🔍 Certified IS Auditor and Certified in Cybersecurity with a keen eye for IT security, IT Risk & Controls, SOC, ITGC, ITAC, compliance, and risk management. I specialize in evaluating IT systems, ensuring regulatory compliance, and strengthening cybersecurity controls (covering logical accesses, change management and IT operations) to protect businesses from threats and vulnerabilities.
What I Offer:
✅IT & Internal Audit engagement (ISO 27001, NIST, COBIT, SOX, HIPAA, PCI-DSS)
✅Risk Assessment & Control Evaluations
✅ Cybersecurity Assessments & Compliance Checks
✅ IT Governance & Internal Control Reviews
✅ Security Policy Development & Implementation
✅ IT General Control Testing, IT Application Control Testing
✅ Business Continuity & Disaster Recovery Planning
Why Work With Me?
✔ 5+ years of experience in IT auditing, SOC Assessment. Internal Audit, Cybersecurity, and Compliance
✔ Expertise in regulatory frameworks & industry best practices
✔ Strong communication skills—clear, actionable reporting
✔ Commitment to helping businesses secure their IT environment
💡 Let’s work together to strengthen your IT security, Business controls, ensure compliance, and mitigate risks effectively. Contact me today to discuss your project!
Security Policies & Procedures Documentation
OS Security
Internal Auditing
IT General Controls Testing
Information Security Audit
SOC 2
Application Audit
IT Compliance Audit
SOC 1
GDPR Compliance Review
ISO 27001
SAP
Policy Writing
Sarbanes-Oxley Act
Cybersecurity Management
NIST Cybersecurity Framework
Hameed U.
Islamabad, Pakistan
$25/hr
5.0
6 jobs
Upwork Top Rated · 100% Job Success · CISM Certified · 10 Years Experience
I help SaaS and cloud-native companies reach audit-ready status for SOC 2, ISO
27001, ISO 42001 and GDPR — on schedule, without disrupting your product roadmap or
slowing down your sales cycle.
I have led compliance programmes across the full lifecycle — from
initial gap assessment and policy design through to auditor coordination
and surveillance audit preparation. My engagements cover every department
that auditors touch: IT, HR, Legal, Finance, DevOps, and Procurement — so
nothing falls through the cracks and you walk into audit day confident.
━━━━━━━━━━━━━━━━━━━━━━━━━━━
WHAT I DELIVER
━━━━━━━━━━━━━━━━━━━━━━━━━━━
▸ SOC 2 Type I & II Readiness
Full gap assessment, control mapping, policy library, and auditor
coordination — from kickoff to clean audit report.
▸ ISO 27001 Certification & Surveillance Support
ISMS design and implementation, Statement of Applicability, risk
register, internal audit programme, and evidence preparation for
certification and surveillance audits.
▸ GDPR Compliance
Data mapping, Records of Processing Activities (RoPA), DPIAs, privacy
notices, Data Processing Agreements, and breach notification procedures.
▸ AI Governance & ISO 42001
Emerging framework — policy design and readiness assessments for
organisations integrating AI into their products and workflows.
▸ Security Policy Library
30+ audit-ready policies written in plain language — policies your
engineers will actually read and follow, not 40-page documents that
sit on a shelf.
▸ Vendor & Third-Party Risk Management
Supplier security assessments, due diligence questionnaires, contract
security clauses, and ongoing monitoring frameworks.
▸ Audit Coordination & Evidence Management
I act as your single point of contact with external auditors —
managing evidence requests, Information Request Lists (IRLs), and
auditor communications so your team can stay focused on the product.
━━━━━━━━━━━━━━━━━━━━━━━━━━━
FRAMEWORKS & STANDARDS
━━━━━━━━━━━━━━━━━━━━━━━━━━━
SOC 2 · ISO 27001:2022 · GDPR · PCI DSS · NIST CSF · ISO 42001 · HIPAA · CIS Controls
ISO 9001 · ISO 20000-1
━━━━━━━━━━━━━━━━━━━━━━━━━━━
WHY CLIENTS CHOOSE ME
━━━━━━━━━━━━━━━━━━━━━━━━━━━
✔ I understand your stack before you explain it
I work exclusively with SaaS and cloud-native teams on AWS, GCP, and
Azure. I speak the language of your engineers, not just your auditors.
