I help SaaS companies, and enterprises identify critical security vulnerabilities before they become costly breaches, compliance issues, or business disruptions.
As an Application Security Consultant and Penetration Tester, I specialize in uncovering real-world security weaknesses across web applications, APIs, network infrastructure, cloud environments, and modern technology platforms. My goal is not only to identify vulnerabilities but also to help organizations understand their security risks, prioritize remediation efforts, and strengthen their overall security posture.
I have worked on security assessments involving enterprise applications, banking platforms, healthcare systems, cloud infrastructures, and business-critical applications. My experience includes identifying authentication flaws, access control weaknesses, business logic vulnerabilities, network misconfigurations, cloud security gaps, API security issues, and attack paths that automated scanners frequently miss.
Core Security Services
• Web Application Penetration Testing (OWASP Top 10 & Business Logic Testing)
• API Security Testing (REST & GraphQL)
• Network & Infrastructure Security Testing
• Cloud Security Assessments (AWS)
• Red Team Operations & Adversary Simulation
• AI / LLM Security Testing
• Vulnerability Assessment & Risk Analysis
• Security Architecture Review
• Email Security Implementation (SPF, DKIM & DMARC)
What You Can Expect
• Comprehensive Manual Security Testing
• Detailed Vulnerability Reports
• Proof-of-Concept Validation
• Risk-Based Prioritization
• Clear Remediation Guidance
• Remediation Validation & Retesting
• Executive and Technical Reporting
Tools & Technologies
• Burp Suite Professional
• Nmap
• Metasploit Framework
• Nessus
• OWASP ZAP
• Wireshark
• SQLMap
• AWS Security Tools
• Kali Linux
Long-Term Security Partnership
Many organizations engage me beyond a single penetration test. I work with clients on recurring security assessments, monthly security reviews, remediation verification, secure development guidance, and continuous security improvement initiatives.
Whether you need a one-time security assessment or a long-term security partner, I focus on delivering actionable security insights that help protect your applications, infrastructure, customers, and reputation.
If you are looking for a security professional who can think like an attacker and provide practical, business-focused security recommendations, I would be happy to discuss your project.
Penetration Testing
Network Penetration Testing
Web Application Security
Vulnerability Assessment
Ethical Hacking
OWASP
API Testing
Metasploit
Cloud Security
Cybersecurity Tool
Security Testing
Network Security
Application Security
Red Team Assessment
Information Security
Mahesh T.
Bengaluru, India
$40/hr
5.0
127 jobs
🔐 Certified Penetration Tester | AWS & Azure Cloud Security | Incident Response Expert 🔐
I’m a results-driven cybersecurity specialist with 13+ years of experience securing cloud infrastructure, web applications, and enterprise environments. I help companies prevent breaches, mitigate risks, and ensure compliance through advanced security architecture and real-world offensive security skills.
🎯 What I Do:
✔️ Cloud Security Hardening – AWS (IAM, EC2, S3, VPC, RDS, Route 53) & Azure (VNET, NSGs, Azure Security Center, Defender)
✔️ Penetration Testing – Full-scope internal/external pentests, web/app/API testing, business logic abuse, OWASP Top 10
✔️ Vulnerability Assessments – Nessus, OpenVAS, Nmap, custom exploit validation, CVSS scoring & prioritization
✔️ Threat Detection & Response – Wazuh setup, real-time event correlation, SIEM deployment, log analysis
✔️ Security Architecture – Designing scalable, secure cloud solutions with strong IAM, encryption, and DR practices
✔️ Cloudflare Optimization – Harden DNS, implement WAF rulesets, rate-limiting, Zero Trust setup
✔️ Incident Response – Triage, forensics, log collection, remediation and recovery plans (NIST, MITRE ATT&CK aligned)
📌 Security Tools I Work With:
- **Offensive Security**: Burp Suite, Metasploit, Nmap, Hydra, SQLmap
- **Defensive Tools**: Wazuh, AWS GuardDuty, Azure Sentinel, Nessus, Suricata
- **Languages/Scripting**: Bash, PowerShell, HTML/JavaScript (for attack emulation & automation)
- **Frameworks/Standards**: OWASP, MITRE ATT&CK, NIST CSF, CIS Benchmarks
🛡️ Certifications:
- AWS Certified Security – Specialty
- Microsoft Certified: Azure Security Engineer Associate
- Licensed Penetration Tester (LPT) | Certified Penetration Testing Professional (CPENT)
- CEH, CCSK
📈 Highlights:
- $200K+ earned, 97% Job Success on Upwork
- 9,300+ hours across 90+ successful projects
- Trusted by startups, fintechs, and regulated industries (HIPAA, GDPR, SOC2)
I’m known for delivering real-world, **actionable security results** — not just checkbox audits. If you’re looking to **secure your infrastructure, detect threats faster, or simulate real-world attacks**, let’s connect!
