Hire the Best Information Security Audit Freelancers
in the United States

More than 3,000 reviews on G2
Rating is 4.5 out of 5.
4.5/5
of Upwork by G2 peer reviewers
William P.

Rutherfordton, North Carolina

$150/hr
5.0
43 jobs

UpWork Recognition: Expert-Vetted | Top-Rated Plus | 100% Job Success Score I provide affordable cyber security solutions to startups, small and medium-sized businesses, non-profits, and other organizations. I organizations that need improved security but don't have the budget to support an enterprise level. I work with these companies to create a security solution that is both affordable and effective. In today's world of ever-increasing cyber threats where small businesses are targeted more frequently, it is vital that these companies have IT Security systems in place. Statistics show that nearly half of small companies that suffer a cyber breach never recover. SPECIALITES: • Vulnerability Analysis • Penetration Testing • Compliance Assessment • Network Security Planning • Consultation • Managed Security Services • Risk Assessment & Management CMMC, HIPAA, SOC2, GDPR,

  • Information Security
  • Ethical Hacking
  • Cybersecurity Management
  • Regulatory Compliance
  • Risk Assessment
  • Penetration Testing
  • Security Analysis
  • Vendor Management
  • Data Privacy
Jonathan S.

Dallas, Texas

$28/hr
4.6
34 jobs

I am a Certified Information Security Analyst with over 13years of proven experience in Enterprise-Level and Start-up Information Security as well as IT Operations. My expertise spans across securing and optimizing complex infrastructures, with a deep focus on threat intelligence, Security Engineering , and Cyber Compliance management. I have successfully contributed to both federal contracts and private sector engagements, delivering tailored security solutions to meet specific organizational needs and regulatory requirements. Core Competencies: • Cyber Security Architecture & Engineering: Skilled in designing and deploying robust security architectures across diverse IT landscapes, integrating best-in-class technologies to mitigate risks and enhance defense capabilities. • Threat Intelligence & Forensics: Expertise in analyzing evolving threat landscapes, developing proactive defense mechanisms, and leading forensic investigations to identify root causes and ensure comprehensive remediation. • Vulnerability Management: Proven ability to assess, prioritize, and address security vulnerabilities through targeted mitigation strategies, ensuring that infrastructure remains resilient and aligned with industry standards. • Compliance & Governance: Extensive experience in aligning security initiatives with regulatory frameworks such as NIST, ISO 27001, PCI-DSS, GDPR, and HIPAA, ensuring that all security controls meet or exceed compliance standards. Key Experience: •Senior Cyber Security Architect: Designed and implemented scalable, secure infrastructures for both on-premise and cloud-based environments. Applied zero-trust principles, multi-layered defenses, and advanced encryption technologies to safeguard sensitive data and critical business assets. •Senior Cyber Security Engineer: Led engineering efforts to secure enterprise networks, deploying next-generation firewalls, intrusion detection systems (IDS), and endpoint protection solutions. Developed automation scripts to streamline security processes and optimize incident response times. •Senior Cyber Security Compliance Consultant: Provided end-to-end compliance consulting services, guiding organizations through the intricacies of regulatory requirements. Developed and implemented security policies, audit protocols, and risk management frameworks to ensure ongoing compliance and governance. Leadership & Project Management: •Led cross-functional teams in cybersecurity projects, driving initiatives from planning through execution while ensuring security objectives were met within scope, time, and budget constraints. •Acted as Adjunct Team Leader, managing diverse cybersecurity teams in federal and private sector environments, ensuring successful delivery of critical security solutions while fostering collaboration and skill development. Technical Expertise: • Proficient in cloud security for platforms such as AWS, Azure, and Google Cloud, implementing advanced security configurations for both public and hybrid cloud environments. • Hands-on experience with security tools such as SIEM (Splunk, QRadar), IDS/IPS, endpoint security, and security automation platforms. • Extensive knowledge in DevSecOps, integrating security practices within CI/CD pipelines to ensure continuous delivery of secure code. As a Senior Cyber Security Architect/Engineer/Compliance Consultant, I bring a strategic, results-driven approach to every project, with a focus on protecting assets, ensuring compliance, and delivering scalable security solutions that evolve with emerging threats and organizational goals.

