UpWork Recognition: Expert-Vetted | Top-Rated Plus | 100% Job Success Score
I provide affordable cyber security solutions to startups, small and medium-sized businesses, non-profits, and other organizations. I organizations that need improved security but don't have the budget to support an enterprise level. I work with these companies to create a security solution that is both affordable and effective. In today's world of ever-increasing cyber threats where small businesses are targeted more frequently, it is vital that these companies have IT Security systems in place. Statistics show that nearly half of small companies that suffer a cyber breach never recover.
SPECIALITES:
• Vulnerability Analysis
• Penetration Testing
• Compliance Assessment
• Network Security Planning
• Consultation
• Managed Security Services
• Risk Assessment & Management
CMMC, HIPAA, SOC2, GDPR,
Information Security
Ethical Hacking
Cybersecurity Management
Regulatory Compliance
Risk Assessment
Penetration Testing
Security Analysis
Vendor Management
Data Privacy
Jonathan S.
Dallas, Texas
$28/hr
4.6
34 jobs
I am a Certified Information Security Analyst with over 13years of proven experience in Enterprise-Level and Start-up Information Security as well as IT Operations. My expertise spans across securing and optimizing complex infrastructures, with a deep focus on threat intelligence, Security Engineering , and Cyber Compliance management. I have successfully contributed to both federal contracts and private sector engagements, delivering tailored security solutions to meet specific organizational needs and regulatory requirements.
Core Competencies:
• Cyber Security Architecture & Engineering: Skilled in designing and deploying robust security architectures across diverse IT landscapes, integrating best-in-class technologies to mitigate risks and enhance defense capabilities.
• Threat Intelligence & Forensics: Expertise in analyzing evolving threat landscapes, developing proactive defense mechanisms, and leading forensic investigations to identify root causes and ensure comprehensive remediation.
• Vulnerability Management: Proven ability to assess, prioritize, and address security vulnerabilities through targeted mitigation strategies, ensuring that infrastructure remains resilient and aligned with industry standards.
• Compliance & Governance: Extensive experience in aligning security initiatives with regulatory frameworks such as NIST, ISO 27001, PCI-DSS, GDPR, and HIPAA, ensuring that all security controls meet or exceed compliance standards.
Key Experience:
•Senior Cyber Security Architect: Designed and implemented scalable, secure infrastructures for both on-premise and cloud-based environments. Applied zero-trust principles, multi-layered defenses, and advanced encryption technologies to safeguard sensitive data and critical business assets.
•Senior Cyber Security Engineer: Led engineering efforts to secure enterprise networks, deploying next-generation firewalls, intrusion detection systems (IDS), and endpoint protection solutions. Developed automation scripts to streamline security processes and optimize incident response times.
•Senior Cyber Security Compliance Consultant: Provided end-to-end compliance consulting services, guiding organizations through the intricacies of regulatory requirements. Developed and implemented security policies, audit protocols, and risk management frameworks to ensure ongoing compliance and governance.
Leadership & Project Management:
•Led cross-functional teams in cybersecurity projects, driving initiatives from planning through execution while ensuring security objectives were met within scope, time, and budget constraints.
•Acted as Adjunct Team Leader, managing diverse cybersecurity teams in federal and private sector environments, ensuring successful delivery of critical security solutions while fostering collaboration and skill development.
Technical Expertise:
• Proficient in cloud security for platforms such as AWS, Azure, and Google Cloud, implementing advanced security configurations for both public and hybrid cloud environments.
• Hands-on experience with security tools such as SIEM (Splunk, QRadar), IDS/IPS, endpoint security, and security automation platforms.
• Extensive knowledge in DevSecOps, integrating security practices within CI/CD pipelines to ensure continuous delivery of secure code.
As a Senior Cyber Security Architect/Engineer/Compliance Consultant, I bring a strategic, results-driven approach to every project, with a focus on protecting assets, ensuring compliance, and delivering scalable security solutions that evolve with emerging threats and organizational goals.
