Hire the Best Information Security Analysts
in Australia

More than 3,000 reviews on G2
Rating is 4.5 out of 5.
4.5/5
of Upwork by G2 peer reviewers
Muhammad Khuram A.

Melbourne, Australia

$30/hr
5.0
4 jobs

Information Security & GRC Specialist | Cybersecurity Product Manager | Risk & Compliance Consultant I am an experienced Cybersecurity and GRC professional with a proven track record in designing, implementing, and managing security frameworks, compliance programs, and risk management strategies across public and private sectors. With a strong technical foundation and a Master’s degree in Information Security, I bridge the gap between governance, compliance, and hands-on technical security. What I Offer: ✅ Governance, Risk & Compliance (GRC): Policy, procedure, and control development aligned with ISO, NIST, SOC2, GDPR, PCI-DSS, Cyber Essentails, Essential 8, NZISM, NCA, SAMA, etc. Internal audits, control testing, and evidence collection for compliance readiness Risk assessments, vendor due diligence, and enterprise risk register management Awareness training programs development ✅ Cybersecurity Consulting & Technical Expertise: Vulnerability assessment & penetration testing (Metasploit, Nessus, BurpSuite) Security operations & monitoring (SIEM, IDS/IPS, NGFW, WAF) Cloud security (AWS, Azure) and virtual environments (VMware, vSphere) Malware analysis, intrusion detection, and incident response ✅ Product Management for GRC Platforms: Lead product roadmaps for compliance, risk, vendor, and policy management modules SME in embedding international best practices (ISO 27001, NIST, COSO, etc.) into product features Experience working closely with developers, QA teams, and stakeholders to deliver secure, user-friendly, and compliance-driven platforms Skilled in customer-facing demos, stakeholder engagement, and executive-level presentations Certifications & Credentials: Certified Information Security Manager CISM - ISACA ISO/IEC 27001 Lead Implementer – PECB International Certificate in Enterprise Risk Management – IRM UK Certified in Cyber Security (CC) – (ISC)² GRC Professional – OneTrust HCIA Security – Huawei | CCNA Security – Cisco Plus certifications in Threat Intelligence, Python, and Network/Endpoint Security Why Work With Me? I combine strategic GRC expertise with deep technical cybersecurity knowledge—rare in the industry. Whether you need end-to-end compliance implementation, risk assessments, vendor security reviews, or product strategy for GRC and cyber security platforms, I can deliver with professionalism, accuracy, and a solutions-focused mindset. Let’s work together to strengthen your organization’s security posture, streamline compliance, and build trust with stakeholders.

  • Information Security
  • Cybersecurity Management
  • Network Security
  • Penetration Testing
  • Vulnerability Assessment
  • Information Security Audit
  • Information Security Awareness
  • Research Documentation
  • Internet Security
  • Network Engineering
Syed Qamber R.

Sydney, Australia

$50/hr
4.9
23 jobs

Following is a summary of my skills: • ISO27001 compliance and gap analysis • IT Security Policies and Frameworks • PCI DSS Assessment level 1 & 2 for merchants and Service provider • Penetration testing • SIEM and Forensics analysis • NIST 800-53 • Risk Assessment and Treatment • Application security vulnerabilities, testing techniques, and the OWASP framework • GDPR • Vulnerability Scanning Experience: • Advise Network and system team to securely build/change Azure and AWS cloud infrastructure for existing and potential clients. • Engage with Client to understand their infrastructure requirements to build and integrate AWS API’s and services. • Maintain and improve ISMS framework that includes SOA, Risk assessment and treatment plan, Risk register and ISM forum to convey the risk to management for their review and support. • Maintain security certifications, including ISO 27001, IRAP and PCI dss. • Conducts Gap assessment as per ISM, PSPF, ISO27001, PCI, NIST and GDPR. • Monitor and assure compliance with information security and privacy regulations, including APRA CPS 234, Privacy Act and GDPR • Manage internal and external audits and remediation • Deliver training programs for security and privacy awareness • Conduct/review security risk assessments of assets and projects • Manage supply chain security • Support Sales and commercials team in responding to security questionnaires • Provides application security services including secure coding techniques and reviews, education & awareness, process and tools, security testing support and guidance for internal software development projects • Reviews information security policies, incident response plans, change management, vulnerability management, patch management policies, etc., as they apply to various facets of the infrastructure in scope. • Performs internal penetration tests, network vulnerability assessments to provide a comprehensive view of the client’s network weaknesses that are exposed to threats. Following are the certifications I have: CISSP CCSP (Cloud security) CEH

