"Top Rated Plus" cybersecurity consultant and published author with 25+ years of experience specializing in penetration testing. Clients hire me when they need senior-level testing that includes clear scoping, reporting that drives remediation, and efficient execution.
I’ve led red team and penetration testing work for Fortune 100 enterprises, government agencies, and startups. My assessments are designed to simulate realistic attacker behavior, prioritize what matters most, and produce results that are easy for technical teams to reproduce and fix.
Areas of expertise:
* Web application testing (OWASP Top 10, authentication/session flaws, access control, input validation, SSRF, IDOR, RCE)
* API testing (token/session handling, authorization boundaries, input validation, business logic, fuzzing where appropriate)
* Internal and external network testing (Windows, Linux, hybrid) with segmentation and control validation
* Active Directory testing (enumeration, privilege escalation simulation, attack path validation)
* AWS and Azure security reviews (misconfigurations, IAM privilege analysis, exposure discovery, logging and monitoring validation)
* Compliance-aligned testing and guidance (PCI DSS, HIPAA, CIS, NIST and more)
What you can expect:
* Strong communication, documented scope, and no surprises
* Findings prioritized by real-world impact, not just scanner output
* Executive summary plus actionable remediation steps your team can use immediately
* Optional live debrief and remediation testing
Certifications: CISSP, CCSP, ISSMP, AWS Security Specialty, AWS Solutions Architect, CCNP Security, and more. Published author of multiple penetration testing books and a frequent security conference speaker.
Penetration Testing
Network Penetration Testing
Network Security
Cloud Security
Cybersecurity Management
Red Team Assessment
OWASP
Security Assessment & Testing
Certified Information Systems Security Professional
Kali Linux
Ethical Hacking
Web Testing
Vulnerability Assessment
Information Security
Application Security
Matthew R.
Grovetown, Georgia
$30/hr
4.9
12 jobs
Experienced analyst and pentester working in Cybersecurity. Looking to consult or actively pentest to help find vulnerabilities and recommend remediations.
I will pentest (ethically "hack") your website, network, and systems to conduct a vulnerability assessment.
I can also conduct forensics. Need to get into a locked phone or computer? Need to recover deleted files? Nothing is every truly gone.
Certifications:
Offensive Security Certified Professional (OSCP)
GIAC Certified Incident Handler (GCIH)
GIAC Certified Windows Security Administrator (GCWN)
GIAC Certified Systems and Network Auditor (GSNA)
GIAC Certified Penetration Tester (GPEN)
CompTIA Security+
CompTIA Pentest+
Certified Ethical Hacker (CEH)
Virtual Hacking Labs Penetration Testing Course
Virtual Hacking Labs Penetration Testing Advanced+
Pertinent Training:
SANS SEC504: Hacker Tools, Techniques, Exploits, and Incident Handling
SANS SEC505: Securing Windows and PowerShell Automation
SANS FOR508: Advanced Incident Response, Threat Hunting, and Digital Forensics
SANS MGT512: Security Leadership Essentials for Managers
SANS AUD507: Auditing & Monitoring Networks, Perimeters & Systems
U.S. CYBERCOM: Cyber Common Technical Core
U.S. CYBERCOM: Cyber Operations Technician Warrant Officer Basic Course
U.S. CYBERCOM: Applied Fundamentals (Windows OS, *NIX, Networking & Tier 1 Forensics Triage)
U.S. CYBERCOM: Hacking Methodologies
U.S. CYBERCOM: Intermediate Scripting (Python/PowerShell)
U.S. CYBERCOM: Cyber Operations Planner Course (COPC)
U.S. CYBERCOM: Cyber Mission Commander Course (MCC)
OFFSEC: Penetration Testing with Kali (60 Days)
Certified Ethical Hacker (CEH)
Virtual Hacking Lab (30 Days)
Penetration Testing
Network Penetration Testing
Vulnerability Assessment
Digital Forensics
Cybersecurity Management
SQL
Unified Threat Management
Security Analysis
Ahmed P.