Information Security
Vulnerability Assessment
Penetration Testing
Firewall
Network Security
Cybersecurity Management
Security Policies & Procedures Documentation
Network Monitoring
Security Infrastructure
Network Penetration Testing
Internet Security
Cloud Security
Compliance Consultation
DevOps
Incident Response Readiness Assessment
Mark P.
Bainbridge Island, Washington
$85/hr
5.0
12 jobs
Senior security oriented technology professional with 10+ years client facing experience as a Solution Architect, Program Manager and Senior Consultant. I help companies prepare for audit engagements with high confidence in a successful outcome.
Strong individual contributor or technical team lead. Seeking to create win-win solutions for company and clients, with attention to value prop and customer ROI.
Specialist in Compliance, Cybersecurity, Risk Assessment, AI Governance, and Security Gap Analysis.
I take ownership, meet deadlines, and focus on results.
Skills and Certifications:
• Certified Information Systems Security Processional (CISSP) #737715
• Certified Cloud Security Professional (CCSP) #737715
• CRISC (Certified in Risk and Information Systems Control) certification in progress
• Audit Engagement Leadership for SOC 1 / 2 Assessments and ISO 27001 Certification
• ISO 27001 Implementation Project Lead
• NIST 800-53 and ISO 31000 Risk Management Frameworks
• Expert knowledge of PCI-DSS, SOC2, ISO27001, NIST 800-171 and other control and risk management frameworks, including AI Governance following the NIST and ISO frameworks
Disaster Recovery Plan
IT Consultation
Request for Proposal
Business Proposal Writing
Cybersecurity Management
IT Compliance Audit
Risk Assessment
Risk Management
Compliance Consultation
Information Security Awareness
Microsoft Visio
Jon W.
Belleville, Illinois
$150/hr
5.0
34 jobs
I'm Jonathan Welzbacher. I'm a fractional CISO who ships code. Fifteen years across IT Audit and Information Security, originally at Deloitte, then on the inside as IT Audit Manager, Director of Information Security GRC, and Information Security Program Manager at companies running on AWS, Azure, and GCP. I hold CISSP, CISA, and CPA. I approach security like an accountant who listens to the owner to understand their risk profile and best deploy their expenses to realize the most benefit for the organization.
I provide the following services:
▸ FRACTIONAL CISO / GRC CONSULTING
• vCISO retainer — strategy, customer questionnaires, vendor procurement & risk, IR tabletops, MDM/IAM/DLP oversight, monthly KRI dashboard, automation and set up of security ops
• SOC 2 & HIPAA Readiness Sprint — 90 days to audit-ready, with policy suite, evidence automation, and auditor handoff
• Internal Audit & GRC co-sourcing — SOX ITGC, ServiceNow or other GRC builds & automation, CMMC, HITRUST, ISO 27001, FedRAMP or other NIST frameworks readiness
▸ SECURITY & AUTOMATION ENGINEERING
• Cloud Security Baseline Build — CIS-benchmarked AWS, GCP or Azure environments with GuardDuty, Macie, IAM-change alarms, CloudFront/TLS hardening, MDM + DLP rollout
• Custom security tooling — CI hooks, Slack Alerting via SNS, GitHub Actions hardening, internal admin dashboards, agent-based scrapers, evidence-collection bots
Recent representative outcomes:
✓ Stood up first SOC 2 + AWS hardening for a Series A SaaS in ~90 days (GuardDuty, Macie DLP, IAM-change alarms, MDM, Workspace DLP, IR/DR tabletop). Successfully achieved SOC2 + HIPAA unqualified reports for 6 clients in past 12 months.
✓ Built HIPAA risk assessment in ServiceNow with quantified likelihood/impact across ePHI assets for a Fortune 250 healthcare benefits manager. Procured and managed HITRUST for same org.
✓ Procured and ran a SOC 2 + ISO 27001 certification for a global B2B sourcing SaaS while owning the engineering-aligned IT risk register.
