Penetration Tester | Web, Mobile & API Security Specialist | Ethical Hacker
Automated vulnerability scanners produce noise; real attackers look for logical flaws.
I help businesses, SaaS founders, and development teams identify and patch critical vulnerabilities before malicious actors find them.
As an active cybersecurity researcher and penetration tester, I specialize in deep manual assessment across Web Applications, Mobile Apps (Android & iOS), and APIs (REST & GraphQL). Whether you are prepping for a production release, fulfilling third-party security requirements, or securing sensitive user data, I deliver actionable findings that developers can fix immediately.
Core Services
Web Application Penetration Testing:
Thorough testing for OWASP Top 10 vulnerabilities, business logic flaws, race conditions, authentication/authorization bypasses, and account takeovers.
API Security Audits:
Deep manual testing of REST, SOAP, and GraphQL endpoints focusing on BOLA/IDOR, broken object-level authorization, mass assignment, and improper rate limiting.
Mobile App Security (iOS & Android):
Static (SAST) and dynamic (DAST) analysis, reverse engineering, insecure local storage, bypasses for root/jailbreak and SSL pinning, and sensitive data leakage.
Vulnerability Assessment & Risk Analysis:
Surface mapping, configuration reviews, and risk scoring using the industry-standard CVSS framework.
What You Receive in the Deliverables
You won’t receive an unedited raw scanner output. You get an enterprise-grade, developer-friendly audit report containing:
Executive Summary:
Plain-English risk overview and business impact analysis for non-technical stakeholders and management.
CVSS-Rated Vulnerability Breakdown:
Clear severity classifications (Critical, High, Medium, Low, Informational).
Step-by-Step Proof of Concept (PoC):
Fully reproducible steps, screenshots, request/response dumps, or exploit scripts so your team can confirm the issue instantly.
Actionable Remediation Guidance:
Concrete code-level or configuration recommendations to resolve the flaw.
Free Re-Testing:
Verification testing on patched vulnerabilities to ensure they are completely closed before closing the project.
How We Work Together
Scope Definition:
We clarify target domains, test environments, API documentation, and staging credentials.
Execution:
In-depth black-box, grey-box, or white-box security testing within agreed rules of engagement.
Delivery & Support:
I provide the initial report and walk your developers through any complex findings.
Need your application audited?
Hit the "Invite" or "Contact" button with your target scope or project requirements, and let’s discuss an assessment plan.
Penetration Testing
Network Penetration Testing
Network Engineering
Computer Network
Computing & Networking
Information Security
Security Testing
Web App Penetration Testing
Bug Bounty
Bug Investigation
WordPress Malware Removal
Vulnerability Assessment
Indrojit D.
Dhaka, Bangladesh
$10/hr
5.0
2 jobs
I'm Indrojit Das, a dedicated Cyber Investigator, Penetration Tester, and Data Detective. With extensive experience in cybersecurity, my mission is to secure your digital landscapes against potential threats, uncover vulnerabilities, and solve digital mysteries.
My Expertise:
🌐 Vulnerability Assessment
🔒 Penetration Testing
🛡 Network Security
🌐 Website & Server Security
🔍 Digital Forensics
🌐 Dark Web Threat Intelligence
🕵️ Digital Investigations
🔐 Incident Response
🦠 Malware Analysis
💾 Data Recovery and Preservation
Why Choose Me?
🔐 Proficiency
🔍 Swift Turnaround
📈 Actionable Insights
💡 Clear Communication
🕑 24/7/365 Availability
Your digital safety is my top priority. Let's work together to secure your online world. Just click "Contact" to begin your journey towards a safer digital future.
Regards,
Indrojit Das
Penetration Testing
Network Penetration Testing
System Security
Cybersecurity Management
Expert
Cyber Threat Intelligence
Web App Penetration Testing
Digital Forensics
Cryptocurrency
OWASP
Internet Security
Security Analysis
Cloud Security
Black Box Testing
Security Assessment & Testing
GM Salman A M.