Penetration Testing
Cloudflare
Kali Linux
Microsoft Azure
Security Testing
Vulnerability Assessment
Application Security
Security Analysis
Amazon Web Services
Information Security
Web App Penetration Testing
Security Assessment & Testing
Security Infrastructure
Information Security Consultation
Steffin S.
Kozhikode, India
$30/hr
4.8
205 jobs
OSCP & CREST-certified Penetration Tester helping SaaS companies, startups, e-commerce platforms, and enterprise teams find real, exploitable security weaknesses before attackers do.
I provide manual-first penetration testing for Web Applications, APIs, Mobile Apps, Networks, Active Directory environments, Infrastructure, and Thick Client/Desktop Applications. My focus is not just finding vulnerabilities, but validating real-world exploitability, explaining business impact, and giving your developers clear remediation guidance they can actually apply.
🔎 Core services I provide:
• Web Application Penetration Testing
• API Security Testing
• Mobile Application Penetration Testing for Android and iOS
• External Network Penetration Testing
• Internal Network & Active Directory Security Assessment
• Thick Client / Windows Desktop Application Testing
• OWASP Top 10 & OWASP WSTG-Based Security Testing
• Vulnerability Assessment & Manual Validation
• OSINT & External Attack Surface Assessment
• Security Retesting & Remediation Validation
• SOC 2, ISO 27001, PCI DSS, Amazon SP-API, and compliance-oriented pentest reports
📄 What you receive:
• A professional penetration testing report
• Clear proof-of-concept evidence and screenshots
• Technical explanation of each vulnerability
• Business impact written in simple, practical language
• Severity rating and CVSS scoring where applicable
• Step-by-step remediation guidance for developers
• Retest results after your team applies fixes
• Executive summary suitable for management, compliance, vendor review, and internal audit
⚡ My testing approach:
I perform Black Box and Grey Box penetration testing depending on your project requirements. I use a manual-first methodology supported by professional tools such as Burp Suite Pro, but I do not rely only on automated scanners. The goal is to identify security issues that matter in real attack scenarios, including authentication flaws, authorization bypasses, SQL Injection, IDOR, access control issues, business logic vulnerabilities, API security weaknesses, injection flaws, misconfigurations, and sensitive data exposure.
🎯 Best fit if you need:
• A security test before launching a product or major feature
• A web application, API, mobile app, network, or infrastructure assessment
• A compliance-ready report for SOC 2, ISO 27001, PCI DSS, vendor review, or investor due diligence
• Manual security testing focused on real exploitability
• Clear communication with practical remediation advice
• Reliable retesting after fixes are completed
🏆 Certifications and experience:
• OSCP
• OSEP
• OSWP
• CREST CPSA
• Top Rated in Information Security / IT Compliance
• Ranked in the Top 50 in multiple bug bounty programs
• Completed 500+ penetration tests and security assessments
• Available across different time zones
• Open to one-time assessments and long-term security engagements
✅ Need a professional penetration test or vulnerability assessment for your web application, API, mobile app, network, or infrastructure?
📩 Send me a message, and I will help you define the right scope, testing approach, timeline, and deliverables for your security goals.
Penetration Testing
Network Penetration Testing
Information Security
Network Security
Security Assessment & Testing
Security Testing
Vulnerability Assessment
System Security
Application Security
Web App Penetration Testing
Website Security
Web Application Security
Black Box Testing
OWASP
Risk Assessment
Anmol T.
