Hire the Best Information Security Analysts

Clients rate our Information Security Analysts
Rating is 4.8 out of 5.
4.8/5
Based on 2,580 client reviews
Vitalii R.

Kyiv, Ukraine

$25/hr
5.0
2 jobs

Hi! I'm a Cybersecurity Engineer with hands-on experience in vulnerability assessments, cloud security reviews, and compliance evidence gathering. My main responcibility is to make clients understand and improve their security posture. I work across the full assessment lifecycle: scanning exposed services, reviewing configurations, validating findings, and delivering clear, actionable remediation reports that your clients can actually use. I'm comfortable operating under NDA and have supported multiple audit during my experience in fintech sector, so I understand the discipline and documentation standards that consulting engagements demand. What I can do: - Conduct vulnerability assessments using Burpsuite Scanner, OpenVAS, Nmap, Acunetix from scoping through validated findings - Review exposed services, firewall configurations, and network infrastructure for security gaps - Perform Microsoft 365 security reviews - Azure security posture analysis aligned with CIS benchmarks and Microsoft Secure Score - Gather and structure technical evidence for compliance projects (PCI DSS, ISO 27001) - Produce detailed, structured remediation reports tailored to any environments Relevant experience: - Conducted web penetration tests using OpenVAS, Burp Suite, OWASP ZAP, and Metasploit - Provided technical evidence and documentation support for internal audits and certifications - Performed risk assessments and security hardening for infrastructure and information systems - Wrote security policies, remediation playbooks, and technical process documentation Understanding of frameworks & certificates: PCI DSS ISO 27001 CIS Benchmarks Tech stack: OS : Linux (Red Hat, Ubuntu), Windows (desktop & server), macOS VM : VMware, VBox SIEM : ELK/Wazuh, ArcSight, Splunk Cloud : Azure, Entra ID, Defender Network : Fortinet IPS&Firewall, Check Point Firewall, F5 WAF Anti-DDoS : Radware, Arbor EDR : Elastic Agent, Trellix PAM : CyberArk NDR : Vectra Vulnerability Detection : Nmap, Metasploit, Burp Suite + Scanner, OWASP ZAP, OpenVAS, Harvester, Sublister, Maltego

  • Information Security
  • Computer Network
  • Computing & Networking
  • Network Engineering
  • System Administration
  • Compliance
  • Penetration Testing
  • Incident Management
  • Cybersecurity Monitoring
  • Virus Removal
  • Security Assessment & Testing
  • Website Security
Muhammad Ahmad B.

Islamabad, Pakistan

$10/hr
5.0
6 jobs

I’m Muhammad Ahmad Bilal, a CISSP-certified Security Architect and Information Security Manager who works at the intersection of security engineering, threat detection, and AI. For the past 9+ years I’ve been designing and running security programs at government scale, protecting critical national applications, large user bases, and high-value data across the public sector. I specialise in turning noisy, complex environments into predictable, defensible systems. That’s included building ML-driven APT detection using TensorFlow and PyTorch, modernising SIEM/SOAR stacks to cut detection and response times by around 40%, and embedding security into the SDLC so vulnerabilities are caught before they ever reach production. I’ve led Zero Trust initiatives, redesigned IAM around least privilege, and driven end-to-end implementations of governance, risk, and compliance programmes aligned with standards like ISO 27001, NIST, PCI, GDPR, and HIPAA. I’m also an educator by choice. As a Lecturer at NUST, I’ve taught Computer and Network Security, Cryptography, Operating Systems, and Data Structures, and supervised 20+ research projects in cybersecurity and machine learning. My academic work includes publications on: - Deep learning–based intrusion detection for IoT - Protocol-aware IDS using datasets such as UNSW-NB15 and Bot-IoT - Federated learning with explainable AI for malicious traffic detection and cellular traffic prediction What I do best: - Design security architectures for large, heterogeneous environments that can actually be operated and maintained by real teams. - Build and tune detection & response: SIEM, EDR, and SOAR use cases, threat hunting workflows, and playbooks that reduce noise while catching what matters. - Integrate security into delivery through secure SDLC practices, code review guidelines, and automation that supports developers instead of blocking them. - Make compliance meaningful, mapping real technical and process controls to standards and regulations so they translate into measurable risk reduction. - Develop people and teams, mentoring analysts and engineers so security becomes an organisational capability, not a one-team bottleneck. In simple terms, my work is about building security systems—technical, procedural, and human—that don’t fall apart the moment something real happens.

  • Information Security
  • Compliance
  • Cyber Threat Intelligence
  • Cybersecurity Management
  • Cybersecurity Monitoring
  • NIST Cybersecurity Framework
  • Cryptography
  • SOC 1
  • SOC 2
  • SOC 3
  • ISO 27001
  • Information Security Audit
  • Information Security Consultation
  • Certified Information Systems Security Professional
  • Information Security Governance
Hamza A.

