Hire the Best Certified Information Systems Security Professional (CISSP)
in the United States

More than 3,000 reviews on G2
Rating is 4.5 out of 5.
4.5/5
of Upwork by G2 peer reviewers
Tim B.

Orlando, Florida

$60/hr
5.0
1 jobs

Most organizations don’t fail audits because they lack security. They fail because their controls don’t hold up under real scrutiny. I’ve spent 10+ years making sure that doesn’t happen. As a CISSP-certified security professional, I spent six years as the sole security practitioner for an enterprise healthcare organization – owning every assessment, every audit, and every remediation from end to end. 24 security assessments. Zero failures. HITRUST certification achieved and maintained. That’s not a team result. That’s mine. What I deliver: ✔ Audit readiness that actually holds – HITRUST, HIPAA, PCI-DSS, NIST CSF ✔ Control gap analysis and mapping (NIST, ISO 27001, HITRUST CSF) ✔ Risk assessments with prioritized, defensible findings ✔ POA&Ms and remediation roadmaps that move the needle ✔ SIEM tuning and threat validation (Splunk, Rapid7, Alert Logic) ✔ Security policies built to survive auditor scrutiny, not just satisfy it By the numbers: • 24 consecutive assessments with zero audit failures • ~30% vulnerability reduction through structured remediation programs • Sole security POC across cloud and hybrid enterprise environments with constrained budgets and no margin for error I don’t just help organizations get compliant. I help them stay compliant when someone is actually looking. If that’s the standard you need, let’s talk.

  • Information Security
  • Certified Information Systems Security Professional
  • Certified Information Security Manager
  • Information Security Awareness
  • Information Security Skills
  • Information Security Consultation
  • Information Security Governance
  • Information Security Threat Mitigation
  • Security Engineering
  • Information Security Audit
  • System Administration
  • Compliance
Thomas W.

Tucson, Arizona

$125/hr
5.0
94 jobs

Need an effective, defensible, responsibly-priced cybersecurity program? My consultancy has helped a wide variety of organizations - from smaller SaaS startups to larger Fortune 1000 brands you know and trust - realize comprehensive, integrated, end-to-end cybersecurity aligned with: • Institutional goals and internal risk appetite. • Client supply chain questionnaires / contract requirements. • Industry and regulatory requirements (e.g. GLBA, PCI-DSS, HIPAA, NYS DFS 23 NYCRR 500, DFARS / CMMC) • NIST Cybersecurity Framework (CSF) and / or good industry practices (e.g. SOC Readiness, NIST Special Publications 800-30, 800-37, 800-53, 800-171) My consulting practice is reputable, insured, and responsibly priced, and you can expect quality results, because I’m an award-winning, former IT / cybersecurity leader with: • Two decades of experience. • M.Sc. in Information Security & Assurance • M.B.A. in Information Technology Management • A wide variety of advanced industry certifications, including the CISSP and CISA. Beyond cybersecurity program compliance, I can represent your organization as a Chief Information Security Officer on a cost-effective, fractional basis supporting any further cybersecurity needs, including: • Risk assessments. • Audit response / defense. • Vulnerability scanning & penetration testing. • Policy development (e.g. Incident Response, Vulnerability Management, Secure Development) • Disaster recovery & business continuity planning. • Third-party risk / supply chain reviews. • Cybersecurity marketing (e.g. architecture diagrams and white paper development that illustrate, showcase good practices) • Capability / tool implementation & support (e.g. Data Loss Prevention, Multi-Factor Authentication) Wherever your organization stands in its cybersecurity journey, I’m almost always able to come up with a responsible, defensible solution within the budget available - often at a fixed cost - so please book a consultation with me to discuss your unique circumstances!

  • Certified Information Systems Security Professional
  • Application Security
  • IT Compliance Audit
  • HIPAA
  • Vulnerability Assessment
  • Security Infrastructure
  • Information Technology Strategy
  • Email Deliverability
  • Network Security
  • Security Analysis
  • Security Assessment & Testing
  • PCI DSS
  • SOC 2
  • NIST Cybersecurity Framework
  • Cybersecurity Management
Montavius R.

