Cybersecurity Expert Job Description Template
An effective description can help you hire the best fit for your job. Check out our tips to provide details that skilled professionals are looking for.
A cybersecurity specialist protects an organization’s data, networks, and systems from unauthorized access and cyberattacks. This role is vital in today’s digital landscape, ensuring sensitive information and software systems remain secure. Companies across industries rely on these professionals to implement advanced security measures, perform vulnerability assessments, and manage incident response protocols. Use the job description template below to attract skilled cybersecurity professionals on Upwork.
Job overview
A cybersecurity specialist is responsible for safeguarding an organization’s data and IT infrastructure by implementing security controls and monitoring for vulnerabilities. They work closely with stakeholders to develop security policies, configure firewalls, and address security breaches swiftly. This role requires strong problem-solving abilities, critical thinking, and adaptability. Ideal candidates often hold certifications such as CISSP or CompTIA Security+, a bachelor’s degree in computer science or information systems, and relevant work experience.
Key responsibilities
- Implementing security measures. Design and deploy firewalls, antivirus systems, and intrusion prevention systems (IPS).
- Conducting audits. Perform regular security audits to ensure compliance with organizational and industry standards.
- Monitoring vulnerabilities. Identify and address weak points in systems to prevent unauthorized access.
- Managing incident response. Lead efforts to mitigate security breaches and restore affected systems promptly.
- Collaborating with stakeholders. Work with leadership and IT teams to align cybersecurity strategies with organizational goals.
- Upgrading security systems. Regularly update software and systems to address evolving cyber threats.
- Performing risk assessments. Evaluate potential risks and recommend strategies for mitigation.
- Training team members. Educate staff on security best practices and the importance of safeguarding sensitive information.
- Developing policies. Create and enforce cybersecurity policies to ensure consistent compliance across the organization.
Qualifications and skills
- Education. A bachelor’s degree in computer science, information systems, or a related field; master’s degree preferred.
- Certifications. Professional certifications such as CISSP, CompTIA Security+, or CEH.
- Technical expertise. Strong understanding of network security, malware protection, and operating systems.
- Experience. 3–5 years of experience in IT security or a related field.
- Problem-solving skills. Ability to address security issues and develop actionable solutions.
- Communication skills. Effective at collaborating with stakeholders and presenting technical concepts clearly.
- Adaptability. Capable of handling high-pressure situations and responding to evolving cyber threats.
- Analytical skills. Proficient in data analysis for vulnerability assessment and risk management.
- Project management. Experience leading security initiatives and coordinating with cross-functional teams.
About our company
At [company name], we prioritize data security and innovation. Our team of skilled professionals collaborates to protect critical information and implement advanced cybersecurity strategies. We foster a culture of continuous improvement, equipping our employees with tools and training to tackle the latest security challenges. Join us to contribute to meaningful cybersecurity projects and advance your career in information security.
What does a cybersecurity specialist do?
A cybersecurity specialist is responsible for safeguarding an organization’s digital assets, including sensitive information, networks, and systems, from cyber threats and unauthorized access. They implement security measures, monitor vulnerabilities, and respond to incidents to maintain the integrity and confidentiality of the organization’s data. These professionals play a critical role in minimizing risks associated with cyberattacks and ensuring compliance with security standards.
Beyond technical tasks, cybersecurity specialists collaborate with stakeholders to develop comprehensive security policies and train employees on best practices for protecting sensitive information. They utilize tools like firewalls, antivirus software, and intrusion prevention systems (IPS) to defend against malware, hacking attempts, and other vulnerabilities. Additionally, they assess emerging cyber threats, adapt security protocols to address new challenges, and provide expert insights to drive strategic decision-making. By bridging the gap between technology and organizational needs, cybersecurity specialists ensure both robust protection and operational efficiency.
Cybersecurity specialist duties and responsibilities
Cybersecurity specialists ensure the safety of an organization’s digital assets through proactive and reactive strategies. Responsibilities include:
- Performing vulnerability assessments. Identify and mitigate risks in networks and systems.
- Configuring firewalls. Set up and manage firewalls and IPS to block unauthorized access.
- Responding to incidents. Lead the investigation and remediation of security breaches.
- Developing security policies. Establish clear guidelines for protecting information and systems.
- Monitoring network activity. Use advanced tools to detect anomalies and potential threats.
- Conducting audits. Regularly review systems to ensure compliance with security standards.
- Collaborating with stakeholders. Work with leadership to align security measures with business objectives.
- Educating employees. Train staff on best practices for handling sensitive information and identifying threats.
- Upgrading systems. Keep security software and systems updated to address emerging threats.
Cybersecurity Experts you can meet on Upwork
- $45/hr$45 hourly
Prashant K.
