Hire the Best Information Security Audit Freelancers
in the United States

More than 3,000 reviews on G2
Rating is 4.5 out of 5.
4.5/5
of Upwork by G2 peer reviewers
Justin H.

Longwood, Florida

$25/hr
5.0
15 jobs

About Me - I'm a versatile freelancer with a proven track record of delivering quality work across multiple platforms and industries. With experience spanning real estate, customer service, and extensive freelance work, I bring a unique combination of business acumen and hands-on problem-solving skills to every project. - Professional Experience - * Freelance Professional | Self-Employed • Successfully built and managed a thriving freelance business across multiple platforms including TaskRabbit, Thumbtack, and Nextdoor • Consistently ranked as a top performer on TaskRabbit, generating substantial revenue through dedicated service • Developed strong client relationships leading to consistent word-of-mouth referrals and repeat business • Managed all aspects of business operations including scheduling, client communications, and financial management * Data Annotation & AI Training Data Specialist | 2+ Years - Extensive experience across the full spectrum of data annotation work, including image annotation, video annotation, bounding boxes, text classification, and tool-use/agentic task evaluation - Outlier (top-rated): completed high volume of projects spanning photo, video, text, and multi-modal AI training tasks - Appen: specialized in audio transcription work, ensuring accurate and detail-oriented output for training datasets - Alignerr: professional voice recording and audio data collection for AI model training - Skilled in RLHF (Reinforcement Learning from Human Feedback), data labeling for LLM fine-tuning, and quality assurance review of annotated datasets - Detail-oriented and consistent, with strong ability to follow complex, evolving labeling guidelines and rubrics - Comfortable with fast platform/tool switching. I'm experienced across multiple annotation interfaces and internal tooling - QA Lead & Founder, Inner House Data — Data Annotation Team. Currently leading a small remote annotation team, overseeing quality assurance, task calibration, and client deliverables for AI training data projects. Experience setting up annotation workflows (Label Studio), managing pricing/scoping based on task complexity, and ensuring consistent output quality across a distributed team. * Independent Security Research & Web Application Testing - Independent security researcher specializing in web application vulnerability assessment - Experienced with OWASP Top 10 (2025) vulnerability identification and documentation - Proficient with Burp Suite, ffuf, and manual penetration testing methodology - Delivered professional security disclosure reports to funded startups - Completed OWASP Top 10 certification via TryHackMe * Real Estate Professional | 2+ Years • Gained valuable experience in client relationship management and negotiation • Developed strong communication and precise organizational skills in a fast-paced environment * Additional Experience • Top Dasher at DoorDash, demonstrating reliability and excellence in service delivery • Past customer service experience at Honda dealership and Universal Studios • Proven ability to excel in diverse work environments - Why Choose Me - ✓ Fast Learner: I quickly adapt to new skills and technologies - from picking up new languages (currently I'm studying Indonesian daily) to picking up guitar, coding, and networking fundamentals ✓ Self-Motivated: I handle my own scheduling and project management ✓ Flexible Availability: Available most days of the week to accommodate your project needs ✓ Proven Track Record: Success across multiple freelance platforms with satisfied clients. (Upwork is the next one on the list!) ✓ Business-Minded: Real estate and entrepreneurial background brings strategic thinking to projects ✓ Reliable: Consistent top performance ratings across all platforms I've worked on - Let's Connect - I'm always expanding my skill set, whether it be diving into coding, mastering networking concepts, or picking up instruments, most recently, guitar. I'm always excited to take on new challenges and help bring your projects to life. Helping you, in turn, helps me learn more skills! Feel free to reach out to discuss how I can contribute to your success.

  • Information Security Audit
  • General Transcription
  • Market Research
  • Voice-Over
  • Voice Acting
  • Voice Recording
  • Male Voice
  • Audio Recording
  • Data Entry
  • Penetration Testing
  • Web Application Audit
  • Web Application Security
  • Cybersecurity Tool
  • Application Audit
  • Network Security
  • Vulnerability Assessment
  • Security Testing
  • Website Security
  • Ethical Hacking
Michael H.