Grovetown, Georgia

$60/hr
5.0
14 jobs

Small businesses deserve enterprise-level Microsoft 365 and Azure environments without enterprise-level complexity and cost. I help companies build, secure, and manage Microsoft cloud environments from the ground up, including Microsoft 365 tenants, Azure infrastructure, Entra ID, Intune, virtual desktops, FSLogix profiles, Azure Virtual Desktop host pools, storage, networking, applications and security baselines. I have 15+ years of hands-on IT and cybersecurity experience supporting enterprise environments, including Microsoft 365, Azure infrastructure, Entra ID, Exchange Online, SharePoint, OneDrive, Teams, Intune, Defender, Purview, and endpoint management just to name a few. I help businesses not only harden their existing environment, but also build new Microsoft cloud environments from the ground up. I can help with full Microsoft 365 tenant setup, Azure resource configuration, domain/DNS setup, email migration, user and group provisioning, SharePoint/OneDrive structure, Teams configuration, Intune enrollment, device compliance, Conditional Access, MFA, security baselines, and clean documentation. I’m a CISSP and Microsoft Certified Azure Solutions Architect Expert with real-world experience helping organizations build secure, manageable, and scalable cloud environments. ✅ What I can help you with Microsoft 365 tenant setup and administration Azure environment setup and configuration Exchange Online, Teams, SharePoint, and OneDrive setup Entra ID user, group, role, and identity management Intune MDM deployment for Windows, iOS, and macOS Device enrollment, compliance policies, and app deployment Conditional Access, MFA, and identity security Security baseline implementation and tenant hardening Email/DNS setup including SPF, DKIM, DMARC, and MX records Cloud migration support and cleanup Vulnerability scanning and remediation such as Security assessments and vulnerability scanning for Microsoft 365, Azure, endpoints, and web applications (OpenVAS/Greenbone or OWASPZAP). Cyber-insurance readiness assessments Documentation, SOPs, and admin handoff guides ⚡ Why clients work with me Clear communication with no technical jargon Secure cloud environments built the right way Fast turnaround and clean execution I do not just identify issues, I fix them Simple documentation your team can actually use Long-term support available 🔒 Let’s build and secure your Microsoft cloud environment Whether you need a new Microsoft 365 tenant built, Azure resources configured, Intune deployed, email/DNS cleaned up, or your environment hardened for cyber insurance, I can help you get it done the right way.

  • Information Security
  • Vulnerability Assessment
  • Microsoft SharePoint
  • Microsoft Azure
  • Computing & Networking
  • Compliance
  • Architectural Design
  • Architecture
  • Microsoft Intune
  • Government Reporting Compliance
  • Microsoft Azure Administration
  • Server
  • Microsoft Endpoint Manager
  • Microsoft Exchange Online
  • Cybersecurity Management
Jeff G.

Sunnyvale, California

$80/hr
4.9
161 jobs

My extensive experience in Cloud,Database and CyberSecurity over the past years include the following: 1). CISSP Certified Information Security Professional 2). CISA: Certified Information Systems Auditor 3). PCI-DSS Security Audit 3) Information Security/Vulnerability Testing 4). Oracle Performance Tuning 5). Oracle Database technologies, SQL Tuning, RMAN, RAC Clustering 6). Database System Security Scans and Vulnerability testing 7). Oracle Certified Professional 8). Oracle Certified Database Security Implementation 9). AWS Solutions/Administration/EC2/S3/Cloud 10). HiTRust Aware/PCI DSS Professional 11). Microsoft Certified: Azure Fundamentals Dedicated, solution driven and well accomplished IT Security Executive with over 20 years of progressive experience in leading the development and execution of complex security architectures and compliance strategies within diverse organizational frameworks. Expert in enhancing security infrastructures across multiple platforms including cloud environments (AWS) and database systems (Oracle, WebLogic). Proven track record of reducing risks through meticulous gap assessments, penetration testing, and continuous systems monitoring, achieving significant improvements in security robustness. Skilled in leading high-impact teams and projects that fortify information security defenses and compliance protocols, adhering to rigorous standards such as SOC2, NIST, CIS, HIPAA, and OWASP. Demonstrated success in implementing critical security updates, leading security training programs, and managing direct client relationships to protect sensitive data effectively. Recognized for transforming security frameworks and cultivating a culture of continuous improvement and proactive threat management, ensuring the security and integrity of critical information assets.

  • Information Security
  • Oracle Performance Tuning
  • Network Penetration Testing
  • Database Administration
  • Security Infrastructure
  • PCI DSS
  • Certified Information Security Manager
  • Information Security Governance
  • Oracle Database
  • Security Engineering
  • Security Operation Center
  • Linux System Administration
  • Oracle Database Administration
  • Data Protection
  • PCI
Nicolas T.

Miami, Florida

$100/hr
5.0
5 jobs

Your Partner for Risk-Based Security, Audit Readiness & Operational Resilience | $65/hr 🗽 U.S. 🌍 Global & willing to travel Proven Track Record in Regulated & Enterprise Environments I’m a Security Engineer from the United States with 10+ years of experience helping regulated organizations strengthen their security posture through risk-based decision making, audit readiness, and operational security. I work directly with leaders, auditors, penetration testers, vendors, and engineering teams to ensure security programs are not just compliant, but effective, prioritized, and aligned to real business risk. Why I Stand Out 🔹 Risk-Based Security Approach I help organizations prioritize security investments and remediation efforts based on real risk, reducing noise and focusing on what materially impacts the business. 🔹 Engineer-First Execution I translate compliance requirements (SOC 2, PCI-DSS, NIST, HIPAA, CMMC) into practical, implementable solutions that work in real environments. 🔹 Audit & Compliance Expertise Experienced in control implementation, remediation tracking, evidence preparation, and working directly with auditors to ensure successful outcomes. 🔹 Real-World Risk Reduction Focused on vulnerability management, DevSecOps integration, and IAM governance to reduce exploitable attack surface, not just produce reports. Core Services 🔹 Audit Readiness & Remediation Control implementation, gap assessments, remediation tracking, audit support, and evidence preparation. 🔹 Risk-Based Vulnerability Management Threat-informed prioritization, CI/CD integration, SAST/DAST, dependency scanning, and actionable remediation strategies. 🔹 DevSecOps & Cloud Security IAM, secrets management, container security, encryption, logging, and secure CI/CD pipeline implementation. 🔹 Identity & Access Governance (IAM) Access reviews, RBAC enforcement, onboarding/offboarding processes, and policy alignment. 🔹 Security Assessments Cloud, network, application, and API security assessments aligned to real-world risk. Who I Work With 🔹 Regulated organizations preparing for audits 🔹 Enterprise teams building or maturing security programs 🔹 SaaS & cloud-native companies implementing DevSecOps 🔹 Organizations needing risk-based prioritization, not just tooling and reports I help teams execute, remediate, and operationalize security in a way that is sustainable long-term. 📞 Let’s connect for a 30-minute discovery call to build a risk-informed, audit-ready, and operationally effective security program.