Noida, India
$10/hr
5.0
2 jobs
🚨 If your application, SaaS platform, or cloud environment has never undergone a professional security assessment, you may have unknown vulnerabilities that attackers can exploit.
I’m a Certified Penetration Tester and Ethical Hacker providing Vulnerability Assessment and Penetration testing (VAPT) services for web applications, APIs, cloud infrastructure, mobile apps, SaaS platforms, and network environments. My goal is not just to find vulnerabilities — but to help you understand real security risks and fix them effectively.
I perform manual penetration testing supported by professional security tools to identify exploitable weaknesses such as authentication flaws, privilege escalation paths, injection vulnerabilities, and business logic issues.
You will receive a clear and actionable security report that helps developers resolve issues and allows management to understand the real business impact.
🎯 My Services
- Vulnerability Assessment & Penetration Testing (VAPT)
- Web Application Penetration Testing (OWASP Top 10)
- API Penetration Testing (REST, GraphQL, authentication flaws, IDOR, injection)
- Cloud Infrastructure Security (AWS, Azure — misconfigurations, IAM, exposed services)
- Network Penetration Testing (internal & external)
- Mobile Application Security (Android & iOS)
- SaaS Platform Security & Penetration Testing (multi-tenant logic, RBAC, privilege escalation)
- CMS Security (WordPress, Laravel, custom apps)
- Retesting after remediation
📋 What You Will Receive
A clear, structured security report designed for both technical teams and business stakeholders, including:
• Executive summary for management and decision-makers
• Detailed vulnerability findings with severity ratings
• CVSS scoring and risk prioritization
• Proof-of-concept evidence (screenshots, request/response captures)
• Business impact explanation for each issue
• Step-by-step remediation guidance for developers
• Retesting validation after fixes are applied
• Reporting that can support ISO 27001 and SOC 2 compliance preparation
🏆 Certifications
- Certified Ethical Hacker Practical — EC-Council
- eLearnSecurity Junior Penetration Tester (eJPT) — INE
- Certified API Penetration Tester — APISec University
- IBM Cybersecurity Analyst
- Cisco Verified Ethical Hacker
- ISO 27001:2022 Lead Auditor
🛠️ Tools I work with
Burp Suite Pro, OWASP ZAP, Nmap, Nessus, Metasploit, MobSF, Wireshark, Postman, and custom Python/Bash scripts and so on.
Whether you're preparing for a security review, compliance audit, or investor due diligence, I can help you understand your attack surface and security risks.
📩 Send me your scope or asset list and I’ll help you determine the best testing approach.
Penetration Testing
Information Security
Web Application Security
Web App Penetration Testing
Nimit J.
New Delhi, India
$30/hr
4.9
29 jobs
🌟 Top Rated🌟
🛡️ Penetration Testing Expert | Certified Cybersecurity Professional
🧠 OSCP & 🏅 CREST Certified | 🚨 8+ years in VAPT (Vulnerability Assessment and Penetration Testing) | ✅ 300+ Web, Mobile, API & Network Pentests
Note: PLEASE don't contact for unethical jobs such as Insta/Facebook/Gmail/Crypto Hacking & Recovery!!!
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🎓 About Me
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Hi, I’m Nimit Jain — a cybersecurity professional specializing in penetration testing (pentesting) and VAPT services. With 8+ years of hands-on experience, I’ve successfully tested and secured 300+ assets for Fortune 500 companies, startups, and regulated sectors.
My core expertise covers web application penetration testing, mobile app security (Android/iOS), API security, thick client testing, and network infrastructure pentesting. I identify real-world risks and deliver actionable remediation aligned with compliance standards.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🏆 Key Certifications
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ OSCP (Offensive Security Certified Professional)
✅ CREST Registered Penetration Tester (CRT)
✅ CREST Practitioner Security Analyst (CPSA)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🌟 Client Testimonials
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🌟 “Working with Nimit was excellent. His penetration testing expertise helped us uncover critical issues and strengthen our security posture. Clear communication and reliable delivery.”
🌟 “Highly skilled in VAPT and pentesting, Nimit gave us valuable insights into our application security. Professional, detail-oriented, and easy to work with.”
🌟 "Nimit was fantastic throughout; worked with tight deadlines and delivered a very good service. Highly recommend !"
