I'm a cybersecurity professional with hands-on SOC operations experience across Microsoft 365 and Azure environments. I help businesses detect, triage, and respond to security threats every day — from suspicious sign-ins and impossible-travel detections to phishing analysis and endpoint incident response.
WHAT I DO:
• SOC L1/L2 triage — review SIEM and EDR alerts, classify allow / watch / deny, escalate to L2/L3 with full evidence and timeline
• Incident investigation — 50+ incidents closed end-to-end across endpoint, identity, and email vectors
• Multi-tenant operations — administered security controls across 25+ Microsoft 365 client environments
• Identity protection — Entra ID, Conditional Access, Privileged Identity Management (PIM), MFA, suspicious sign-in detection
• Email security — phishing analysis, Safe Links / Safe Attachments, SPF / DKIM / DMARC, header analysis with PhishTool
• Detection engineering — custom Wazuh rules, Microsoft Sentinel analytics, MITRE ATT&CK mapping, Sigma rules
TOOLS I WORK WITH:
Microsoft Sentinel • Microsoft Defender XDR • Defender for Endpoint • Wazuh • Splunk • The Hive • Microsoft Intune • Microsoft Entra ID • Microsoft Purview • Autopsy • Volatility • FTK Imager • Burp Suite • Nmap • Metasploit
CERTIFICATIONS:
• Microsoft AZ-500 — Azure Security Engineer Associate
• Microsoft SC-200 — Security Operations Analyst Associate
• Microsoft AZ-900 — Azure Fundamentals
• Blue Team Level 1 (BTL1) — Security Blue Team
• Certified Cyber Defender Level 2 (CCDL2)
• Security Analyst Level 1 (SAL1)
• CompTIA Security+
• Junior Penetration Tester (PT1)
IN PROGRESS: HTB CPTS • CompTIA CySA+ • CompTIA PenTest+ • Certified Kubernetes Administrator (CKA)
WHY CLIENTS HIRE ME:
• Honest classification — I don't false-positive everything to look busy, and I don't miss real threats
• Documentation discipline — every ticket has complete evidence, timeline, and remediation context
• Shift coverage — comfortable with US business hours from Bangladesh (GMT+6)
• Communication — clear written English, clean shift handovers, structured incident reports
AVAILABLE: 30+ hours per week, starting immediately. Open to short paid trial tasks so you can verify the technical fit before committing.
Penetration Testing
Digital Forensics
Database Security
Ethical Hacking
Security Operation Center
WordPress Malware Removal
WordPress Security
Website Security
Email Security
Hosting Setup
Cloud Security
Cloud Architecture
Muhammad Ariful H.
Dhaka, Bangladesh
$20/hr
5.0
5 jobs
I specialize in Cybersecurity, Governance, Risk & Compliance (GRC), ISO 27001, PCI DSS, Cloud Security, Microsoft Security, Security Assessments, and Penetration Testing. With over 7 years of practical experience, I help organizations identify risks, strengthen security controls, achieve compliance, and prepare for successful certification audits.
My expertise spans vulnerability assessments, penetration testing, security architecture, risk management, security documentation, internal audits, Microsoft security technologies, identity and access management, cloud security, SIEM, Windows/Linux administration, and regulatory compliance. I combine technical expertise with business-focused security strategies to deliver practical, scalable, and audit-ready solutions for organizations of all sizes.
Facebook
Database Management System
Database Security
Business Card
Network Security
Network Monitoring
Cybersecurity Tool
Data Entry
Photo Editing
Database Query
Database Maintenance
Marketing Strategy
Cyber Threat Intelligence
Forex Trading
Bitcoin
Database Administration
MD JAHANGIR A.
Dhaka, Bangladesh
$20/hr
4.7
73 jobs
Hello, and welcome to my Upwork profile!
I'm an experienced offensive cybersecurity expert with over 12 years of experience in penetration testing and cybersecurity management.