Satkhira, Bangladesh
$30/hr
5.0
57 jobs
🚨 If your application, SaaS platform, or cloud environment has never undergone a professional security assessment, you may have unknown vulnerabilities that attackers can exploit.
I’m a Certified Penetration Tester and Ethical Hacker providing Vulnerability Assessment and Penetration testing (VAPT) services for web applications, APIs, cloud infrastructure, mobile apps, SaaS platforms, and network environments. My goal is not just to find vulnerabilities — but to help you understand real security risks and fix them effectively.
I perform manual penetration testing supported by professional security tools to identify exploitable weaknesses such as authentication flaws, privilege escalation paths, injection vulnerabilities, and business logic issues.
You will receive a clear and actionable security report that helps developers resolve issues and allows management to understand the real business impact.
🎯 My Services
- Vulnerability Assessment & Penetration Testing (VAPT)
- Web Application Penetration Testing (OWASP Top 10)
- API Penetration Testing (REST, GraphQL, authentication flaws, IDOR, injection)
- Cloud Infrastructure Security (AWS, Azure — misconfigurations, IAM, exposed services)
- Network Penetration Testing (internal & external)
- Mobile Application Security (Android & iOS)
- SaaS Platform Security & Penetration Testing (multi-tenant logic, RBAC, privilege escalation)
- CMS Security (WordPress, Laravel, custom apps)
- Retesting after remediation
📋 What You Will Receive
A clear, structured security report designed for both technical teams and business stakeholders, including:
• Executive summary for management and decision-makers
• Detailed vulnerability findings with severity ratings
• CVSS scoring and risk prioritization
• Proof-of-concept evidence (screenshots, request/response captures)
• Business impact explanation for each issue
• Step-by-step remediation guidance for developers
• Retesting validation after fixes are applied
• Reporting that can support ISO 27001 and SOC 2 compliance preparation
🏆 Certifications
- Certified Ethical Hacker Practical — EC-Council
- eLearnSecurity Junior Penetration Tester (eJPT) — INE
- Certified API Penetration Tester — APISec University
- IBM Cybersecurity Analyst
- Cisco Verified Ethical Hacker
- ISO 27001:2022 Lead Auditor
🛠️ Tools I work with
Burp Suite Pro, OWASP ZAP, Nmap, Nessus, Metasploit, MobSF, Wireshark, Postman, and custom Python/Bash scripts and so on.
Whether you're preparing for a security review, compliance audit, or investor due diligence, I can help you understand your attack surface and security risks.
📩 Send me your scope or asset list and I’ll help you determine the best testing approach.
Penetration Testing
Network Penetration Testing
Vulnerability Assessment
Malware Removal
Information Security
Application Security
Security Assessment & Testing
Cybersecurity Management
Web App Penetration Testing
WordPress Malware Removal
Website Security
Ethical Hacking
Web Application Security
System Administration
OWASP
MD HASANUR R.
Pabna Sadar, Bangladesh
$15/hr
4.9
27 jobs
CEH ( Certified Ethical Hacker).
I am a Professional Ethical Hacker and Expert in Penetration testing and Website Security and Network Scanning
I have 5+ experience in projects ranging from, Bug hunting, penetration testing, network Testing, Website Security, analysis, vulnerability assessment, and testing to investigative and forensic work. I bring high standards and tried and tested methodology with manual bug Hunting and techniques to deliver you professional results.