✔ I write policies people actually follow
Every policy I deliver is proportionate, readable, and built around
your actual workflows — not copied from a template library.
✔ I cover the full scope — not just one layer
Most consultants focus on IT controls. I work across HR, Legal,
Finance, DevOps, and Procurement — the departments auditors always
reach into and that always catch companies off guard.
✔ I have coordinated with major audit firms
I have prepared evidence packages and managed IRL submissions for
surveillance and certification audits coordinated with firms including - so I know exactly what auditors look for and what they push back on.
✔ I deliver structure, not just advice
Every engagement produces working artefacts: trackers, dashboards,
policy documents, risk registers, and roadmaps — not slide decks with
recommendations you have to figure out how to implement.
━━━━━━━━━━━━━━━━━━━━━━━━━━━
WHO I WORK WITH
━━━━━━━━━━━━━━━━━━━━━━━━━━━
I work primarily with SaaS companies preparing for their
first SOC 2 or ISO 27001 audit, and with established companies managing
surveillance audits or expanding their compliance scope into GDPR or
AI governance.
Typical client profile:
→ 20–300 employees
→ Cloud-native infrastructure (AWS / GCP / Azure)
→ Small or no internal security team
→ Facing an enterprise customer security review or upcoming audit
→ Compliance is blocking a deal or a funding round
ISO 27001
SOC 2
PCI DSS
GDPR
Privacy Policy Writing
Privacy Impact Assessment
California Consumer Privacy Act
Risk Management
IT Compliance Audit
SaaS
Data Privacy
Faiz A.
Karachi, Pakistan
$3/hr
5.0
7 jobs
My profile with having extensive experience over 12 years in IT including banking/firm/software houses industry experience.
I am recognized for my ability to assess situations, identify problems and devise solutions moreover being certified ISO 27001 Lead Auditor, certified in Ethical Hacking CEH, CISA certified and MS (Info security), enjoy facing challenges and come to you with demonstrated problem-solving skills in IT Auditing / Gap Analysis during work engagement. Below are the summarized skills set.
-Information Security Analysis
-Gap Analysis / Risk Analysis
-IS Auditing & Continuous Auditing
-ISO 27001 LA assessment
-Vulnerability /pen test assignments
-PCIDSS compliance
-Incident Response Solution
-Security Program Management
-IT Infrastructure Management
-DR Plan & Services
Our team also consists of OSCP, CEH, CISA, ISO 27001, ISO 20000, ISO 23001, CPTE and CISM certified professional and have been doing all the assessments from past 12 years.
please connect to reach out further.
I hope to hear from you soon and look forward to meet face to face for challenges associated with the suitable IT Auditing & Security assignments.
System Security
Vulnerability Assessment
Encryption
Penetration Testing
Information Security
Internal Control
ISO 27001
PCI DSS
Ethical Hacking
Data Protection
Financial Audit
Network Penetration Testing
Big Data
Data Privacy
GDPR Compliance Review
Bilal Z.
Lahore, Pakistan
$30/hr
4.7
79 jobs
💪 Top Rated Plus | 🚀 10+ Years of Leadership in Cybersecurity, Goverance, Compliance & Risk Management | 7000+ Hours on Upwork
As a Cybersecurity, Risk, and Compliance Leader, I help organizations build, lead, and scale security management programs that align with global standards - protecting businesses from evolving threats while ensuring compliance and operational excellence.
With 10+ years of proven leadership, I’ve guided global enterprises to achieve, maintain, and mature certifications and frameworks such as SOC2 Type 1, SOC2 Type 2, ISO27001, ISO27701, ISO42001 (AI Management System), NIST CSF 2.0, CMMC Level 1, CMMC Level 2, CMMI, FISMA, FedRAMP, GDPR, PDPL, SAMA, PCI-DSS, and HIPAA.