- 5.0
- (22 jobs)
Pune, MHCybersecurity Experts
OAuthGoogle WorkspaceLDAPSaaS DevelopmentApplication IntegrationMicrosoft AzureGoogle Workspace AdministrationSecurity Assertion Markup LanguageMulti-Factor AuthenticationUser Identity ManagementMicrosoft Azure AdministrationOKTASystem SecurityCybersecurity ManagementI help startups, scale-ups, and enterprises implement secure, scalable, and user-friendly authentication systems using Keycloak and other modern identity providers. With 6+ years of specialized experience in Identity and Access Management (IAM), I design and deliver production-ready Single Sign-On (SSO) solutions, passwordless authentication, and fine-grained authorization that reduce security risks while improving user experience. My core expertise includes: Keycloak implementation, optimization, clustering, custom extensions (SPI), realm design, and high-availability setups (Docker + Kubernetes) Complex SSO/Federation using OIDC, SAML 2.0, OAuth2 Integration with Microsoft Entra ID, Okta, Auth0, AWS Cognito, Google Workspace, Salesforce, Oracle IAM, and others Advanced security: MFA (WebAuthn, TOTP, YubiKey), RBAC/ABAC (OpenFGA, OPA), conditional & risk-based authentication User provisioning & lifecycle management with SCIM 2.0, LDAP/AD sync, and bulk migrations Troubleshooting and fixing common identity issues (redirect loops, token errors, SAML assertion problems, session management) I work fluently with Spring Boot, .NET, Node.js/NestJS, React/Next.js, Golang, and strong DevOps practices (AWS, Oracle Cloud, Terraform, CI/CD). Whether you need a fresh Keycloak setup, migration from Auth0/Okta/Cognito, custom authenticator development, or long-term IAM strategy — I deliver clean, well-documented solutions quickly (often within days for standard implementations). Let's discuss how I can secure and simplify authentication for your application. My Expertise: ✅ SSO / Identity Federation - SSO Login Setup (Web, Mobile, Cloud) - Custom Identity Provider Integration (SAML/OAuth-based) - Role-Based & Attribute-Based Access Control (RBAC/ABAC) ✅ Authorization & MFA - Fine-grained access via OpenFGA, OPA, RBAC/ABAC - MFA setup: OTP, TOTP, YubiKey, WebAuthn, Push - Conditional access, risk-based auth, step-up auth ✅ User Lifecycle / SCIM / Provisioning - SCIM 2.0 integrations - AD/LDAP sync - Scripted provisioning & deprovisioning - Bulk user provisioning and migration via SCIM APIs (Auth0 to OCI IAM) ✅ Troubleshooting Identity Nightmares - Fixing SAML assertion issues - OAuth callback errors - Token/session misconfigurations - Resolving redirect loops, login failures 🛠️ Identity Providers I’ve Worked With (100+): ✅ Google SSO login ✅ Microsoft Entra ID (Azure AD) SSO ✅ Okta SSO Integration ✅ Keycloak SSO ✅ Oracle IAM – OCI IAM, OAM, OIM ✅ Oracle Student Financial Aid (SFA) ✅ GitHub SSO ✅ Ping Federate SSO Login ✅ Auth0 Universal Login Setup ✅ OneLogin SSO Integration ✅ Shibboleth IdP/SP ✅ JumpCloud SSO Login/Provisioning ✅ ForgeRock IAM ✅ IdentityServer4/8 ✅ WSO2 Identity Server ✅ SimpleSAMLphp ✅ Custom SAML SPs ✅ AWS Cognito SSO ✅ Salesforce SSO ✅ G Suite Login ✅ Apple & Facebook OAuth ✅ ADFS (Active Directory Federation Services) 🏆 Why Work With Me? - Rapid SSO & IAM Setup (often within hours) - Deep experience debugging login/session/token issues - Clear, documented implementations - Flexible for both one-time fixes and long-term IAM strategy 🧰 Technical Expertise Languages: C#, Java, JavaScript, Python, PHP, Golang, Bash Frameworks & Libraries: Spring Boot, Spring Security, .NET, Node.js (Express), Django, React,NEXT JS, NEST JS, Angular. Security & Authentication: SAML2, OAuth2, OpenID Connect (OIDC), JWT, WS-Fed, MFA, SCIM, RBAC, CIBA. DevOps & Cloud Infrastructure: AWS, Oracle Cloud (OCI), Docker, Kubernetes (K8s/EKS), GitHub/Gitlabs Actions, CI/CD Pipelines Application & Deployment Management: Multi-stage Docker builds, Deployment automations, Gitlabs/Github/Jenkins CI/CD, enterprise rollout via Group Policy (GPO). If you're looking for an IAM expert who can secure your authentication workflows, integrate SSO solutions across platforms, and build scalable identity management systems, let's connect! - $55/hr$55 hourly
Saeed U.
