Hire the best PCI Compliance specialists

Check out PCI Compliance specialists with the skills you need for your next job.
  • $55 hourly
    IT Professional with over 30 years experience. 15+ years experience in web development. 8+ Years experience in PCI-DSS Consultation, including level 1 companies, working with QSA's to swiftly obtain compliance. For the past five years, I have been providing GDPR consultation to many small to medium-sized companies. Three years experience with ISO 27001 helping clients get and maintain ISO 27001 accredited certification. I spent 20 years working in various IT roles, mainly support, engineering, and web development, within one of the largest companies in the world. I was awarded Charted IT Professional status from the British Computer Society in July 2008. Since then, I have run my own company with a small team producing web-based platforms and services and offering freelance compliance consultation to small businesses. I have also worked as a CTO on several start-up projects managing their entire IT infrastructure and gaining valuable PCI compliance experience, essential to all e-commerce projects. Due to my experience and varied IT roles, I have a good knowledge of web design, programming, databases, security, SEO, troubleshooting, technical writing & more. I am a highly organised and reliable individual, utilising existing knowledge and experiences to find practical solutions to even the most complex project.
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    Compliance Consultation
    Data Privacy
    Vulnerability Assessment
    Information Security
    PCI DSS
    Data Protection
    Website Security
    PCI
    Compliance
    ISO 27001
    Risk Assessment
    Information Security Audit
    GDPR
    Web Content Accessibility Guidelines
    Security Analysis
  • $150 hourly
    I am the CEO & founder of BetterCyber Consulting, a cybersecurity consulting, technology, and managed services company helping startups and micro, small, and mid-sized companies create secure operating environments to increase business opportunities. I am also part of Upwork's Expert-Vetted Talent program. My priority is to create cost-effective, business-focused, and risk-driven cybersecurity solutions to help my clients secure their information assets against cyber threats. Before leaving corporate America, I held several cybersecurity positions, from operations to strategy and architecture, in Fortune 100 companies, such as PayPal Holdings, Inc. and Marathon Petroleum Corporation. I hold a bachelor's degree in Telecommunications Engineering from the Airforce University in Argentina, a master's degree in Information Security Engineering from the SANS Technology Institute, and many cybersecurity certifications, including CISSP (Certified Information Systems Security Professional) and GSE (GIAC Security Expert).
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    Information Security
    Security Policies & Procedures Documentation
    Cybersecurity Management
    System Monitoring
    Cloud Security
    Internet Security
    Information Security Audit
    Security Management
    Information Security Awareness
    Security Engineering
    Security Infrastructure
    Security Analysis
    Email Security
    PCI
    Network Monitoring
  • $70 hourly
    My extensive experience in DATABASE AND CYBERSECURITY over the past years include the following: 1). CISSP; Information security, cybersecurity 2) INFORMATION SECURITY/CYBERSECURITY/Vulnerability Testing 3). Oracle Performance Tuning 4). EBS R12 applications 5). Oracle Database technologies, SQL tuning,flashback, RMAN, RAC and others 6). Database System Security Scans and Vulnerability testing 7). Oracle Certified Professional 10g and 11g, 12c 9). Oracle Certified Database Security Implementation 10) AWS Solutions/Administration/EC2/S3/Cloud 11). HITRust Aware/PCI DSS Aware Please let me know if you have any questions.
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    PCI
    Data Protection
    Oracle Database Administration
    Linux System Administration
    Security Operation Center
    Security Engineering
    Oracle Database
    Information Security Governance
    Certified Information Security Manager
    PCI DSS
    Security Infrastructure
    Database Administration
    Network Penetration Testing
    Oracle Performance Tuning
    Information Security
  • $30 hourly
    With a degree in Computer Engineering and a passion for writing, my experience spans across writing whitepapers, blogs, research reports, content for websites, thesis for academic submissions, sales pitch, business proposals and more. I am highly organized and schedule my time to get things accomplished accordingly. I am detail-oriented and an excellent researcher. I can be entrusted with big projects as I prefer to complete my work before deadlines giving you ample time to review my work and provide feedback. I take pride in my work
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    Robotics
    Amazon Web Services
    Artificial Intelligence
    Blockchain
    Website Copywriting
    Editing & Proofreading
    ISO 27001
    Cloud Security
    Network Security
    Policy Writing
    Technical Writing
    Disaster Recovery
    PCI
    Project Risk Management
    Information Security
  • $125 hourly
    Do you want to sell Enterprise clients with confidence? Money-back guaranteed ISO 27001/SOC 2/FedRAMP/PCI projects and affordable virtual CISO (vCISO) service from the top (1M+ earnings) Security, Compliance, and Certification consultant on Upwork. 💪Facing the challenges of the security and privacy implications of AI products? -> Helped dozens of AI tech-focused SaaS solutions to address Enterprise requirements and score large clients. 😢Can you count the number of clients/prospects lost due to your company not providing the right answers to the questionnaires or not being certified for ISO 27001, SOC 2, FedRAMP, or PCI-DSS? 😢Are you busy developing your product or business and don’t have time and resources to be consumed by compliance efforts and endless meetings, halting your production for months? 💰Do you want to save money by knowing the right approach, security tool, or solution? 💪Want to have continuous access to a certified, creditable security, compliance, and privacy professional to manage your security framework? -> Continous virtual CISO (vCISO / fractional CISO) service with affordable weekly payments! 💪💸Do you want to feel confident that your security project will be successful? --> ISO 27001/SOC 2/PCI-DSS Certification projects are delivered with a MONEY BACK GUARANTEE! If you don’t get certified, all my fees will be refunded! 😟Need world-class, battle-proof security and privacy policies? Maybe need it quickly? The kind of ones that have passed audits by KMPG, PWC, Deloitte, E&Y, Pepsi, Rolex, Uber, Verizon, Facebook, and many others? 🤔Already purchased a DIY compliance tool (Drata, Vanta, Thoropass/HeyLaika, Sprinto, OneTrust Compliance Automatization/Tugboat Logic, SecureFrame, Strike Graph, Audit Board, and so on) but don’t know the next step or don’t have time for it? 😱Do you want to ensure your remote work team works securely? 📣If you answered yes to any of the above, you can easily get it solved! Click on the green invite button located at the top right corner to invite or message me. 📣📣 Working with me, you will: ★ Get the burden of security and compliance management taken off your shoulder, so you can focus on building your company ★ Get an end-to-end, professionally managed service ★ Get a consultant aiming for long-term support and providing advice and services to enable you to achieve growth-phase plans and targets by establishing a solid security and governance framework to win Enterprise clients. 📣That is what my clients are saying about my work: 📣 “Attila was a massive time saver for our team. He quickly grasped our service and helped complete a security questionnaire for an important Enterprise client within short notice.” - CEO of GoCertify.me. “Attila is a pro-security consultant. He is your guy if you want to prepare, implement and achieve ISO 27001, SOC2, or other security certifications. We got our ISO 27001 certification completed with excellent results with the help and guidance from Attila.” CEO of Kendis.io Securing your business, passing security assessments by clients or prospects, and achieving a security certification (SOC 2 report, ISO 27001, PCI-DSS, HIPAA, or FedRAMP) 𝙨𝙝𝙤𝙪𝙡𝙙 𝙣𝙤𝙩 𝙗𝙚 𝙖 𝙘𝙪𝙢𝙗𝙚𝙧𝙨𝙤𝙢𝙚 𝙖𝙣𝙙 𝙥𝙖𝙞𝙣𝙛𝙪𝙡 𝙚𝙭𝙚𝙧𝙘𝙞𝙨𝙚. 👌 --- My stats are: ✅Saved tens of thousands $$$$$ for clients, advising them on the right security tools, solutions, and approach ✅Enabled businesses to generate increases in ARR 💵 by getting them compliant and secure ✅#1 in Information Security and IT compliance categories (1M+ earned) ✅Supporting all time zones ✅Long-term engagements ✅Professional certifications (CISA, CISSP, ISO 27001 IA) Security questionnaire and vendor assessment tools: CyberGRX, Panorays, KY3P (S&P, PWC), RSM, CyberVadis, SIG, CAIQ, VAS, HECVAT, OneTrust, Compliance management tools: Drata, Vanta, Onetrust Compliance Automatization - Tugboat Logic, Sprinto, SecureFrame, Thoropass (HeyLaika), Trust Cloud, Strike Graph, Audit Board, ISMS.online, Instant27001.com Security/Compliance frameworks: ISO 27001, SOC 2, FedRAMP, NIST 800-53, NIST 800-171, NIST CSF, TISAX, HIPAA, HITRUST CSF, GDPR, NERC, ISO 27017, ISO 27018, CMMC, CMMI, TX-RAMP, StateRAMP, AZ-RAMP, NY DFS 23 / NYCRR Part 500, PCI-DSS, FFIEC, C5, ENISA, Center of Information Security (CIS), IRAP. Projects not for me: ✖Asking to hack/crack/access someone else accounts, systems, social media, etc ✖Asking to fill security questionnaires, providing the appropriate answers but not implementing controls ✖Asking to create falsified audit or assessment reports