  • Information Security
  • Vulnerability Assessment
  • Penetration Testing
  • Firewall
  • Network Security
  • Cybersecurity Management
  • Security Policies & Procedures Documentation
  • Network Monitoring
  • Security Infrastructure
  • Network Penetration Testing
  • Internet Security
  • Cloud Security
  • Compliance Consultation
  • DevOps
  • Incident Response Readiness Assessment
Mark P.

Bainbridge Island, Washington

$85/hr
5.0
12 jobs

Senior security oriented technology professional with 10+ years client facing experience as a Solution Architect, Program Manager and Senior Consultant. I help companies prepare for audit engagements with high confidence in a successful outcome. Strong individual contributor or technical team lead. Seeking to create win-win solutions for company and clients, with attention to value prop and customer ROI. Specialist in Compliance, Cybersecurity, Risk Assessment, AI Governance, and Security Gap Analysis. I take ownership, meet deadlines, and focus on results. Skills and Certifications: • Certified Information Systems Security Processional (CISSP) #737715 • Certified Cloud Security Professional (CCSP) #737715 • CRISC (Certified in Risk and Information Systems Control) certification in progress • Audit Engagement Leadership for SOC 1 / 2 Assessments and ISO 27001 Certification • ISO 27001 Implementation Project Lead • NIST 800-53 and ISO 31000 Risk Management Frameworks • Expert knowledge of PCI-DSS, SOC2, ISO27001, NIST 800-171 and other control and risk management frameworks, including AI Governance following the NIST and ISO frameworks

  • Disaster Recovery Plan
  • IT Consultation
  • Request for Proposal
  • Business Proposal Writing
  • Cybersecurity Management
  • IT Compliance Audit
  • Risk Assessment
  • Risk Management
  • Compliance Consultation
  • Information Security Awareness
  • Microsoft Visio
Jon W.

Belleville, Illinois

$150/hr
5.0
34 jobs

I'm Jonathan Welzbacher. I'm a fractional CISO who ships code. Fifteen years across IT Audit and Information Security, originally at Deloitte, then on the inside as IT Audit Manager, Director of Information Security GRC, and Information Security Program Manager at companies running on AWS, Azure, and GCP. I hold CISSP, CISA, and CPA. I approach security like an accountant who listens to the owner to understand their risk profile and best deploy their expenses to realize the most benefit for the organization. I provide the following services: ▸ FRACTIONAL CISO / GRC CONSULTING • vCISO retainer — strategy, customer questionnaires, vendor procurement & risk, IR tabletops, MDM/IAM/DLP oversight, monthly KRI dashboard, automation and set up of security ops • SOC 2 & HIPAA Readiness Sprint — 90 days to audit-ready, with policy suite, evidence automation, and auditor handoff • Internal Audit & GRC co-sourcing — SOX ITGC, ServiceNow or other GRC builds & automation, CMMC, HITRUST, ISO 27001, FedRAMP or other NIST frameworks readiness ▸ SECURITY & AUTOMATION ENGINEERING • Cloud Security Baseline Build — CIS-benchmarked AWS, GCP or Azure environments with GuardDuty, Macie, IAM-change alarms, CloudFront/TLS hardening, MDM + DLP rollout • Custom security tooling — CI hooks, Slack Alerting via SNS, GitHub Actions hardening, internal admin dashboards, agent-based scrapers, evidence-collection bots Recent representative outcomes: ✓ Stood up first SOC 2 + AWS hardening for a Series A SaaS in ~90 days (GuardDuty, Macie DLP, IAM-change alarms, MDM, Workspace DLP, IR/DR tabletop). Successfully achieved SOC2 + HIPAA unqualified reports for 6 clients in past 12 months. ✓ Built HIPAA risk assessment in ServiceNow with quantified likelihood/impact across ePHI assets for a Fortune 250 healthcare benefits manager. Procured and managed HITRUST for same org. ✓ Procured and ran a SOC 2 + ISO 27001 certification for a global B2B sourcing SaaS while owning the engineering-aligned IT risk register. DM me "SOC 2" for a free 30-minute readiness call — I'll respond within 24 hours with a scoped fixed-fee proposal.

