I help SaaS companies, and enterprises identify critical security vulnerabilities before they become costly breaches, compliance issues, or business disruptions.
As an Application Security Consultant and Penetration Tester, I specialize in uncovering real-world security weaknesses across web applications, APIs, network infrastructure, cloud environments, and modern technology platforms. My goal is not only to identify vulnerabilities but also to help organizations understand their security risks, prioritize remediation efforts, and strengthen their overall security posture.
I have worked on security assessments involving enterprise applications, banking platforms, healthcare systems, cloud infrastructures, and business-critical applications. My experience includes identifying authentication flaws, access control weaknesses, business logic vulnerabilities, network misconfigurations, cloud security gaps, API security issues, and attack paths that automated scanners frequently miss.
Core Security Services
• Web Application Penetration Testing (OWASP Top 10 & Business Logic Testing)
• API Security Testing (REST & GraphQL)
• Network & Infrastructure Security Testing
• Cloud Security Assessments (AWS)
• Red Team Operations & Adversary Simulation
• AI / LLM Security Testing
• Vulnerability Assessment & Risk Analysis
• Security Architecture Review
• Email Security Implementation (SPF, DKIM & DMARC)
What You Can Expect
• Comprehensive Manual Security Testing
• Detailed Vulnerability Reports
• Proof-of-Concept Validation
• Risk-Based Prioritization
• Clear Remediation Guidance
• Remediation Validation & Retesting
• Executive and Technical Reporting
Tools & Technologies
• Burp Suite Professional
• Nmap
• Metasploit Framework
• Nessus
• OWASP ZAP
• Wireshark
• SQLMap
• AWS Security Tools
• Kali Linux
Long-Term Security Partnership
Many organizations engage me beyond a single penetration test. I work with clients on recurring security assessments, monthly security reviews, remediation verification, secure development guidance, and continuous security improvement initiatives.
Whether you need a one-time security assessment or a long-term security partner, I focus on delivering actionable security insights that help protect your applications, infrastructure, customers, and reputation.
If you are looking for a security professional who can think like an attacker and provide practical, business-focused security recommendations, I would be happy to discuss your project.
Penetration Testing
Web Application Security
Vulnerability Assessment
Ethical Hacking
OWASP
API Testing
Network Penetration Testing
Metasploit
Cloud Security
Cybersecurity Tool
Security Testing
Network Security
Application Security
Red Team Assessment
Information Security
Sandeep S.
Delhi, India
$15/hr
5.0
165 jobs
Web Penetration Testing(OWASP Top 10 methodology) | Network Penetration testing | OWASP API Security | Mobile Vulnerability Assessment(iOS and Android) | Source Code Reviews(.Net, Java, PHP) | Vulnerability Assessment and Penetration Testing | SIEM team (Cloud(AWS and Azure) Security, File Integrity Monitoring and Event Monitoring, Endpoint Security and Encryption, Data Loss Prevention, Network Access Control, Threat Monitoring (Email Traffic and Malware Analysis), Privileged Access and Identity Management)
Have 7+ years of experience in both black box and white box testing penetration testing. Perform VAPT (Vulnerability Assessment and Penetration Testing) services for web applications, networks, mobile; source code reviews; malware analysis; server hardening; and security analysis etc. Conduct penetration testing in a systematic approach. Follow the standard methodology of the industry like OWASP Testing Guide v4(OTGv4); SANS top 25; NIST SP 800-115; PCI DSS to perform penetration testing so that client can concentrate on their professions without worrying about security threats.
Web Application Testing: Do web application penetration testing with the latest methodology like OWASP Top-10, SANS Top-25. Perform both manual and automated penetration testing for vulnerabilities like Injection flaws(such as SQL, NoSQL, OS, and LDAP injection etc),Broken Authentication, Sensitive Data Exposure,XML External Entities (XXE), Broken Access Control,Security Misconfiguration, Cross-site scripting(XSS), Insecure Deserialization, Using Components with Known Vulnerabilities,Insufficient Logging & Monitoring. Also, perform source code reviews for many technologies like Java, NET, PHP etc.
Approach for Manual Web-Application Penetration Testing: Conduct manual testing with following controls:
* Configuration and Deployment Management Testing
* Identity Management Testing
* Authentication Testing
* Authorization Testing
* Session Management Testing
* Input Validation Testing
* Testing for Error Handling
* Testing for weak Cryptography
* Business Logic Testing
* Client Side Testing
Tools that use for Automated Web Penetration Testing: Acunetix, Burp-Suite, Netsparker, Nexpose, Nikto, IBM AppScan, HP fortify, W3af etc.
Network penetration testing: Provide both external and internal network Penetration Testing so that your Network Infrastructure is secured from the real world attacks. Do both manual and automated network penetration testing.