Carbondale, Illinois
$65/hr
5.0
10 jobs
Penetration Tester | Ethical Hacker | Red Team | Web & Network Security
Need a Penetration Tester or Ethical Hacker to identify security vulnerabilities before attackers find them?
I am a Cybersecurity Specialist and Penetration Tester specializing in Penetration Testing, Ethical Hacking, Red Teaming, Web Application Security, Network Security, Active Directory Security, API Security, Vulnerability Assessment, and Adversary Emulation.
I help businesses find, validate, and clearly document security vulnerabilities across web applications, APIs, networks, cloud environments, and Active Directory infrastructure.
My Cybersecurity and Penetration Testing services include:
• Penetration Testing and Ethical Hacking
• Web Application Penetration Testing
• Network Penetration Testing
• API Penetration Testing
• Active Directory Penetration Testing
• Red Team Operations and Adversary Emulation
• Vulnerability Assessment and Security Testing
• AWS and Cloud Security Testing
• EDR Testing and Security Control Validation
• Phishing Simulations and Social Engineering Assessments
• Incident Response Support
• OWASP Top 10 Security Testing
• Security Assessment and Vulnerability Reporting
• Threat Detection and TTP Research
I have led 12+ Active Directory-focused CTF events with 120+ participants and have experience automating offensive security workflows, evaluating security solutions, building security test environments using Atomic Red Team and AWS Lambda, and executing controlled attack campaigns.
I also have experience assessing APIs, web applications, enterprise networks, Active Directory environments, cloud infrastructure, and AI systems.
Certifications:
• PNPT - Practical Network Penetration Tester
• CRTO - Certified Red Team Operator
• CompTIA Security+
• CCNA
My core skills include Penetration Testing, Cybersecurity, Ethical Hacking, Red Teaming, Network Security, Web Security, Application Security, Active Directory, Vulnerability Assessment, Vulnerability Management, API Security, Cloud Security, AWS Security, EDR, Adversary Emulation, OWASP, Incident Response, Threat Detection, Security Testing, and Offensive Security.
If you need a Penetration Tester, Ethical Hacker, Red Team Specialist, or Cybersecurity Consultant for a security assessment, I can help identify vulnerabilities and provide clear actionable remediation recommendations.
Penetration Testing
Network Penetration Testing
Computing & Networking
Vulnerability Assessment
System Security
Application Security
Windows Server
Linux System Administration
Linux
Cisco Certified Network Associate
Python
Scripting
Web Application Security
Web Application
Michael H.
Baltimore, Maryland
$125/hr
5.0
116 jobs
Stop relying on automated scans. I find the vulnerabilities they miss.
I’m a senior penetration tester and vulnerability researcher with deep experience across enterprise networks, web apps / APIs and cloud platforms.
Most testers just run automated tools and hand you a generic report. I simulate how an attacker actually thinks, perform thorough testing, and deliver professional, tailored reporting suitable not just for your own remediation efforts but also for audit / compliance.
Benefits of manual testing:
- Chaining multiple low/medium findings to show more significant impact
- Breaking multi-tenant isolation
- Bypassing auth controls (JWT, OAuth, misconfigurations)
- Identifying cost-amplification / abuse vectors (e.g., billing attacks in serverless environments)
- ZERO false positives (and wasted time trying to remediate non-issues)
- REAL severity scoring (not just CVSS or ratings with no connection to actual impact/risk for your systems and data)
What I Deliver
- Manual, attacker-style testing (not just scans)
- Clear, prioritized findings with real business impact
- Proof-of-concept exploits where it matters
- Practical remediation guidance your devs can use immediately
- Optional retesting to verify fixes
Common Engagements
- SaaS / multi-tenant application security testing
- API and authentication testing (JWT, OAuth, session flaws)
- Cloud security reviews (GCP, AWS, Azure, O365)
- DevOps security reviews (Gitlab/hub, BitBucket, etc.)