Baltimore, Maryland

$125/hr
5.0
115 jobs

Stop relying on automated scans. I find the vulnerabilities they miss. I’m a senior penetration tester and vulnerability researcher with deep experience across enterprise networks, web apps / APIs and cloud platforms. Most testers just run automated tools and hand you a generic report. I simulate how an attacker actually thinks, perform thorough testing, and deliver professional, tailored reporting suitable not just for your own remediation efforts but also for audit / compliance. Benefits of manual testing: - Chaining multiple low/medium findings to show more significant impact - Breaking multi-tenant isolation - Bypassing auth controls (JWT, OAuth, misconfigurations) - Identifying cost-amplification / abuse vectors (e.g., billing attacks in serverless environments) - ZERO false positives (and wasted time trying to remediate non-issues) - REAL severity scoring (not just CVSS or ratings with no connection to actual impact/risk for your systems and data) What I Deliver - Manual, attacker-style testing (not just scans) - Clear, prioritized findings with real business impact - Proof-of-concept exploits where it matters - Practical remediation guidance your devs can use immediately - Optional retesting to verify fixes Common Engagements - SaaS / multi-tenant application security testing - API and authentication testing (JWT, OAuth, session flaws) - Cloud security reviews (GCP, AWS, Azure, O365) - DevOps security reviews (Gitlab/hub, BitBucket, etc.) - Pre-SOC2 / investor readiness assessments - High-intensity black-box pentests Why Clients Hire Me - I go beyond the scan—I find what others miss - I understand both offense and architecture - I communicate clearly with both engineers and leadership - I’ve worked on MANY real-world, high-impact systems I also help organizations: - Investigate breaches - Contain active threats - Recover compromised systems (Note: I do not assist with social media account recovery.)

  • Security Analysis
  • Security Engineering
  • Web Application Security
  • Ethical Hacking
  • Penetration Testing
  • Certified Information Systems Security Professional
  • Security Assessment & Testing
  • OWASP
  • White Box Testing
  • Network Security
  • Security Infrastructure
  • Vulnerability Assessment
  • Web App Penetration Testing
  • Network Penetration Testing
  • Incident Management
Bruce P.

New York City, New York

$140/hr
5.0
2 jobs

I help small and mid-sized businesses and organizations understand their cybersecurity risks, strengthen their security posture, and make practical improvements aligned with real-world necessities. My clients are not looking for enterprise-grade security models or unnecessary complexity; they want to understand where they are exposed, what matters most, and what needs to be fixed. Or, what doesn’t need to be fixed at all. For 20 years, my consulting practice, FineLine Security, has focused on practical cybersecurity, infrastructure security, and data protection for small and mid-sized companies across many business sectors. My approach emphasizes operationally sound controls such as least privilege, role-based access control, and zero-trust principles designed to reduce real-world business risk without creating unnecessary complexity. Security breaches don’t originate from the stereotypical hacker wearing a black hoodie and an eye mask. They result from weak processes, excessive access, inconsistent controls, outdated systems, and security gaps that accumulate unnoticed. I work with organizations that need clear, prioritized recommendations that can be realistically implemented and maintained over time. My background combines hands-on IT leadership with governance, risk, and audit expertise. My certifications include CISSP, CISA, and CISM, and my approach reflects that perspective; security should be structured, measurable, and aligned with the operational realities of the business. Clients typically engage me to: • Assess current security posture and identify meaningful risks • Develop or refine security policies and procedures • Evaluate gaps against recognized frameworks and regulatory expectations • Prepare for audits, client security reviews, and compliance initiatives • Prioritize remediation efforts based on actual business risk • Translate technical security concerns into practical business decisions I work particularly well with organizations that want an experienced advisor who can communicate clearly with both technical and non-technical stakeholders. For organizations looking to get started quickly, I offer a focused fixed-price security assessment designed as a practical first step. This includes a structured consultation, identification of key risks and exposures, and a concise written summary with prioritized recommendations and next steps. While I am newer to Upwork, consulting work itself is very familiar territory. My goal has always been to help organizations make thoughtful, practical security improvements that meaningfully reduce risk without creating unnecessary operational burden.