Approach for Manual Network Penetration Testing: Manually check for IDS/IPS, Server, Networks switch, Network Router, VPN, Firewalls, Anti-virus, Password etc.
Tools that use for automated network penetration testing: OpenVas, Wireshark, Nessus, Metasploit, Armitage, Scapy etc.
Mobile Application Penetration Testing: Perform mobile applications application penetration testing with the latest OWASP methodology(MSTG). Performed both manual and automated penetration testing for vulnerabilities like Weak Server Side Controls, Insecure Data Storage, Insufficient Transport Layer Protection, Unintended Data Leakage, Poor Authorization and Authentication, Broken Cryptography, Client Side Injection, Security Decisions Via Untrusted Inputs, Improper Session Handling, Lack of Binary Protections.
Tools: Burp-Suite, HP fortify, Dex2Jar, Apktool, framework-res.apk, iNalyzer.
Source Code Reviews: Perform source code reviews for both front and back-end languages. Perform source code reviews standard methodology like OWASP top 10. Do manual and automated source code reviews for various web based security vulnerabilities like SQL injection, Cross site scripting (XSS), CSRF, RFI,LFI, Authentication bypass etc.
Tools: CheckMarx, IBM Appscan source for analysis, Microfocus HP Fortify.
Security Analysis and Server Hardening: Regularly check and maintain your systems, servers to ensure that they comply with the standards. Do hardening application checks the item automatically on a daily basis and monitors all critical networks and server components. We support various frameworks like CIS benchmarking for Desktops & Web Browsers, Mobile Devices, Network Devices, Servers – Operating Systems, Virtualization Platforms & Cloud etc.
Social Engineering: Have experience in social engineering vectors: Vishing, Phishing, Smishing, Impersonation. Used the following social engineering cycle to conduct social engineering:
Gather Information: Here Information gathered from company websites, social media and other publications.
Plan Attack: Next step is outline how intends to execute the attack
Acquire Tools: After planning, next include computer programs that an attacker will use when launching the attack.
Attack: Exploit the weaknesses in the target system.
Use acquired knowledge: Information gathered during the social engineering tactics is used in attacks such as password guessing.
Tools: SET(Kali-Linux); GetGoPhish
Network Security
Vulnerability Assessment
Penetration Testing
Information Security
Internet Security
Security Analysis
Software QA
Network Penetration Testing
Website Security
Web Application Security
Information Security Audit
Web Testing
Jeel V.
Surat, India
$18/hr
5.0
15 jobs
🏆 Top Rated Freelancer | ⭐ 100% Job Success | 💼 12+ Completed Projects | 💰 $4K+ Earned on Upwork
Hello, I'm Jeel Vekariya.
I'm a Cybersecurity Expert with 5+ years of experience helping startups, businesses, and organizations improve their security. I help clients find and fix security issues before they become real problems.
My expertise includes Vulnerability Assessment & Penetration Testing (VAPT), Ethical Hacking, Offensive Security, Web Application Security, API Security, Mobile Application Security, Network Security, Cloud Security, Active Directory Security, Source Code Review, Red Teaming, and AI & LLM Security Testing.
My Goal
✦ Find security vulnerabilities
✦ Reduce security risks
✦ Protect your business
✦ Improve your overall security
━━━━━━━━━━━━━━━━━━━━
Why Choose Me
➤ 5+ Years of Experience
➤ Top Rated Freelancer
➤ 100% Job Success
➤ Professional Security Testing
➤ Manual & Automated Testing
➤ Easy-to-Understand Reports
➤ Practical Security Recommendations
➤ Retesting Support
➤ Fast Communication
➤ On-Time Delivery
➤ Complete Confidentiality
━━━━━━━━━━━━━━━━━━━━
Services I Offer
➤ Web Application Penetration Testing
➤ API & Microservices Security Testing
➤ Mobile Application Security Testing (Android, iOS & Hybrid)
➤ Network Penetration Testing
➤ Active Directory (AD) Penetration Testing
➤ Thick Client Application Testing
➤ SPA & Serverless Application Testing
➤ AI & LLM Security Testing
➤ Red Team Assessments
➤ AWS, Azure & GCP Security Reviews
➤ Static Application Security Testing (SAST)
➤ Dynamic Application Security Testing (DAST)
➤ Source Code Review
➤ Software Composition Analysis (SCA)
➤ Data Breach Investigation
➤ Dark Web Investigation
➤ Corporate OSINT Investigation
━━━━━━━━━━━━━━━━━━━━
Security Expertise
✔ OWASP Top 10 Testing
✔ SQL Injection (SQLi)
✔ Cross-Site Scripting (XSS)
✔ Cross-Site Request Forgery (CSRF)
✔ Authentication & Session Testing
✔ Business Logic Testing
✔ File Upload Security Testing
✔ Remote Code Execution (RCE)
✔ REST & GraphQL API Security
✔ JWT & OAuth Security
✔ BOLA Testing
✔ Privilege Escalation
✔ Cloud Security Review
✔ Docker & Kubernetes Security
✔ Linux & Windows Server Security
✔ WordPress, Shopify & Magento Security
━━━━━━━━━━━━━━━━━━━━
Tools & Technologies
Web & API Security
Burp Suite Pro • OWASP ZAP • Postman
Network Security
Nmap • Nessus • Metasploit • Wireshark
Mobile Security
MobSF • Frida • JADX • Objection
Cloud Security
AWS • Microsoft Azure • Google Cloud Platform (GCP)
Container Security
Docker • Kubernetes
Operating Systems
Kali Linux • Linux • Windows Server
━━━━━━━━━━━━━━━━━━━━
My Work Process
➤ Step 1: Understand your project and security requirements.