- 5.0
- (45 jobs)
Lahore, PUNJABCybersecurity Experts
Information Security ConsultationInformation SecurityCybersecurity ManagementSecurity Policies & Procedures DocumentationPCICloud Security FrameworkNIST SP 800-53SOC 2HIPAAInformation Security AuditIT General Controls TestingSecurity Operation CenterISO 27001SOC 2 ReportI’ve helped companies get ISO 27001/SOC-2/PCI-DSS/FedRAMP/CMMC certifications and compliance against standards such as NIST and HIPAA. I offer 𝗠𝗢𝗡𝗘𝗬-𝗕𝗔𝗖𝗞 𝗚𝗨𝗔𝗥𝗔𝗡𝗧𝗘𝗘 to my clients against ISO 27001, SOC 2 and PCI-DSS compliance! Are your clients requesting security certifications or compliance against HIPAA, ISO 27001, SOC 2, PCI-DSS, or FedRAMP etc.? Do you want a cost effective solution for achieving and maintaining compliance? Do you want help is filling out the security assessment questionnaires and want someone to respond in a way that you are able to win the deal? Do you want surety/ confirmation that your certification project will be a success and you won't loose money over consultation? If you have already purchased a DIY compliance tool (Drata, Vanta, Thoropass/HeyLaika, Sprinto, OneTrust Compliance Automatization/Tugboat Logic, SecureFrame, and so on) but don’t have the time and energy to achieve and maintain compliance) Do you want to enhance your company's current security posture? MY PROFILE I have over 10 years of experience and have worked within IT GRC (Governance, Risk, Compliance), internal controls and review assurance roles within financial, telecom, fintech and banking industry. The combination of Information technology, accounting & auditing has molded me into an individual who can perform IS Audits (General Controls, Application Controls, Specialized Audits, IT policy & SOPs), IT risk reviews (Risk Assessments, BCP & DR, Risk Mitigation & Control Design), Ethical Hacking, Functional Reviews & QA (Quality Assurance) Services, IT security consultancy (IS Policy & Implementation under different frameworks i.e. 27001, NIST, COBIT 5, PCI, HiTrust, HIPAA, GDPR, SOC 2, SOX) and pre-implementation & post-implementation project reviews, BRD creation by following industry best practices. I can secure your cloud environment with expertise in AWS and Azure by following security hardening best practices. I have also served as DPO (Data Protection Officer) for various clients to help them conform with GDPR requirements. MY CREDENTIALS - CISSP (Certified Information Systems Security Professional) - USA - CISA (Certified in Information System Audit) - USA - CRISC (Certified in Risk & Information Systems Control) - USA - CGEIT (Certified in Governance of Enterprise IT) - USA - SQL Fundamentals (Oracle) - EH (Ethical Hacker) - Cyber security Fundamentals Certification - Kaspersky - Google Analytics - NSE 5 (Network Security Analyst) Tags: Information Security Analyst Chief Information Security Officer ( CISO ) Information Security Manager SOC Analyst SOC (Security Operations Center) Tools: SIEM, CrowdStrike Falcon, Fortinet, FortiAnalyzer, FortiGate, FortiSIEM, Stellar Cyber, Cylance, Splunk, AWS CloudWatch, Microsoft Defender (Azure), AWS CloudTower, GCP - $75/hr$75 hourly
Md Azizur R.
- 4.9
- (31 jobs)
Dhaka, DHAKACybersecurity Experts
Secure SDLCSecurity AnalysisCloud SecurityISO 27001Security EngineeringSecurity Policies & Procedures DocumentationSecurity TestingSource Code ScanningInformation SecurityPenetration TestingApplication SecurityCybersecurity ManagementNetwork SecurityDatabase SecurityVulnerability AssessmentI help organizations become audit-ready, secure, and compliant - without overengineering or slowing down business. With 17+ years in cybersecurity, I operate as a Fractional CISO (vCISO), bridging technical execution, risk governance, and compliance across fast-growing SaaS companies, fintech, and enterprise environments. I specialize in building end-to-end security programs aligned with: ISO/IEC 27001 SOC 2 NIS2 Directive HIPAA 🎯 What I Deliver 🔐 Compliance & Audit Readiness SOC 2 Type I & II end-to-end readiness ISO 27001 ISMS design, implementation & audit support NIS2 gap assessment & full implementation roadmap HIPAA compliance for SaaS, VoIP, and cloud platforms 🛡️ Security Leadership (vCISO) Security strategy aligned with business goals Risk management (NIST CSF, CIS Controls) Board-level reporting (Risk vs Cost vs Impact) Vendor & third-party risk management ⚙️ Technical & Cloud Security AWS / GCP / Azure security architecture & hardening DevSecOps & Secure SDLC (SAST, DAST, IAST integration) Application & API security testing Identity & Access Management (IAM / PAM) 🔍 Offensive Security & Assurance Penetration testing (Web, mobile and Network) Red team simulation & threat modeling Secure code review & vulnerability management 🧠 Why Clients Hire Me I don’t just deliver policies - I deliver working security programs I translate technical risk into business decisions I align compliance with real-world architecture (AWS, SaaS, DevOps) I help you pass audits AND actually be secure 🏆 Credentials CISM • CISA • CEH • ECSA • LPT (Master) ISO 27001 Lead Implementer (BSI) AWS Security Specialty • Azure Security (AZ-500) 💡 Engagement Model Fractional CISO (ongoing advisory) Compliance programs (SOC 2 / ISO 27001 / NIS2 / HIPAA) Security assessments & remediation Audit readiness & evidence preparation 🚀 Let’s Talk If you're preparing for an audit, scaling securely, or need a CISO-level partner without full-time cost, I can help you get there efficiently.