  • Cybersecurity Management
  • Cyber Threat Intelligence
  • Business
  • Cybersecurity Monitoring
  • Security Engineering
  • Risk Management
  • Vulnerability Assessment
  • Compliance
  • DevOps
  • Privacy
  • SOC 2
  • NIST Cybersecurity Framework
  • PCI DSS
  • Application Security
  • Governance, Risk Management & Compliance
  • Information Security Governance
  • Cloud Security
  • ISO 27001
Alexander B.

White Hall, Maryland

$80/hr
5.0
3 jobs

Hello, I am Alex Brown. I am a Certified Information System Security Professional (CISSP) and Offensive Security Certified Professional (OSCP) with 13 years of industry experience and a masters degree in Cybersecurity. The majority of my career I have spent working with NIST 800-37 Risk Management Framework (RMF), performing security assessments, architecting security solutions, and applying security remediations. I have worked through all 6 stages of the RMF process from system categorization to system maintenance. I have developed cyber documentation to support security controls, developed polices and procedures to enforce system security practices and document system configuration. In addition, I have implemented technical security controls such as Windows and Linux patches, Windows and Linux OS configuration settings, and network device firmware and configuration settings. I have extensive experience in vulnerability assessment, security analysis, and applying security controls. I am extremely familiar with industry scanning tools such as Nessus and DISA Security Technical Implementation Guides (STIGs). I have worked with other security tools including Kali Linux and Metasploit. I have worked with application firewalls including Windows Firewall, iptables, and Symantec Enterprise Protection. I have extensive experience analyzing results from security scans, assessing risk, and applying measures to mitigate or remediate the security issue. I have developed Vulnerability Assessment Reports identifying the open vulnerabilities impacting the organizations system. I have developed Risk Assessment Reports where open vulnerabilities are assessed for overall risk by looking at likelihood of a vulnerability being exploited and the impact it would have on the organization. I have maintained Plan of Actions and Milestones (POA&M) where ongoing non-compliant security controls are tracked and assigned completion expectations and criteria. In addition to my technical knowledge and experience in the cyber field, I have also performed project management activities on cyber efforts. I have managed control accounts, maintained schedules, managed sub-contractors, and worked directly with customer clients on cyber deliverables. I have a strong background in understanding expectations to meet customer demands with strict schedule and cost demands.

  • Certified Information Systems Security Professional
  • Bash Programming
  • Vulnerability Assessment
  • Red Hat Enterprise Linux
  • Cybersecurity Management
  • Information Security Audit
  • Security Analysis
  • Windows 10 Administration
  • Microsoft Windows PowerShell
  • Penetration Testing
  • Nessus

How it works

Post a job for freePost a job

Tell us what you need. Create your own job post or generate one with AI then filter talent matches.

Hire top talent fast

Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.

Collaborate easily

Use Upwork to chat or video call, share files, and track project progress right from the app.

Payment simplified

Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.

Don't just take our word for it

How do I hire a Certified Information Systems Security Professional (CISSP) in the United States on Upwork?

You can hire a Certified Information Systems Security Professional (CISSP) in the United States on Upwork in four simple steps:

  • Create a job post tailored to your Certified Information Systems Security Professional (CISSP) project scope. We'll walk you through the process step by step.
  • Browse top Certified Information Systems Security Professional (CISSP) talent on Upwork and invite them to your project.
  • Once the proposals start flowing in, create a shortlist of top Certified Information Systems Security Professional (CISSP) profiles and interview.
  • Hire the right Certified Information Systems Security Professional (CISSP) for your project from Upwork, the world's largest work marketplace.

At Upwork, we believe talent staffing should be easy.

How much does it cost to hire a Certified Information Systems Security Professional (CISSP)?

Rates charged by Certified Information Systems Security Professionals (CISSP) on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.

Why hire a Certified Information Systems Security Professional (CISSP) in the United States on Upwork?

As the world's work marketplace, we connect highly-skilled freelance Certified Information Systems Security Professionals (CISSP) and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Certified Information Systems Security Professional (CISSP) team you need to succeed.

Can I hire a Certified Information Systems Security Professional (CISSP) in the United States within 24 hours on Upwork?

Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Certified Information Systems Security Professional (CISSP) proposals within 24 hours of posting a job description.