I help startups, SaaS companies, fintechs, and enterprises strengthen their security posture, achieve compliance, and reduce cyber risk through practical, business-focused cybersecurity solutions.
With 12+ years of hands-on experience, I specialize in Governance, Risk & Compliance (GRC), ISO 27001 implementation, penetration testing, SOC operations, vulnerability management, and technical security documentation. My approach combines deep technical expertise with compliance knowledge to deliver secure, scalable, and audit-ready environments.
What I Can Help You With
✔ ISO 27001 implementation, ISMS development & audit readiness
✔ Risk assessments, gap analysis & security control implementation
✔ Governance, Risk & Compliance (GRC)
✔ Web, API & Network Penetration Testing (OWASP Top 10)
✔ Vulnerability Assessments (Nessus, OpenVAS, Burp Suite, Nmap)
✔ Security Operations Center (SOC) & SIEM (IBM QRadar, Splunk, Wazuh)
✔ Incident Response & Digital Forensics
✔ Network & System Administration (Windows Server, Active Directory, Microsoft 365)
✔ Cloud Security (AWS & Azure)
✔ Security Policies, Procedures, SOPs & Technical Documentation
✔ Vendor Security Reviews & Third-Party Risk Assessments
Technical Expertise
Security & Compliance
ISO 27001
NIST Cybersecurity Framework
GDPR
SOC 2
PCI DSS
Security Risk Management
Security Tools
IBM QRadar
Splunk
Wazuh
Burp Suite
Nessus
OpenVAS
Nmap
Metasploit
Kali Linux
Wireshark
Recent Experience
• Delivered ISO 27001 implementation and GRC consulting for SaaS, fintech, and regulated organizations.
• Performed web application, API, and infrastructure penetration testing with detailed remediation reporting.
• Designed and optimized SOC monitoring, SIEM use cases, and incident response workflows.
• Developed security policies, risk assessments, audit documentation, governance frameworks, and executive reports.
• Supported organizations with compliance readiness, security architecture reviews, and vendor risk assessments.
Education & Certification
• MS in Computer Engineering
• PECB Certified ISO/IEC 27001 Lead Implementer
Why Clients Hire Me
✔ 12+ years of practical cybersecurity experience
✔ Strong technical and compliance expertise
✔ Clear communication and professional technical writing
✔ Security solutions aligned with business objectives
✔ Reliable, detail-oriented, and committed to delivering high-quality results
Whether you need an ISO 27001 consultant, penetration tester, SOC specialist, cybersecurity advisor, or technical security writer, I can help you build secure, compliant, and resilient systems.
Let's discuss how I can support your next cybersecurity project.
Information Security Audit
Vulnerability Assessment
Ethical Hacking
Python
Article Writing
Artificial Intelligence
Network Security
Penetration Testing
Incident Management
Zero Trust Architecture
Technical Support
ISO 27001
Kali Linux
Digital Forensics
Certified Information Security Manager
Data Analytics
SOC 2
Technical Writing
Content Writing
Research Documentation
Muhammad Muqeet K.
Lahore, Pakistan
$35/hr
4.9
29 jobs
Top Rated Freelancer on Upwork for more than 3 years specializing in PCI DSS, SOC2 certifications, vCISO, penetration testing and vulnerability assessment services.
Got 5+ long term clients after building their Information Security Governance program from the scratch and getting them certified against SOC2 Type 2 and PCI DSS certifications.
A high ratio of client retention by delivering top notch penetration test and vulnerability assessments reports.
Seasoned professional with 10 years of experience in Information Security Governance, operations, Risk & Compliance. I provide PCI DSS and SOC2 audit certification services, conduct penetration tests and implementation and management of SIEM solutions.
Information Security Audit
Penetration Testing
Vulnerability Assessment
Cybersecurity Management
Information Security Consultation
PCI
Information Security Governance
Documentation
LogRhythm
ISO 27001
SOC 2 Report
Risk Assessment
Enterprise Risk Management
IT Compliance Audit
Web App Penetration Testing
Hamza A.
Lahore, Pakistan
$8/hr
4.6
2 jobs
🔍 Certified IS Auditor and Certified in Cybersecurity with a keen eye for IT security, IT Risk & Controls, SOC, ITGC, ITAC, compliance, and risk management. I specialize in evaluating IT systems, ensuring regulatory compliance, and strengthening cybersecurity controls (covering logical accesses, change management and IT operations) to protect businesses from threats and vulnerabilities.