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    Certified Information Security Manager
    Artificial Intelligence
    SOC 2
    Information Security Audit
    Certified Information Systems Security Professional
    FedRAMP
    ISO 27001
    Security Assessment & Testing
    Penetration Testing
    Information Security Consultation
    IT Compliance Audit
    Cybersecurity Management
    Security Policies & Procedures Documentation
    Risk Assessment
    Information Security
  • $200 hourly
    𝗜'𝗺 𝗮𝗻 𝗲𝘅𝗽𝗲𝗿𝘁 𝘀𝗲𝗿𝘃𝗲𝗿 𝗮𝗱𝗺𝗶𝗻𝗶𝘀𝘁𝗿𝗮𝘁𝗼𝗿 & 𝗰𝗹𝗼𝘂𝗱 𝗮𝗿𝗰𝗵𝗶𝘁𝗲𝗰𝘁 𝘄𝗶𝘁𝗵 𝗱𝗲𝗰𝗮𝗱𝗲𝘀 𝗼𝗳 𝗲𝘅𝗽𝗲𝗿𝗶𝗲𝗻𝗰𝗲; 𝗵𝗲𝗿𝗲 𝘁𝗼 𝗵𝗲𝗹𝗽 𝗮𝗹𝗹𝗲𝘃𝗶𝗮𝘁𝗲 𝘆𝗼𝘂𝗿 𝗽𝗮𝗶𝗻 𝗽𝗼𝗶𝗻𝘁𝘀! 𝗜 𝗽𝗿𝗶𝗱𝗲 𝗺𝘆𝘀𝗲𝗹𝗳 𝗼𝗻 𝗽𝗿𝗼𝘃𝗶𝗱𝗶𝗻𝗴 𝘄𝗵𝗶𝘁𝗲-𝗴𝗹𝗼𝘃𝗲 𝗰𝗼𝗻𝗰𝗶𝗲𝗿𝗴𝗲-𝗹𝗲𝘃𝗲𝗹 𝘀𝘂𝗽𝗽𝗼𝗿𝘁. 𝗖𝗵𝗲𝗰𝗸 𝗼𝘂𝘁 𝗺𝘆 𝗿𝗲𝘃𝗶𝗲𝘄𝘀; 𝗺𝘆 𝗰𝗹𝗶𝗲𝗻𝘁𝘀 𝗿𝗮𝘃𝗲 𝗮𝗯𝗼𝘂𝘁 𝗺𝘆 𝘀𝗲𝗿𝘃𝗶𝗰𝗲𝘀. 𝗔𝗻𝗱 𝗜'𝗹𝗹 𝗯𝗲 𝘀𝘂𝗿𝗲 𝘆𝗼𝘂 𝗱𝗼 𝘁𝗼𝗼! 📞 Invite me to your Upwork job to book a free consultation call. I’m not your average tech. As a member of your team, I go above and beyond to provide you with an exceptional experience: ✅ Unparalleled reliability, patience, communication & professionalism ✅ Over a decade of server/system administration experience ✅ 100% track record with over 5,000 Upwork hours ✅ Exceptional problem-solving skills ✅ Very fast learner of new technologies Here are just a few of the technologies & service providers that I have extensive experience working with: 🛠 Amazon Web Services AWS (EC2, RDS, S3, Route53, Lamda, +) 🛠 Google Cloud Platform & Google Suite Administrator 🛠 Azure Cloud Architect & Server Administrator 🛠 Digital Ocean, Linode, Godaddy, Bluehost, Hostgator & many other hosts 🛠 cPanel/WHM, Plesk, Webmin, DirectAdmin, No Panel Servers 🛠 LAMP stack (Linux, Apache, MySQL, PHP) ⚡ I am fully insured with $1,000,000 in professional liability coverage. Anyone touching your critical servers should be! I specialize in server & application security, performance optimization, and on-demand support services. However, the list doesn’t end there. I’ve spent every working day of the past decade putting out fires. I’ve dealt with hacked servers & websites, mission-critical technical failures, application failures, and many other issues. It has been my utmost pleasure to take on the challenge of both resolving the technical issues while providing customer service with a smile during the most difficult of times. Being the best in class, excellence requires effort. Simply meeting expectations is not sufficient. Anticipating and satisfying one’s unknown needs is what makes for an incredible consultant. Beyond my technical skills, these are lessons the past decade has afforded me. ⭐⭐⭐⭐⭐ 𝟱-𝗦𝘁𝗮𝗿 𝗥𝗲𝘃𝗶𝗲𝘄𝘀 ❝ Steven is the best freelancer I have ever hired (and I have hired very many in various venues). Whipsmart, committed, and conscientious, I am utterly blown away by the quality of his work, and of his funny, personable manner. Highest possible recommendation. ❞ ❝ Steven is fantastic and goes above and beyond for his clients. We will 100% use him again and recommend him enthusiastically. THANK YOU! ❞ ❝ Steven is amazing. Hire him before he raises his rate. Super helpful and responsive. If you need help with anything related to servers, hosting, migration, performance optimization, WordPress support, security or overall optimization, look no further. ❞ ❝ Steven is a Gem. Simply put, Steven is the most knowledgeable IT person I have ever met. He helped me navigate through a very delicate situation that threatened to shut down my business completely. Without Steven, I probably would have had to close down my business and let my people go. He has a DEEP working knowledge of servers and server admin as well Wordpress and many other tools. He is EXTREMELY Professional and a great communicator. I will hire Steven again. ❞ I can support you with… + Linux & Windows Server Administration + Cloud Architecture, Performance & Cost Optimizations + Best practice performance optimization, server security & on-demand support. + Deployment of elastic cloud server clusters. + Managed migrations & system upgrades. + Mitigation of DDoS attacks & other malicious activity. + PCI Compliance & Resolution of failed vulnerability audits & scans. + Application Support - WordPress, Moodle, Magento, WHMCS, Drupal + Disaster Recovery - Backup plan creation & testing. + Additional Web Host Support - When your hosting provider drops the ball. + Mail Security & Authentication - SPF, DKIM, DMARC Support + DNS Management + Project Management + Customer Support + Marketing - PR, SEM (search engine marketing), Pay-Per-Click (PPC) on Google, Bing, Facebook, Twitter, and others. Extensive SEO work (on-page & off-page optimization). Re-targeting campaigns (Adroll, Perfect Audience, Google, Facebook, Youtube) Affiliate marketing via directly managed programs & third-party networks (CJ, Shareasale, ClickBank, Pepperjam, and others.) Mail marketing automation (Mailchimp, Infusionsoft, Marketo, Convertkit) and many CRM systems. + Development - PHP & Python. + Business Management - I've worn many other hats during the management of my business, including work in HR, support, sales, finance, marketing, PR, etc. I'd love to use this experience to help you out! Drop me a line to further discuss your needs. Thanks, 𝗦𝘁𝗲𝘃𝗲𝗻 𝗛. 𝗖𝗹𝗮𝗿𝗸𝗲 Clarkes.Team
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    Amazon Web Services
    Google Cloud Platform
    DigitalOcean
    Website Optimization
    PCI
    Keap Marketing
    Malware Removal
    PHP
    Cloudflare
    Vulnerability Assessment
    Mailchimp
    Linux System Administration
    Magento
    WordPress
    Workspace
  • $30 hourly
    I have executed some 44 projects in upwork in information security, governance, IT service management, SIEM, and others and earned customer accolades. I continue to nurture my skills that will benefit my customers. I am all for value creation in IT because every penny spent must return value and do the business and IT a secure and safer workplace. Govind has spent 25 years in the IT and he is - ISO 27001 Lead Implementer from PECB Canada - ITIL Expert V3 , ITIL4 FL, ITIL4 MPT Certified - Certified ISO 27001 Lead Auditor, ISO 22301 Lead Auditor, ISO 20000 Lead Auditor - COBIT5 certified in the IT Governance - PMP, PRINCE2, - CSQA, - ISO 20000 Implementer - DevOps Master Currently pursuing education in CISSP and Data Privacy Skills :- Over last decades he has extensively worked and provided solutions in below areas. He brings multiple skills. - Implementing GRC - HIPAA, SOX, PCI/DSS, HITRUST 9.3, FedRamp, SOC2 (T1/T2) - Implementing Unified Controls for Security (UCF) - Implementing Information Security framework using ISO 27001/SOC2/ISO 22301 - Cybersecurity incident response management using NIST, SANS, ISO 27035, COBIT - Risk Assessment, IT Auditing - Jira Implementation both Project and ServiceDesk - Gap Analysis of IT Asset management, Compliance, COBIT Processes - Implementing Best Practices using ITIL/COBIT5 Processes - Implementing BPM Solutions using Appian, Bonitasoft, AgilePoint - Implementing Monitoring framework for IT Devices using Zabbix - Performance and Capacity solutions - Workflow automation - IT Service management using ServiceNow as a architecture - Implementing DevOps End to end for CI, CT, CD - Gap Analysis for CMDB and road map for improvements - A well groomed developer in scripting and development in various technologies - Attlasian Jira admin activities - Robotic Process Automation using UIPath, BluePrism, AutomationAnywhere Education : He is a post graduate in the Statistics with a specialty in Operations research and SQC. He then did Post graduate diploma in the Reliability. He has worked in niche technologies and fortune 500 clients since 2 decades across the globe. Extras :- He is editor of a book called "How to reduce cost of software testing" published by CRC Press and has spoken in conferences and written articles. Passion for Excellence:- He is passionate on creating value in the information technology space and is doing research in various areas such as IT Asset management, IT Cost management, Performance and scalability management. He is eager to help clients in below skills a.Implementing IT Governance, Risk and Compliance using COBIT5 framework b.Implementing ITIL best practices c.Implementing Test Automation using Selenium and other tools d.Implementing DevOps solutions in cloud and non cloud e.Implementing Security solutions using ISO 27001 and COBIT5 framework f.Implementing Business Process Automation using Bonitasoft, Agilepoint NX, Appian, BPM Online and others g.Implementing SIEM using Zabbix and other tools h.Implementing ServiceNow ITSM Tool as an architect i.Implementing a monitoring framework using Zabbix for capacity management j.Compliance like HIPPA, PCI DSS j.IT Audits Availability : I am available for assignments immediately on request. Major clients Worked : British Telecom, MetLife, Liberty Life, Euromax, Covad, UHI and many more. Visas : I had H1 Visa US, WP for UK, Netherlands, South Africa. Currently have B1 visa for US and can travel if there is a need Will be glad to associate to create value in IT