- Pre-SOC2 / investor readiness assessments
- High-intensity black-box pentests
Why Clients Hire Me
- I go beyond the scan—I find what others miss
- I understand both offense and architecture
- I communicate clearly with both engineers and leadership
- I’ve worked on MANY real-world, high-impact systems
I also help organizations:
- Investigate breaches
- Contain active threats
- Recover compromised systems
(Note: I do not assist with social media account recovery.)
Penetration Testing
Network Penetration Testing
Security Analysis
Security Engineering
Web Application Security
Ethical Hacking
Certified Information Systems Security Professional
Security Assessment & Testing
OWASP
White Box Testing
Network Security
Security Infrastructure
Vulnerability Assessment
Web App Penetration Testing
Incident Management
Aamir T.
Oakley, California
$40/hr
4.2
55 jobs
Organizations don't fail because they lack technology. They fail because security weaknesses remain undiscovered until attackers exploit them.
𝑨𝒓𝒆 𝒚𝒐𝒖 𝒍𝒐𝒐𝒌𝒊𝒏𝒈 𝒇𝒐𝒓 𝒂 𝒄𝒚𝒃𝒆𝒓𝒔𝒆𝒄𝒖𝒓𝒊𝒕𝒚 𝒑𝒓𝒐𝒇𝒆𝒔𝒔𝒊𝒐𝒏𝒂𝒍 𝒘𝒉𝒐 𝒄𝒂𝒏 𝒊𝒅𝒆𝒏𝒕𝒊𝒇𝒚 𝒔𝒆𝒄𝒖𝒓𝒊𝒕𝒚 𝒓𝒊𝒔𝒌𝒔, 𝒔𝒕𝒓𝒆𝒏𝒈𝒕𝒉𝒆𝒏 𝒚𝒐𝒖𝒓 𝒊𝒏𝒇𝒓𝒂𝒔𝒕𝒓𝒖𝒄𝒕𝒖𝒓𝒆, 𝒊𝒎𝒑𝒓𝒐𝒗𝒆 𝒄𝒐𝒎𝒑𝒍𝒊𝒂𝒏𝒄𝒆 𝒑𝒐𝒔𝒕𝒖𝒓𝒆, 𝒂𝒏𝒅 𝒔𝒆𝒄𝒖𝒓𝒆 𝒚𝒐𝒖𝒓 𝒄𝒍𝒐𝒖𝒅 𝒆𝒏𝒗𝒊𝒓𝒐𝒏𝒎𝒆𝒏𝒕𝒔 𝒃𝒆𝒇𝒐𝒓𝒆 𝒂𝒕𝒕𝒂𝒄𝒌𝒆𝒓𝒔 𝒇𝒊𝒏𝒅 𝒗𝒖𝒍𝒏𝒆𝒓𝒂𝒃𝒊𝒍𝒊𝒕𝒊𝒆𝒔?
I help startups, enterprises, and government organizations build secure, compliant, and resilient environments. 𝑾𝒊𝒕𝒉 15+ 𝒚𝒆𝒂𝒓𝒔 𝒐𝒇 𝒉𝒂𝒏𝒅𝒔-𝒐𝒏 𝒆𝒙𝒑𝒆𝒓𝒊𝒆𝒏𝒄𝒆 𝒊𝒏 𝒄𝒚𝒃𝒆𝒓𝒔𝒆𝒄𝒖𝒓𝒊𝒕𝒚, 𝒊𝒏𝒇𝒐𝒓𝒎𝒂𝒕𝒊𝒐𝒏 𝒔𝒆𝒄𝒖𝒓𝒊𝒕𝒚, 𝒔𝒚𝒔𝒕𝒆𝒎 𝒂𝒅𝒎𝒊𝒏𝒊𝒔𝒕𝒓𝒂𝒕𝒊𝒐𝒏, 𝒄𝒍𝒐𝒖𝒅 𝒔𝒆𝒄𝒖𝒓𝒊𝒕𝒚, 𝒄𝒐𝒎𝒑𝒍𝒊𝒂𝒏𝒄𝒆, 𝒂𝒏𝒅 𝑫𝒆𝒗𝑺𝒆𝒄𝑶𝒑𝒔, 𝑰 𝒅𝒆𝒍𝒊𝒗𝒆𝒓 𝒑𝒓𝒂𝒄𝒕𝒊𝒄𝒂𝒍 𝒔𝒆𝒄𝒖𝒓𝒊𝒕𝒚 𝒔𝒐𝒍𝒖𝒕𝒊𝒐𝒏𝒔 𝒕𝒉𝒂𝒕 𝒓𝒆𝒅𝒖𝒄𝒆 𝒓𝒊𝒔𝒌 𝒂𝒏𝒅 𝒔𝒖𝒑𝒑𝒐𝒓𝒕 𝒃𝒖𝒔𝒊𝒏𝒆𝒔𝒔 𝒈𝒓𝒐𝒘𝒕𝒉.