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🌐 Penetration Testing Expertise
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🔹 Web Applications: Secured against OWASP Top 10 vulnerabilities
🔹 Mobile Apps: Pentested Android & iOS for real-world exploits
🔹 APIs: Conducted API VAPT for secure integrations
🔹 Thick Clients: Enterprise-grade security assessments
🔹 Network Security: Infrastructure pentests to expose misconfigurations
Industry Focus:
✔️ Banking, Financial Services & Insurance (BFSI)
✔️ Healthcare & Pharma
✔️ E-Commerce Platforms
✔️ Manufacturing & Critical Infrastructure
✔️ Government & Public Sector
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
📜 Compliance & Standards
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Expert in ISO 27001, HIPAA, GDPR, PCI DSS, and FDA compliance. Methodologies include OWASP, NIST, and SANS guidelines, ensuring high-quality penetration testing reports for audits and certifications.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🔬 Research & CVEs
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🛡️ CVE-2019-12744 – Remote Code Execution
🛡️ CVE-2019-12745 – Cross-Site Scripting (XSS)
🛡️ CVE-2019-12801 – Cross-Site Scripting (XSS)
🛡️ CVE-2019-12932 – Cross-Site Scripting (XSS)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🚀 Advanced Skills
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✔️ Red & Blue Teaming engagements
✔️ Cloud Security Pentesting (AWS, Azure, GCP)
✔️ Social Engineering & Phishing Simulations
✔️ Advanced API & Mobile Application VAPT
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🤝 Why Work With Me
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ 8+ years of penetration testing experience across industries
✅ Proven track record securing 300+ assets
✅ Compliance-aligned VAPT reports for SOC2, PCI DSS, HIPAA audits
✅ Clear communication & timely delivery
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🎯 Get in Touch
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
I help businesses strengthen their security posture through end-to-end penetration testing (VAPT). Whether it’s a web app pentest, API security test, or network infrastructure VAPT, I deliver actionable findings that make your systems resilient.
📞 FREE Consultation Available Daily
🕗 8:00 AM IST – 11:00 PM IST (1:30 AM – 3:30 PM EST)
Penetration Testing
Network Penetration Testing
Application Security
Vulnerability Assessment
Information Security
Security Testing
Security Assessment & Testing
Information Security Consultation
Network Security
Kali Linux
Web App Penetration Testing
Security Analysis
Website Security
Information Security Audit
Ethical Hacking
Prashant D.
Bengaluru, India
$25/hr
4.9
13 jobs
6+ years as an Offensive Security Researcher, OSCP and CEH v12 certified, I help startups, SaaS companies, and enterprises think like an attacker before real attackers do through hands-on Penetration Testing, Red Teaming, and Vulnerability Assessment (VAPT) across web, mobile, API, network, and cloud environments.
My approach is simple: real offensive security isn't a scanner dump it's manual exploitation, chained attack paths, and a prioritized, developer-ready remediation plan mapped to your actual business risk.
With a strong software engineering background, I read source code, trace data flows, and reason about architecture catching business-logic flaws, privilege-escalation chains, and design weaknesses that automated tools always miss.
🎯 PENETRATION TESTING & VAPT
Full-scope Vulnerability Assessment and Penetration Testing (VAPT) across the OWASP Top 10, OWASP API Security Top 10, and PTES/OSSTMM methodologies: broken access control, IDOR, SSRF, SQLi/NoSQLi/command/template injection, XSS, CSRF, insecure deserialization, auth/session flaws, privilege escalation, and business-logic abuse.
Web App Pentesting: React, Angular, Vue, Next.js, Node.js, Django/Flask/FastAPI, Spring, Laravel, Rails, .NET, Go
Mobile Pentesting: Android & iOS per OWASP MASVS/MASTG, static + dynamic analysis, reverse engineering, insecure storage, API/backend abuse
API Pentesting: REST, GraphQL, SOAP auth bypass, rate-limit abuse, mass assignment, BOLA/BFLA
Network Pentesting: internal/external, Active Directory attacks (Kerberoasting, pass-the-hash, lateral movement, privilege escalation), segmentation testing
Every finding is manually verified (zero false positives), CVSS-scored, and delivered with an executive summary + technical deep dive + exact remediation steps, plus a free retest.
