Need a Web Application or API penetration test that goes beyond automated scanner output?
I’m an OSCP, OSEP, OSWP and CREST CPSA-certified Penetration Tester with 100% Job Success, Top Rated status, 190+ completed Upwork engagements and experience delivering 400+ penetration tests and security assessments.
I help SaaS companies, startups, e-commerce platforms and enterprise teams identify real, exploitable security weaknesses before product launches, major releases and compliance reviews.
My approach is manual-first. I investigate vulnerabilities that automated scanners often miss, including authentication weaknesses, authorization bypasses, IDOR/BOLA, privilege escalation, tenant-isolation failures, business-logic flaws, race condition flaws and chained attack scenarios.
CORE SERVICES
• Web Application Penetration Testing
• API Security Testing
• Mobile Application Penetration Testing
• External and Internal Network Penetration Testing
• Active Directory and Infrastructure Assessments
• Thick Client Application Testing
• Security Retesting and Remediation Verification
WHAT YOU RECEIVE
• A professional executive and technical report
• Reproducible proof-of-concept evidence
• Risk ratings and CVSS scoring where applicable
• Clear business-impact explanations
• Developer-focused remediation guidance
• Retesting after fixes are implemented
Reports can support SOC 2, ISO 27001, PCI DSS, Amazon SP-API, vendor-security reviews and internal audits.
Redacted Web Application and API penetration-testing report samples are available upon request.
Send me your application type, number of user roles, approximate API endpoints or hosts, testing environment and preferred timeline. I will help you define the appropriate scope, methodology and deliverables.
Penetration Testing
Network Penetration Testing
Information Security
Network Security
Security Assessment & Testing
Security Testing
Vulnerability Assessment
System Security
Application Security
Web App Penetration Testing
Website Security
Web Application Security
Black Box Testing
OWASP
Risk Assessment
Jeel V.
Surat, India
$16/hr
5.0
15 jobs
Hi, I’m Jeel Vekariya, a Cybersecurity Expert with 5+ years of hands-on experience helping businesses, startups, SaaS companies, and organizations identify vulnerabilities, reduce security risks, and protect their applications and infrastructure.
I specialize in Vulnerability Assessment & Penetration Testing (VAPT), Ethical Hacking, Offensive Security, Application Security, API Security, Mobile Security, Network Security, Cloud Security, and Security Research.
My approach is simple:
Find the vulnerability → Validate the risk → Explain the impact → Recommend the fix → Retest
━━━━━━━━━━━━━━━━━━━━
WHAT I CAN HELP YOU WITH
✦ Web Application Penetration Testing
➤ OWASP Top 10 Testing
➤ Authentication & Authorization Testing
➤ IDOR / BOLA & Broken Access Control
➤ SQL Injection (SQLi)
➤ Cross-Site Scripting (XSS)
➤ CSRF & SSRF
➤ File Upload & Path Traversal
➤ Remote Code Execution (RCE)
➤ Command Injection
➤ Business Logic Vulnerabilities
➤ Session & JWT Security
➤ Security Misconfiguration
✦ API Security Testing
➤ REST API Penetration Testing
➤ GraphQL Security Testing
➤ OWASP API Security Top 10
➤ API Authentication & Authorization
➤ OAuth & JWT Security Testing
➤ BOLA / IDOR Testing
➤ Rate Limiting & Abuse Testing
➤ API Gateway Security
➤ Business Logic Testing
✦ Mobile Application Security
➤ Android & iOS Penetration Testing
➤ Mobile API Security Testing
➤ Static & Dynamic Analysis
➤ Authentication & Authorization Testing
➤ Secure Data Storage Testing
➤ SSL/TLS Security Testing
➤ MobSF, Frida & JADX Analysis
✦ Network & Infrastructure Security
➤ Internal & External Network Penetration Testing
➤ Vulnerability Assessment
➤ Network Security Assessment
➤ Firewall Security Review
➤ Server Security Testing
➤ Linux & Windows Security Testing
➤ Active Directory Security Assessment
➤ Privilege Escalation Testing
✦ Cloud & Infrastructure Security
➤ AWS Security Assessment
➤ Microsoft Azure Security Assessment
➤ Google Cloud (GCP) Security Review
➤ IAM & Access Control Review
➤ Cloud Configuration Assessment
➤ Docker & Kubernetes Security
➤ Infrastructure Security Testing
➤ Security Hardening
✦ Application & Specialized Security
➤ Source Code Review
➤ Secure Code Review
➤ SAST / DAST
➤ Software Composition Analysis (SCA)
➤ AI & LLM Security Testing
➤ Red Team Security Assessments
➤ Security Configuration Review
➤ OSINT & Cybersecurity Research
━━━━━━━━━━━━━━━━━━━━
HOW I WORK
➤ Understand your application, infrastructure, and scope
➤ Review the attack surface and potential entry points
➤ Perform manual and automated security testing
➤ Validate vulnerabilities and reduce false positives
➤ Assess technical and business impact
➤ Provide reproducible Proof of Concept (PoC)
➤ Explain the vulnerability in clear language
➤ Provide practical remediation recommendations
➤ Retest fixes after remediation
I don't simply provide automated scanner results. I focus on finding meaningful security issues and giving your team information they can actually use to fix them.