  • Certified Information Systems Security Professional
  • Vulnerability Assessment
  • Nessus
  • AT&T Cybersecurity
  • GDPR
  • OWASP
  • HIPAA
  • PCI
  • Data Protection
  • Employee Training
Felix H.

Warragul, Australia

$25/hr
5.0
9 jobs

Seeing suspicious logins, spam bursts, or unknown activity? I help you identify the source, contain the risk, and secure your accounts—fast. I specialize in log monitoring, threat detection, and email security investigations using SIEM (Security Onion / Elastic). I analyze system & auth logs to uncover unauthorized access, brute force attempts, and abnormal patterns. Recent work includes: - Email Security Exposure Report - MacOS App Beta Software Tester Report - Mini SIEM Dashboard → parsed logs, visualized alerts, identified suspicious IP activity - Simulated attacks (Kali → Ubuntu) and validated detections via Zeek + Elastic You get a solution and clear report, risk level, and actionable fixes—not just raw data. Message me with your issue (alerts, hacked account, suspicious traffic). I’ll assess quickly and propose next steps.

  • Cybersecurity Management
  • Security Analysis
  • Vulnerability Assessment
  • Python
  • SQL
  • Kali Linux
  • Cybersecurity Tool
  • Cybersecurity Monitoring
  • NIST Cybersecurity Framework
  • Network Analysis
  • Network Monitoring
  • Email Security
  • Incident Response Plan
  • Threat Detection
Fahad H.

Sydney, Australia

$55/hr
5.0
1 jobs

Welcome to my profile As a certified and qualified Cybersecurity Consultant holding CISA, CISM, CCISO, and CRISC credentials, I bring a wealth of expertise in implementing and auditing information security frameworks. I also serve as a Lead Auditor for ISO 27001, with extensive experience in driving initiatives across information security & risk assessment, as well as cloud compliance for businesses of all sizes. My background includes hands-on involvement with ISO 27001, PCI DSS, NIST, SOC 2, and GDPR compliance services. My passion lies in helping organizations streamline processes, improve operational efficiency, and protect their critical crown jewels information assets. I have helped and assisted clients globally in: - Comprehensive Auditing: In-depth audits for ISO 27001 (Information Security Management Systems), ensuring compliance and identifying areas for improvement. - Compliances Help organizations achieve and maintain compliance with SOC 2 & PCI DSS requirements, ensuring the highest levels of security and data protection services including (+) PCI DSS & SOC 2 Readiness Assessment, (+) PCI DSS & SOC 2 Audit Preparation, (+) SOC 2 Type I & Type II Reports, (+) PCI DSS & SOC 2 Ongoing Compliance Support, (+) PCI DSS Compliance for all levels. - Conducting ASV & penetration testing. - Improve & uplift the security posture of the organisation. - Tailored advice and strategies to meet your specific organizational needs, while aligning with international standards. - Guidance on implementing best practices for ongoing quality and security enhancements. Risk Management: Expert analysis and recommendations to mitigate risks, ensuring robust and resilient systems. Why choose me: - Proven Track Record: Years of experience successfully auditing and consulting various companies, leading to enhanced quality and security standards. - Client-Centric Approach: I prioritize understanding your unique challenges and goals to provide the most effective solutions. - Detail-Oriented: Meticulous attention to detail, ensuring no aspect of your systems is overlooked - Conduct cybersecurity health check and gap analysis against various frameworks & standards. - Develop Cybersecurity Strategy and Framework. - Effective Communication: Clear and concise communication to ensure you are informed and engaged throughout the auditing process. - Help connect and liaise with PCI QSA, ISO 27001 Lead Auditor, and SOC 2 auditor to perform attestation and compliance services as well. Whether you're seeking ISO, PCI, or SOC 2 certification, attestation, maintaining compliance, or enhancing systems, I’m here to help elevate your quality and security standards.