I do not provide generic recommendations or automated scan reports. I deliver actionable security insights, practical remediation strategies, and measurable improvements that directly support business objectives.
𝐖𝐡𝐞𝐧 𝐜𝐥𝐢𝐞𝐧𝐭𝐬 𝐞𝐧𝐠𝐚𝐠𝐞 𝐦𝐞, 𝐭𝐡𝐞𝐲 𝐠𝐚𝐢𝐧 𝐚 𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐩𝐚𝐫𝐭𝐧𝐞𝐫 𝐜𝐚𝐩𝐚𝐛𝐥𝐞 𝐨𝐟 𝐮𝐧𝐝𝐞𝐫𝐬𝐭𝐚𝐧𝐝𝐢𝐧𝐠 𝐛𝐨𝐭𝐡 𝐭𝐞𝐜𝐡𝐧𝐢𝐜𝐚𝐥 𝐜𝐡𝐚𝐥𝐥𝐞𝐧𝐠𝐞𝐬 𝐚𝐧𝐝 𝐛𝐮𝐬𝐢𝐧𝐞𝐬𝐬 𝐫𝐞𝐪𝐮𝐢𝐫𝐞𝐦𝐞𝐧𝐭𝐬.
💼 𝐄𝐱𝐩𝐞𝐫𝐭𝐢𝐬𝐞:
✔ Penetration Testing (Web, API, Network, Cloud)
✔ Vulnerability Assessment & Risk Management
✔ ISO 27001, SOC 2, NIST & Security Compliance
✔ Cloud Security (AWS & Azure)
✔ DevSecOps & CI/CD Security
✔ Identity & Access Management (IAM)
✔ Windows & Linux System Administration
✔ Security Architecture & Infrastructure Hardening
✔ SIEM, Security Monitoring & Incident Response
🛠️ 𝐖𝐡𝐚𝐭 𝐈 𝐃𝐞𝐥𝐢𝐯𝐞𝐫
🔹 Comprehensive Security Assessments
🔹 Actionable Remediation Recommendations
🔹 Compliance Gap Analysis & Readiness Support
🔹 Cloud & Infrastructure Security Reviews
🔹 Secure DevOps Implementation
🔹 Security Policies, Standards & Procedures
🔹 Risk Reduction & Security Improvement Strategies
⭐ 𝐖𝐡𝐲 𝐖𝐨𝐫𝐤 𝐖𝐢𝐭𝐡 𝐌𝐞?
✔ 15+ Years of Proven Cybersecurity Experience
✔ Expertise Across Security, Compliance, Infrastructure, and Cloud
✔ Business-Focused Security Solutions
✔ Strong Technical and Strategic Leadership
✔ Deep Understanding of Modern Threat Landscapes
✔ Clear Communication and Executive-Level Reporting
✔ Trusted Advisor for Long-Term Security Initiatives
✔ Hands-On Experience with Complex Security Environments
Cybersecurity is no longer optional. A single vulnerability, misconfiguration, or compliance failure can lead to financial loss, operational disruption, regulatory penalties, and reputational damage.
