Most of your codebase is code you didn't write. I secure it.
I'm a principal-level security engineer who hardens software supply chains end to end — from the dependency entering your build to the provenance that ships to production. I work in regulated environments where getting it wrong isn't an option.
What I deliver:
SBOM pipelines with Syft, Trivy, and GUAC — generation and continuous analysis wired into your build
Dependency risk triage with OpenSSF Scorecard, so your team fixes what matters instead of drowning in alerts
Build provenance aligned to SLSA — prove how your artifacts were built, don't just hope they're clean
Policy-as-Code with Kyverno and OSCAL — guardrails that block bad builds and produce audit-ready evidence
Frameworks: NIST SSDF, ISO 27001, SLSA, OpenSSF, EU CRA, PCI-DSS
You get working tooling and clear remediation — not just a report. Message me and let's scope it.
Project Management Office
Open Source
AI Governance
Cybersecurity Management
GitHub
Atlassian Confluence
Jira
GDPR
C
Embedded Linux
GitLab
JFrog Artifactory
Cyber Threat Intelligence
DevOps
Vulnerability Assessment
Threat Detection
Magesh M.
Chennai, India
$12/hr
5.0
3 jobs
L2/L3 technical support is the strongest part of my background. Most of my work has been in escalations, troubleshooting, and issue ownership — cases that were no longer straightforward and needed proper investigation.
My approach is to check logs, understand system behavior, reproduce the issue where possible, document findings clearly, and coordinate with engineering when deeper analysis or a code-level fix is needed. I stay with cases through to resolution.
I have worked across cloud and on-prem environments on issues involving APIs, authentication, SSO/LDAP/MFA, ETL and data workflows, storage integrations, and recurring production problems. I have also worked in Zendesk-driven environments where response quality, follow-up, and clear communication mattered alongside the technical fix.
My customer-facing experience includes large enterprise organizations across the US and Europe — banking, telecom, insurance, and other high-scale sectors — where the technical issue mattered, but so did clarity, pace, and ownership.
My approach on every case: understand the issue properly, gather the right evidence, keep communication clear, document what matters, and move it forward.
---
TOOLING AND PLATFORMS
- Support platforms: Zendesk · Jira · Salesforce · ServiceNow · Intercom
- Log and diagnostic tools: Kibana · Splunk · Elasticsearch · New Relic
- Identity and access: Azure AD / Entra ID · ADFS · Okta · LDAP · SAML · MFA
- Cloud platforms: AWS · Azure · GCP (across supported environments)
- Infrastructure exposure: Docker · Kubernetes · TCP/IP · VPN · Load Balancers
- Content and storage integration: SharePoint · Box · S3
SCRIPTING, AUTOMATION, AND DATA
- REST API — integration troubleshooting, structured request/response analysis, consumption scripting
- SQL, PostgreSQL and MS SQL Server; database-level investigation, query-driven root cause analysis
- PowerShell - file system automation, metadata extraction, CSV/JSON export pipelines, operational scripting
- Power Query (M) - multi-source ETL, schema normalization, incremental refresh, reconciliation workflows
- Excel VBA — orchestration, validation, reporting automation, self-service operational tooling
- Power BI — dashboard-ready data preparation, operational reporting, visualization
- Automation — Zendesk and Jira triggers, webhooks, workflow automation, AI-assisted routing
Python
SQL
Technical Support
Customer Support
Zendesk API
IT Support
Binesh S.
Chennai, India
$50/hr
4.8
143 jobs
Profile Summary
Seasoned Information Security Professional with 22+ years of experience across, Application Security, VAPT, Cloud Security, Email Security and Risk Governance. I specialize in designing secure, compliant and automated environments that protect enterprise assets from the code level to the cloud. From hardening AI infrastructure to mastering email deliverability, I ensure every layer of the digital stack is resilient.
Offensive Security: VAPT, Red Teaming, and OWASP Top 10 mitigation.
Infrastructure: Expert-level Linux/Windows migration and AI model pipeline security.