✅Professional at Bug Bounty Hunting
✅Professional at Penetration Testing
✅System Hacking
✅Network Scanning
✅Professional at API Testing
✅Professional at Android and IOS Penetration Testing
✅Professional in Security Testing
✅Professional at Web Application Security
✅Professional at Vulnerability Assessment
✅Professional at Network Penetration Testing
✅Professional at Hacked site Recover
✅ Professional at Malware Removal/Virus Removal
✅ Website Testing part manually
= Brute Force Attack
= Unauthorized access to card
= Business logic flaws allow the unauthorized transfer of funds
= Unauthorized access to customer data
= Unauthorized access to the example.com website
= Authentication related issues
= Authorization related issues
= Data Exposure
= Smuggling Testing
= Bypass Rate Limit Protection
= Bypass Authentication
= Broken Access Control
= Information Disclosure
= Remote Code Execution (RCE)
= Server-Side Request Forgery (SSRF)
= Subdomain Takeover
= Account Takeover
= Code Execution
= Content Discovery
= Cross-Site Request Forgery (CSRF)
= SQL Injection (SQLI)
= HTML Injection / Content Injection
= Cross-Site Scripting (XSS)
= Command Injection
= Local File Inclusion (LFI)
= Insecure Direct Object Reference (IDOR)
= XML External Entity (XXE)
= Remote File Inclusion (RFI)
= URL Redirection
✅System Testing
1. Password Cracking
2. Privilege Escalation
3. Malware Analysis
4. System Exploitation
5. Post Exploitation
6. Social Engineering
7. Network Sniffing
8. Denial of Service (DoS) Attacks
9. Security Misconfigurations
10. Vulnerability Scanning and Exploitation
12. Exploit Development
✅ Network Scanning
Network Scanning List
1. Network Discovery
2. Port Scanning
3. Vulnerability Scanning
4. Service Version Detection
5. Network Mapping
6. Network Protocol Analysis
7. Wireless Network Scanning
8. SNMP Scanning
9. DNS Enumeration:
10. Network Performance Testing
11. Firewall and IDS/IPS Evasion
12. IoT and SCADA Network Scanning:
13. Cloud Network Scanning
✅ Penetration Testing Tools:
= Metasploit
= BurpSuite Professional
= Nessus Professional
= Acunetix Proffessional
= Nuclei
= Nmap
= FFUF
= Gau
= Waybackurls
= SQLMAP
= wpscan
= OWASP ZAP, etc.
Terms of Services:
• 100% Customer Satisfaction
• Guaranteed Refund if not satisfied
Penetration Testing
Network Penetration Testing
Security Assessment & Testing
Security Testing
Information Security
Bug Bounty
Web Testing
Web Application Security
Vulnerability Assessment
Bug Investigation
Website Security
Ethical Hacking
API Testing
Cloud Security
AI Security
Web Application Audit
Foysal H.
Dhaka, Bangladesh
$29/hr
5.0
53 jobs
I help startups, SaaS companies, fintech organizations, healthcare providers, and enterprises identify and eliminate security vulnerabilities before they become data breaches.
With 10+ years of offensive security experience and more than 200 successful penetration testing engagements, I provide manual, risk-focused security assessments that uncover vulnerabilities automated scanners often miss.
My assessments follow industry-recognized methodologies, including OWASP Testing Guide, OWASP ASVS, OWASP MASVS, PTES, NIST SP 800-115, and MITRE ATT&CK, delivering actionable findings that improve your security posture and support compliance initiatives.
Core Expertise
• Web Application Penetration Testing (OWASP Top 10)
• API Security Testing (REST, GraphQL, SOAP)
• Mobile Application Security (Android & iOS)
• Network Penetration Testing (Internal & External)
• Active Directory Security Assessments
• Cloud Security Reviews (AWS, Azure & Google Cloud)
• Authentication & Authorization Testing
• Business Logic Vulnerability Assessment
• LLM/AI Application Security Assessment
• Red Team & Adversary Simulation
• Secure Configuration Reviews
Industries Served
• Financial Services & FinTech
• Healthcare
• SaaS Platforms
• E-commerce
• Government
• Telecommunications
Deliverables
Every engagement includes:
✔ Executive Summary for management
✔ Detailed technical report
✔ CVSS-based risk ratings
✔ Step-by-step Proof of Concept
✔ Remediation guidance
✔ Security consultation
✔ Complimentary revalidation after remediation
Compliance Support
My assessments help organizations prepare for or strengthen compliance with:
• ISO 27001
• SOC 2
• PCI DSS
• HIPAA
• OWASP
Certifications
OSCP+ •OSCP• CREST • LPT Master • CRTP • C|PENT • CEH • ISO 27001 Lead Auditor and Lead Implementor
I believe penetration testing should provide clear business value—not just vulnerability lists. Every assessment is tailored to your environment, your threat model, and your compliance requirements, with practical recommendations your team can act on immediately.