What I Offer:
✅IT & Internal Audit engagement (ISO 27001, NIST, COBIT, SOX, HIPAA, PCI-DSS)
✅Risk Assessment & Control Evaluations
✅ Cybersecurity Assessments & Compliance Checks
✅ IT Governance & Internal Control Reviews
✅ Security Policy Development & Implementation
✅ IT General Control Testing, IT Application Control Testing
✅ Business Continuity & Disaster Recovery Planning
Why Work With Me?
✔ 5+ years of experience in IT auditing, SOC Assessment. Internal Audit, Cybersecurity, and Compliance
✔ Expertise in regulatory frameworks & industry best practices
✔ Strong communication skills—clear, actionable reporting
✔ Commitment to helping businesses secure their IT environment
💡 Let’s work together to strengthen your IT security, Business controls, ensure compliance, and mitigate risks effectively. Contact me today to discuss your project!
Information Security Audit
Security Policies & Procedures Documentation
OS Security
Internal Auditing
IT General Controls Testing
SOC 2
Application Audit
IT Compliance Audit
SOC 1
GDPR Compliance Review
ISO 27001
SAP
Policy Writing
Sarbanes-Oxley Act
Cybersecurity Management
NIST Cybersecurity Framework
Faiz A.
Karachi, Pakistan
$3/hr
5.0
7 jobs
My profile with having extensive experience over 12 years in IT including banking/firm/software houses industry experience.
I am recognized for my ability to assess situations, identify problems and devise solutions moreover being certified ISO 27001 Lead Auditor, certified in Ethical Hacking CEH, CISA certified and MS (Info security), enjoy facing challenges and come to you with demonstrated problem-solving skills in IT Auditing / Gap Analysis during work engagement. Below are the summarized skills set.
-Information Security Analysis
-Gap Analysis / Risk Analysis
-IS Auditing & Continuous Auditing
-ISO 27001 LA assessment
-Vulnerability /pen test assignments
-PCIDSS compliance
-Incident Response Solution
-Security Program Management
-IT Infrastructure Management
-DR Plan & Services
Our team also consists of OSCP, CEH, CISA, ISO 27001, ISO 20000, ISO 23001, CPTE and CISM certified professional and have been doing all the assessments from past 12 years.
please connect to reach out further.
I hope to hear from you soon and look forward to meet face to face for challenges associated with the suitable IT Auditing & Security assignments.
Information Security
Financial Audit
System Security
Vulnerability Assessment
Encryption
Penetration Testing
Internal Control
ISO 27001
PCI DSS
Ethical Hacking
Data Protection
Network Penetration Testing
Big Data
Data Privacy
GDPR Compliance Review
Aamir R.
Islamabad, Pakistan
$30/hr
4.9
43 jobs
Are you preparing for ISO 27001, SOC 2, HIPAA, PCI-DSS, GDPR, or Cyber Essentials compliance and need practical cybersecurity support?
I help startups, SaaS companies, healthcare technology businesses, fintech teams, e-commerce companies, and growing organizations become audit-ready, reduce security risks, and build practical information security programs without unnecessary complexity.
I am a CISSP-certified Cybersecurity GRC professional with 9+ years of experience in cybersecurity governance, risk management, compliance, security documentation, audit readiness, and vulnerability risk management. I have worked with organizations across banking, healthcare technology, retail commerce, consulting, and international business environments.
My work is focused on clear deliverables. Whether you need a complete ISMS, SOC 2 control documentation, a compliance gap assessment, security policies, vendor risk review, risk register, or audit-ready evidence pack, I can help you create practical, professional, and business aligned outputs.
I understand that most businesses do not need overly complicated cybersecurity paperwork. They need clear documentation, realistic controls, organized evidence, and actionable recommendations that auditors, clients, and leadership can understand.
My goal is to make cybersecurity and compliance easier for your business by giving you structured guidance, reliable documentation, and clear next steps.
Let’s work together to strengthen your security posture, meet client or audit requirements, and move your compliance project forward with confidence.
Information Security Audit
Information Security
Digital Forensics
Information Security Consultation
Cybersecurity Management
Malware Removal
Artificial Intelligence
Certified Information Systems Security Professional
Governance, Risk Management & Compliance
Information Security Awareness
Cloud Security
Cybersecurity Monitoring
Web Application Security
Certified Information Security Manager
Arbaz A.
Lahore, Pakistan
$35/hr
5.0
1 jobs
🔐 Your enterprise deal is stalling — because security is unresolved.
A customer asks for a SOC 2 report. An ISO 27001 certificate. A completed security questionnaire. Your team doesn't have the answers, and the deal slows down.
