IT Support Specialist with hands-on experience in Microsoft 365, Google Workspace, Microsoft Entra ID, Intune, technical troubleshooting, and user account administration. Currently pursuing a BSc in Cyber Security at De Montfort University, with hands-on experience gained through technical labs, networking projects, and IT support environments.
I have experience supporting users with hardware, software, networking, email systems, and cloud-based platforms. My background includes Microsoft 365 administration, Google Workspace management, Entra ID user management, Intune device enrollment, Windows administration, DNS management, and technical troubleshooting. I also have experience providing customer-focused support through my role at E.ON Next, where I resolved customer issues, handled sensitive information, and maintained high service standards in a fast-paced environment.
Services I Offer:
• IT Support and Helpdesk Assistance
• Microsoft 365 Administration and Support
• Google Workspace Administration
• Microsoft Entra ID User and Group Management
• Intune Device Enrollment and Management
• User Onboarding and Offboarding
• Password Resets and Access Management
• Email Configuration and Troubleshooting
• Windows Administration and Technical Support
• Network Troubleshooting and Connectivity Support
• Remote Support and Issue Resolution
• Technical Documentation and Reporting
I am committed to delivering reliable support, clear communication, and professional service. My goal is to help businesses maintain efficient IT operations, improve user productivity, and resolve technical issues quickly and effectively.
Penetration Testing
Vulnerability Assessment
Cybersecurity Monitoring
Network Security
IT Support
Technical Support
Linux
Windows Administration
Python
Web Development
JavaScript
Information Security
Academic Research
Technical Writing
Artificial Intelligence
Cyber Threat Intelligence
Risk Assessment
C++
Technical Documentation
Customer Service
Rafay B.
London, United Kingdom
$100/hr
4.9
83 jobs
I am a globally acclaimed Cyber security consultant and Internet Security Specialist with a proven track record in security engineering and discovering Critical Zero Day Security Issues in a significant number of Web Applications, Products and Browsers which have helped protecting Privacy and Security of millions of users globally. My research on Cyber Security has been featured in BBC, Forbes, WSJ, Tech Crunch and many International media outlets. My mission is to fortify your digital defenses by harnessing the power of cutting-edge AI/ML technologies.
I currently hold the following educational degrees and certifications:
✅ Masters in Cyber-Security and Forensics
✅ Certified Information Systems Security Professional (CISSP)
✅ Certified Information Security Auditor (CISA)
✅ Offensive Security Certified Professional (OSCP)
✅ CREST Practitioner Security Analyst (CPSA)
✅ Offensive Security Web Expert (OSWE)
✅Offensive Security Wireless Professional (OSWP)
Security/Compliance Frameworks:
ISO 27001, SOC2, PCI-DSS, HIPAA, NY DFS 23/ NYCRR Part 500, NIST, CIS, GDPR, HIPAA, FedRAMP, NIST 800-53, NIST 800-171, NIS2, DORA
Services I Offer:
Penetration Testing
Vulnerability Assessment
PCI-DSS SAQ Filing + ASV
PCI compliance assessment
Cloud Security (AWS, Azure and GCP)
Red Teaming Assessment
Threat Modelling
Security Architecture Review
Web 3.0 Wallet Security
Smart Contract Audits
Cloudflare WAF Protection
DDOS Protection Expert
Bot Protection Expert
WordPress Security
Penetration Testing
Web App Penetration Testing
Website Security
Cybersecurity Management
NIST Cybersecurity Framework
Web Application Audit
Cloud Security
ISO 27001
GDPR Compliance Review
PCI DSS
NIST SP 800-53
SOC 2
Network Security
Firewall
Ijaz T.
London, United Kingdom
$20/hr
5.0
2 jobs
That vulnerability your scanner flagged last? It already missed three others.
Automated tools were built for speed, not depth. They catch surface-level issues and hand you a report full of findings that look thorough but leave the real risks untouched. Business logic flaws, broken access controls and chained API vulnerabilities are not things a scanner reasons though they require someone who thinks like an attacker and understands how applications are actually built.
With 15 years of web application penetration testing experience and both OSCP and OSWE certifications, the vulnerabilities that matter most are exactly what gets found here.