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    Unified Threat Management
    Project Risk Management
    Business Continuity Plan
    ISO/IEC 20000
    Risk Assessment
    HITRUST Common Security Framework
    SOC 2 Report
    PCI
    Information Security
    HIPAA
    Compliance
    Governance, Risk Management & Compliance
    COBIT
    ISO 27001
    ITIL
  • $60 hourly
    I am a Certified Compliance and Ethics Professional - International (provided by SCCE). I have an Advanced Diploma in Accounting and Business (provided by ACCA). I am ACCA certified. I have 13 years of experience in Compliance, Internal Audit, and Risk Management in Fortune 500 companies in diverse industries (Information Technology, Financial Services, Pharmaceuticals, FMCG, Telecom, and others). I am an experienced professional with a proven track record of delivering profitability, sustainable business growth, operational optimization, and driving innovation. My areas of focus: 1. FCPA, UKBA Compliance. 2. AML/CTF. 3. KYC (Due Diligence). 4. Information Security (ISO 27001, SOC2, NIST). 5. Data Privacy (GDPR, HIPAA, CCPA, PECR, etc). 6. PCI:DSS Compliance. 7. Risk Management (ERM). 8. Internal Audit. 9. Contracts and Policies writing. 10. MSA and ADA compliance. Feel free to contact me whenever it will be convenient for you. Looking forward to hearing from you and hope for our productive cooperation. Regards,
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    Internal Control
    Information Security Audit
    PCI
    Policy Writing
    Anti-Money Laundering
    IT Compliance Audit
    GDPR
    ISO 27001
    ISO 9001
    Due Diligence
  • $45 hourly
    PCI DSS Consultant for all PCI DSS Level 1-4 v3.2 for payment gateways organizations and E-commerce brands. Involved with QSA, responsible for VAPT, Patching, Worked on Hardening security. Helping and consult to meet all 12 Major Requirements and 200+ sub requirements, for E-commerce Level 3 and 4 SAQ. Regular security audits, cost optimization, backup audits. I am always look for new challenges Expert in the field of ISO 27K1 and PCI DSS compliance. Accomplished in handling highly sensitive information and managing global services. Expert as Internal Auditor for SOC 2 & 3 assessments and helped SAAS based, Fintech & Cryptocurrency companies to achieve SOC report every year.
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    System Security
    SOC 2
    Governance, Risk Management & Compliance
    Information Security Consultation
    Information Security
    Company Policy
    Amazon Web Services
    Information Security Audit
    ISO 27001
    Risk Assessment
    NIST SP 800-53
    IT Compliance Audit
    Compliance Consultation
    PCI DSS
  • $150 hourly
    Please don't contact me regarding hacked accounts. There is nothing I can do and it's illegal to try and hack them back. Sorry! For over 10 years my greatest passion has been cyber security. For the first 6 years I worked for NCC Group, the largest cyber security consultancy in the world and gained a wide range of skills and experience working for high street banks, global corporations and UK government ministries. I've now moved on and have started my own business, my greatest passion is helping small and medium sized businesses fix their security problems. I eat, drink and sleep cyber security. I have experience testing a wide range of technologies, including but not limited to web applications, internal networks, external networks, mobile applications, network devices and Wi-Fi. Having a broad range of experience allows me to rapidly place in context of the asset I'm testing within the clients environment. My focus is on helping web and mobile developers, network administrators and business owners ensure their products adhere, not just to best practice but to the highest security standards. By using a combination of manual and automated testing I am able to produce results in a timely and cost effective manner. I assist with remediation by providing advice on which areas of vulnerability to focus on first and how best to implement fixes. I have a track record of understanding highly technical security issues and being able to convey them to both a technical and management audience. I'm always happy to discuss client requirements and work with them to identify the best methods to achieve their objectives. As part of the process, I offer a pre and post engagement call to ensure we are a perfect match and that I have achieved your goals.
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    PCI
    Information Security Awareness
    Electron
    Configuration Management
    Ethical Hacking
    Cybersecurity Management
    Penetration Testing
    Encryption
    Firewall
    Network Monitoring
    Network Penetration Testing
    Computer Network
    Website Security
    Mobile App Testing
  • $100 hourly
    Hello I am an experienced cyber security professional and owner of the UK based boutique consultancy Periculo.co.uk Having drawn on my experience over a number of years, working with a huge variety of customers ranging from construction companies to banks, charities and MOD contractors I became a freelancer to offer affordable expertise that benefits everyone. I strongly believe that every organisation needs to take security and compliance seriously however not all have the big budget that most consultancys demand for their work. Through my own internal processes I'm able to quickly deliver high quality, best in class security and compliance consultancy and testing. My organisation is accredited to Cyber Essentials, Cyber Essentials Plus, IASME Gold and GDPR readiness - so I practice what I preach and know how to implement it in an efficient way. If you require an affordable security and compliance expert who always reaches a solution with the appropriate risk v reward balance then please get in touch. - Able to assess, audit and certify to GDPR ready, IASME Gold, Cyber Essentials and Cyber Essentials + - GDPR Advisory - Providing project consultancy (From small changes to extensive, high risk programs) - Providing operational consultancy and escalation - Supplier and internal assessments - Infrastructure Security and configuration, AWS, Azure - Security operations consultancy and build - Business and technical policy, standards author Cover all aspects of security including penetration testing, vulnerability scanning etc. ** I am currently available for hire**
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    ISO 27001
    Information Security Audit
    Vulnerability Assessment
    Penetration Testing
    Information Security
    Cybersecurity Management
    Security Testing
    Technical Writing
    Microsoft Office 365
    PCI
    Cloud Computing
    Network Security
    Data Protection
    Information Security
  • $75 hourly
    An experienced Information Security Specialist with 20 years of experience: Cyber Security Framework (SANS, NIST, CIS, ISO, GDPR, SWIFT CSP & CSCF) Implementer, PCI DSS QSA, SOC 2, ISO 27001 Lead Auditor, ISO 27001 Lead Implementer, Certified Data Privacy Solutions Engineer (CDPSE), IT Audit compliance consultant
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    NIST SP 800-53
    SOC 2 Report
    Cybersecurity Management
    Policy Writing
    Information Security Consultation
    Regulatory Compliance
    Website Security
    Security Policies & Procedures Documentation
    HIPAA
    Vulnerability Assessment
    PCI DSS
    IT Compliance Audit
    ISO 27001
    Information Security Audit
    Cybersecurity Management
  • $50 hourly
    I am a cyber-security professional with experience in Information Security audits, Risk Management, Risk Assessment, Vendor Risk Assessment, Information Security Policy and procedures formulation, compliance with various security standards for several global clients and also performed cyber-security compliance assessments using NIST 800-53, NIST CSF based controls and supports remediation and mitigation activities. I have a deep understanding of various laws such as HIPAA. GDPR, Data Protection Act and standards such as ISO 27001:2013, PCI-DSS etc.
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    IT Compliance Audit
    Information Security Audit
    Financial Audit
    Data Privacy
    GDPR
    PCI DSS