Lahore, Pakistan

$8/hr
4.6
2 jobs

🔍 Certified IS Auditor and Certified in Cybersecurity with a keen eye for IT security, IT Risk & Controls, SOC, ITGC, ITAC, compliance, and risk management. I specialize in evaluating IT systems, ensuring regulatory compliance, and strengthening cybersecurity controls (covering logical accesses, change management and IT operations) to protect businesses from threats and vulnerabilities. What I Offer: ✅IT & Internal Audit engagement (ISO 27001, NIST, COBIT, SOX, HIPAA, PCI-DSS) ✅Risk Assessment & Control Evaluations ✅ Cybersecurity Assessments & Compliance Checks ✅ IT Governance & Internal Control Reviews ✅ Security Policy Development & Implementation ✅ IT General Control Testing, IT Application Control Testing ✅ Business Continuity & Disaster Recovery Planning Why Work With Me? ✔ 5+ years of experience in IT auditing, SOC Assessment. Internal Audit, Cybersecurity, and Compliance ✔ Expertise in regulatory frameworks & industry best practices ✔ Strong communication skills—clear, actionable reporting ✔ Commitment to helping businesses secure their IT environment 💡 Let’s work together to strengthen your IT security, Business controls, ensure compliance, and mitigate risks effectively. Contact me today to discuss your project!

  • Security Policies & Procedures Documentation
  • OS Security
  • Internal Auditing
  • IT General Controls Testing
  • Information Security Audit
  • SOC 2
  • Application Audit
  • IT Compliance Audit
  • SOC 1
  • GDPR Compliance Review
  • ISO 27001
  • SAP
  • Policy Writing
  • Sarbanes-Oxley Act
  • Cybersecurity Management
  • NIST Cybersecurity Framework
Md N.

Comilla, Bangladesh

$12/hr
4.9
107 jobs

✅Malware removal from ⦿ Wordpress ⦿ Shopify ⦿ PrestaShop ⦿ Wix ⦿ Magento ⦿ Squarespace ⦿ PHP ✅WordPress Design: ⦿ Wordpress Expert ⦿ Wordpress Designer ⦿ Wordpress Elementor Pro ⦿ Website Optimizaton ⦿ CMS ⦿ Shopify ⦿ Customer Wordpress Website ⦿ Ecommerce ⦿ Divi Theme ⦿ Premium Plugins ✅Fix Google Ads Disapproved for Malicious Software ✅Penetration testing and Vulnerability Assessment. ✅Cloudflare Setup and DDoS Security. ✅ Wordpress Migration I'm a full-time freelancer as a Cyber Security Specialist, Malware Analyst, and Penetration Tester. I can remove malware, delete viruses, do penetration tests, do vulnerability assessments, and remove malicious (Plugins, Themes, and Software). remove the Google warning from your website. I've 5 years of experience as a website security specialist in Ignite tech solutions. Also, I'm a freelancer on Fiverr and Upwork. I've got a level two badge on Fiverr. ✅Service I will provide: 0) Penetration testing and Vulnerability Assessment. 1) WordPress Malware Removal and Security. 2) Shopify Malware Removal and Security. 3) Cloudflare Setup and DDoS Security. 4) Website Backup and Migration from old host/server/domain to new host/server/domain. 5) Google Ads Disapproved for malicious software. ✅Wordpress service: ⦿Remove Malware. ⦿Penetration Testing / Vulnerability Testing ⦿Wordpress Malware removal. ⦿Website Security. ⦿Clean Server / Server Maintenence / cPanel / WHM Panel ⦿Delete Virus / Virus Removal ⦿Remove Google blacklist/ Red screen. ⦿Remove Japanese or Chinese search results. ⦿Security patch installation ⦿Remove malware ⦿Fix the hosting site suspended ⦿Delete junk or virus script ⦿Add SSL Certificate / Setup Cloudflare ⦿Database error / Remove malware from the database ⦿Fix emails problem / Emails not coming ⦿Spam emails coming / Unwanted emails coming ⦿Critical and Fatal Error ⦿Remove the PHP backdoor ⦿Blacklist Removal, McAfee blacklist ⦿WordPress version update ⦿Install Cloudflare SSL ⦿Fix Login Issue / Broken dashboard ⦿Remove website redirect URL / Fix redirecting issues ⦿Internal 404 or 505 Error ⦿Remove the PHP shell ⦿Unwanted / Bulk email coming ⦿White/Empty Screen ⦿Error Establishing Database Connection ⦿Theme/Plugin Broken ⦿Improve website security ⦿Corrupt .htaccess file ⦿Solve PHP memory limit ⦿Core files issues ⦿Upload size problem ⦿Forgot Username/password ✅Backup and Migration Service: I will backup WordPress sites, duplicate, clone, copy, host migration, WordPress migration, Transfer, move websites, and domain migration any WordPress website for personal and business. ⦿Database Backup and Transfer ⦿Change primary addon domain/domain/subdomain ⦿Move WP from root domain/subdomain/addon domain to main ⦿Old host to another new host ⦿Clone and duplicate the WordPress website ⦿Update WordPress version/theme/plugin ✅Penetration Test and Vulnerability Service: I will perform penetration and vulnerability tests with the VAPT report ⦿According to a security report, about 90% of websites are vulnerable to malicious attacks. ⦿A website is an essential part of your Business. The thing is how secure is your website? ⦿I will perform an advanced deep scan and penetration testing on your web application with a professional report which includes all vulnerabilities. ⦿Let me help you in making your website secure against hackers: ⦿Vulnerability Checklist: ⦿ Web attack vulnerabilities.[Input Validation, Code Execution, Bypass Authentication, SQL Injection, CSRF, LFI, Cross-site Scripting, Uploader Issues, Remote Code Execution, Buffer Overflow, Session Hijacking] ⦿ Information Gathering [Server Info, Open Port] ⦿ Authorization Testing [HTTP Header] ⦿ Data Validation Testing [XSS] ⦿ Denial of Service Testing [DDos Test] ⦿ Security Testing ✅Cloudflare service: ⦿Fix A Record, CNAME Record ⦿Fix NS, MX record ⦿Cloudflare setup ⦿Email Routing ⦿Configure Emails ⦿Add SSL ⦿Cloudflare SSL ⦿Cloudflare error fix ⦿Free SSL ⦿DDOS protection from Hackers ⦿setup DNS ⦿Website Security ⦿Enable green padlock ⦿Improve Website speed ⦿Setup firewall Errors I will fix: Mail Delivery Issue 500 internal server error 502 bad gateway or error 504 gateway timeout 503 service is temporarily unavailable 520: web server returns an unknown error 521 web server is down 522: connection timed out 524: a timeout occurred 525: SSL handshake failed 526: invalid SSL certificate Cloudflare Benefits: ⦿Minification ⦿HTTP/2 Protocol ⦿DNS Security ⦿Cloud WAF ⦿Image Optimization ⦿Browser Caching ⦿WebSockets ⦿Load Balancing ⦿Optimized Network Routing ✅I can work with any CMS like: ⦿Magento, OpenCart, Drupal, Joomla, Prestashop, WordPress, SHOPIFY, LARAVEL, SQUARESPACE, WIX, WOOCOMMERCE, BigCommerce, Blogger, Hubspot CMS, Typo3, Weebly, Webflow, CMS Hub. ✅Why Me: ⦿I will provide a Professional Report ⦿Give you technical support ⦿Quality Work