➤ Step 2: Perform manual and automated security testing.
➤ Step 3: Validate vulnerabilities through penetration testing.
➤ Step 4: Review the risks and their impact.
➤ Step 5: Deliver a detailed report with findings, screenshots, CVSS scores, and clear recommendations.
➤ Step 6: Retest after fixes and confirm everything is secure.
━━━━━━━━━━━━━━━━━━━━
What You Will Receive
✔ Detailed VAPT Report
✔ Executive Summary
✔ Technical Findings
✔ CVSS Risk Scores
✔ Proof of Concept (PoC)
✔ Clear Remediation Recommendations
✔ Retesting Support
✔ Professional Communication
✔ Complete Confidentiality
━━━━━━━━━━━━━━━━━━━━
Client Feedback
⭐ "Professional, knowledgeable, and delivered a thorough security audit on time."
⭐ "Detailed security report with clear and helpful recommendations."
⭐ "Excellent communication and high-quality penetration testing work."
⭐ "We look forward to working with Jeel again."
━━━━━━━━━━━━━━━━━━━━
I believe cybersecurity is not just about finding vulnerabilities. It is about helping businesses build secure and reliable applications, systems, and cloud environments.
Whether you need Web Application Penetration Testing, API Security Testing, Mobile Application Testing, Network Security Assessment, Cloud Security Review, Active Directory Testing, Source Code Review, Red Teaming, or OSINT Investigation, I'm here to help.
Let's work together to make your business more secure.
Penetration Testing
Vulnerability Assessment
Ethical Hacking
Web Application Security
Mobile App Testing
API Testing
Network Penetration Testing
Cloud Security
Application Security
Cyber Threat Intelligence
Red Team Assessment
WordPress Security
Information Security
Web App Penetration Testing
Cybersecurity Management
Sairaj J.
Pune, India
$25/hr
4.9
31 jobs
I am a dedicated Security Researcher and DevSecOps Engineer with a profound passion for cybersecurity and system integrity. My career revolves around ensuring the safety, resilience, and efficiency of digital systems by combining advanced technical expertise with a proactive approach to identifying and mitigating risks. As a Cybersecurity Engineer and Analyst, I specialize in securing infrastructure, analyzing vulnerabilities, and implementing robust security measures across diverse environments.
With a strong background in Linux system administration, CI/CD pipelines, and containerization, I bring a holistic approach to integrating security into every stage of the software development lifecycle. My expertise extends to penetration testing, OSINT, automation, and creating tailored CLI utilities for enhanced productivity and security. I am adept at identifying and resolving system vulnerabilities, ensuring compliance with industry standards, and optimizing operational workflows.
Whether it’s safeguarding digital assets, implementing DevSecOps practices, or performing in-depth security analyses, I am committed to delivering solutions that protect and enhance your organization's technological infrastructure. Let's collaborate to build secure, efficient, and future-ready systems.
Kali Linux
Linux
System Administration
Bash
DevOps
GitHub
Automated Workflow
API Testing
Scripting
System Programming
Programming Bug Fix
AI Security
Cyber Threat Intelligence
Penetration Testing
Python
AI Development
Vulnerability Assessment
Mahesh T.
Bengaluru, India
$40/hr
5.0
128 jobs
🔐 Certified Penetration Tester | AWS & Azure Cloud Security | Incident Response Expert 🔐
I’m a results-driven cybersecurity specialist with 13+ years of experience securing cloud infrastructure, web applications, and enterprise environments. I help companies prevent breaches, mitigate risks, and ensure compliance through advanced security architecture and real-world offensive security skills.