    PCI
    ISO 27001
    Risk Assessment
    Cybersecurity Management
  • $125 hourly
    Having worked for many Fortune 100 companies, I now run a boutique cybersecurity consultancy called Careful Security. We serve businesses of all sizes, We providing a 360-degree cybersecurity solution by #Securing Website #Protecting Data #Pass an audit/vendor questionnaire/cyber-insurance questionnaire #SIEM Solution for security monitoring and alerting Past Accomplishments # Designed and Implemented security controls for Warner Bros. iconic shows and movies such as Harry Potter, The Game of Thrones, Curb your enthusiasm. ## Secured video games for EA Sports - FIFA, The Sims, and Madden. ### Secured financial information for high net-worth clients for Goldman Sachs. #### Managed security of personal information for the millions of policyholders in State Farm Insurance. ##### Presented at Conferences and written articles for security journals.
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    PCI
    Email Security
    Certified Information Systems Security Professional
    ISO 27001
    Security Engineering
    Security Infrastructure
    Compliance Consultation
    Cloud Security Framework
    Web Application Security
    Information Security Audit
    Information Security
    Vulnerability Assessment
    Penetration Testing
    Security Policies & Procedures Documentation
  • $25 hourly
    I'm a linux sysadmin and have worked in a web hosting company for more than eight years and now doing a full-time sysadmin consulting.  I handle servers from co-locations/data centers to different vps and cloud hosting providers such as Rackspace, Amazon, Linode, DigitalOcean, and Softlayer.  I managed mostly lamp-stack servers on CentOS/RHEL and Debian/Ubuntu and several cPanel/WHM servers for shared hosting clients.  I have designed and deployed mid to large scale highly scalable, fault tolerant, automated and secure IT infrastructures using cutting edge complex technologies such as cloud computing, aws/ec2, NoSQL databases, hadoop, load balancers, chef/puppet configuration management systems, varnish cache, nginx/apache web servers, solr search and indexing, virtualization, LAMP and python frameworks, RoR etc.   Operating Systems: - Servers: RHEL, CentOS, Debian, Ubuntu, openSUSE, solaris Cloud and Hosting Providers: - Manage instances deployed in Rackspace, Amazon, and Linode - Manage dedicated servers in datacenter co-locations and Softlayer Virtualization and Cloud technologies: - Xen: setup, configure, and manage virtual machines running Debian and CentOS -openvz : setup, configure, manage and migrate virtual machines running on CentOS - OpenStack and Eucalyptus: setup, configure, and manage private cloud deployments Hosting Control Panels: - Manage multiple cPanel servers for shared hosting clients and services - Previous experiences include Plesk, zpanel, directadmin, and Webmin control panels DNS: -- Manage DNS cluster on Cpanel DNSOnly versions. Manage zones hosted and integrated with Cpanel servers. - Manage Bind DNS service on dedicated and Cpanel servers (WHM and DNSOnly versions). Manage zones hosted at Softlayer and integrated with Cpanel servers - Managed DNS from different hosting providers (Godaddy, NetworkSolutions, SRSPlus) as well as migrating entire DNS/NameServers between different providers.  Backups: - Cpanel Backups, and different rsync scripts (rsnapshot, rsback, rdiff), remote ftp backup. - Administer backups from cloud providers such as AmazonS3 and Rackspace CloudBackup Version Control Systems: - Git: setup and manage dedicated git hosting server running Gitolite and Gitlab - Github: manage organizations and private repositories. Setup deploy keys and webhooks Alerts and Monitoring: - Configure Nagios/opesview and cacti for servers and services monitoring - Server graphing with NewRelic and Pingdom services. Previous work experience includes Cacti, Graphite, MRTG, and PRTG. Drupal CMS Administration: - Managed Drupal 5,6, and 7 sites on LAMP-stack from different hosting providers - Drupal server and site performance evaluation, tuning, and optimizations - Setup and configure Drupal integration with CiviCRM, ApacheSolr/Tomcat, Memcached, APC, and Varnish - Applies Drupal standard and security updates on different site environments Server Security: - Experienced with setting up PCI Compliant servers. Scanning tools include dedicated Nessus server and third-party scanner like Trustwave and ControlScan - Setup and manage firewall rules with iptables, ufw, configserver firewall (csf), Rackspace RackConnect, AWS SecurityGroups, dedicated firewall devices.  - Rkhunter, Chkrootkits, SSHD, TCP Wrapper, fail2ban.
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    Google Cloud Platform
    WebHost Manager (WHM)
    AWS Systems Manager
    Plesk
    PCI
    OpenVZ
    cPanel
    Apache Administration
    LAMP Administration
    Linux System Administration
  • $95 hourly
    I am a Cyber Security and Information Technology expert with 20 years experience ranging from small start-ups to multi-billion euro businesses. I hold a CISSP, the gold standard of Information Security Qualifications. I specialise in Strategy, Governance, Risk and Compliance - this makes me ideal for projects such as: Helping you achieve Cyber Essentials or IASME Governance status PCI-DSS & ISO 27001 compliance programs and audits Being your Cyber Security / Info Sec manager or CISO on a part-time basis Selecting and managing IT and Cyber Security suppliers on your behalf Writing, reviewing and updating your IT and Cyber Security policies Security Awareness Training I am an award winning public speaker and trainer and my Cyber Security Awareness Training is very popular delivered in person or from my online studio to clients around the world.
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    GDPR
    Security Infrastructure
    Information Security Awareness
    ISO 27001
    PCI DSS
    Information Security Audit
    Information Security Governance
    Certified Information Systems Security Professional
    PCI
    Information Security
    Security Policies & Procedures Documentation
    Incident Response Plan
    Vulnerability Assessment
    Security Assessment & Testing
    Network Security
  • $165 hourly
    I am an accomplished and experienced Cyber Security Engineer, CISO, and consultant with over 20 years experience in government, commercial, non-profit and private organizations. I'm a Certified Information Systems Security Professional (CISSP) and CMMC Registered Practitioner. My education includes a Master's degree in Information Assurance and Security specializing in Digital Forensics, a Bachelor's Degree in Information Technology, and daily, hands-on work governing, securing and administering complex information technology environments. My current efforts include cybersecurity compliance implementations for regulated industries and government contractors including the NIST Cybersecurity Framework, Risk Management Framework, NIST SP 800-171, and Cybersecurity Maturity Model Certification (CMMC). For those not bound to other regulatory guidelines, I assist with implementation of the Center for Internet Security (CIS) Critical Security Controls and the CIS Risk Assessment Method. I assist with expert advice, gap assessments, requirements and implementation reviews. I help develop and refine cybersecurity documentation including System Security Plans, POA&Ms, and Policies and procedures. I will share national background check results for qualified opportunities.
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    Gap Analysis
    Vulnerability Assessment
    Cybersecurity Monitoring
    Amazon Web Services
    Governance, Risk Management & Compliance
    Security Engineering
    Security Policies & Procedures Documentation
    Security Information & Event Management
    Cloud Security
    Information Security Awareness
    Cybersecurity Management
    Certified Information Systems Security Professional
    Network Security
    Cybersecurity Management
    Information Security
  • $54 hourly