- $45/hr$45 hourly
Prashant K.
- 5.0
- (22 jobs)
Pune, MHCybersecurity Experts
OAuthGoogle WorkspaceLDAPSaaS DevelopmentApplication IntegrationMicrosoft AzureGoogle Workspace AdministrationSecurity Assertion Markup LanguageMulti-Factor AuthenticationUser Identity ManagementMicrosoft Azure AdministrationOKTASystem SecurityCybersecurity ManagementI help startups, scale-ups, and enterprises implement secure, scalable, and user-friendly authentication systems using Keycloak and other modern identity providers. With 6+ years of specialized experience in Identity and Access Management (IAM), I design and deliver production-ready Single Sign-On (SSO) solutions, passwordless authentication, and fine-grained authorization that reduce security risks while improving user experience. My core expertise includes: Keycloak implementation, optimization, clustering, custom extensions (SPI), realm design, and high-availability setups (Docker + Kubernetes) Complex SSO/Federation using OIDC, SAML 2.0, OAuth2 Integration with Microsoft Entra ID, Okta, Auth0, AWS Cognito, Google Workspace, Salesforce, Oracle IAM, and others Advanced security: MFA (WebAuthn, TOTP, YubiKey), RBAC/ABAC (OpenFGA, OPA), conditional & risk-based authentication User provisioning & lifecycle management with SCIM 2.0, LDAP/AD sync, and bulk migrations Troubleshooting and fixing common identity issues (redirect loops, token errors, SAML assertion problems, session management) I work fluently with Spring Boot, .NET, Node.js/NestJS, React/Next.js, Golang, and strong DevOps practices (AWS, Oracle Cloud, Terraform, CI/CD). Whether you need a fresh Keycloak setup, migration from Auth0/Okta/Cognito, custom authenticator development, or long-term IAM strategy — I deliver clean, well-documented solutions quickly (often within days for standard implementations). Let's discuss how I can secure and simplify authentication for your application. My Expertise: ✅ SSO / Identity Federation - SSO Login Setup (Web, Mobile, Cloud) - Custom Identity Provider Integration (SAML/OAuth-based) - Role-Based & Attribute-Based Access Control (RBAC/ABAC) ✅ Authorization & MFA - Fine-grained access via OpenFGA, OPA, RBAC/ABAC - MFA setup: OTP, TOTP, YubiKey, WebAuthn, Push - Conditional access, risk-based auth, step-up auth ✅ User Lifecycle / SCIM / Provisioning - SCIM 2.0 integrations - AD/LDAP sync - Scripted provisioning & deprovisioning - Bulk user provisioning and migration via SCIM APIs (Auth0 to OCI IAM) ✅ Troubleshooting Identity Nightmares - Fixing SAML assertion issues - OAuth callback errors - Token/session misconfigurations - Resolving redirect loops, login failures 🛠️ Identity Providers I’ve Worked With (100+): ✅ Google SSO login ✅ Microsoft Entra ID (Azure AD) SSO ✅ Okta SSO Integration ✅ Keycloak SSO ✅ Oracle IAM – OCI IAM, OAM, OIM ✅ Oracle Student Financial Aid (SFA) ✅ GitHub SSO ✅ Ping Federate SSO Login ✅ Auth0 Universal Login Setup ✅ OneLogin SSO Integration ✅ Shibboleth IdP/SP ✅ JumpCloud SSO Login/Provisioning ✅ ForgeRock IAM ✅ IdentityServer4/8 ✅ WSO2 Identity Server ✅ SimpleSAMLphp ✅ Custom SAML SPs ✅ AWS Cognito SSO ✅ Salesforce SSO ✅ G Suite Login ✅ Apple & Facebook OAuth ✅ ADFS (Active Directory Federation Services) 🏆 Why Work With Me? - Rapid SSO & IAM Setup (often within hours) - Deep experience debugging login/session/token issues - Clear, documented implementations - Flexible for both one-time fixes and long-term IAM strategy 🧰 Technical Expertise Languages: C#, Java, JavaScript, Python, PHP, Golang, Bash Frameworks & Libraries: Spring Boot, Spring Security, .NET, Node.js (Express), Django, React,NEXT JS, NEST JS, Angular. Security & Authentication: SAML2, OAuth2, OpenID Connect (OIDC), JWT, WS-Fed, MFA, SCIM, RBAC, CIBA. DevOps & Cloud Infrastructure: AWS, Oracle Cloud (OCI), Docker, Kubernetes (K8s/EKS), GitHub/Gitlabs Actions, CI/CD Pipelines Application & Deployment Management: Multi-stage Docker builds, Deployment automations, Gitlabs/Github/Jenkins CI/CD, enterprise rollout via Group Policy (GPO). If you're looking for an IAM expert who can secure your authentication workflows, integrate SSO solutions across platforms, and build scalable identity management systems, let's connect! - $55/hr$55 hourly
Saeed U.