━━━━━━━━━━━━━━━━━━━━
SECURITY REPORTS & DELIVERABLES
✔ Executive Summary
✔ Detailed Technical Findings
✔ Vulnerability Description
✔ CVSS-Based Severity Rating
✔ Proof of Concept
✔ Screenshots & Evidence
✔ Steps to Reproduce
✔ Business Impact
✔ Remediation Recommendations
✔ Prioritized Findings
✔ Retesting Support
My reports are designed to be useful for both developers and business stakeholders, making it easier to understand the issue, its impact, and how to resolve it.
━━━━━━━━━━━━━━━━━━━━
TOOLS & TECHNOLOGIES
Web & API: Burp Suite Pro, OWASP ZAP, Postman
Network: Nmap, Nessus, Metasploit, Wireshark
Mobile: MobSF, Frida, JADX, Objection
Cloud: AWS, Microsoft Azure, GCP
Containers: Docker, Kubernetes
Operating Systems: Kali Linux, Linux, Windows Server
━━━━━━━━━━━━━━━━━━━━
CORE SECURITY EXPERTISE
✔ Vulnerability Assessment & Penetration Testing
✔ Web Application Security
✔ API Security
✔ Mobile Application Security
✔ Network & Infrastructure Security
✔ Cloud Security
✔ Active Directory Security
✔ Authentication & Authorization
✔ IDOR / BOLA
✔ SQL Injection & XSS
✔ SSRF & CSRF
✔ Business Logic Testing
✔ Privilege Escalation
✔ Secure Code Review
✔ AI / LLM Security
✔ Red Teaming
✔ OWASP Security Testing
━━━━━━━━━━━━━━━━━━━━
WHY CLIENTS WORK WITH ME
➤ 5+ years of cybersecurity experience
➤ Top Rated Upwork Freelancer
➤ 100% Job Success
➤ Manual + automated security testing
➤ Clear and professional security reports
➤ Practical remediation guidance
➤ Developer-friendly findings
➤ Professional communication
➤ On-time delivery
➤ Confidential and authorized testing
My goal is not only to find vulnerabilities. I want to help you understand the risk, fix the problem, and improve your overall security posture.
➔ Let's discuss your security requirements and find the vulnerabilities before attackers do.
Penetration Testing
Network Penetration Testing
Vulnerability Assessment
Ethical Hacking
Web Application Security
Mobile App Testing
API Testing
Cloud Security
Application Security
Cyber Threat Intelligence
Red Team Assessment
WordPress Security
Information Security
Web App Penetration Testing
Cybersecurity Management
Nimit J.
New Delhi, India
$30/hr
4.9
32 jobs
🌟 Top Rated🌟
🛡️ Penetration Testing Expert | Certified Cybersecurity Professional
🧠 OSCP & 🏅 CREST Certified | 🚨 8+ years in VAPT (Vulnerability Assessment and Penetration Testing) | ✅ 300+ Web, Mobile, API & Network Pentests
Note: PLEASE don't contact for unethical jobs such as Insta/Facebook/Gmail/Crypto Hacking & Recovery!!!
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🎓 About Me
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Hi, I’m Nimit Jain — a cybersecurity professional specializing in penetration testing (pentesting) and VAPT services. With 8+ years of hands-on experience, I’ve successfully tested and secured 300+ assets for Fortune 500 companies, startups, and regulated sectors.
My core expertise covers web application penetration testing, mobile app security (Android/iOS), API security, thick client testing, and network infrastructure pentesting. I identify real-world risks and deliver actionable remediation aligned with compliance standards.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🏆 Key Certifications
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ OSCP (Offensive Security Certified Professional)
✅ CREST Registered Penetration Tester (CRT)
✅ CREST Practitioner Security Analyst (CPSA)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🌟 Client Testimonials
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🌟 “Working with Nimit was excellent. His penetration testing expertise helped us uncover critical issues and strengthen our security posture. Clear communication and reliable delivery.”
🌟 “Highly skilled in VAPT and pentesting, Nimit gave us valuable insights into our application security. Professional, detail-oriented, and easy to work with.”