𝑰 𝒅𝒐𝒏'𝒕 𝒋𝒖𝒔𝒕 𝒊𝒅𝒆𝒏𝒕𝒊𝒇𝒚 𝒗𝒖𝒍𝒏𝒆𝒓𝒂𝒃𝒊𝒍𝒊𝒕𝒊𝒆𝒔, 𝑰 𝒉𝒆𝒍𝒑 𝒐𝒓𝒈𝒂𝒏𝒊𝒛𝒂𝒕𝒊𝒐𝒏𝒔 𝒆𝒍𝒊𝒎𝒊𝒏𝒂𝒕𝒆 𝒓𝒊𝒔𝒌𝒔, 𝒔𝒕𝒓𝒆𝒏𝒈𝒕𝒉𝒆𝒏 𝒅𝒆𝒇𝒆𝒏𝒔𝒆𝒔, 𝒂𝒏𝒅 𝒃𝒖𝒊𝒍𝒅 𝒔𝒆𝒄𝒖𝒓𝒊𝒕𝒚 𝒑𝒓𝒐𝒈𝒓𝒂𝒎𝒔 𝒕𝒉𝒂𝒕 𝒔𝒖𝒑𝒑𝒐𝒓𝒕 𝒃𝒖𝒔𝒊𝒏𝒆𝒔𝒔 𝒈𝒓𝒐𝒘𝒕𝒉.
𝐈𝐟 𝐲𝐨𝐮'𝐫𝐞 𝐥𝐨𝐨𝐤𝐢𝐧𝐠 𝐟𝐨𝐫 𝐚 𝐜𝐲𝐛𝐞𝐫𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐩𝐫𝐨𝐟𝐞𝐬𝐬𝐢𝐨𝐧𝐚𝐥 𝐰𝐡𝐨 𝐜𝐨𝐦𝐛𝐢𝐧𝐞𝐬 𝐝𝐞𝐞𝐩 𝐭𝐞𝐜𝐡𝐧𝐢𝐜𝐚𝐥 𝐞𝐱𝐩𝐞𝐫𝐭𝐢𝐬𝐞 with a business-focused approach, let's discuss how I can help secure your environment.
Connect with me today! 🌐
#CyberSecurity #InformationSecurity #Pentest #Compliance # DevOps #System Administration #IAM #GRC #CloudSecurity #SecurityOps #NIST #GuardianOfYourData #Cybersecurity #EthicalHacking #InformationSecurity
Penetration Testing
Information Security
Network Security
Cloud Security
Cloud Testing
Threat Detection
Microsoft Azure
Compliance
SOC 2
Linux System Administration
Vulnerability Assessment
DevOps
ISO 27001
Risk Assessment
Incident Response Plan
Google Workspace Administration
Data Analysis
Encryption
Investigative Reporting
Information Security Audit
Dwight G.
Ashburn, Virginia
$85/hr
5.0
13 jobs
I am a mid level to senior cybersecurity professional with 7+ years of hands-on experience delivering penetration testing, vulnerability assessments, risk analysis, and compliance-driven security programs for commercial, enterprise, and government environments.
I help organizations find real security gaps, reduce risk, and meet regulatory requirements—without unnecessary complexity or vendor lock-in.
Team Gala_Layo's background spans offensive security (Red Team), defensive controls, cloud security, identity & access management, and governance frameworks including NIST, ISO 27001, HIPAA, PCI-DSS, FedRAMP, and CMMC etc...I specialize in translating technical findings into executive-ready risk insights that drive action.
I am the President and Technical Lead at Gala_Layo, a cybersecurity firm trusted by federal agencies, regulated industries, and high-risk organizations.