Tools: Burp Suite Pro, OWASP ZAP, Nmap, Metasploit, Cobalt Strike, Nuclei, sqlmap, Nessus, ffuf, BloodHound, Mimikatz, Hashcat, John the Ripper, Wireshark
🕵️ RED TEAMING & ADVERSARY SIMULATION
End-to-end Red Team engagements simulating real-world TTPs mapped to MITRE ATT&CK: initial access, phishing simulation, C2 infrastructure, privilege escalation, lateral movement, persistence, and data exfiltration testing people, process, and technology together, not just systems. Purple Team collaboration to strengthen detection and response (SOC/EDR/SIEM evasion & tuning).
☁️ CLOUD SECURITY (AWS, Azure & GCP)
IAM and least-privilege reviews, network segmentation, exposed storage (S3/Blob/GCS), privilege-escalation paths, and CIS Benchmark hardening. Cloud penetration testing and CSPM assessments using Prowler, ScoutSuite, and Pacu.
⚙️ DEVSECOPS & INFRASTRUCTURE SECURITY
Security embedded into CI/CD (GitHub Actions, GitLab CI, Jenkins), container/Kubernetes security (Trivy, Grype, RBAC, Pod Security Standards), and IaC security review for Terraform/CloudFormation/Ansible (Checkov, tfsec). SAST, DAST, SCA, and secrets scanning integration (Semgrep, Snyk, SonarQube, Gitleaks, TruffleHog).
🤖 AI / LLM SECURITY
Offensive testing of AI/ML and LLM-powered features against the OWASP Top 10 for LLM Applications and MITRE ATLAS: prompt injection, jailbreaks, model DoS, sensitive-data leakage, insecure output handling, and excessive agency in agentic systems.
🧠 SECURITY ENGINEERING & RESEARCH
Secure code review, threat modeling (STRIDE, attack trees), reverse engineering (Java/bytecode, anti-tamper analysis), malware analysis fundamentals, and security architecture design.
🤝 HOW I WORK:
1️⃣ Free scoping call to define objectives, rules of engagement, and scope
2️⃣ Testing/assessment with clear, regular communication
3️⃣ A prioritized report Executive Summary + technical detail + exact fixes
4️⃣ Free retest and debrief once your team remediates
Every engagement is handled under strict confidentiality, signed Rules of Engagement, and full written authorization. I don't oversell if you don't need a service, I'll tell you honestly.
Keywords: penetration testing, ethical hacking, VAPT, red teaming, purple team, OSCP, CEH, offensive security, web app pentest, mobile pentest, API pentest, network pentest, Active Directory pentest, cloud security, AWS pentest, Azure pentest, GCP pentest, DevSecOps, cybersecurity consultant, vulnerability assessment, security audit, ISO 27001, SOC 2, GDPR compliance, MITRE ATT&CK, OWASP Top 10, secure code review, threat modeling, AI security, LLM security.
📩 Message me with your project details, and I'll respond with a clear, no-pressure scoping plan.
Penetration Testing
Web Application Security
Vulnerability Assessment
Information Security
OWASP
API
Cloud Security
DevOps
Kubernetes
IT Compliance Audit
ISO 27001
SOC 2
Network Security
Risk Assessment
NIST Cybersecurity Framework
Information Security Audit
Information Security Governance
Governance, Risk Management & Compliance
Information Security Consultation
How it works
Post a job for freePost a job
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a Network Pentester in India on Upwork?
You can hire a Network Pentester in India on Upwork in four simple steps:
Create a job post tailored to your Network Pentester project scope. We'll walk you through the process step by step.
Browse top Network Pentester talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top Network Pentester profiles and interview.
Hire the right Network Pentester for your project from Upwork, the world's largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a Network Pentester?
Rates charged by Network Pentesters on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a Network Pentester in India on Upwork?
As the world's work marketplace, we connect highly-skilled freelance Network Pentesters and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Network Pentester team you need to succeed.
Can I hire a Network Pentester in India within 24 hours on Upwork?
Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Network Pentester proposals within 24 hours of posting a job description.