DM me "SOC 2" for a free 30-minute readiness call — I'll respond within 24 hours with a scoped fixed-fee proposal.
Information Security
HITRUST Common Security Framework
HIPAA
SOC 2 Report
NIST Cybersecurity Framework
Sarbanes-Oxley Act
Internal Auditing
API Development
Python
Incident Management
Incident Response Plan
Risk Management
FedRAMP
Splunk
AWS CloudTrail
Eric L.
North Wilkesboro, North Carolina
$50/hr
5.0
41 jobs
Eric Lunsford - Cybersecurity Assessor | Compliance Consultant | vCISO
Certification - CCA | CCP | RPA | RP | SSCP | Pentest+ | Project+ | Sec+ | Net+ | A+| ECS
I am Eric Lunsford, a cybersecurity professional with over 20 years of experience in management and leadership roles across the military and private IT sectors. I specialize in Cybersecurity, Governance & Compliance, Risk Management, and Secure Infrastructure Design.
As a CMMC Certified Assessor (CCA), Certified CMMC Professional (CCP), Registered Practitioner Advanced (RPA), and Registered Practitioner (RP), I provide both formal CMMC/NIST 800-171 assessments and consulting services tailored to the unique needs of organizations within the Department of Defense (DoD) Defense Industrial Base (DIB) as well as Federal and Local Agencies.
I hold certifications and credentials from the U.S. Army, ISC², CompTIA, Cisco, and EC-Council with specialization in Network Management, Cybersecurity, Encryption, and Information Assurance.
I have provided regulatory and compliance assistance to over 100+ DoD supply chain organizations, helping companies strengthen their Supplier Performance Risk Score (SPRS), protect Federal Contract Information (FCI), secure Controlled Unclassified Information (CUI), and harden their networks and device configurations against threats.
Specialties
• Cybersecurity Auditing & Assessments (CMMC L1–L3, NIST 800-171, NIST 800-53)
• Governance, Risk, and Compliance (GRC) documentation and program development
• Network & Device Configuration Management aligned with DoD STIGs and CIS benchmarks
• Virtual CISO (vCISO) Services for strategic security and compliance oversight
• Policy & Procedure Development for security, privacy, and IT operations
• AI & Emerging Technology Integration for compliance and security automation
Frameworks & Compliance Expertise
• NIST 800-53 – Federal systems
• FedRAMP, StateRAMP, TX-RAMP – Federal/State cloud systems
• NIST 800-171 – Contractor systems handling CUI
• CMMC L1, L2, L3 – DoD contractor readiness and assessments
• ISO/IEC 27000, 27001, 27002 – Information Security Management Systems
• SOX – Financial reporting compliance
• SOC 2 Type II – Service organization security controls
• PCI-DSS – Payment card industry compliance
• PHI, PII, Privacy Regulations – HIPAA and data protection requirements
Project Deliverables & Capabilities
Compliance Deliverables:
• System Security Plans (SSP)
• Plans of Action and Milestones (POA&M)
• Risk Management Plans & Assessments
• Incident Response Plans & Processes
• Change & Configuration Management Plans
• Gap Analyses & Remediation Plans
• Security Policies, Procedures, Processes, Checklists, and Matrixes
Technical Deliverables:
• Secure Network & Topology Flow Diagrams
• Scope Boundary Definitions
• Encryption & Data Protection Programs
• Endpoint Management & Mobile Device Management
• System Testing Metrics, Storage, Backup, and Archiving solutions
Consulting & Training:
• GAP Assessments with remediation roadmaps
• Policy development and compliance readiness coaching
• Education & training for executives, HR, IT Admins, and staff
• Full lifecycle compliance project management
• Evidence collection, attestations, and audit preparation
Professional Experience
Throughout my career, I have served as:
• Virtual Chief Information Security Officer (vCISO) – Advising executive teams on compliance and risk strategies
• Senior Security Engineer – Implementing secure infrastructures and advanced encryption standards
• Secure Infrastructure Specialist – Designing DoD-compliant architectures
• Project Manager – Leading compliance, remediation, and IT modernization efforts
• Security Operations Center (SOC) Analyst – Monitoring, detecting, and responding to threats
Why Work With Me?