My expertise lies in identifying and exploiting vulnerabilities in complex systems and networks, as well as designing and implementing security solutions that mitigate these risks. I'm well-versed in a wide range of offensive cybersecurity techniques, including:
Network and Web Application Penetration Testing
Mobile Application Penetration Testing
Vulnerability Assessments
Red Teaming Exercise
Social Engineering
Physical Security Testing
Wireless Security Testing
Cloud Security Testing
API Security Testing
In addition to my technical skills, I also have extensive experience managing cybersecurity teams and projects. I'm well-versed in industry standards such as ISO 27001, NIST, and PCI-DSS, and I can provide guidance on compliance requirements as well as best practices for cybersecurity management.
I'm a self-motivated and detail-oriented professional who takes pride in delivering high-quality results on every project I work on. I'm also a clear and effective communicator with experience presenting technical findings to both technical and non-technical audiences.
If you're looking for an experienced offensive cybersecurity expert to help secure your organization's assets, look no further. I'm confident in my ability to provide top-notch cybersecurity services that will help you identify and mitigate the risks facing your organization.
Contact me today to learn more about how I can help!
Information Security Audit
Penetration Testing
Digital Forensics
Security Assessment & Testing
Firewall
Information Security Consultation
Vulnerability Assessment
Network Security
Elearning
Security Analysis
Articulate Storyline
Cloud Security Framework
IT Service Management
Security Infrastructure
Ahmad S.
Dhaka, Bangladesh
$35/hr
5.0
6 jobs
ISO 27001 Lead Auditor, PCIP, CEH, SOC 2 Consultant & Vanta-Certified Admin who takes teams from “we think we’re secure” to audit-ready in 45 days or less.
What I deliver:
• ISO 27001:2022 gap analysis → SoA & full ISMS
• PCI DSS v4.0 readiness (SAQ, ROC, compensating controls)
• SOC 2 Type I/II scoping, evidence mapping, policy packs
• GDPR data-flow mapping & DPIA support
• HIPAA Security Rule guidance (on request)
• Fast implementation via Vanta, Drata, Scrut, Secureframe, Tugboat—whichever platform you use
Recent wins
• 3 ISO 27001 + 2 PCI DSS certifications in 2025 — all first-pass
• Built a SOC 2 Type II program for a SaaS startup in 30 days
• Cut audit findings from 18 → 0 for a FinTech in one review cycle
How I work
• 30-min discovery call
• Fixed milestones (gap, docs, internal audit)
• Live progress dashboard (Vanta/Drata/Scrut/excel) + weekly sync
Ready to ditch compliance guesswork? Invite me to your job and let’s chat.
ISO 27001
PCI DSS
SOC 2
GDPR Compliance Review
Cloud Security
NIST Cybersecurity Framework
Information Security Governance
Risk Management
Vulnerability Assessment
Penetration Testing
Cybersecurity Management
HIPAA
Data Protection
AI Policy
Privacy Policy
Mahadi Hasan T.
Sundarganj, Bangladesh
$25/hr
5.0
2 jobs
𝗪𝗲𝗯𝘀𝗶𝘁𝗲 𝗵𝗮𝗰𝗸𝗲𝗱? 𝗠𝟯𝟲𝟱 𝘁𝗲𝗻𝗮𝗻𝘁 𝗻𝗲𝘃𝗲𝗿 𝗮𝘂𝗱𝗶𝘁𝗲𝗱? 𝗦𝗲𝗿𝘃𝗲𝗿 𝗻𝗼𝗯𝗼𝗱𝘆 𝗵𝗮𝗿𝗱𝗲𝗻𝗲𝗱? 𝗜 𝗳𝗶𝗻𝗱 𝗶𝘁, 𝗳𝗶𝘅 𝗶𝘁, 𝗮𝗻𝗱 𝗵𝗮𝗻𝗱 𝘆𝗼𝘂 𝘁𝗵𝗲 𝗿𝗲𝗽𝗼𝗿𝘁 𝘁𝗵𝗮𝘁 𝗽𝗿𝗼𝘃𝗲𝘀 𝗶𝘁.
Your site is redirecting to spam. Your tenant has gaps nobody has checked. Your server was deployed and never hardened. Or your team needs IT support that answers the same day, not a ticket that sits for three days.
I cover all of it - Microsoft 365, cloud, websites and networks - plus the hands-on IT support that keeps everything running.