- 5.0
- (45 jobs)
Lahore, PUNJABCybersecurity Experts
Information Security ConsultationInformation SecurityCybersecurity ManagementSecurity Policies & Procedures DocumentationPCICloud Security FrameworkNIST SP 800-53SOC 2HIPAAInformation Security AuditIT General Controls TestingSecurity Operation CenterISO 27001SOC 2 ReportI’ve helped companies get ISO 27001/SOC-2/PCI-DSS/FedRAMP/CMMC certifications and compliance against standards such as NIST and HIPAA. I offer 𝗠𝗢𝗡𝗘𝗬-𝗕𝗔𝗖𝗞 𝗚𝗨𝗔𝗥𝗔𝗡𝗧𝗘𝗘 to my clients against ISO 27001, SOC 2 and PCI-DSS compliance! Are your clients requesting security certifications or compliance against HIPAA, ISO 27001, SOC 2, PCI-DSS, or FedRAMP etc.? Do you want a cost effective solution for achieving and maintaining compliance? Do you want help is filling out the security assessment questionnaires and want someone to respond in a way that you are able to win the deal? Do you want surety/ confirmation that your certification project will be a success and you won't loose money over consultation? If you have already purchased a DIY compliance tool (Drata, Vanta, Thoropass/HeyLaika, Sprinto, OneTrust Compliance Automatization/Tugboat Logic, SecureFrame, and so on) but don’t have the time and energy to achieve and maintain compliance) Do you want to enhance your company's current security posture? MY PROFILE I have over 10 years of experience and have worked within IT GRC (Governance, Risk, Compliance), internal controls and review assurance roles within financial, telecom, fintech and banking industry. The combination of Information technology, accounting & auditing has molded me into an individual who can perform IS Audits (General Controls, Application Controls, Specialized Audits, IT policy & SOPs), IT risk reviews (Risk Assessments, BCP & DR, Risk Mitigation & Control Design), Ethical Hacking, Functional Reviews & QA (Quality Assurance) Services, IT security consultancy (IS Policy & Implementation under different frameworks i.e. 27001, NIST, COBIT 5, PCI, HiTrust, HIPAA, GDPR, SOC 2, SOX) and pre-implementation & post-implementation project reviews, BRD creation by following industry best practices. I can secure your cloud environment with expertise in AWS and Azure by following security hardening best practices. I have also served as DPO (Data Protection Officer) for various clients to help them conform with GDPR requirements. MY CREDENTIALS - CISSP (Certified Information Systems Security Professional) - USA - CISA (Certified in Information System Audit) - USA - CRISC (Certified in Risk & Information Systems Control) - USA - CGEIT (Certified in Governance of Enterprise IT) - USA - SQL Fundamentals (Oracle) - EH (Ethical Hacker) - Cyber security Fundamentals Certification - Kaspersky - Google Analytics - NSE 5 (Network Security Analyst) Tags: Information Security Analyst Chief Information Security Officer ( CISO ) Information Security Manager SOC Analyst SOC (Security Operations Center) Tools: SIEM, CrowdStrike Falcon, Fortinet, FortiAnalyzer, FortiGate, FortiSIEM, Stellar Cyber, Cylance, Splunk, AWS CloudWatch, Microsoft Defender (Azure), AWS CloudTower, GCP - $75/hr$75 hourly
Md Azizur R.