✅ OSCP and OSWE certified with 15 years of hands-on web application penetration testing
✅ API security testing across REST, GraphQL, BOLA, JWT and OAuth attack surfaces
✅ Full OWASP Top 10 coverage using real working exploits, not recycled scan output
✅ Business logic flaws, auth bypasses and access control gaps that no scanner will catch
✅ SaaS, fintech and startup clients across the US, UK, Europe and Australia
✅ Virtual CISO support for SaaS, fintech and AI companies without a full-time security hire
✅ ISO 27001 implementation and ISMS structuring to pass audits and satisfy enterprise buyers
✅ Security questionnaires handled end-to-end so compliance never stalls a deal
✅ Audit-ready policies, procedures and control frameworks beyond checkbox compliance
✅ Hands-on GRC platform work across Vanta, Drata, Secureframe and Thoropass
Certifications:
✅ Offensive Security Certified Professional (OSCP)
✅ Certified Ethical Hacker (CEH)
✅ eLearnSecurity Junior Penetration Tester (eJPT)
✅ GIAC Penetration Tester (GPEN)
✅ Offensive Security Web Expert (OSWE)
✅ GIAC Web Application Penetration Tester (GWAPT)
✅ Certified AppSec Practitioner (CAP)
✅ AWS Certified Security – Specialty
✅ Microsoft Certified: Azure Security Engineer Associate
Here's the thing: most penetration testing engagements produce the same report. Same ten findings, same scanner, same template. That is not useful to a development team trying to fix real problems, and it is not useful to a business trying to understand real risk. The vulnerabilities that lead to actual breaches live inside application logic, API design and access control architecture. Finding them requires manual testing, genuine attack thinking and an understanding of where developers cut corners under deadline pressure.
Web Application Penetration Testing
Testing covers the full attack surface authentication, session management, input validation, business logic, access control and injection vulnerabilities mapped across the complete OWASP Top 10. Burp Suite Professional, OWASP ZAP, Nuclei, ffuf, SQLmap and XSStrike are used alongside deep manual testing to find chained vulnerabilities and logic flaws that no automated tool reaches on its own.
Scope covers single-page applications in React, Angular and Vue, backend platforms including PHP, Node.js, Python, Java and .NET, and extends into microservices and cloud-native environments across AWS, Azure and GCP.
API Security Testing
Every REST and GraphQL endpoint gets tested for broken object-level authorisation, excessive data exposure, broken function-level authorisation, mass assignment, JWT vulnerabilities, OAuth misconfigurations and rate-limiting bypasses. Testing covers both technical weaknesses and business logic abuse, not just surface HTTP checks that any scanner can run.
GraphQL engagements go further into introspection abuse, batching attacks, nested query exploitation and field-level authorisation gaps.
Application Security Audit and Vulnerability Assessment
Every audit combines manual penetration testing with SAST via Semgrep, SCA via Snyk and container scanning via Trivy to deliver a full picture of code-level, dependency and infrastructure risk. Findings are prioritised by real exploitability and business impact, not by CVSS score alone.
Compliance-Aligned Testing
Audit work maps directly to OWASP ASVS, SOC 2, GDPR and NIST CSF requirements — useful for SaaS companies approaching enterprise sales, startups preparing for investor due diligence and platforms handling regulated or sensitive user data.
All findings are documented with detailed technical evidence, including proof-of-concept exploitation steps, affected endpoints, request/response analysis, and attack flow breakdowns where applicable. The reporting structure is designed to support engineering teams in reproducing and fixing issues efficiently, with clear mapping to OWASP Top 10 and relevant security controls. Each vulnerability includes prioritized remediation guidance, validation notes
Send a message to discuss scope. A short conversation is all it takes to get started.
WordPress Security
Penetration Testing
Vulnerability Assessment
Web App Penetration Testing
Website Security
Malware Removal
WordPress Malware Removal
Ethical Hacking
Network Penetration Testing
Network Security
Application Security
Application Audit
Security Analysis
Security Assertion Markup Language
Security Assessment & Testing
Security Testing
Cloud Security Framework
NIST Cybersecurity Framework
Kubernetes
Cloud Security
Muhammad Y.
Watford, United Kingdom
$20/hr
5.0
3 jobs
I'm a cybersecurity specialist with an MSc in Cybersecurity from the University of Hertfordshire (UK) and a BSc in Cybersecurity from FAST-NUCES, backed by industry certifications including eCPPT, CRTP, CEH (Practical), and AWS Cloud Practitioner , with OSCP in progress.
Over the past few years, I've delivered 80+ successful client projects on freelance platforms with a consistent 5-star rating, and have hands-on professional experience conducting VAPT engagements aligned with OWASP, PTES, and NIST SP 800-115 standards.