  • Cybersecurity Management
  • Security Testing
  • Incident Response Plan
  • Security Policies & Procedures Documentation
  • NIST Cybersecurity Framework
  • Network Penetration Testing
  • IT Compliance Audit
  • Web App Penetration Testing
  • GDPR Compliance Review
  • NIST SP 800-53
  • Risk Assessment
  • Web Application Audit
  • ISO 27001
Deval V.

Hamilton, Australia

$30/hr
4.9
24 jobs

Hello, I am Deval. I am a Cybersecurity and Data Analytics professional who takes pride in solving problems and delivering real value. I have worked with clients across healthcare, banking, fintech, and retail to secure systems and make sense of complex data. My core expertise lies in cybersecurity. I help businesses set up and secure cloud environments, configure and harden firewalls, deploy SIEM tools like Splunk and AlienVault, and conduct thorough vulnerability assessments using tools such as Nessus, Tenable, and Acunetix. I also support organizations in strengthening their governance and risk posture through GRC implementation, policy development, control assessments, and compliance readiness (ISO 27001, SOC 2, HIPAA, GDPR). Additionally, I facilitate Red Teaming and Table-Top Exercises to help clients evaluate their incident response maturity, lateral movement readiness, IAM hygiene, and organizational resilience. In addition to cybersecurity, I also specialise in data analysis and Power BI reporting. I help clients clean and model their data, design insightful dashboards, and build reports that support day-to-day and strategic decision making. Cybersecurity Services: • SIEM implementation and dashboarding (Splunk, AlienVault, LogRhythm) • Cloud architecture and cloud security (AWS, Azure, GCP) • Firewall setup, configuration, and hardening (Sophos, Palo Alto, SonicWall, Imperva) • Vulnerability assessments and reporting (Nessus, Tenable, Acunetix) • GRC implementation & audit readiness (ISO 27001, SOC2, HIPAA, GDPR) • Red Teaming & Table-Top Exercises (TTX) for SOC, IR, IAM, Cloud, and Network Security • IAM security review (RBAC, least privilege, privileged access, cloud IAM posture) Power BI and Data Services: • Power BI dashboards with custom DAX measures and filters • Data cleaning, transformation, and business-ready modeling • Visual reporting and performance tracking • Excel to Power BI migration and report automation I am committed to delivering high-quality work, clear communication, and solutions that actually work for your business. Client satisfaction is my top priority, and I am happy to provide a proof of concept or initial walkthrough to help you get started. Let us build something impactful together.

  • Cybersecurity Management
  • Network Security
  • Vulnerability Assessment
  • CentOS
  • Splunk
  • Linux System Administration
  • Amazon Web Services
  • Network Administration
  • Antivirus & Security Software
  • WordPress
  • Web Application Firewall
  • Palo Alto Firewalls
  • Elasticsearch
  • Microsoft Power BI
  • Data Analysis

How it works

Post a job for freePost a job

Tell us what you need. Create your own job post or generate one with AI then filter talent matches.

Hire top talent fast

Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.

Collaborate easily

Use Upwork to chat or video call, share files, and track project progress right from the app.

Payment simplified

Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.

Don't just take our word for it

How do I hire a Information Security Analyst in Australia on Upwork?

You can hire a Information Security Analyst in Australia on Upwork in four simple steps:

  • Create a job post tailored to your Information Security Analyst project scope. We'll walk you through the process step by step.
  • Browse top Information Security Analyst talent on Upwork and invite them to your project.
  • Once the proposals start flowing in, create a shortlist of top Information Security Analyst profiles and interview.
  • Hire the right Information Security Analyst for your project from Upwork, the world's largest work marketplace.

At Upwork, we believe talent staffing should be easy.

How much does it cost to hire a Information Security Analyst?

Rates charged by Information Security Analysts on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.

Why hire a Information Security Analyst in Australia on Upwork?

As the world's work marketplace, we connect highly-skilled freelance Information Security Analysts and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Information Security Analyst team you need to succeed.

Can I hire a Information Security Analyst in Australia within 24 hours on Upwork?

Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Information Security Analyst proposals within 24 hours of posting a job description.