    Hello, I am a Certified Information Security Management System Auditor (ISO/IEC 270001) with 15+ years’ experience in Privacy and Security Compliance. I spearheaded the implementation of the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules for the State of Colorado encompassing 60+ computer information systems and 300+ physical facilities. • Ensured compliance with privacy and security frameworks (HIPAA/HITECH, CCPA, GDPR, PCI, etc.). • Defined policies, procedures and controls in line with ISO-27001 and NIST standards. • Reviewed legal agreements (BAs, RFPs, etc.), negotiated and drafted privacy and compliance agreements with customers and partners. • Implemented continuous improvements to privacy and security compliance through an ongoing risk management process utilizing multiple Governance, Risk and Compliance (eGRC) solutions. • Developed and delivered privacy and security awareness training programs to 7000+ employees and 500+ contractors annually. • Authored privacy and security policies, wrote standard operating procedures and ensured they were implemented and followed. • Audited all types of Covered Entities and Business Associates including Hospitals, Clinics, Dental Facilities, the Department of Corrections, Child Welfare, Mental Health Institutes, Nursing Homes, Insurance Companies, Back Ground Investigation Units, Alcohol and Drug Abuse Treatment providers and facilities across the state of Colorado including 64 counties and numerous private business associates. • Designated as the Privacy and Security Authority. Investigated OCR complaints and violations, monitored all Privacy and Security Breach Notifications. • PRIVACY and SECURITY RISK ASSESSMENTS/AUDITS: is a view of an organization’s compliance with its privacy and security policies and procedures, applicable laws, regulations, service-level agreements, standards adopted by the entity and other contracts. The audit measures how closely the organization’s practices align with its legal obligations and stated practices. The results of the assessment or audit are documented for management sign-off and analyzed to develop recommendations for improvement and a remediation plan. Resolution of the issues and vulnerabilities noted are monitored to ensure appropriate corrective action. Ad hoc assessments/audits may arise as the result of a privacy or security event or due to a request from an enforcement authority. INFORMATION MANAGEMENT: a. Data sharing and transfers i. Data inventory ii. Data classification b. Privacy program development c. Managing User Preferences d. Incident response programs e. Workforce Training f. Accountability g. Data retention and disposal (FACTA) h. Online Privacy i. Privacy notices j. Vendor management i. Vendor incidents k. International data transfers i. U.S. Safe Harbor and Privacy Shield ii. Binding Corporate Rules (BCRs) iii. Standard Contractual Clauses iv. Other approved transfer mechanisms l. Other key considerations for U.S.-based global multinational companies i. GDPR requirements m. Resolving multinational compliance conflicts i. EU data protection versus e-discovery PROFESSIONAL CERTIFICATIONS ISO/IEC 27001 – Certified Lead Auditor, Information Security Management System Audit CIPP and CIPP/G – International Association of Privacy Professionals CHP – Certified HIPAA Professional, HIPAA Academy CSCS – Certified Security Compliance Specialist, HIPAA Academy CPC – Certified Procedural Coders, American Academy of Procedural Coders ISO/IEC 27001 specifies a management system that is intended to bring information security under management control and gives specific requirements. Organizations that meet the requirements may be certified by an accredited certification body following successful completion of an audit. Information security management systems — Requirements. The 2013 release of the standard specifies an information security management system in the same formalized, structured and succinct manner as other ISO standards specify other kinds of management systems. ISO/IEC 27002 — Code of practice for information security controls - essentially a detailed catalog of information security controls that might be managed through the ISMS. IAPP (CIPP) - The International Association of Privacy Professionals is a nonprofit, non-advocacy membership association founded in 2000. It provides a forum for privacy professionals to share best practices, track trends, advance privacy management issues, standardize the designations for privacy professionals and provide education and guidance on opportunities in the field of information privacy.
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    Security Engineering
    Financial Audit
    Information Security
    Legal Research
    GDPR
    Privacy Law
    PCI
    Information Security Audit
    Information Security Governance
    Risk Assessment
    Compliance
    ISO 27001
    Policy Development
    HIPAA
    Policy Writing
  • $55 hourly
    I’ve helped companies get ISO 27001/SOC-2/PCI-DSS/FedRAMP/CMMC certifications and compliance against standards such as NIST and HIPAA. I offer 𝗠𝗢𝗡𝗘𝗬-𝗕𝗔𝗖𝗞 𝗚𝗨𝗔𝗥𝗔𝗡𝗧𝗘𝗘 to my clients against ISO 27001, SOC 2 and PCI-DSS compliance! Are your clients requesting security certifications or compliance against HIPAA, ISO 27001, SOC 2, PCI-DSS, or FedRAMP etc.? Do you want a cost effective solution for achieving and maintaining compliance? Do you want help is filling out the security assessment questionnaires and want someone to respond in a way that you are able to win the deal? Do you want surety/ confirmation that your certification project will be a success and you won't loose money over consultation? If you have already purchased a DIY compliance tool (Drata, Vanta, Thoropass/HeyLaika, Sprinto, OneTrust Compliance Automatization/Tugboat Logic, SecureFrame, and so on) but don’t have the time and energy to achieve and maintain compliance, Do you want to know and enhance your company's current security posture? MY PROFILE I have over 7 years of experience and have worked within IT GRC (Governance, Risk, Compliance), internal controls and review assurance roles within financial, telecom, fintech and banking industry. The combination of Information technology, accounting & auditing has molded me into an individual who can perform IS Audits (General Controls, Application Controls, Specialized Audits, IT policy & SOPs), IT risk reviews (Risk Assessments, BCP & DR, Risk Mitigation & Control Design), Functional Reviews & QA (Quality Assurance) Services, IT security consultancy (IS Policy & Implementation under different frameworks i.e. 27001, NIST, COBIT 5, PCI, HiTrust, HIPAA, GDPR, SOC 2, SOX) and pre-implementation & post-implementation project reviews, BRD creation by following industry best practices. I can secure your cloud environment with expertise in AWS and Azure by following security hardening best practices. MY CREDENTIALS - CISSP (Certified Information Systems Security Professional) - USA - CISA (Certified in Information System Audit) - USA - CRISC (Certified in Risk & Information Systems Control) - USA - CGEIT (Certified in Governance of Enterprise IT) - USA - SQL Fundamentals (Oracle) - CEH Certified (Certified Ethical Hacker) - Cyber security Fundamentals Certification - Kaspersky - Google Analytics - NSE 5 (Network Security Analyst) Tags: Information Security Analyst Chief Information Security Officer ( CISO ) Information Security Manager SOC Analyst SOC (Security Operations Center) Tools: SIEM, CrowdStrike Falcon, Fortinet, FortiAnalyzer, FortiGate, FortiSIEM, Stellar Cyber, Cylance, Splunk, AWS CloudWatch, Microsoft Defender (Azure), AWS CloudTower, GCP
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    Information Security Consultation
    Information Security
    Cybersecurity Management
    Security Policies & Procedures Documentation
    Security Information & Event Management
    PCI
    Cloud Security Framework
    NIST SP 800-53
    SOC 2
    HIPAA
    Information Security Audit
    IT General Controls Testing
    Security Operation Center
    ISO 27001
    SOC 2 Report
  • $50 hourly
    Following is a summary of my skills: • ISO27001 compliance and gap analysis • IT Security Policies and Frameworks • PCI DSS Assessment level 1 & 2 for merchants and Service provider • Penetration testing • SIEM and Forensics analysis • NIST 800-53 • Risk Assessment and Treatment • Application security vulnerabilities, testing techniques, and the OWASP framework • GDPR • Vulnerability Scanning Experience: • Advise Network and system team to securely build/change Azure and AWS cloud infrastructure for existing and potential clients. • Engage with Client to understand their infrastructure requirements to build and integrate AWS API’s and services. • Maintain and improve ISMS framework that includes SOA, Risk assessment and treatment plan, Risk register and ISM forum to convey the risk to management for their review and support. • Maintain security certifications, including ISO 27001, IRAP and PCI dss. • Conducts Gap assessment as per ISM, PSPF, ISO27001, PCI, NIST and GDPR. • Monitor and assure compliance with information security and privacy regulations, including APRA CPS 234, Privacy Act and GDPR • Manage internal and external audits and remediation • Deliver training programs for security and privacy awareness • Conduct/review security risk assessments of assets and projects • Manage supply chain security • Support Sales and commercials team in responding to security questionnaires • Provides application security services including secure coding techniques and reviews, education & awareness, process and tools, security testing support and guidance for internal software development projects • Reviews information security policies, incident response plans, change management, vulnerability management, patch management policies, etc., as they apply to various facets of the infrastructure in scope. • Performs internal penetration tests, network vulnerability assessments to provide a comprehensive view of the client’s network weaknesses that are exposed to threats. Following are the certifications I have: CISSP CCSP (Cloud security) CEH