Governance: Certified (CISSP, CISA, CISM, CRISC, CGEIT) leader in ISO 27001, PCI DSS, and NIST frameworks.
Network Security Architecture:
Design and implementation of firewalls (NGFW), IPS/IDS, VPNs, VLAN segmentation, and zero-trust models for enterprise and data center environments.
Expertise in deep-packet inspection, application-layer filtering, and threat intelligence integration to detect, prevent, and respond to advanced threats.
MFA, SSO, JML workflows, passwordless authentication, IDOR, privilege escalation and governance-driven IAM programmes
Code security, data protection, and vulnerability management standards
Threat modeling and risk rating using STRIDE/DREAD or CVSS
SonicWall TZ 500, 600, SOHOW
Plesk & WHM Panel expert, Tomcat, Apache, Ngnix & IIS
Database Security hardening MySQL, Mariadb, MSSQL & Oracle
HTTP Security Header, Server Side include, XXE, XSLT, CSRF. PKI, SSL TLS 1.2 &1.3 http 1.1, http2, http3
Network Security IPv6/IPv4, ZTNA
CrowdStrike/ Sentinel/ Trend Micro Endpoint Security,
Microsoft Purview & Symantec DLP Solution
SIEM - QRadar, DNIF Google Chronicle & Mandiant SOAR
Regular risk assessments and control validation
AppSec risk register maintenance
Shift Everywhere Security
SAST, DAST, IAST, RAP, and SCA tools (Nessus, Qualys Guard, SonarQube, Fortify, Checkmarx, Veracode, Burp Suite, OWASP ZAP, MobSF, Postman)
Image vulnerability scanning (Trivy, Clair)
DNS Security
Kubernetes/Docker configuration hardening
Runtime protection for containers
Mode Security , Cloudflare WAF
Threat Modeling & Attack Surface Reduction
MFA, SSO, JML workflows, password less authentication, and governance-driven IAM programmes
Security Automation & Infrastructure as Code (IaC)
Compliance & Risk Governance (ISO 27002, SOC 2, HIPAA, PCI DSS)
Security Operations ( IAM, EDR/MDR SIEM/SOAR, Incident Response)
Application, Database & Systems Security
Wordpress/Magento/Drupal Security Hardening
Cloud-Native & Container Security
Cloud Security & AI Platform Expertise
Implemented CASB, CSPM, CWPP & CNAPP
Amazon Web Services (AWS):
Secured workloads leveraging EC2, S3, IAM, VPC, CloudFront, RDS, and Route 53 with enterprise controls.
Deployed AWS WAF & Shield, GuardDuty, Inspector, Security Hub, and Audit Manager for compliance automation.
Container Security - AWS ECS, EKS, ECR, Fargate
Integrated Amazon Bedrock
Microsoft Azure:
Extensive experience with Azure OpenAI, AI Studio, Azure ML, Sentinel, RDP, VPN, Intune Defender for Cloud, and Purview.
Deployed Confidential Computing, Data Lake, Cosmos DB, and AKS using secure-by-design principles, encryption-at-rest, and real-time compliance monitoring.
Google Cloud Platform (GCP):
Implemented Sensitive Data Protection, IAM, VPC, SCC, Confidential Computing, Cloud Armor, and KMS for resilient data governance.
Applied AI/ML security frameworks (SAIF, Model Armor, Guardrails) to safeguard sensitive workloads and mitigate model-level risks.
Email Security SPF, DKIM, DMARC, BIMI, RBL, Blocklist check , Microsoft Exchange/ O365/Google Workspace/Power MTA, Qmail, Postfix, Smartermail etc, Email phishing Simulation & campaign
AI Infrastructure Security
N8N and OpenClaw AI workflow configuration.
My work includes protecting data pipelines, securing model training and deployment environments, enforcing IAM controls, and hardening GPU/compute clusters. I assess risks in model storage, APIs, and inference endpoints, implement monitoring for data integrity and model misuse, and ensure compliance with security and governance frameworks. I provide actionable recommendations to strengthen resilience, privacy, and the overall security posture of AI systems.