  • Information Security
  • HITRUST Common Security Framework
  • HIPAA
  • SOC 2 Report
  • NIST Cybersecurity Framework
  • Sarbanes-Oxley Act
  • Internal Auditing
  • API Development
  • Python
  • Incident Management
  • Incident Response Plan
  • Risk Management
  • FedRAMP
  • Splunk
  • AWS CloudTrail
Eric L.

North Wilkesboro, North Carolina

$50/hr
5.0
41 jobs

Eric Lunsford - Cybersecurity Assessor | Compliance Consultant | vCISO Certification - CCA | CCP | RPA | RP | SSCP | Pentest+ | Project+ | Sec+ | Net+ | A+| ECS I am Eric Lunsford, a cybersecurity professional with over 20 years of experience in management and leadership roles across the military and private IT sectors. I specialize in Cybersecurity, Governance & Compliance, Risk Management, and Secure Infrastructure Design. As a CMMC Certified Assessor (CCA), Certified CMMC Professional (CCP), Registered Practitioner Advanced (RPA), and Registered Practitioner (RP), I provide both formal CMMC/NIST 800-171 assessments and consulting services tailored to the unique needs of organizations within the Department of Defense (DoD) Defense Industrial Base (DIB) as well as Federal and Local Agencies. I hold certifications and credentials from the U.S. Army, ISC², CompTIA, Cisco, and EC-Council with specialization in Network Management, Cybersecurity, Encryption, and Information Assurance. I have provided regulatory and compliance assistance to over 100+ DoD supply chain organizations, helping companies strengthen their Supplier Performance Risk Score (SPRS), protect Federal Contract Information (FCI), secure Controlled Unclassified Information (CUI), and harden their networks and device configurations against threats. Specialties • Cybersecurity Auditing & Assessments (CMMC L1–L3, NIST 800-171, NIST 800-53) • Governance, Risk, and Compliance (GRC) documentation and program development • Network & Device Configuration Management aligned with DoD STIGs and CIS benchmarks • Virtual CISO (vCISO) Services for strategic security and compliance oversight • Policy & Procedure Development for security, privacy, and IT operations • AI & Emerging Technology Integration for compliance and security automation Frameworks & Compliance Expertise • NIST 800-53 – Federal systems • FedRAMP, StateRAMP, TX-RAMP – Federal/State cloud systems • NIST 800-171 – Contractor systems handling CUI • CMMC L1, L2, L3 – DoD contractor readiness and assessments • ISO/IEC 27000, 27001, 27002 – Information Security Management Systems • SOX – Financial reporting compliance • SOC 2 Type II – Service organization security controls • PCI-DSS – Payment card industry compliance • PHI, PII, Privacy Regulations – HIPAA and data protection requirements Project Deliverables & Capabilities Compliance Deliverables: • System Security Plans (SSP) • Plans of Action and Milestones (POA&M) • Risk Management Plans & Assessments • Incident Response Plans & Processes • Change & Configuration Management Plans • Gap Analyses & Remediation Plans • Security Policies, Procedures, Processes, Checklists, and Matrixes Technical Deliverables: • Secure Network & Topology Flow Diagrams • Scope Boundary Definitions • Encryption & Data Protection Programs • Endpoint Management & Mobile Device Management • System Testing Metrics, Storage, Backup, and Archiving solutions Consulting & Training: • GAP Assessments with remediation roadmaps • Policy development and compliance readiness coaching • Education & training for executives, HR, IT Admins, and staff • Full lifecycle compliance project management • Evidence collection, attestations, and audit preparation Professional Experience Throughout my career, I have served as: • Virtual Chief Information Security Officer (vCISO) – Advising executive teams on compliance and risk strategies • Senior Security Engineer – Implementing secure infrastructures and advanced encryption standards • Secure Infrastructure Specialist – Designing DoD-compliant architectures • Project Manager – Leading compliance, remediation, and IT modernization efforts • Security Operations Center (SOC) Analyst – Monitoring, detecting, and responding to threats Why Work With Me? I provide end-to-end cybersecurity and compliance services—from initial gap analysis and roadmap development to full assessments and audits. My approach is hands-on, practical, and tailored to each organization’s environment, ensuring not only compliance but also stronger overall security. Whether you need a CMMC assessment, NIST 800-171 consulting, ISO 27001 program build, or a vCISO to lead your security strategy, I bring the experience, certifications, and proven track record to help your organization succeed. Contact me with any questions or project requests. Let’s build your compliance roadmap and strengthen your cybersecurity posture. Eric Lunsford