- 4.9
- (31 jobs)
Dhaka, DHAKACybersecurity Experts
Secure SDLCSecurity AnalysisCloud SecurityISO 27001Security EngineeringSecurity Policies & Procedures DocumentationSecurity TestingSource Code ScanningInformation SecurityPenetration TestingApplication SecurityCybersecurity ManagementNetwork SecurityDatabase SecurityVulnerability AssessmentI help organizations become audit-ready, secure, and compliant - without overengineering or slowing down business. With 17+ years in cybersecurity, I operate as a Fractional CISO (vCISO), bridging technical execution, risk governance, and compliance across fast-growing SaaS companies, fintech, and enterprise environments. I specialize in building end-to-end security programs aligned with: ISO/IEC 27001 SOC 2 NIS2 Directive HIPAA 🎯 What I Deliver 🔐 Compliance & Audit Readiness SOC 2 Type I & II end-to-end readiness ISO 27001 ISMS design, implementation & audit support NIS2 gap assessment & full implementation roadmap HIPAA compliance for SaaS, VoIP, and cloud platforms 🛡️ Security Leadership (vCISO) Security strategy aligned with business goals Risk management (NIST CSF, CIS Controls) Board-level reporting (Risk vs Cost vs Impact) Vendor & third-party risk management ⚙️ Technical & Cloud Security AWS / GCP / Azure security architecture & hardening DevSecOps & Secure SDLC (SAST, DAST, IAST integration) Application & API security testing Identity & Access Management (IAM / PAM) 🔍 Offensive Security & Assurance Penetration testing (Web, mobile and Network) Red team simulation & threat modeling Secure code review & vulnerability management 🧠 Why Clients Hire Me I don’t just deliver policies - I deliver working security programs I translate technical risk into business decisions I align compliance with real-world architecture (AWS, SaaS, DevOps) I help you pass audits AND actually be secure 🏆 Credentials CISM • CISA • CEH • ECSA • LPT (Master) ISO 27001 Lead Implementer (BSI) AWS Security Specialty • Azure Security (AZ-500) 💡 Engagement Model Fractional CISO (ongoing advisory) Compliance programs (SOC 2 / ISO 27001 / NIS2 / HIPAA) Security assessments & remediation Audit readiness & evidence preparation 🚀 Let’s Talk If you're preparing for an audit, scaling securely, or need a CISO-level partner without full-time cost, I can help you get there efficiently. - $125/hr$125 hourly
Luciano F.
- 5.0
- (20 jobs)
Winter Garden, FLCybersecurity Experts
Network Penetration TestingJavaScriptPythonPHPWeb App Penetration TestingProject Risk ManagementCybersecurity ManagementSecurity TestingIncident ManagementAI SecurityRisk AssessmentVulnerability AssessmentPenetration TestingThreat DetectionCyber Threat IntelligenceCI/CDAmazon GuardDutyInfrastructure as CodeNIST SP 800-53FedRAMPZero Trust ArchitectureCloud SecurityI help organizations reduce cybersecurity risk, secure products, meet compliance requirements, and build practical security capabilities. I am an experienced Chief Information Security Officer, penetration tester, cybersecurity instructor, course creator, and founder of LufSec. I work with startups, SaaS companies, enterprise teams, and training organizations that need senior cybersecurity expertise without unnecessary complexity or full-time overhead. My services include: FRACTIONAL CISO AND SECURITY LEADERSHIP • Build or mature cybersecurity programs • Perform security, risk, and compliance assessments • Develop security strategies, roadmaps, policies, and metrics • Prepare organizations for SOC 2, ISO 27001, NIST, GDPR, CCPA, and customer security reviews • Evaluate security architecture, vendors, cloud environments, and operational controls • Support executive teams, boards, auditors, customers, and investors • Implement vulnerability management, incident response, DevSecOps, security awareness, and third-party risk programs PENETRATION TESTING AND APPLICATION SECURITY • Web application penetration testing • API security testing • Cloud and infrastructure security assessments • Vulnerability validation and risk prioritization • OWASP Top 10 testing • Authentication, authorization, session, business-logic, and access-control testing • Executive and technical reports with clear remediation guidance • Retesting and remediation support AI AND LLM SECURITY • AI application and agent security assessments • Prompt injection and indirect prompt injection testing • LLM red teaming and adversarial testing • Sensitive-data exposure and unsafe tool-use analysis • AI governance, acceptable-use policies, and enterprise guardrails • Secure adoption of ChatGPT, Claude, Microsoft Copilot, and other AI assistants • AI security workshops for technical and non-technical teams CYBERSECURITY TRAINING AND CUSTOM COURSE DEVELOPMENT • Customized corporate cybersecurity workshops • Instructor-led remote and onsite training • Cybersecurity course design and curriculum development • Hands-on labs, demonstrations, assessments, and instructor materials • Executive, technical, and non-technical audience training • Topics including penetration testing, web hacking, AI security, cloud security, IoT security, secure development, governance, and compliance WHY CLIENTS HIRE ME • Active CISO-level leadership experience • More than two decades of cybersecurity experience • Strong combination of executive strategy and hands-on technical capability • Experience implementing security programs in SaaS and enterprise environments • Practical communication for executives, engineers, auditors, customers, and students • Published cybersecurity author, instructor, podcaster, and course creator • Founder of LufSec and host of Inside Cyber Minds • Native Portuguese speaker with professional English fluency I do not deliver generic reports, recycled policies, or theoretical presentations. My work is designed to produce a measurable outcome: reduced risk, stronger controls, clearer decisions, improved compliance readiness, actionable technical findings, or a workforce that knows how to operate securely. Send me a message with your environment, challenge, timeline, and expected outcome. I will help you determine the most effective scope and approach. - $100/hr$100 hourly
Brenton K.