Security Audit,
Risk Assessment and Audit Compliance, with a strong track record in securing enterprise systems, networks, applications and multi-cloud environments. My professional journey includes leading ISO 27002, ISO42001, HIPAA, PCI DSS, SOX, ITGC, CIS, NIST, NIS2, GDPR, CCPA, HIPPA and SOC 2 audits, implementing GRC frameworks, and ensuring regulatory alignment and risk mitigation across complex organizations.
BCP/DR, RPO, RTO, MTTD, MTTR Business Impact Assessment and Privacy Impact assessment
GRC Tools - Security Score Card, BitSite, Auditboard, OneTrust, RSA Archer, ServiceNow GRC, Drata & Vanta
IT Compliance Audit
Risk Assessment
Penetration Testing
Web Application Security
OWASP
AI Security
Cloud Security
Information Security
Application Security
Vulnerability Assessment
Web Application Audit
Email Security
Plesk
Governance, Risk Management & Compliance
DevOps
Jana J.
Chennai, India
$100/hr
5.0
12 jobs
Is your API built to survive the machine-driven economy?
Traditional API gateways fail under traffic from autonomous AI agents and enterprise B2B clients. If your architecture cannot support secure, friction-free consumption, locked out of high-margin markets.
I am an independent systems researcher and consultant. I specialize in eliminating bottlenecks in the API supply chain and securing it from end to end. I treat Identity and Access Management (IAM) as the primary commercial enabler for your platform. My designs follow a single rule:
Revenue = Consumption × Trust.
I provide the language-independent protocol blueprints and Resource Server (RS) strategies your team needs to transform passive endpoints into highly monetizable corporate storefronts.
🛠 The Adaptive Protocol Framework
I design adaptive blueprints to enforce strict security boundaries at your Resource Server layer, maximizing market readiness without engineering overkill:
Enterprise B2B & AI Agents: High-value integration combining SCIM 2.0 (instant directory sync to drop onboarding from months to minutes), Model Context Protocol (MCP) (autonomous agent tool discovery), and FAPI 2.0 + DPoP context bridging at the RS perimeter.
The Non-Negotiable AI Baseline: If automated agents consume your API, I architect the RS to validate sender-constrained requests bound cryptographically to the client's private key, neutralizing token leakage and proxy-interception liabilities.
High-Scale B2C: Lightweight identity pipelines utilizing OIDC or SAML to maintain high-scale federation while preserving consumer privacy.
📦 Consultation Deliverables
I equip your internal development team with the precise specifications to build out the API in their preferred stack:
Ecosystem Contract Modeling: Complete mapping of trust boundaries, identity assertions, and cryptographic scopes across all entities (AS-RS-Client/Agent topology) via the OpenAPI Specification (OAS).
Resource Server Scaffolding: A language-agnostic reference template codebase mapping core entity relationships and protocol verification semantics out of the box.
Ongoing Engineering Advisory: High-level protocol validation, design reviews, and contract milestone oversight throughout your implementation journey to ensure absolute security compliance.
💼 Engagement Terms
Rate: $100 / Hour
Scope: Architectural direction, protocol oversight, and contract validation. Your internal engineering team retains full ownership over final technology stack choices, implementation, and deployment.
Click "Message" to future-proof your developer infrastructure and stabilize your platform's transition to the machine economy.
MongoDB
Node.js
JavaScript
Python
Perl
HTML5
Java
OAuth
User Authentication
Auth0
OKTA
HubSpot
Google Cloud Platform
OWASP
MERN Stack
Docker Compose
Git
Angu H.
Chennai, India
$35/hr
4.8
49 jobs
I am a Registered Penetration Tester & Ethical Hacker holding OSCP, CRTP, CEH, and CISSP certifications. I design custom tools and scripts for penetration testing and work extensively with Kali Linux. I perform comprehensive manual testing using Burp Suite, Metasploit, Nmap, SQLMap, Wireshark, and industry-standard frameworks. I safely develop, test, and modify exploits based on target environments.