  • Information Security Audit
  • Information Security
  • Cybersecurity Management
  • Risk Assessment
  • Security Policies & Procedures Documentation
  • Compliance
  • Risk Management
  • ISO 27001
  • GDPR
  • SOC 2
Michael C.

Canyon, Texas

$150/hr
5.0
3 jobs

I help organizations build, strengthen, and mature cybersecurity governance, risk, and compliance (GRC) programs that stand up to real-world operational and audit scrutiny. As an Information Security professional with experience supporting defense contractors, manufacturers, federal environments, and commercial organizations, I specialize in translating complex security and compliance requirements into practical, sustainable business processes. Whether your organization is pursuing SOC 2, ISO/IEC 27001, NIST Cybersecurity Framework (CSF), NIST SP 800-53, NIST SP 800-171, or CMMC assessment readiness, my focus is helping you reduce risk while building programs that remain effective long after an assessment is complete. My expertise includes: • Governance, Risk, and Compliance (GRC) program development and maturation • SOC 2 and ISO/IEC 27001 readiness assessments • NIST Cybersecurity Framework (CSF) implementation • NIST SP 800-53 and NIST SP 800-171 compliance • CMMC Level 1 and Level 2 assessment readiness • Risk assessments and security gap analyses • Security policies, standards, procedures, SSPs, and POA&Ms • Control mapping and evidence development • Virtual CISO (vCISO) advisory services • Microsoft 365 Commercial and GCC High security governance Throughout my career, I've worked as a Business Information Security Officer (BISO), cybersecurity consultant, and assessor, partnering with executive leadership to improve security maturity, prepare organizations for external assessments, and implement governance processes aligned with business objectives. My approach is practical, execution-focused, and rooted in real-world operational experience. I don't recommend unnecessary complexity or expensive rebuilds when existing programs can be strengthened through sound governance, risk management, and well-designed security controls. I work collaboratively with leadership, IT, compliance, and operational teams to create solutions that are technically sound, operationally achievable, and auditor defensible. If your organization needs help with: • Preparing for a SOC 2, ISO 27001, NIST, or CMMC assessment • Performing a cybersecurity risk or gap assessment • Developing security documentation and governance processes • Building or improving an Information Security Program • Establishing a practical GRC roadmap • Aligning security controls with regulatory or contractual requirements • Executive cybersecurity strategy and vCISO guidance I'd welcome the opportunity to discuss your objectives and help you build a security and compliance program that delivers measurable business value.

  • Information Security
  • Risk Management
  • Risk Assessment
  • Cybersecurity Management
  • Compliance
  • NIST Cybersecurity Framework
  • NIST SP 800-53
  • CMMC
  • SOC 2
  • ISO 27001
  • Security Policies & Procedures Documentation
  • Internal Auditing
  • Microsoft Intune
  • Microsoft Endpoint Manager
Imran S.

Arlington, Virginia

$87/hr
5.0
4 jobs

I am a seasoned Cyber Security Practitioner with over two decades of experience. My expertise spans a wide range of compliance and security frameworks, including ISO 27001, CMMC, SOX ITGC, NIST RMF, AICPA SOC-2 Type 1 and Type 2 attestations, FedRAMP, FISMA, and HIPAA. I am adept at aiding senior management in achieving strategic cybersecurity and IT security objectives, crafting security development roadmaps, and conducting maturity assessments. Throughout my 20-year career, I have collaborated with various private sector entities, notably large financial organizations, and have also engaged with U.S. federal government civilian agencies. My role often involved leading projects to assess clients' security and compliance standards against regulatory and industry-specific frameworks. I hold a degree in Computer Science from the City University of New York, Queens College, and hold several professional certifications, including Certified Information Systems Security Professional (CISSP), Project Management Professional (PMP), ISO 27001 Lead Auditor, and Certified Chief Information Security Officer (C|CISO). I am a U.S citizen and currently reside in state of Maryland.