- 5.0
- (6 jobs)
Louisville, KYCybersecurity Experts
Game UI/UX DesignApp DevelopmentAI App DevelopmentDevOpsWeb DesignApp DesignAI DevelopmentSoftware DesignFinance & AccountingXeroIntuit QuickBooksFinancial ConsultingVendor & Supplier OutreachProject ManagementCybersecurity ManagementMy name is Brenton Keye, owner of Le Famille Consultants which is a consulting firm providing expert guidance in health care equipment, the construction industry, transportation and logistics; finances, technology including software development, web site design, cybersecurity, app development. Our expertise, knowledge and large network allows us to source a solution to your problems. We have a team of developers in front end and back end design totaling over 15 years experience working on some of the most notable developments. With over 12 years of experience, my niche lies in supplier diversity and corporate tax advocacy, serving clients in the healthcare, construction, and technology sectors. I specialize in securing tax breaks and incentives for clients through diverse federal government certifications. My expertise and commitment have allowed me to serve as a contracted consultant for reputable corporations, such as LB Foster, Health 770, and CJ Mahan Construction. If you have a product or brand that you want to market to big name retailers, I can help you push your items into these stores using supplier diversity initiatives. I have several years in account management and project management skills working with the United States Corps of Engineers, United States Coast Guards and several state municipalities groups. I have worked with several fortune 100 companies including the leading steel supplier in the world who utilize supplier diversity, I have had successful years as an independent consultant accumulating over $3 million in sales in less than 2 years. I am a member of several supplier diversity organizations which help corporations receive tax incentives, some of those certifying agencies including the Department of Veterans Affairs which is listed and shows certifications on my Upwork profile. PTIN P03455384 ACDBE Certified DBE Certified (CA,TX,AZ,KY,OH,WA,HI,NY,NJ,LA) SBE Certified Sam.gov Certified SDVOSB Certified - $40/hr$40 hourly
Jawad Saqib B.
- 4.8
- (45 jobs)
Rawalpindi, PUNJABCybersecurity Experts
Code ReviewPythonSecurity AnalysisWebsite SecurityMobile App TestingSecurity EngineeringCloud SecurityNetwork SecurityPenetration TestingSecurity Assessment & TestingCybersecurity ManagementMalware RemovalInformation SecurityVulnerability AssessmentInformation Security Consultation✅ Amongst the Top 1000 hackers worldwide Web Pentesting | Mobile App Pentesting | API Pentesting | Vulnerability Assessment | Python & Bash Automation I work with companies to make their digital assets secure and provide solutions to enhance their security parameters. I create cybersecurity content on hackingloops.com explaining the practicalities and how-tos of the vulnerability and exploitation Part-time bug bounty hunter at Bugcrowd & Intigriti. Feel free to contact me for your queries and security-related issues. - $50/hr$50 hourly
Ashish J.
- 5.0
- (26 jobs)
Ahmedabad, GUJARATCybersecurity Experts
Network ArchitectureCisco UCSServer VirtualizationInformation SecurityCisco MerakiARCserveFortinetSophos Sophos UTMNetwork DesignWeb Application FirewallCybersecurity ManagementNetwork SecurityCisco ISECisco ASAFirewallDedicated and highly experienced Network Security professional with 20+ years of proven expertise in designing, implementing, and maintaining robust network and security. Oversee large-scale IT projects, networks, and infrastructures. Outstanding results and complete projects on time. Firewalls: • Sophos UTM, XG and XGS all models, Dynamic routing and XDR. • Fortigate all models, FortiManager, FortiAnalyser., FortiAP, FortiSwitch • Checkpoint Firewall • Cisco Meraki, Cisco Firepower (FMC) Cisco ASA-5515, 5520,5550,5506-x. • Cisco Wireless Access point and WLC. • Cisco ISE • Watchguard all models Dynamic Routing. • Firewall Configuration migration. • Sophos Firewall policy, Dynamic routing, HA, SD-WAN, VPN and other configurations Managing, Troubleshooting. • Fortigate Firewall Policy configuration, Dynamic routing, HA, SD-WAN, External Connectors configuration. Managing, Troubleshooting. • FortiNAC, FortiManager. FortiAnalyzer, Fortinet SASE & EMS. • Watchguard Firewall Policy, Dynamic routing, UTM, SD-WAN configuration, HA, Managing, Troubleshooting. • Cisco Firewall Policy configuration, VPN, Failover, IPS-IDS Managing, Troubleshooting. • Cisco Meraki MX deployment and troubleshooting. • Cisco Identity Service Engine ISE design and deployment with HA Managing, Troubleshooting. • All Firewall VPN - IPSec, Site-To-Site VPN, SSL VPN. • ManageEngine Endpoint Central implementation and support Routing & Switching • Cisco Routers almost all router including ISR 1000,4000 series Managing, Troubleshooting. • Cisco Switching Catalyst all models, Nexus all models Managing, Troubleshooting. • Routing Protocol - OSPF, EIGRP, and BGP. • NAT, Policy-based Routing, QoS, Traffic shaping. 1:- Send me an invite 2:- Lets connect over the call or message. 3:- I will ask you few questions for your requirements 4:- Will provide you exact plan for your goal with expected duration 5:- After agree on all points and looks good we can execute the plan Just click on Invite button and let's work together. #SDWAN #Fortinet #Fortigate #FortiNAC #PaloAlto #DNACenter #SDN #ISE #IdentityServicesEngine #Firepower #CiscoUmbrella #EmailSecurityAppliance #WebSecurityAppliance #CloudWebSecurity #ciscoasa #Meraki #Stealthwatch #ManageEngine #Sophos #Watchguard #VPN #ASA #Telepresence #IPCameras #ASR1K #ASR9K #NexusSwitches #PrimeInfrastructure #IPTelephony #NetworkDesigning #Monitoring #SecurityInfrastructure #Acronis #Arcserve - $35/hr$35 hourly
Dondranreb T.