WordPress Security
Penetration Testing
Vulnerability Assessment
Web Application Security
Digital Forensics
WordPress Malware Removal
WordPress
Cryptography
Ethical Hacking
Network Penetration Testing
Information Security
Security Testing
OWASP
Kali Linux
WordPress Bug Fix
Osama Z.
Middlewich, United Kingdom
$25/hr
4.9
16 jobs
✅ Protect your website, SaaS platform, or IoT system from hackers. I deliver penetration testing + clear reports that keep your business safe and compliant.
I’m a cybersecurity consultant helping businesses, startups, and SaaS platforms secure their websites, web applications, and digital products against today’s evolving threats.
With an MSc in Cybersecurity (UK) and hands-on project experience, I deliver penetration testing + clear business-ready reports that help clients strengthen security without drowning in technical jargon.
🔹 Services I Offer
Website & Web Application Security Testing (WordPress, SaaS, APIs)
Penetration Testing (Web, Cloud, Network, IoT)
IoT & Embedded Device Risk Audits
Secure Architecture Reviews (STRIDE, SaaS, cloud platforms)
Malware / Vulnerability Assessments & Compliance Reports
Detailed Reporting (CVSS scores, PoCs, and step-by-step remediation)
🔹 Recent Work
Audited an e-reader app for token manipulation, DRM bypass, and scraping resistance.
Compared IDS tools (Snort vs Suricata) for high-throughput network monitoring.
Delivered red-team simulations using Kali Linux, Burp Suite, Nessus, and Metasploit.
🔹 Why Clients Hire Me
MSc Cybersecurity (Distinction, UK) + real-world Upwork client results
Tools: Burp Suite, ZAP, Wireshark, Nessus, Snort, Suricata, Ghidra, Splunk
Clear communication for both executives & technical teams
100% satisfaction or money-back guarantee
💬 Let’s discuss your project — I’ll help secure your website, app, or IoT system with expert-led testing and compliance-ready reporting.
Penetration Testing
Application Security
Firewall
Digital Forensics
Information Security Consultation
Security Testing
Information Security
Information Security Audit
Risk Assessment
Incident Response Plan
AI Security
Business with 10-99 Employees
Business with 1-9 Employees
IT Consultation
Threat Detection
Ahmar S.
Milton Keynes, United Kingdom
$20/hr
4.8
43 jobs
An ambitious and optimistic person with excellent communication and team leading skills and clear career goals. Result oriented and well-disciplined with ability to manage multiple assignments efficiently under extreme pressure while meeting tight schedules.
I have 6+ years experience of Data Entry & Web Researching with proficiency in Microsoft Office & task management softwares. I have worked as VA & Data Entry Professional for tech, healthcare, ecommerce & real estate companies and carry knowledge in following categories with working on various projects.
- Virtual Assistant(5+ Years)
- Web Researching (5+ Years)
- Lead Generation (3+ Years)
- Information Security(1 Year)
- Software Engineering
- Quality Assurance(2-3 Years)
- Penetration Testing (Masters Degree in Information Security with Research Thesis)
I have done Masters in Information Security with Certification in Ethical Hacking and i am all-rounder in various domains mentioned above.
Penetration Testing
Vulnerability Assessment
Network Security
Firewall
Information Security
Data Entry
Security Analysis
Microsoft Excel
Google Docs
Security Infrastructure
English
Critical Thinking Skills
How it works
Post a job for freePost a job
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a Internet Security Specialist in the United Kingdom on Upwork?
You can hire a Internet Security Specialist in the United Kingdom on Upwork in four simple steps:
Create a job post tailored to your Internet Security Specialist project scope. We'll walk you through the process step by step.
Browse top Internet Security Specialist talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top Internet Security Specialist profiles and interview.
Hire the right Internet Security Specialist for your project from Upwork, the world's largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a Internet Security Specialist?
Rates charged by Internet Security Specialists on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a Internet Security Specialist in the United Kingdom on Upwork?
As the world's work marketplace, we connect highly-skilled freelance Internet Security Specialists and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Internet Security Specialist team you need to succeed.
Can I hire a Internet Security Specialist in the United Kingdom within 24 hours on Upwork?
Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Internet Security Specialist proposals within 24 hours of posting a job description.
Find more freelancers
Top cities for Internet Security Specialists in the United Kingdom