I currently work as a full-time security consultant specializing in penetration testing and vulnerability assessment across web applications, APIs, cloud infrastructure, and mobile platforms. I help organizations identify real, exploitable security risks through black-box, grey-box, and white-box testing methodologies. I have proven experience identifying critical and high-risk vulnerabilities across banking, telecom, insurance, government, SaaS, healthcare, and EdTech platforms. My work has led to multiple zero-day discoveries and CVE records in widely used products, including SHAREit, Upwork Time Tracker, and Avast Anti Virus.
I bring 6+ years of hands-on experience as an information security professional. I have led and executed hundreds of penetration tests, VAPT engagements, red team operations, and security audits. My experience spans large enterprises with thousands of assets as well as startups seeking strong security foundations. I have deep expertise in assessing network security, cloud infrastructure (AWS, Azure), API security, web application security, and mobile application penetration testing (iOS and Android) across modern technology stacks.
Core Competencies:
• Web & Application Security: OWASP Top 10, authentication & authorization, access control, session management, business logic flaws, IDOR/BOLA, injection vulnerabilities
• API Security: GraphQL, REST, OWASP API Top 10, OAuth/OIDC, SSO/SAML, token misuse, microservices
• Cloud & Infrastructure: AWS (IAM privilege escalation, EC2/EKS, Lambda, S3, VPC, CloudTrail/GuardDuty), Azure, container/Kubernetes security
• Specialized: AI/LLM security, mobile app security, thick client, admin panel security
• Network: Internal AD testing, external penetration testing, lateral movement
Working with me, you receive:
★ Actionable Deliverables: Detailed penetration test reports with executive summaries, risk severity classification (Critical/High/Medium/Low), CVSS scoring, proof of concept (PoC) with screenshots and logs, clear remediation recommendations, and impact analysis
★ Comprehensive Manual Testing: Complete hands-on security assessment (not automated scans) with immediate notification of high-impact exploitable issues
★ Customized Approach: Tailored testing for compliance needs (HECVAT, HIPAA, FERPA, Amazon SP-API,GDPR ,SOC2 ,ISO27001 ,PCIDSS), third-party security reviews, or proactive security hardening
★ Clear Communication: Developer-friendly reports and direct collaboration with engineering teams and non-security stakeholders
★ Timely Delivery: Comprehensive reports delivered on time without compromising quality
★ Unlimited Retesting: Vulnerability retest and fix validation included
★ Critical Bug Discovery: Proven ability to identify attack chains often missed by automated pentests
My Track Record:
✅ Top-rated in information security and IT compliance
✅ Saved clients tens of thousands by identifying critical vulnerabilities before attackers
✅ Ranked Top 50 at multiple bug bounty programs
✅ Multiple CVE discoveries and responsible disclosures
✅ Professional certifications: OSCP, CISSP, CEH, CRTP
✅ Experience across SaaS, healthcare, EdTech, e-commerce, fintech, and enterprise
✅ Supporting all time zones for immediate-start and ongoing engagements
Report Deliverables Include:
► Executive Summary & Attestation Letter (for compliance documentation)
► Assessment Methodology & Scope
► Risk Severity Classification with CVSS scores
► Detailed Findings: CVSS score, technical description, proof of exploitation (screenshots, request samples, logs), reproduction steps, impact analysis, and fix-ready remediation recommendations
► Retest Report: Multiple validation rounds included
My Expertise:
★ Web Application Penetration Testing (OWASP Top 10)
★ API Security Testing (REST, GraphQL, OWASP API Top 10)
★ Cloud Security Assessment (AWS, Azure - IAM, containers, serverless)
★ Mobile Application Penetration Testing (iOS, Android)
★ AI/LLM Security Testing
★ Internal Active Directory and External Network Penetration Testing
★ Vulnerability Assessment and Penetration Testing (VAPT)
★ Backend API and Microservices Security
★ Thick Client Penetration Testing
★ Security Audits for SaaS, Healthcare, EdTech, E-commerce
★ Third-Party Security Reviews and Compliance Testing
★ Production Environment Security Assessment
★ OSINT Assessment
Sound like a fit? 🟢 Press '...' button and then 'Send Message' button in the top right-hand corner
Penetration Testing
Information Security
Vulnerability Assessment
Security Analysis
Network Security
Application Security
API Testing
Mobile App Testing
Web App Penetration Testing
Red Team Assessment
OWASP
Ethical Hacking
Security Assessment & Testing
Cybersecurity Management
Naveen K.