  • Information Security
  • Malware Removal
  • WordPress Website Design
  • Penetration Testing
  • Vulnerability Assessment
  • Network Security
  • CMS Development
  • WordPress Malware Removal
  • Virus Removal
  • Cloudflare
  • SSL
  • Ethical Hacking
  • cPanel
  • WordPress Bug Fix
  • WordPress Security
Safi Ullah K.

Peshawar, Pakistan

$25/hr
5.0
4 jobs

I'm a Senior SOC Analyst with 5+ years of experience helping organizations detect, investigate, and respond to cyber threats before they become costly incidents. I specialize in Security Operations Center (SOC) monitoring, SIEM engineering, threat hunting, incident response, cloud security monitoring, and Microsoft security solutions. I have hands-on experience monitoring enterprise environments, investigating security alerts, reducing false positives, improving detection coverage, and strengthening organizations against modern cyber attacks. Whether you need a dedicated SOC analyst, Microsoft Sentinel expert, SIEM engineer, or threat hunter, I can help secure your environment with proven security operations. What I Can Do : ✔ 24/7 Security Monitoring ✔ Microsoft Sentinel Administration ✔ Microsoft Defender XDR ✔ Incident Response ✔ Alert Triage ✔ Threat Hunting ✔ SIEM Deployment ✔ SIEM Optimization ✔ Detection Rule Creation ✔ MITRE ATT&CK Mapping ✔ IOC Investigation ✔ Log Analysis ✔ Malware Investigation ✔ Endpoint Security ✔ Cloud Security Monitoring ✔ Azure Security ✔ AWS Security ✔ Security Automation ✔ SOC Maturity Improvement ✔ Security Dashboards ✔ Vulnerability Analysis ✔ Security Reporting SIEM Platforms : Microsoft Sentinel , Defender, Splunk What You'll Get : ✔ Fast Incident Investigation ✔ Reduced False Positives ✔ Better Detection Rules ✔ Improved SOC Visibility ✔ Actionable Security Reports ✔ Faster Threat Detection ✔ Stronger Cloud Security ✔ Professional Communication ✔ Reliable Delivery If you're looking for an experienced SOC Analyst who can improve your security operations and respond quickly to threats, let's work together.

