
Kubernetes/Docker configuration hardening
Runtime protection for containers
Mode Security , Cloudflare WAF
Threat Modeling & Attack Surface Reduction
MFA, SSO, JML workflows, password less authentication, and governance-driven IAM programmes
Security Automation & Infrastructure as Code (IaC)
Compliance & Risk Governance (ISO 27002, SOC 2, HIPAA, PCI DSS)
Security Operations ( IAM, EDR/MDR SIEM/SOAR, Incident Response)
Application, Database & Systems Security
Wordpress/Magento/Drupal Security Hardening
Cloud-Native & Container Security
Cloud Security & AI Platform Expertise
Implemented CASB, CSPM, CWPP & CNAPP
Amazon Web Services (AWS):
Secured workloads leveraging EC2, S3, IAM, VPC, CloudFront, RDS, and Route 53 with enterprise controls.
Deployed AWS WAF & Shield, GuardDuty, Inspector, Security Hub, and Audit Manager for compliance automation.
Container Security - AWS ECS, EKS, ECR, Fargate
Integrated Amazon Bedrock
Microsoft Azure:
Extensive experience with Azure OpenAI, AI Studio, Azure ML, Sentinel, RDP, VPN, Intune Defender for Cloud, and Purview.
Deployed Confidential Computing, Data Lake, Cosmos DB, and AKS using secure-by-design principles, encryption-at-rest, and real-time compliance monitoring.
Google Cloud Platform (GCP):
Implemented Sensitive Data Protection, IAM, VPC, SCC, Confidential Computing, Cloud Armor, and KMS for resilient data governance.
Applied AI/ML security frameworks (SAIF, Model Armor, Guardrails) to safeguard sensitive workloads and mitigate model-level risks.
Email Security SPF, DKIM, DMARC, BIMI, RBL, Blocklist check , Microsoft Exchange/ O365/Google Workspace/Power MTA, Qmail, Postfix, Smartermail etc, Email phishing Simulation & campaign
AI Infrastructure Security
N8N and OpenClaw AI workflow configuration.
My work includes protecting data pipelines, securing model training and deployment environments, enforcing IAM controls, and hardening GPU/compute clusters. I assess risks in model storage, APIs, and inference endpoints, implement monitoring for data integrity and model misuse, and ensure compliance with security and governance frameworks. I provide actionable recommendations to strengthen resilience, privacy, and the overall security posture of AI systems.
Security Audit,
Risk Assessment and Audit Compliance, with a strong track record in securing enterprise systems, networks, applications and multi-cloud environments. My professional journey includes leading ISO 27002, ISO42001, HIPAA, PCI DSS, SOX, ITGC, CIS, NIST, NIS2, GDPR, CCPA, HIPPA and SOC 2 audits, implementing GRC frameworks, and ensuring regulatory alignment and risk mitigation across complex organizations.
BCP/DR, RPO, RTO, MTTD, MTTR Business Impact Assessment and Privacy Impact assessment
GRC Tools - Security Score Card, BitSite, Auditboard, OneTrust, RSA Archer, ServiceNow GRC, Drata & Vanta
Information Security
IT Compliance Audit
Risk Assessment
Penetration Testing
Web Application Security
OWASP
AI Security
Cloud Security
Application Security
Vulnerability Assessment
Web Application Audit
Email Security
Plesk
Governance, Risk Management & Compliance
DevOps
How it works
Post a job for freePost a job
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a Certified Information Systems Security Professional (CISSP) in India on Upwork?
You can hire a Certified Information Systems Security Professional (CISSP) in India on Upwork in four simple steps:
Create a job post tailored to your Certified Information Systems Security Professional (CISSP) project scope. We'll walk you through the process step by step.
Browse top Certified Information Systems Security Professional (CISSP) talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top Certified Information Systems Security Professional (CISSP) profiles and interview.
Hire the right Certified Information Systems Security Professional (CISSP) for your project from Upwork, the world's largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a Certified Information Systems Security Professional (CISSP)?
Rates charged by Certified Information Systems Security Professionals (CISSP) on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a Certified Information Systems Security Professional (CISSP) in India on Upwork?
As the world's work marketplace, we connect highly-skilled freelance Certified Information Systems Security Professionals (CISSP) and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Certified Information Systems Security Professional (CISSP) team you need to succeed.
Can I hire a Certified Information Systems Security Professional (CISSP) in India within 24 hours on Upwork?
Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Certified Information Systems Security Professional (CISSP) proposals within 24 hours of posting a job description.
Find more freelancers
Top cities for Certified Information Systems Security Professional (CISSP) in India