What I Do Best
============
Penetration Testing & Ethical Hacking
---------------------------------------------
* Network, web application, API, wireless, and cloud penetration testing
* OWASP Top 10, SANS Top 25, manual exploitation & validation
* Tooling: Metasploit, Burp Suite Pro, Nessus, Nmap, OpenVAS, Aircrack-ng, Wireshark
* Actionable reports with proof-of-concept, risk scoring, and remediation guidance
Vulnerability & Risk Assessments
---------------------------------------
* NIST-aligned security risk assessments
* Vulnerability scanning & continuous risk scoring
* Risk registers, POA&M development, and control gap analysis
* STIGS
Tools: Tenable.sc, Qualys, Rapid7, ServiceNow GRC, RegScale
Cloud & Identity Security
------------------------------
* AWS & Azure security posture reviews
* IAM, MFA, SSO, and privileged access reviews
* WAF and cloud security configuration audits
Tools: Okta, Azure AD (Entra ID), Auth0, CyberArk
Governance, Risk & Compliance (GRC)
----------------------------------------------
* NIST RMF, NIST CSF 2.0, ISO 27001, HIPAA, PCI-DSS
* FedRAMP, CMMC, FFIEC, GSA compliance support
* Policy, SOP, and incident response plan authoring
* Change Control Advisory Board (CAB) experience
AI & Emerging Technology Security
-------------------------------------------
* Secure-by-Design and MLSecOps advisory
* AI risk assessments & Responsible AI impact analysis
* Prompt injection & LLM threat modeling
* Integration of AI into security workflows safely and responsibly
Industries Served
---------------------
* Government & Federal Contractors
* Healthcare & Life Sciences
* Financial Services
* Cloud & SaaS
* Critical Infrastructure
* Small & Mid-Sized Businesses (SMBs)
Tools & Technologies
-------------------------
* Operating Systems: Kali Linux, Ubuntu, Windows, macOS
* Languages: Python, JavaScript, Shell
* Security Tools: Nessus, Burp Suite, Metasploit, Rapid7, Qualys, Splunk
* Cloud: AWS, Azure
* Dev & Code: GitLab, VS Code, Snyk, SonarQube
* Virtualization: VMware, VirtualBox
Certifications & Education
-------------------------------
* Certified Ethical Hacker (CEH)
* CompTIA Security+
Security Clearance
------------------------
* Top Secret
Education
------------
* M.S. Information & Communications Technology – Information Systems Security
University of Denver (GPA 4.0, magna cum laude)
Why Clients Hire Me
------------------------
✔ Real-world offensive & defensive experience
✔ Clear, business-focused reporting (not scanner noise)
✔ Deep federal & regulatory knowledge
✔ Ability to explain complex risks to non-technical stakeholders
✔ Trusted advisor—not just a tool operator
Typical Projects
-------------------
* Penetration Testing & Red Team Engagements
* Vulnerability Assessments & Risk Registers
* NIST / ISO / HIPAA Readiness Assessments
* Cloud Security Reviews (AWS / Azure)
* Incident Response Planning & Tabletop Exercises
* AI & Emerging Tech Risk Assessments
Penetration Testing
NIST Cybersecurity Framework
Vulnerability Assessment
Web Application Security
Network Security
API Testing
Governance, Risk Management & Compliance
Risk Assessment
Zero Trust Architecture
Cloud Security Framework
Incident Response Readiness Assessment
User Identity Management
Compliance Testing
Information Security Audit
Cybersecurity Management
How it works
Post a job for freePost a job
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a Network Pentester in the United States on Upwork?
You can hire a Network Pentester in the United States on Upwork in four simple steps:
Create a job post tailored to your Network Pentester project scope. We'll walk you through the process step by step.
Browse top Network Pentester talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top Network Pentester profiles and interview.
Hire the right Network Pentester for your project from Upwork, the world's largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a Network Pentester?
Rates charged by Network Pentesters on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a Network Pentester in the United States on Upwork?
As the world's work marketplace, we connect highly-skilled freelance Network Pentesters and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Network Pentester team you need to succeed.
Can I hire a Network Pentester in the United States within 24 hours on Upwork?
Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Network Pentester proposals within 24 hours of posting a job description.
Find more freelancers
Top states for Network Pentesters in the United States