🌟 "Nimit was fantastic throughout; worked with tight deadlines and delivered a very good service. Highly recommend !"
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🌐 Penetration Testing Expertise
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🔹 Web Applications: Secured against OWASP Top 10 vulnerabilities
🔹 Mobile Apps: Pentested Android & iOS for real-world exploits
🔹 APIs: Conducted API VAPT for secure integrations
🔹 Thick Clients: Enterprise-grade security assessments
🔹 Network Security: Infrastructure pentests to expose misconfigurations
Industry Focus:
✔️ Banking, Financial Services & Insurance (BFSI)
✔️ Healthcare & Pharma
✔️ E-Commerce Platforms
✔️ Manufacturing & Critical Infrastructure
✔️ Government & Public Sector
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
📜 Compliance & Standards
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Expert in ISO 27001, HIPAA, GDPR, PCI DSS, and FDA compliance. Methodologies include OWASP, NIST, and SANS guidelines, ensuring high-quality penetration testing reports for audits and certifications.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🔬 Research & CVEs
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🛡️ CVE-2019-12744 – Remote Code Execution
🛡️ CVE-2019-12745 – Cross-Site Scripting (XSS)
🛡️ CVE-2019-12801 – Cross-Site Scripting (XSS)
🛡️ CVE-2019-12932 – Cross-Site Scripting (XSS)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🚀 Advanced Skills
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✔️ Red & Blue Teaming engagements
✔️ Cloud Security Pentesting (AWS, Azure, GCP)
✔️ Social Engineering & Phishing Simulations
✔️ Advanced API & Mobile Application VAPT
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🤝 Why Work With Me
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ 8+ years of penetration testing experience across industries
✅ Proven track record securing 300+ assets
✅ Compliance-aligned VAPT reports for SOC2, PCI DSS, HIPAA audits
✅ Clear communication & timely delivery
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🎯 Get in Touch
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
I help businesses strengthen their security posture through end-to-end penetration testing (VAPT). Whether it’s a web app pentest, API security test, or network infrastructure VAPT, I deliver actionable findings that make your systems resilient.
📞 FREE Consultation Available Daily
🕗 8:00 AM IST – 11:00 PM IST (1:30 AM – 3:30 PM EST)
Penetration Testing
Network Penetration Testing
Application Security
Vulnerability Assessment
Information Security
Security Testing
Security Assessment & Testing
Information Security Consultation
Network Security
Kali Linux
Web App Penetration Testing
Security Analysis
Website Security
Information Security Audit
Ethical Hacking
Kunal N.
Pune, India
$20/hr
5.0
6 jobs
🌐 Top 10 % on Upwork 📅 11+ Years of Experience | ✅ Penetration Tester | 🌐 80+ projects outside Upwork | 🚀 Quick Response Time | 🕒 On-Time Delivery | 🛡️ Post Contract Support
I help SaaS companies, and enterprises identify critical security vulnerabilities before they become costly breaches, compliance issues, or business disruptions.
As an Application Security Consultant and Penetration Tester, I specialize in uncovering real-world security weaknesses across web applications, APIs, network infrastructure, cloud environments, and modern technology platforms. My goal is not only to identify vulnerabilities but also to help organizations understand their security risks, prioritize remediation efforts, and strengthen their overall security posture.
I have worked on security assessments involving enterprise applications, banking platforms, healthcare systems, cloud infrastructures, and business-critical applications. My experience includes identifying authentication flaws, access control weaknesses, business logic vulnerabilities, network misconfigurations, cloud security gaps, API security issues, and attack paths that automated scanners frequently miss.
Core Security Services
• Web Application Penetration Testing (OWASP Top 10 & Business Logic Testing)
• API Security Testing (REST & GraphQL)
• Network & Infrastructure Security Testing
• Cloud Security Assessments (AWS)
• Red Team Operations & Adversary Simulation
• AI / LLM Security Testing
• Vulnerability Assessment & Risk Analysis
• Security Architecture Review
• Email Security Implementation (SPF, DKIM & DMARC)
What You Can Expect
• Comprehensive Manual Security Testing
• Detailed Vulnerability Reports
• Proof-of-Concept Validation
• Risk-Based Prioritization
• Clear Remediation Guidance
• Remediation Validation & Retesting
• Executive and Technical Reporting
Tools & Technologies
• Burp Suite Professional
• Nmap
• Metasploit Framework
• Nessus
• OWASP ZAP
• Wireshark
• SQLMap
• AWS Security Tools
• Kali Linux
Long-Term Security Partnership
Many organizations engage me beyond a single penetration test. I work with clients on recurring security assessments, monthly security reviews, remediation verification, secure development guidance, and continuous security improvement initiatives.