If you're planning a new product launch, preparing for an audit, or simply want confidence in your security posture, let's discuss your scope. I'll provide a clear testing plan, timeline, and deliverables before the engagement begins.
Penetration Testing
Network Penetration Testing
Ethical Hacking
Cryptography
Web App Penetration Testing
Cybersecurity Tool
Kali Linux
Vulnerability Assessment
Information Security
Governance, Risk Management & Compliance
AI Governance
OWASP
Security Testing
ISO 27001
Red Team Assessment
AI Security
Application Security
Security Operation Center
Digital Forensics
Nazmul S.
Dhaka, Bangladesh
$20/hr
4.5
22 jobs
I am an Ethical Hacker and Penetration tester who has been providing security and test results as a report for corporations and individuals.
"Ethical Hacking - Securing PC & mobile, running tests for vulnerabilities & server-side security (7+ experience)"
Server Security Misconfiguration
-Hardening
-Broken Authentication and Session Management
-Insecure OS/Firmware
-Broken Cryptography
-Automotive Security Misconfiguration
-Sensitive Data Exposure
-Cross-Site Scripting (XSS)
-Cross-Site Request Forgery (CSRF)
-Application-Level Denial-of-Service (DoS)
-Insecure OS/Firmware
-Server-Side Injection
-Client-Side Injection
-Sensitive Data Exposure
-Malware Detected
-Location Tracking
Expert in
1. Hardening operating system ( Windows and Linux)
2. Penetration Testing of web applications with the report and mitigation suggestion.
3. Total security assessment of the Application.
4. Code analysis Static and Dynamic with the recommendation for mitigation.
5. Backdoor script identification and remove
6.Hidden link removal
7. WordPrass best security enhancement, firewall integration
8. Linux server administration, security, firewall
9. DDoS mitigation, firewall (Cloudflare, CSF)
10. Domain/email blacklist removal
Security Incident Response:
✔️ Get access information, and begin the investigation immediately.
✔️ Identify the source of an intrusion, and fix the vulnerability.
✔️ Clean up malware, and recover the website.
✔️ Implement advanced security measures.
✔️ Frequently update the client with the current status.
✔️ Keep track of all actions performed, and provide a full audit report.
You can contact me for a free consultation, or website health checkup, and explore if we’d be a good fit to work together.
Let me help you fix your website and make sure it’s 100% clean and protected from security threats
Penetration Testing
Vulnerability Assessment
WordPress Malware Removal
SSL
Web Application Security
DevOps
AWS OpsWorks
Linux System Administration
Web App Penetration Testing
ISO 27001
Web Development
NIST Cybersecurity Framework
AI Code Generator
AI Security
Claude
AI App Development
SOC 1
How it works
Post a job for freePost a job
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a Network Pentester in Bangladesh on Upwork?
You can hire a Network Pentester in Bangladesh on Upwork in four simple steps:
Create a job post tailored to your Network Pentester project scope. We'll walk you through the process step by step.
Browse top Network Pentester talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top Network Pentester profiles and interview.
Hire the right Network Pentester for your project from Upwork, the world's largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a Network Pentester?
Rates charged by Network Pentesters on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a Network Pentester in Bangladesh on Upwork?
As the world's work marketplace, we connect highly-skilled freelance Network Pentesters and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Network Pentester team you need to succeed.
Can I hire a Network Pentester in Bangladesh within 24 hours on Upwork?
Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Network Pentester proposals within 24 hours of posting a job description.