- 4.7
- (361 jobs)
San Jose del Monte, BULACANCybersecurity Experts
Cybersecurity ManagementHIPAATechnical ReportSOC 2 ReportAircallSOC 2Microsoft OutlookWorkspaceGoogle Apps ScriptGoogle Workspace AdministrationData EntryEmail SecurityDNSData MigrationEmail SupportI am a Certified Google Workspace Administrator and a versatile IT professional with a diverse skill set honed over nine years in the tech industry, including working with a renowned multinational company in technical support. Google Workspace Mastery: Expert in all facets of Google Workspace administration, from user creation and email management to full suite deployment. Vanta and SOC 2 Audit Specialist: Skilled in compliance and security standards, ensuring your business meets critical regulatory requirements. Report Analysis & Cybersecurity: Proficient in analyzing complex data and implementing robust cybersecurity measures to protect digital assets. Google Ads Certification: Qualified in managing effective Google Ads campaigns and enhancing your digital marketing strategies. Email System Expertise: I am proficient at email migration, setup, and troubleshooting across platforms like G Suite, Office 365, and Zoho. DNS Configuration: Advanced knowledge of DNS zone file configurations ensures seamless domain and email operations. Customer Service and Tech Support: Over six years of experience providing top-tier customer service and technical support, resolving issues efficiently, and maintaining high customer satisfaction. As a self-motivated and highly skilled IT Administrator, I am committed to leveraging my expertise to provide innovative solutions, streamline operations, and drive your business's digital success. I am looking forward to collaborating on your next project! - $150/hr$150 hourly
Luciana O.
- 5.0
- (231 jobs)
Boerne, TXCybersecurity Experts
PCI DSSNIST SP 800-53CMMCRisk AssessmentCloud SecurityInternet SecurityInformation Security AuditInformation Security AwarenessSecurity EngineeringSecurity AnalysisEmail SecurityPenetration TestingInformation SecuritySecurity Policies & Procedures DocumentationCybersecurity ManagementI am the founder of BetterCyber Consulting, a cybersecurity consulting and managed services firm specializing in startups, small businesses, and mid-sized companies. As an Upwork Expert-Vetted Cybersecurity Consultant, I help businesses identify risks, implement security controls, and meet compliance requirements without unnecessary costs or complexity. My experience in cybersecurity includes positions at Fortune 100 companies like PayPal and Marathon Petroleum. I hold several security certifications and earned a master’s degree in Information Security Engineering from The SANS Technology Institute. I offer the following cybersecurity services: ● Technical Security Assessments – Security reviews for AWS, Azure, Google Cloud, Microsoft 365, Google Workspace, Slack, and more. ● Penetration Testing – Web, cloud, mobile, and on-premises security testing. ● Compliance Assessments – NIST 800-171 & 800-53, FedRAMP, ISO 27001, CIS Controls, CMMC, HIPAA, and SOC 2. ● Security Strategy & Architecture – Build scalable security programs. ● Incident Response & Threat Mitigation – Detect and respond to threats. ● Managed Security Services – Ongoing security monitoring and advisory. ● Virtual CISO (vCISO) Services – Security leadership for businesses without a full-time CISO. Want to browse more talent?
Sign up
Join the world’s work marketplace

Post a job to interview and hire great talent.
Hire Talent
Find work you love with like-minded clients.
Find WorkCloud Architects
Business Development Consultants
Certified AWS Cloud Architects
Ethical Hacking
Network Engineering
Cloud Engineer
DevOps
Penetration Testing
Network Security
YouTube Marketing
Web Development
Web Design
Vue.js
Virtual Assistant
User Experience Design
Translation