Whether you need a one-time security assessment or a long-term security partner, I focus on delivering actionable security insights that help protect your applications, infrastructure, customers, and reputation.
If you are looking for a security professional who can think like an attacker and provide practical, business-focused security recommendations, I would be happy to discuss your project.
Penetration Testing
Network Penetration Testing
Web Application Security
Vulnerability Assessment
Ethical Hacking
OWASP
API Testing
Metasploit
Cloud Security
Cybersecurity Tool
Security Testing
Network Security
Application Security
Red Team Assessment
Information Security
N U S.
Chennai, India
$4/hr
5.0
2 jobs
I specialize in security engineering with hands-on experience in web, mobile (Android), API, and network security. My expertise lies in vulnerability assessment and penetration testing, where I excel at identifying critical vulnerabilities and implementing effective remediation strategies. I create secure and scalable systems, driven by a passion for offensive security and bug bounty hunting.
Notably, I developed a secure data recovery system that achieved a 95% data retrieval accuracy and increased efficiency in restoring overwritten data by 40%. Additionally, I built a healthcare decision support system leveraging deep neural networks, significantly enhancing prediction accuracy.
If you need a security expert who can deliver robust solutions and improve your system's security posture, let’s connect and discuss your project's needs.
Penetration Testing
Network Penetration Testing
Computer Network
Computing & Networking
Vulnerability Assessment
Web App Penetration Testing
Information Security
Compliance
Mobile QA
Cybersecurity Tool
Cybersecurity Monitoring
Python
NIST Cybersecurity Framework
Amit S.
Delhi, India
$12/hr
4.9
42 jobs
Hi, I am Amit Singh and having 10+ years of significant and well-diversified experience in Cybersecurity domains, including ⭐Web Application penetration testing (SaaS, Cloud etc.)⭐Network Penetration testing(Servers, Active Directory, IoT etc.)⭐Web API pen-testing ⭐Mobile penetration testing (android & iOS)⭐Web 3.0 DApps & Smart Contract pen-testing (Blockchain technology)⭐ Source Code Review etc.
🏆Top Rated Profile on Upwork
✅I have performed penetration tests & vulnerability assessments and delivered professional reports to companies all over the world in accordance with:
☑️ Offensive Security (OSCP) standards
☑️ OWASP Top 10 Vulnerability
☑️ OWASP API Security Top 10 Vulnerability
☑️ OWASP Mobile Security Top 10 Vulnerability
☑️ Application Security Verification Standard 4.0 (ASVS 4.0)
☑️ CWE Top 25 Most Dangerous Software Errors
☑️ ISO 27001 Penetration Testing
☑️ Payment Card Industry Data Security Standard (PCI DSS)
☑️ General Data Protection Regulation (GDPR)
☑️ Common Vulnerability Scoring System (CVSS)
☑️ Open Source Security Testing Methodology Manual (OSSTMM)
✅ Cybersecurity Certifications:-
☑️ Certified eLearnSecurity Web application penetration tester (eWPT)
☑️ Certified API Security Professional( CASP)
☑️Certified Ethical hacker(CEH)
✅ The deliverable will be a professional Penetration Testing/Vulnerability Assessment report which includes:
☑️ Executive Summary
☑️ Assessment Methodology
☑️ Type of Tests
☑️Risk Level Classifications
☑️ Result Summary
☑️ Table of Findings
☑️ Detailed Findings. Each finds listed within the report will contain a CVSS score, Issue Description, Proof of Concept, Remediation, and Reference sections.
✅ Tool List (Acunetix, Nessus, BurpSuite Professional, Nmap, Netsparker, Metasploit Framework, OpenVAS, Mimikatz, SQLmap, Nikto, checkmax and Zaproxy etc.
Note-For more info lets connect over the chat section. Thanks
Penetration Testing
Network Penetration Testing
Security Testing
Network Security
Vulnerability Assessment
Web Application Security
Internet Security
Information Security Audit
Website Security
API Testing
OWASP
Code Review
Web App Penetration Testing
Security Assessment & Testing
Ethical Hacking
How it works
Post a job for freePost a job
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a Network Pentester in India on Upwork?
You can hire a Network Pentester in India on Upwork in four simple steps:
Create a job post tailored to your Network Pentester project scope. We'll walk you through the process step by step.
Browse top Network Pentester talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top Network Pentester profiles and interview.
Hire the right Network Pentester for your project from Upwork, the world's largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a Network Pentester?
Rates charged by Network Pentesters on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a Network Pentester in India on Upwork?
As the world's work marketplace, we connect highly-skilled freelance Network Pentesters and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Network Pentester team you need to succeed.
Can I hire a Network Pentester in India within 24 hours on Upwork?
Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Network Pentester proposals within 24 hours of posting a job description.