𝗪𝗛𝗔𝗧 𝗜 𝗗𝗢
🛡️ SECURITY AUDITS & COMPLIANCE — from $99
✅ IT security audits and vulnerability assessments (OWASP Top 10, CVSS scored) — findings ranked by business risk, not scanner noise
✅ Risk registers mapped to NIST CSF and ISO 27001 Annex A controls — so your auditor accepts the report instead of sending it back
✅ SOC 2 and ISO 27001 gap assessments, policy suites, audit readiness
✅ Security questionnaires and vendor due diligence completed for you — off your desk in days, not weeks
☁️ MICROSOFT 365 & CLOUD SECURITY — from $129
✅ M365 tenant audit: MFA, Conditional Access, legacy auth, admin roles
✅ Email security: SPF, DKIM, DMARC, anti-phishing, forwarding rules — business email compromise is how most SMEs actually lose money
✅ Microsoft Secure Score review and measurable improvement — the sample report in my portfolio takes a tenant from 38% to 85%
✅ AWS EC2 and Linux VPS hardening: SSH, firewall, Fail2ban, tested backups — I restore your backup while you watch, so you know it works
🌐 WEB & NETWORK SECURITY — from $99
✅ Website malware removal, hack cleanup, Google blacklist recovery
✅ Root-cause log analysis — I find how they got in, not just what they left — cleanup without this gets you reinfected within a week
✅ Website hardening: WAF, 2FA, security headers, file permissions
✅ Network security: firewalls, VPNs, segmentation
🖥️ REMOTE IT SUPPORT & M365 HELPDESK — from $99
✅ Mailbox, permissions, licence and account issues
✅ Employee onboarding and secure offboarding (access revoked and verified) — so a leaver can't still reach your data three months later
✅ Password and MFA lockouts, devices, VPN, Teams and SharePoint
✅ Ongoing support for teams with no in-house IT
⚙️ LINUX & SERVER ADMINISTRATION
✅ Ubuntu, Debian, CentOS, Rocky, Amazon Linux
✅ Nginx and Apache hardening, TLS, automated off-site backups with restore tests
🎓 CERTIFICATIONS
✔️ CompTIA Security+ (SY0-701)
✔️ Microsoft Certified: Security, Compliance and Identity Fundamentals (SC-900)
✔️ Microsoft Cybersecurity Analyst Professional
✔️ Google Cybersecurity Professional Certificate
✔️ Google IT Support Professional Certificate
📈 In progress: CySA+ and ISO 27001 Lead Auditor. I'll always tell you exactly where my certification stands before you hire me.
𝗛𝗢𝗪 𝗜𝗧 𝗪𝗢𝗥𝗞𝗦
1️⃣ Free scoping
Tell me what's happening. I review it and tell you what's actually wrong, in plain English, at no charge. Scoping is free; the work isn't.
2️⃣ Fixed plan and price
Exact deliverables, timeline and cost before anything starts. No scope creep.
3️⃣ Hands-on fix
I do the work myself — cleanup, hardening, configuration, audit or support — with progress updates so you're never left guessing.
4️⃣ Verification
I prove it worked: malware gone, Secure Score re-scored, restore tested, findings retested. Then I walk you through what changed and why.
5️⃣ Ongoing support (optional)
Monthly monitoring, IT helpdesk, or periodic security check-ins so the problem doesn't quietly come back.
𝗪𝗛𝗬 𝗖𝗟𝗜𝗘𝗡𝗧𝗦 𝗛𝗜𝗥𝗘 𝗠𝗘
🎯 One person across security, cloud, M365 and IT support — no coordination overhead between three freelancers who blame each other.
🔍 Honest scoping. If your auditor requires a manual penetration test with OSCP or CREST credentials, I'll tell you before you hire me, not after.
📄 Reports you can send onward — executive summary for leadership, technical detail with reproduction steps for your engineers.
🌏 Based in Bangladesh, working reliable overlap with UK, US and AUS hours.
𝗪𝗛𝗔𝗧 𝗬𝗢𝗨 𝗖𝗔𝗡 𝗩𝗘𝗥𝗜𝗙𝗬 𝗥𝗜𝗚𝗛𝗧 𝗡𝗢𝗪
Every certificate on this profile links to its issuer's verification page — click any of them. And my portfolio has a sample deliverable from each service: a Microsoft 365 audit report, a risk register with CVSS scoring, and a server hardening checklist with before and after Lynis scores. Read the work before you hire me, not after.