  • Information Security
  • Penetration Testing
  • ISO 27001
  • Federal Information Security Management Act of 2002
  • SOC 2
  • FedRAMP
  • NIST SP 800-53
  • Risk Assessment
  • Risk Management
  • Governance, Risk & Compliance Software
  • CMMC
  • NIST Cybersecurity Framework
  • HITRUST Common Security Framework
  • HIPAA
  • Compliance Consultation
  • Regulatory Compliance
  • Vulnerability Assessment
  • Blog Writing
  • Content Writing
  • SEO Content
Adnan S.

Queens County, New York

$25/hr
5.0
3 jobs

Is your website, network, cloud, or business system truly secure or only “working fine” until an attacker finds the weak point? I help businesses identify vulnerabilities, reduce cyber risk, and strengthen security with clear testing, reporting, and remediation guidance. I am a Certified Cybersecurity Consultant with hands-on experience in Vulnerability Assessment & Penetration Testing, SOC/SIEM monitoring, ISO 27001 compliance, SOC 2 audit support, network security, phishing awareness, and security documentation. I work with tools and technologies including Nmap, Burp Suite, Metasploit, OpenVAS, Nessus, Wazuh SIEM/XDR, Kali Linux, Parrot OS, Palo Alto Firewall, Cisco ASA, Active Directory, ServiceNow, Saviynt, HighBond, Microsoft Office 365, GitLab CI/CD, and Kubernetes security environments. Services I can help you with: i. Vulnerability Assessment & Penetration Testing ii. Website, Web App & Network Security Testing iii. Nmap, Burp Suite, Metasploit, Nessus & OpenVAS Testing iv. SOC/SIEM Setup, Monitoring & Wazuh Deployment v. ISO 27001 Policies, Procedures & Security Controls vi. SOC 2 Audit Support & Compliance Documentation vii. Phishing Awareness Campaigns & Security Training viii. Firewall, VPN & Network Security Review ix. Active Directory & Access Rights Review x. Security Incident Documentation & Remediation Guidance xi. Cybersecurity Reports with Risk Rating & Fix Recommendations My background includes cybersecurity teaching, cyber defense lab implementation, information security documentation, Proofpoint phishing campaign setup, SOC-2 audit support, IAM access review campaigns, Kubernetes production environment exposure, Wazuh SOC deployment, and enterprise network administration. I do not just provide automated scan results. I focus on giving you clear findings, business impact, risk severity, screenshots where needed, and step-by-step remediation guidance so your team can fix the issues properly. Let’s secure your systems before vulnerabilities become real business risks.

  • Information Security Audit
  • Information Security
  • Cybersecurity Management
  • Penetration Testing
  • Vulnerability Assessment
  • Network Security
  • Web Application Security
  • Ethical Hacking
  • ISO 27001
  • Security Analysis
  • Risk Assessment
  • Firewall
  • SOC 2
  • Compliance
  • VPN
  • Cisco ASA
  • Internet Security
  • Cloud Security
  • Malware Removal

How it works

Post a job for freePost a job

Tell us what you need. Create your own job post or generate one with AI then filter talent matches.

Hire top talent fast

Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.

Collaborate easily

Use Upwork to chat or video call, share files, and track project progress right from the app.

Payment simplified

Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.

Don't just take our word for it

How do I hire a Information Security Audit Freelancer in the United States on Upwork?

You can hire a Information Security Audit Freelancer in the United States on Upwork in four simple steps:

  • Create a job post tailored to your Information Security Audit Freelancer project scope. We'll walk you through the process step by step.
  • Browse top Information Security Audit Freelancer talent on Upwork and invite them to your project.
  • Once the proposals start flowing in, create a shortlist of top Information Security Audit Freelancer profiles and interview.
  • Hire the right Information Security Audit Freelancer for your project from Upwork, the world's largest work marketplace.

At Upwork, we believe talent staffing should be easy.

How much does it cost to hire a Information Security Audit Freelancer?

Rates charged by Information Security Audit Freelancers on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.

Why hire a Information Security Audit Freelancer in the United States on Upwork?

As the world's work marketplace, we connect highly-skilled freelance Information Security Audit Freelancers and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Information Security Audit Freelancer team you need to succeed.

Can I hire a Information Security Audit Freelancer in the United States within 24 hours on Upwork?

Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Information Security Audit Freelancer proposals within 24 hours of posting a job description.