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    Nessus
    HIPAA
    Certified Information Systems Security Professional
    PCI
    GDPR
    Employee Training
    AT&T Cybersecurity
    Data Protection
    Vulnerability Assessment
    OWASP
  • $175 hourly
    As a Top Rated vCISO with a 100% job success rate, rest assured that I execute at a high level of expertise, integrity, and professionalism. I am the President & Founder of Aspire Cyber, a full-service consulting firm that rapidly delivers privacy and cybersecurity compliance solutions to help small and medium-sized businesses satisfy their legal, regulatory, and contractual requirements. Aspire Cyber was founded on the core belief that every business should have access to world-class cybersecurity talent, regardless of budget or security needs. I have over 20 years ​of experience managing information security projects and implementing strategic cybersecurity controls for the United States Army, Bank of America, and numerous Fortune 100 companies. We offer entirely “Done For You” solutions that help your business rapidly achieve compliance while we manage everything. Don’t waste 6-18 months trying to figure this out yourself. Regulatory and industry cybersecurity frameworks have hundreds of different controls you must comply with and require knowledge of IT, Cybersecurity, HR, Legal, and more. Aspire Cyber is a leading provider of comprehensive cybersecurity compliance solutions. Our team of experts has a proven track record of implementing NIST SP 800-171 practices to help defense contractors achieve Cybersecurity Maturity Model Certification (CMMC). We make it easy for your business to prove it's a safe choice for handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Schedule a free call with me to learn how our team of dedicated cybersecurity experts can help save you months of time and, in many cases, five or even six figures in excessive spending trying to become compliant without expert guidance. ★High Profile Clients ✔ I worked for the United States Army, Lockheed Martin, Bank of America, Hewlett-Packard Enterprise, and many others. Aspire Cyber specializes in the following areas: ★ Risk Assessment and Auditing - We have conducted over 200 Information Security, Business Continuity, and Cloud assessments. -Compliance (NIST, PCI, HIPAA, ISO 27001, GDPR, CCPA, COPPA, FedRAMP) - Cybersecurity Advisor -Cloud Secure Design -Data Privacy Officer (DPO) -Cloud Security -Policy Writing -Penetration Testing -Application Security -Incident Response -Vulnerability Management -Third-Party Risk Management -Security Awareness Training ★ I hold the following degrees and certifications: ✅ Certified CMMC Assessor (CCA) ✅ Certified CMMC Professional (CCP) ✅ CMMC Provisional Instructor ✅ Certified Information Systems Security Professional (CISSP) ✅ Certified Cloud Security Professional (CCSP) ✅ Certified Information Security Manager (CISM) ✅ Certified Risk and Information Systems Control (CRISC) ✅ CMMC Registered Practitioner ✅ CompTIA Security+ ✅ CompTIA A+ ✅ Master of Business Administration (MBA) ✅ Graduate Certificate Cybersecurity Technology WHY CHOOSE ASPIRE CYBER? -Professionalism: We treat all clients respectfully and adhere to the highest ethical standards. -Fast: We always aim to deliver your project ahead of schedule. -Expertise: We have vast experience across various cybersecurity and compliance areas. -Responsiveness: Constant and effective communication is the key to a successful engagement. 🙋🏼‍♂️Our team is eager to partner with your organization to deliver cybersecurity compliance solutions rapidly. Contact Aspire Cyber today to learn how we can fulfill your cybersecurity needs.
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    Cloud Security Framework
    NIST SP 800-53
    Policy Writing
    Information Security Governance
    FedRAMP
    Information Security Awareness
    Risk Assessment
    NIST Cybersecurity Framework
    Business Continuity Plan
    Information Security Audit
    Information Security
    Incident Response Plan
    Security Testing
    Vulnerability Assessment
    Cybersecurity Management
  • $45 hourly
    For over 16 years, I’ve helped companies and startups get ISO 27001/SOC2/PCI DSS/FedRAMP/HIPAA/HITRUST/NIST/CMMC certifications to pass assessments and strike deals with enterprise clients. Worked with US DoD and US Federal Agencies on compliance and cyber security technical writing projects. 𝗠𝗢𝗡𝗘𝗬-𝗕𝗔𝗖𝗞 𝗚𝗨𝗔𝗥𝗔𝗡𝗧𝗘𝗘! Press “...” on the top, then “Send a Message" to talk with me now. Securing your business, achieving a security certification (SOC 2, ISO 27001, PCI-DSS, HIPAA, or FedRAMP) for your company, or answering a security questionnaire should not be a cumbersome and painful exercise. You are looking for me if: ❓Lost business or leads due to lack of ISO 27001/HIPAA/HITRUST/SOC 2/PCI/FedRAMP certifications ❓Clients demanding information security certifications (PCI-DSS, SOC 2, ISO 27001, HIPAA, HITRUST, FedRAMP, CMMC 2). ❓Need guidance on choosing between SOC 2 and ISO 27001. ❓Seeking to safeguard intellectual property and company data. ❓Uncertain about how to respond to a security assessment questionnaire from a major client. ❓Limited time and resources for compliance efforts and meetings. ❓Struggling to understand the certification process, costs, and timelines. ❓Looking for the #1 Compliance, Security, and Certification Consultant @ Upwork with the best ROI. ❓Interested in implementing a compliance tool (Drata, Vanta, HeyLaika, Tugboat, Compliance Machine, etc.) but need guidance or lack time. Working with me, you will: ★ Get an end-to-end, professionally managed service ★ Get a consultant aiming for long-term support and providing advice and services after the certification achieved ★ Cut corners, and save time and money with a streamlined process ★ Gain an understanding of different security and compliance requirements ★ Be able to assure your clients and sell to Enterprise-level clients As a virtual/fractional CISO, I have created a streamlined and efficient workflow to take this off your shoulder and help the company achieve growth-phase plans and targets by establishing a solid security and governance framework to win Enterprise clients. That is what my clients are saying about me: "Muhammad delivered the project as per our expectations. His knowledge on security standards like NIST/ISO is commendable. He worked with our CTO and technical team to gather relevant information in a very collaborative and structured manner. We would be happy to take his services around IT compliance and security in the future as well." - CEO of Denarii.cash (acquired by Careem) ""Muhammad did a terrific job for us on a very short timeline (less than 48 hours from Proposal to Project Completion). The deliverable and outcome were exactly what we asked for and Mohammad was very accommodating on scheduling. His expertise was exactly as represented and what we needed. He worked well with our team from a standing start. We would definitely use him again!"" - CEO of Anonos "Muhammad immediately became an invaluable member of our team. He kept us on track, knew what was around every corner, and guided us to the finish line with a superior product. Highly recommended." - CISO of MSAG (a Service-Disabled, Veteran-Owned Small Businesses) "Ali was very professional, knowledgeable, and easy to work with." - CEO of DataKitchen.io You will get all the support, tools, and knowledge to get your company and saas/solution / product secured and compliant with ISO 27001, SOC 2, HIPAA, CMMC, PCI-DSS, FedRAMP, StateRAMP, NY DFS, GDPR (or other data privacy) compliance framework by identifying the best solutions and managing the whole process. As your remote (virtual) Information Security Officer (ISO) or Chief Information Security Officer (CISO), you will get all the following information security and compliance-related services: ✅ Information security management strategy, assessments, action plan, ✅ Participating in calls during client or vendor engagements, representing the company's Security team, ✅ Vendor relations, ✅ Security framework implementation and certification (ISO 27001/17/18, SOC 2, HIPAA, PCI-DSS) ✅ Risk assessment, management, treatment plan, remediation tracking ✅ Answering and filling security assessment questionnaires (OneTrust, SIG, CyberGRX, CAIQ, HEVCAT, VAS, or any other questionnaire), ✅ Information security policy and procedure creation/update/review, ✅ Budgeting, ✅ Security operation ✅ Unique, company-specific tasks ✅ Internal audit, gap assessments, ✅ Consulting, ✅ On-demand/part-time/full-time. Additional to the vCISO and certification services, I can provide the same benefits to you as one-off projects. My stats: ✅#1 in Information Security and IT compliance categories (100K+ earned in 2 years) ✅Constant Top-Rated status ✅Over 20+ completed projects ✅82+ hours via Upwork ✅Supporting all time zones ✅Long-term engagements