Chennai, India
$30/hr
5.0
10 jobs
## Cyber Security Expert | Penetration Tester | VAPT | SIEM | SOC | OSCP+
#Protect Your Business from Cyber Threats with CyberSecurity Expert
I help growing businesses and enterprises secure their digital assets and achieve compliance through comprehensive cybersecurity solutions. With 12+ years of hands-on experience and elite certifications (OSCP, CEH), I've protected companies across finance, healthcare, SaaS, and enterprise sectors from costly security breaches.
As the Founder of Codesecure Solutions, I lead a team of skilled professionals delivering enterprise-grade security services that prevent breaches, ensure compliance, and build long-term digital resilience.
##My Core Services:
# VAPT as a Service - Complete vulnerability assessments that identify security gaps in the system
• Web, Mobile, API, Network, and Cloud penetration testing
• OWASP Top 10, API Security Top 10 coverage with business logic testing
• Black-box, gray-box, and white-box methodologies
• Executive and technical reports with prioritized remediation roadmaps
# SOC as a Service - 24/7 security monitoring and incident response to detect threats in real-time
• Wazuh SIEM deployment with custom detection rules
• Real-time threat monitoring and automated alerting
• File integrity monitoring and compliance reporting
• Incident response playbooks and threat hunting
# GRC as a Service - Compliance solutions for SOC 2, HIPAA, ISO 27001.
• Gap analysis and risk assessment
• Policy development and security control implementation
• Audit preparation and ongoing compliance monitoring
• Risk mitigation strategies and governance frameworks
# Additional Security Services:
• Secure Code Review (SAST) - Multi-language code analysis (PHP, Python, JavaScript, Java)
• Cloud Security Audits - AWS & Azure configuration hardening and IAM optimization
• WAF Configuration - Cloudflare custom rules, bot mitigation, and API protection
• Security Automation - SOAR workflows for faster incident response
# Recent Results:
- Secured a fintech platform handling $50M+ transactions (zero breaches in 2+ years)
- Achieved SOC 2 Type II compliance for 15+ SaaS companies on first audit attempt
- Reduced security incident response time by 80% through custom SIEM configurations
- Identified critical vulnerabilities in 200+ applications before production deployment
# Why Choose Us:
• Elite OSCP certification
• 100% client satisfaction rate with transparent communication
• 24/7 availability for urgent security incidents
• Money-back guarantee if you're not fully satisfied
• Strict NDA adherence and zero tolerance for shortcuts
# Perfect For:
• Growing companies preparing for compliance audits
• Businesses that have experienced security incidents
• Organizations in regulated industries requiring ongoing security oversight
• Companies needing enterprise security without enterprise costs
Ready to secure your business? Send me a message with your specific security challenges, and I'll provide a free 30-minute consultation to discuss how we can protect your digital assets and ensure compliance.
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a LDAP Specialist near Chennai, on Upwork?
You can hire a LDAP Specialist near Chennai, on Upwork in four simple steps:
Create a job post tailored to your LDAP Specialist project scope. We’ll walk you through the process step by step.
Browse top LDAP Specialist talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top LDAP Specialist profiles and interview.
Hire the right LDAP Specialist for your project from Upwork, the world’s largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a LDAP Specialist?
Rates charged by LDAP Specialists on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a LDAP Specialist near Chennai, on Upwork?
As the world’s work marketplace, we connect highly-skilled freelance LDAP Specialists and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream LDAP Specialist team you need to succeed.
Can I hire a LDAP Specialist near Chennai, within 24 hours on Upwork?
Depending on availability and the quality of your job post, it’s entirely possible to sign up for Upwork and receive LDAP Specialist proposals within 24 hours of posting a job description.