  • Cybersecurity Management
  • Information Security Consultation
  • FedRAMP
  • ISO 27001
  • Incident Response Plan
  • IT Compliance Audit
  • NIST SP 800-53
  • SOC 2 Report
  • Security Policies & Procedures Documentation
  • Risk Assessment
  • Security Infrastructure
  • Certified Information Systems Security Professional
Jonathan P.

Bakersfield, California

$85/hr
5.0
5 jobs

With over 15 years of invaluable experience in the IT industry, I bring a wealth of expertise to the table. Specifically, I have dedicated 8 years of my career to specializing in compliance standards such as HIPAA, HITECH, NERC, ISO 27001, FISMA, and ADA. My approach involves a meticulous step-by-step process that enables me to thoroughly analyze and address the unique needs of your organization. Having successfully dealt with HIPAA security breaches in the past, I am well-equipped to handle time-sensitive matters with utmost dedication. My primary goal is to ensure that my clients avoid substantial fines and penalties by promptly remedying any compliance issues. If you are in search of a comprehensive risk assessment, I am pleased to offer my services detailed below.: Security Risk Analysis o Annual Risk Assessment o Business Associate Agreement (BAA) o IT Security Documentation o IT Policy and Procedures o Report Analysis o Remediation Recommendations Website Compliance o Review website for ADA, CCPA, and GDPR compliance o HIPAA compliance is by scope only. o Security screenings o Monitoring o Backups o Remediation Strategies Network Vulnerability Assessment o Scoping o Threat Assessment o Setup & Configuration o Vulnerability Report Analysis o Remediation Recommendations Monthly Monitoring o Monthly Security Monitoring and Alerts o HIPAA compliance and alerts against malicious events o Website monitoring, compliance, monthly reports.

  • Information Security Audit
  • Risk Assessment
  • HIPAA
  • ISO 27001
  • IT Compliance Audit
  • Network Security
  • Vulnerability Assessment
  • Security Analysis
  • Network Monitoring
  • Information Technology Strategy
  • Fortinet
  • FortiGate Firewall
  • Cisco
  • Network Engineering
  • Firewall

How it works

Post a job for freePost a job

Tell us what you need. Create your own job post or generate one with AI then filter talent matches.

Hire top talent fast

Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.

Collaborate easily

Use Upwork to chat or video call, share files, and track project progress right from the app.

Payment simplified

Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.

Don't just take our word for it

How do I hire a Information Security Audit Freelancer in the United States on Upwork?

You can hire a Information Security Audit Freelancer in the United States on Upwork in four simple steps:

  • Create a job post tailored to your Information Security Audit Freelancer project scope. We'll walk you through the process step by step.
  • Browse top Information Security Audit Freelancer talent on Upwork and invite them to your project.
  • Once the proposals start flowing in, create a shortlist of top Information Security Audit Freelancer profiles and interview.
  • Hire the right Information Security Audit Freelancer for your project from Upwork, the world's largest work marketplace.

At Upwork, we believe talent staffing should be easy.

How much does it cost to hire a Information Security Audit Freelancer?

Rates charged by Information Security Audit Freelancers on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.

Why hire a Information Security Audit Freelancer in the United States on Upwork?

As the world's work marketplace, we connect highly-skilled freelance Information Security Audit Freelancers and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Information Security Audit Freelancer team you need to succeed.

Can I hire a Information Security Audit Freelancer in the United States within 24 hours on Upwork?

Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Information Security Audit Freelancer proposals within 24 hours of posting a job description.