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    SOC 2
    Information Security Governance
    Information Security Audit
    Cloud Security
    GDPR
    Penetration Testing
    Information Security Consultation
    NIST SP 800-53
    Security Assessment & Testing
    Cybersecurity Management
    IT Compliance Audit
    ISO 27001
    Information Security
    Risk Assessment
    Security Policies & Procedures Documentation
  • $200 hourly
    🌟 Upwork TOP RATED Expert Cybersecurity Consultant with 100% Job success rate 🌟 ✅ Penetration Testing: Standard, Web application, mobile applications. ✅ Compliance: CMMC, DFARS, NIST 800-53, NIST 800-171, PCI, HIPAA, GDPR, ISO, SOC, SOX, GLBA, FedRAMP, CCPA, and more. ✅ Incident Response: Ransomware recovery, hacking response, forensic investigations. ✅ vCISO: Virtual Chief Information Security Officer. ✅ Vulnerability Management: Vulnerability Scanning Hello, It is great to meet you (virtually)! My name is Tyler. I have over 15 years of cyber-security experience in multiple verticals. I have worked with fortune 500 brands, government, military, and intelligence agencies. 🌟 I have provided expert cybersecurity and compliance consulting for startups to hundreds of businesses! 🌟 My core expertise resides in: compliance and governance (PCI, HIPAA, SOX, DFS, DFARS, ISO, NIST, GDPR, and more), ethical hacking, incident response, penetration testing, secure design and architecture, and public speaking. I am an excellent writer and also possess business savvy. Pairing technical expertise with exemplary writing skills is my forte. I am also fluent in Brazilian Portuguese. I currently hold the following educational degrees and certifications: ✅ Master of Business Administration (MBA) ✅ Bachelor of Science in Cyber-Security ✅ Certified Information Systems Security Professional (CISSP) ✅ GIAC Certified Incident Handler (GCIH) ✅ GIAC Security Essentials Certification (GSEC) ✅ Microsoft Certified Systems Expert (MCSE) ✅ Microsoft Certified Systems Administrator (MCSA) ✅ Microsoft Certified IT Professional (MCITP) ✅ CompTIA Security+ ✅ CompTIA A+ ✅ CIW Web Design Associate WHY CHOOSE ME OVER OTHER FREELANCERS? -Professionalism: I treat all clients with respect and honor their trust in my services. -Expertise: I have expertise across many cybersecurity, information technology, and compliance areas. -Responsiveness: Constant and effective communication is the key to a successful engagement. -Dedication: When i take on a task or project, you deserve my undivided attention and focus! -Versatility: I can easily pivot from many different tasks. Whether your project is a standard penetration test or a Chief Information Security Officer engagement, I have the ability, knowledge, experience, and credentials to adjust based on your requirements. -I have led over 150 incident response cases. -I have brought over 75 organizations to full compliance for DFARS, NIST, PCI, HIPAA, GDPR, and more. -I have conducted over 200 penetration tests. ✅ I will ensure that you get the results that you deserve. My clients trust me to complete their tasks and I ALWAYS deliver! Whether you are seeking a long term partner or a short term project, I am ready to deliver the high quality results that you deserve.
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    Certified Information Systems Security Professional
    HIPAA
    Defense Federal Acquisition Regulation Supplement
    Policy Writing
    GDPR
    Internet Security
    Security Analysis
    Information Security
    Encryption
    Security Assessment & Testing
    Application Security
    Incident Response Plan
    Vulnerability Assessment
    Network Security
    Penetration Testing
  • $35 hourly
    A motivated professional with proven expertise in: -DevOps -Data Engineering -Cybersecurity In addition to being a self-starter, I also excel in a team setting and have successfully completed projects with big industry players from fortune 500 companies. 1) DevOps: -CI/CD Pipelines -Configuration Management -Micro Services Deployment -Infrastructure as Code -Cloud Assessment -Cost Optimization -Cloud Migration -Multi Cloud Solution -Designing and Deployment 1a) Cloud Native Application Services: -Application Assessment -Integration Services -Cloud Native Application Development -Application Modernization -Bespoke Application Development -Mobile App Development 1b) Cloud Services: -Openstack Services -VMware Services -AWS (Amazon Web Services) -Alibaba Cloud Services -Microsoft Azure Services -Huawei Cloud Services -Office365 2) 24/7 Managed Services: -Network Support Services -Managed NOC Services -Cloud Managed Services -End User Managed Services -Outsourcing Services -Datacenter Managed Services 3) Data Sciences -Data Management -Data Integrations (ETL) -Data Tuning & Optimizations -BI (Business Intelligence) -Big Data Engineering -IoT -Data Analytics -ML & AI Services 4) Cyber Security: -Digital Security Assessment -Managed SOC -Cyber Security Consultancy -Cyber Security Trainings 5) Web Development: -Front End Development -Backend Development -UI/UX -Database Design
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    Microsoft Power BI
    Google Cloud Platform
    Data Analysis
    Network Administration
    Virtualization
    Automation
    DevOps
    Service Cloud Administration
    Help Desk Technology International ServicePRO
    Microsoft Dynamics CRM
    System Administration
    Microsoft SQL Server
    Mobile App Development
    Amazon Web Services
  • $155 hourly
    My specialties are: - Understanding your requirements - Clearly communicating with you - Finding and implementing the best solution for you - Building easy to use and great looking custom software - Writing high-performance​ applications - Standing behind my work!
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    Penetration Testing
    Ethical Hacking
    PCI
    HIPAA
    Payment Processing
    PHP
    Linux System Administration
    C++
    MySQL
    MySQL Programming
  • $220 hourly
    Former private sector and government executive with leadership, consulting, advising, strategic and business development at the forefront of my professional skills. Compliance expertise in: FISMA, NIST CSF, NIST SPs 800 Series, HIPAA, FedRAMP, PCI DSS, Sarbanes Oxley, GLBA, GDPR, ISO 27001. CISSP with more than 20 years in cybersecurity and IT. Cybersecurity professor and skilled trainer in risk management and compliance, with expertise in developing professionals into the cyber managers and leaders they want to become. I teach fundamentals and advanced coursework in risk assessments, security testing, business continuity, secure application development, and securing emerging technologies. Business expertise in grant and proposal writing, as well as policy and procedure development. Technical writing to include strategic plans, white papers, briefing papers, and presentations. I have been writing, convincing, persuading, and communicating effectively through writing my entire career. I am also effective in providing business capture and business development support.
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    Nonprofit Organization
    Certified Information Systems Security Professional
    Data Protection
    Policy Writing
    Information Security Audit
    Compliance
    Technical Writing
    Tech & IT
    Technical Documentation
    Risk Analysis
    Risk Assessment
    Business Continuity Plan
    Business Consulting
    Enterprise Risk Management
    Project Risk Management
  • $240 hourly
    I have provided HIPAA consulting services for the last 20 years and over that time served over 1,000 clients. Client experience includes work with covered entities including hospitals, physicians, other health providers, insurers, union health plans and county government agencies. Experience with business associates include software vendors, IT managed services providers, cloud computing vendors, mobile app developers, medical billing services, value-added resellers, third-party administrators and pharmaceutical marketing companies. Services include virtual Privacy/Security Officer, policy and procedure development, policy gap analysis, computer security risk analysis, technical vulnerability analysis, vendor audits, HIPAA training, business associate contracting and other HIPAA related services. Other related experience includes use of security frameworks including ISO 27001/27002, NIST and HITRUST as well as the PCI DSS. I have worked with other government regulations including 42 CFR Part 2, GxP, FERPA, IDEA, DEA Regulations for E-prescribing of controlled substances and state laws relating to medical privacy and data breach in over 20 states.
    vsuc_fltilesrefresh_TrophyIcon PCI Compliance
    Data Privacy
    Information Security
    Policies & Procedures
    Project Risk Management
    Risk Assessment
    Security Analysis
    Information Security Governance
    Vulnerability Assessment
    PCI
    ISO 27001
    GDPR
    HIPAA
  • Want to browse more freelancers?
    Sign up