I provide end-to-end cybersecurity and compliance services—from initial gap analysis and roadmap development to full assessments and audits. My approach is hands-on, practical, and tailored to each organization’s environment, ensuring not only compliance but also stronger overall security.
Whether you need a CMMC assessment, NIST 800-171 consulting, ISO 27001 program build, or a vCISO to lead your security strategy, I bring the experience, certifications, and proven track record to help your organization succeed.
Contact me with any questions or project requests. Let’s build your compliance roadmap and strengthen your cybersecurity posture.
Eric Lunsford
Cybersecurity Management
Information Security Consultation
FedRAMP
ISO 27001
Incident Response Plan
IT Compliance Audit
NIST SP 800-53
SOC 2 Report
Security Policies & Procedures Documentation
Risk Assessment
Security Infrastructure
Certified Information Systems Security Professional
Jonathan P.
Bakersfield, California
$85/hr
5.0
5 jobs
With over 15 years of invaluable experience in the IT industry, I bring a wealth of expertise to the table. Specifically, I have dedicated 8 years of my career to specializing in compliance standards such as HIPAA, HITECH, NERC, ISO 27001, FISMA, and ADA.
My approach involves a meticulous step-by-step process that enables me to thoroughly analyze and address the unique needs of your organization. Having successfully dealt with HIPAA security breaches in the past, I am well-equipped to handle time-sensitive matters with utmost dedication. My primary goal is to ensure that my clients avoid substantial fines and penalties by promptly remedying any compliance issues.
If you are in search of a comprehensive risk assessment, I am pleased to offer my services detailed below.:
Security Risk Analysis
o Annual Risk Assessment
o Business Associate Agreement (BAA)
o IT Security Documentation
o IT Policy and Procedures
o Report Analysis
o Remediation Recommendations
Website Compliance
o Review website for ADA, CCPA, and GDPR compliance
o HIPAA compliance is by scope only.
o Security screenings
o Monitoring
o Backups
o Remediation Strategies
Network Vulnerability Assessment
o Scoping
o Threat Assessment
o Setup & Configuration
o Vulnerability Report Analysis
o Remediation Recommendations
Monthly Monitoring
o Monthly Security Monitoring and Alerts
o HIPAA compliance and alerts against malicious events
o Website monitoring, compliance, monthly reports.
Information Security Audit
Risk Assessment
HIPAA
ISO 27001
IT Compliance Audit
Network Security
Vulnerability Assessment
Security Analysis
Network Monitoring
Information Technology Strategy
Fortinet
FortiGate Firewall
Cisco
Network Engineering
Firewall
How it works
Post a job for freePost a job
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a Information Security Audit Freelancer in the United States on Upwork?
You can hire a Information Security Audit Freelancer in the United States on Upwork in four simple steps:
Create a job post tailored to your Information Security Audit Freelancer project scope. We'll walk you through the process step by step.
Browse top Information Security Audit Freelancer talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top Information Security Audit Freelancer profiles and interview.
Hire the right Information Security Audit Freelancer for your project from Upwork, the world's largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a Information Security Audit Freelancer?
Rates charged by Information Security Audit Freelancers on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a Information Security Audit Freelancer in the United States on Upwork?
As the world's work marketplace, we connect highly-skilled freelance Information Security Audit Freelancers and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Information Security Audit Freelancer team you need to succeed.
Can I hire a Information Security Audit Freelancer in the United States within 24 hours on Upwork?
Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Information Security Audit Freelancer proposals within 24 hours of posting a job description.
Find more freelancers
Top states for Information Security Audit Freelancers in the United States