🎯 What I Do:
✔️ Cloud Security Hardening – AWS (IAM, EC2, S3, VPC, RDS, Route 53) & Azure (VNET, NSGs, Azure Security Center, Defender)
✔️ Penetration Testing – Full-scope internal/external pentests, web/app/API testing, business logic abuse, OWASP Top 10
✔️ Vulnerability Assessments – Nessus, OpenVAS, Nmap, custom exploit validation, CVSS scoring & prioritization
✔️ Threat Detection & Response – Wazuh setup, real-time event correlation, SIEM deployment, log analysis
✔️ Security Architecture – Designing scalable, secure cloud solutions with strong IAM, encryption, and DR practices
✔️ Cloudflare Optimization – Harden DNS, implement WAF rulesets, rate-limiting, Zero Trust setup
✔️ Incident Response – Triage, forensics, log collection, remediation and recovery plans (NIST, MITRE ATT&CK aligned)
📌 Security Tools I Work With:
- **Offensive Security**: Burp Suite, Metasploit, Nmap, Hydra, SQLmap
- **Defensive Tools**: Wazuh, AWS GuardDuty, Azure Sentinel, Nessus, Suricata
- **Languages/Scripting**: Bash, PowerShell, HTML/JavaScript (for attack emulation & automation)
- **Frameworks/Standards**: OWASP, MITRE ATT&CK, NIST CSF, CIS Benchmarks
🛡️ Certifications:
- AWS Certified Security – Specialty
- Microsoft Certified: Azure Security Engineer Associate
- Licensed Penetration Tester (LPT) | Certified Penetration Testing Professional (CPENT)
- CEH, CCSK
📈 Highlights:
- $200K+ earned, 97% Job Success on Upwork
- 9,300+ hours across 90+ successful projects
- Trusted by startups, fintechs, and regulated industries (HIPAA, GDPR, SOC2)
I’m known for delivering real-world, **actionable security results** — not just checkbox audits. If you’re looking to **secure your infrastructure, detect threats faster, or simulate real-world attacks**, let’s connect!
Kali Linux
Cloudflare
Microsoft Azure
Security Testing
Vulnerability Assessment
Application Security
Security Analysis
Penetration Testing
Amazon Web Services
Information Security
Web App Penetration Testing
Security Assessment & Testing
Security Infrastructure
Information Security Consultation
Subin S.
Coimbatore, India
$20/hr
5.0
26 jobs
I secure, harden, and monitor Linux servers for businesses that cannot afford downtime, breaches, or blind spots in their infrastructure. 100% Job Success | Top Rated | 1,600+ hours on Upwork.
If your servers lack proper monitoring, your SIEM is not deployed, your firewall rules are a mess, or your DNS keeps breaking, I fix it properly, not temporarily.
What I deliver:
- Wazuh SIEM/XDR deployment: full setup, agent enrollment, custom rules, dashboards, and alerting across Linux and Windows endpoints
- Server monitoring stacks: Wazuh, Zabbix, Nagios, Grafana - deployed, configured, and tuned to reduce alert noise
- Linux server hardening to production-grade standards (Ubuntu, Debian, CentOS)
- Firewall policy design and enforcement (UFW, iptables, pfSense)
- DNS architecture with failover, DNSSEC, and SPF/DKIM/DMARC for email security
- Cloud infrastructure security across AWS, Azure, GCP, and DigitalOcean
- NGINX and Apache optimization for high-traffic environments
- CI/CD pipeline security and infrastructure automation with Docker and Bash
- Log analysis, threat detection, and incident response
Recent work:
- Deployed and managed Wazuh SIEM across multi-server environments with real-time alerting and compliance monitoring
- Built hardened Linux environments for production workloads and educational content delivery
- Architected DNS with failover for multi-region deployments
Experience includes serving as Cybersecurity & Infrastructure Manager for a venture firm, Senior DNS & Network Security Engineer at a security company, and Infrastructure & Security Consultant for a US-based consulting firm.
I respond within 5 hours. Message me with details about your server, monitoring, or security challenge and I will tell you exactly how I can help.
Linux System Administration
Network Engineering
Cybersecurity Management
Network Security
Server Administration
Network Monitoring
Firewall
Cloud Security
System Security
Docker
NGINX
Bash
VPN
Infrastructure as Code
How it works
Post a job for freePost a job
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a Kali Linux Freelancer in India on Upwork?
You can hire a Kali Linux Freelancer in India on Upwork in four simple steps:
Create a job post tailored to your Kali Linux Freelancer project scope. We'll walk you through the process step by step.
Browse top Kali Linux Freelancer talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top Kali Linux Freelancer profiles and interview.
Hire the right Kali Linux Freelancer for your project from Upwork, the world's largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a Kali Linux Freelancer?
Rates charged by Kali Linux Freelancers on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a Kali Linux Freelancer in India on Upwork?
As the world's work marketplace, we connect highly-skilled freelance Kali Linux Freelancers and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Kali Linux Freelancer team you need to succeed.
Can I hire a Kali Linux Freelancer in India within 24 hours on Upwork?
Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Kali Linux Freelancer proposals within 24 hours of posting a job description.