💬 Message me with what's happening — a hacked site, a tenant nobody has audited, a server nobody hardened, or a team with no IT cover. I'll reply the same business day with what's actually wrong and what it takes to fix it. Scoping costs nothing and puts you under no obligation to hire me.
Information Security Audit
Information Security
Vulnerability Assessment
Network Security
SOC 2
ISO 27001
Microsoft Azure
Office 365
Cloud Security
Amazon Web Services
Website Security
Malware Removal
IT Support
Linux System Administration
NIST Cybersecurity Framework
Security Assessment & Testing
Compliance
Microsoft Endpoint Manager
Email Security
Google Workspace Administration
Md Azizur R.
Dhaka, Bangladesh
$75/hr
4.9
35 jobs
I help organizations become audit-ready, secure, and compliant - without overengineering or slowing down business.
With 17+ years in cybersecurity, I operate as a Fractional CISO (vCISO), bridging technical execution, risk governance, and compliance across fast-growing SaaS companies, fintech, and enterprise environments.
I specialize in building end-to-end security programs aligned with:
ISO/IEC 27001
SOC 2
NIS2 Directive
HIPAA
🎯 What I Deliver
🔐 Compliance & Audit Readiness
SOC 2 Type I & II end-to-end readiness
ISO 27001 ISMS design, implementation & audit support
NIS2 gap assessment & full implementation roadmap
HIPAA compliance for SaaS, VoIP, and cloud platforms
🛡️ Security Leadership (vCISO)
Security strategy aligned with business goals
Risk management (NIST CSF, CIS Controls)
Board-level reporting (Risk vs Cost vs Impact)
Vendor & third-party risk management
⚙️ Technical & Cloud Security
AWS / GCP / Azure security architecture & hardening
DevSecOps & Secure SDLC (SAST, DAST, IAST integration)
Application & API security testing
Identity & Access Management (IAM / PAM)
🔍 Offensive Security & Assurance
Penetration testing (Web, mobile and Network)
Red team simulation & threat modeling
Secure code review & vulnerability management
🧠 Why Clients Hire Me
I don’t just deliver policies - I deliver working security programs
I translate technical risk into business decisions
I align compliance with real-world architecture (AWS, SaaS, DevOps)
I help you pass audits AND actually be secure
🏆 Credentials
CISM • CISA • CEH • ECSA • LPT (Master)
ISO 27001 Lead Implementer (BSI)
AWS Security Specialty • Azure Security (AZ-500)
💡 Engagement Model
Fractional CISO (ongoing advisory)
Compliance programs (SOC 2 / ISO 27001 / NIS2 / HIPAA)
Security assessments & remediation
Audit readiness & evidence preparation
🚀 Let’s Talk
If you're preparing for an audit, scaling securely, or need a CISO-level partner without full-time cost, I can help you get there efficiently.
Information Security
Vulnerability Assessment
Database Security
Network Security
Cybersecurity Management
Application Security
Penetration Testing
Source Code Scanning
Security Testing
Security Policies & Procedures Documentation
Security Engineering
ISO 27001
Cloud Security
Security Analysis
Secure SDLC
How it works
Post a job for freePost a job
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a Information Security Audit Freelancer in Bangladesh on Upwork?
You can hire a Information Security Audit Freelancer in Bangladesh on Upwork in four simple steps:
Create a job post tailored to your Information Security Audit Freelancer project scope. We'll walk you through the process step by step.
Browse top Information Security Audit Freelancer talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top Information Security Audit Freelancer profiles and interview.
Hire the right Information Security Audit Freelancer for your project from Upwork, the world's largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a Information Security Audit Freelancer?
Rates charged by Information Security Audit Freelancers on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a Information Security Audit Freelancer in Bangladesh on Upwork?
As the world's work marketplace, we connect highly-skilled freelance Information Security Audit Freelancers and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Information Security Audit Freelancer team you need to succeed.
Can I hire a Information Security Audit Freelancer in Bangladesh within 24 hours on Upwork?
Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Information Security Audit Freelancer proposals within 24 hours of posting a job description.
Find more freelancers
Top cities for Information Security Audit Freelancers in Bangladesh