  • Information Security
  • Threat Detection
  • Cloud Security
  • Security Operation Center
  • Application Security
  • Vulnerability Assessment
  • Splunk
  • Cyber Threat Intelligence
  • SOC 1
  • SOC 2
  • Python
  • Automation
  • Cybersecurity Monitoring
  • Incident Response Plan
Lucca D.

Santana de Parnaiba, Brazil

$10/hr
5.0
1 jobs

I help businesses identify vulnerabilities, analyze network traffic, and improve their cybersecurity. My services include: • Vulnerability assessment and basic penetration testing (web, network) • Network traffic analysis using Wireshark • Intrusion detection and monitoring (Snort) • Security auditing and system hardening (Linux/Windows) I have hands-on experience with tools such as Nmap, Nikto, Burp Suite, and Wireshark, applying OWASP Top 10 and MITRE ATT&CK methodologies. I can help you: • Detect security issues in your system • Analyze suspicious network activity • Improve your system security configuration • Support basic SOC operations and log analysis As a Computer Engineer, I bring a deep understanding of systems, allowing me to identify vulnerabilities more effectively and provide practical solutions. Additional experience: • Backend development (Python, Java, REST APIs) • Embedded systems and IoT (ESP32, Arduino, C programming)

  • Information Security
  • Compliance
  • Computer Network
  • Python
  • Java
  • C
  • Web Development
  • Back-End Development
  • SOC 1
  • Embedded C
  • Embedded System
  • JavaScript
  • API
  • API Integration
  • Security Testing
  • C++

How it works

Post a job for freePost a job

Tell us what you need. Create your own job post or generate one with AI then filter talent matches.

Hire top talent fast

Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.

Collaborate easily

Use Upwork to chat or video call, share files, and track project progress right from the app.

Payment simplified

Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.

Don't just take our word for it

Information Security Analysts Hiring FAQs

What is an information security analyst?

With the scale and complexity of networked environments growing every year, the need for seasoned information security analysts has become more prevalent. Upwork provides access to information security talent adept at overseeing and managing risk in the areas of network security, cyber security, and endpoint security.

How do you hire an information security analyst?

You can source information security analysts on Upwork by following these three steps:

  • Write a project description. You’ll want to determine your scope of work and the skills and requirements you are looking for in an information security analyst.
  • Post it on Upwork. Once you’ve written a project description, post it to Upwork. Simply follow the prompts to help you input the information you collected to scope out your project.
  • Shortlist and interview information security analysts. Once the proposals start coming in, create a shortlist of the professionals you want to interview. 

Of these three steps, your project description is where you will determine your scope of work and the specific type of information security analyst you need to complete your project.  

How much does it cost to hire an information security analyst?

Rates can vary due to many factors, including expertise and experience, location, and market conditions.

  • An experienced information security analyst may command higher fees but also work faster, have more-specialized areas of expertise, and deliver higher-quality work.
  • A contractor who is still in the process of building a client base may price their information security analyst services more competitively. 

Which one is right for you will depend on the specifics of your project. 

How do you write an information security analyst job post?

Your job post is your chance to describe your project scope, budget, and talent needs. Although you don’t need a full job description as you would when hiring an employee, aim to provide enough detail for a contractor to know if they’re the right fit for the project.

Job post title

Create a simple title that describes exactly what you’re looking for. The idea is to target the keywords that your ideal candidate is likely to type into a job search bar to find your project. Here are some sample information security analyst job post titles:

  • Need marketing manager with experience in information data security
  • Cyber security analyst needed to oversee corporate governance project
  • Database analyst with security experience needed for financial institution

Project description

An effective information security analyst job post should include: 

  • Scope of work: From developing security policies to implementing network security strategies, list all the deliverables you’ll need. 
  • Project length: Your job post should indicate whether this is a smaller or larger project. 
  • Background: If you prefer experience with certain industries, software, or environments, mention this here. 
  • Budget: Set a budget and note your preference for hourly rates vs. fixed-price contracts.

Information security analyst job responsibilities

Here are some examples of information security analyst job responsibilities:

  • Help manage the enterprise information security infrastructure for a software development company
  • Support vulnerability review, management, and remediation efforts
  • Create the incident response plan and implement the business continuity plan 

Information security analyst job requirements and qualifications

Be sure to include any requirements and qualifications you’re looking for in an Information security analyst. Here are some examples:

  • Bachelor’s degree in IS or related field 
  • Minimum 5 years experience in vulnerability scanning and remediation
  • Excellent knowledge of Microsoft Windows and virtualization technologies