How it works

 

1. Post a job (it’s free)

Tell us what you need. Provide as many details as possible, but don’t worry about getting it perfect.

2. Talent comes to you

Get qualified proposals within 24 hours, and meet the candidates you’re excited about. Hire as soon as you’re ready.

3. Collaborate easily

Use Upwork to chat or video call, share files, and track project progress right from the app.

4. Payment simplified

Receive invoices and make payments through Upwork. Only pay for work you authorize.

Trusted by 5M+ businesses

How do I hire a PCI Compliance Specialist on Upwork?

You can hire a PCI Compliance Specialist on Upwork in four simple steps:

  • Create a job post tailored to your PCI Compliance Specialist project scope. We’ll walk you through the process step by step.
  • Browse top PCI Compliance Specialist talent on Upwork and invite them to your project.
  • Once the proposals start flowing in, create a shortlist of top PCI Compliance Specialist profiles and interview.
  • Hire the right PCI Compliance Specialist for your project from Upwork, the world’s largest work marketplace.

At Upwork, we believe talent staffing should be easy.

How much does it cost to hire a PCI Compliance Specialist?

Rates charged by PCI Compliance Specialists on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.

Why hire a PCI Compliance Specialist on Upwork?

As the world’s work marketplace, we connect highly-skilled freelance PCI Compliance Specialists and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream PCI Compliance Specialist team you need to succeed.

Can I hire a PCI Compliance Specialist within 24 hours on Upwork?

Depending on availability and the quality of your job post, it’s entirely possible to sign up for Upwork and receive PCI Compliance Specialist proposals within 24 hours of posting a job description.

Schedule a call