I step in as your fractional vCISO and fix that, fast.
With 10+ years building and running security programs — and a technical foundation in infrastructure, endpoint, identity, and network security — I've helped SaaS, healthcare, fintech, and managed services companies go from zero compliance posture to full audit readiness.
🎯 What I deliver:
• 📋 Compliance programs — SOC 2 (Type 1 & 2), ISO 27001:2022, ISO 42001 (AI Governance), ISO 27701 (Privacy), ISO 22301 (BCM), HIPAA, PCI DSS, GDPR, FedRAMP, CIS Controls — gap assessments, implementation, evidence collection, and audit preparation from start to finish
• 🛡️ Fractional vCISO — security program design, policy & procedure library, risk register, vendor risk management, board-level reporting, AI/SaaS third-party risk, and supply chain risk
• 🔑 Identity & Access Management — Microsoft Entra ID, Conditional Access, Privileged Access Management, MFA deployment, JML processes, and password manager deployment (Keeper, 1Password, Bitwarden, ITGlue)
• 💻 Endpoint & device management — Microsoft Intune (end-to-end), IBM MaaS360, Cisco Meraki MDM, system hardening, BitLocker, Windows hardening, Microsoft 365 Business Premium configuration
• 🛰️ Security operations — SIEM deployment & tuning (Splunk, QRadar, Microsoft Sentinel, Wazuh, Elastic/ELK), MDR (BlackPoint, Huntress, Sentinel Suite, TrendMicro), DFIR, vulnerability management, threat intelligence
• ⚙️ Compliance automation — Vanta, Drata, Secureframe, GRC engineering
• ☁️ Cloud security — AWS, Azure, GCP
• 📐 Framework alignment — NIST CSF 2.0, NIST SP 800-53, ISO 27005/31000, COBIT, CIS Controls
🔧 Why my compliance work is different:
Most compliance consultants work from a checklist. I've actually built what I audit — I've deployed MDM solutions, run enterprise vulnerability management programs, managed SAST and application security pipelines, operated MDR platforms, and hardened endpoints and infrastructure across managed services client bases. That technical depth means the controls I design actually work in the real world, not just on paper. When your auditor asks hard questions, I already know the answers.
📌 My track record includes:
• ✔ Built and operated end-to-end ISMS as fractional vCISO — from policy library to enterprise risk register
• ✔ Leading ISO 27001 ISMS lifecycle, ISO 27005 risk assessments, and ISO 27701 (PIMS) implementation at enterprise level
• ✔ Deployed and managed MDM solutions (Intune, MaaS360, Meraki) and EDR/MDR platforms across MSP client bases
• ✔ Designed and executed enterprise-wide vulnerability management programs, AppSec pipelines (SAST), and security awareness programs
• ✔ Led AI/SaaS third-party risk assessments and board-level security reporting
🔄 How I engage:
Scoping call → gap assessment → prioritized roadmap → implementation → audit support. Open to short engagements (policy review, gap assessment, security posture assessment, endpoint hardening) or long-term fractional vCISO retainers.
📩 Message me with your target framework, environment, or challenge — I'll send back a clear path forward within 24 hours.
Information Security
PCI DSS
ISO 27001
NIST Cybersecurity Framework
NIST SP 800-53
GDPR
HIPAA
Incident Management
Risk Management
Cloud Security
SOC 2
Data Privacy
Governance, Risk Management & Compliance
Gap Analysis
Policy Development
Microsoft Endpoint Manager
Microsoft Intune
How it works
Post a job for freePost a job
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a Information Security Audit Freelancer in Pakistan on Upwork?
You can hire a Information Security Audit Freelancer in Pakistan on Upwork in four simple steps:
Create a job post tailored to your Information Security Audit Freelancer project scope. We'll walk you through the process step by step.
Browse top Information Security Audit Freelancer talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top Information Security Audit Freelancer profiles and interview.
Hire the right Information Security Audit Freelancer for your project from Upwork, the world's largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a Information Security Audit Freelancer?
Rates charged by Information Security Audit Freelancers on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a Information Security Audit Freelancer in Pakistan on Upwork?
As the world's work marketplace, we connect highly-skilled freelance Information Security Audit Freelancers and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Information Security Audit Freelancer team you need to succeed.
Can I hire a Information Security Audit Freelancer in Pakistan within 24 hours on Upwork?
Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Information Security Audit Freelancer proposals within 24 hours of posting a job description.
Find more freelancers
Top cities for Information Security Audit Freelancers in Pakistan