🔐 Leadership & Technical Expertise
📊 Governance, Risk & Compliance (GRC):
Driving end-to-end enterprise compliance programs across SOC2 Type 1, SOC2 Type 2, ISO27001, ISO27701, ISO42001 (AI Management System), NIST CSF 2.0, CMMC Level 1, CMMC Level 2, CMMI, FISMA, FedRAMP, GDPR, PDPL, SAMA, PCI-DSS, and HIPAA.
🧩 CMMI & ISO42001 Implementation:
Establishing maturity models and AI governance frameworks to enhance organizational process efficiency and responsible AI compliance.
📝 Policy & Framework Development:
Designing and implementing enterprise-grade security policies, standards, and procedures covering access control, risk management, vendor due diligence, data protection, and incident response.
👨💼 vCISO Leadership:
Providing Virtual CISO services for executive-level direction, audit readiness, and strategic oversight aligned with board governance.
☁️ Cloud, Endpoint & AI Security:
Delivering MDM, MAM, and endpoint security strategies that ensure secure digital transformation across Microsoft 365, Google Workspace, AWS, and Azure.
📡 Advanced Security Operations:
Overseeing SIEM design, configuration, and monitoring (Splunk, QRadar, Exabeam) to enhance detection and response maturity.
⚙️ Compliance Automation:
Leveraging modern platforms like Drata, Vanta, TrustCloud, Scrut Automation, and JIRA to simplify control mapping, streamline evidence collection, and accelerate audits.
🚀 Impact as a Cybersecurity & Compliance Leader
✔️ Guided multiple organizations from 0% to 100% compliance readiness for SOC2 Type 1, SOC2 Type 2, ISO27001, ISO27701, ISO42001 (AI Management System), NIST CSF 2.0, CMMC Level 1, CMMC Level 2, CMMI, FISMA, FedRAMP, GDPR, PDPL, SAMA, PCI-DSS, and HIPAA.
✔️ Reduced audit fatigue and compliance complexity through automated workflows and risk-based prioritization.
✔️ Built scalable and sustainable cybersecurity programs that improve resilience, maturity, and business continuity.
✔️ Delivered strategic security governance that balances compliance, innovation, and operational efficiency.
🧠 Core Skill Set
Information Security Governance & Risk Management
SOC2 Type 1 / SOC2 Type 2 / ISO27001 / ISO27701 / ISO42001 Implementation
CMMC, CMMI, FedRAMP, and HIPAA Compliance Readiness
NIST CSF 2.0, NIST 800-53, and Privacy Framework Alignment
Policy, Procedure & Control Development
Third-Party Risk & Vendor Management
SIEM, MDM, MAM, DLP, and Endpoint Security
Security Awareness, Training, and Phishing Simulations
Compliance Automation (Drata, Vanta, TrustCloud, Scrut, JIRA)
Gap Assessments, Internal Audits, and Remediation Planning
📩 Let’s Work Together
If your business needs a proven Cybersecurity & Compliance Leader to build a governance program, achieve certifications, or deliver vCISO guidance, let’s connect.
My mission is to help your organization stay secure , compliant , and resilient - while driving continuous improvement and operational maturity.
Information Security Consultation
Cybersecurity Management
Penetration Testing
Risk Assessment
GDPR
ISO 27001
NIST SP 800-53
Governance, Risk Management & Compliance
HIPAA
SOC 2 Report
CMMC
Gap Analysis
Certified Information Security Manager
Privacy Impact Assessment
SOC 2
Arbaz A.
Lahore, Pakistan
$35/hr
5.0
1 jobs
🔐 Your enterprise deal is stalling — because security is unresolved.
A customer asks for a SOC 2 report. An ISO 27001 certificate. A completed security questionnaire. Your team doesn't have the answers, and the deal slows down.
I step in as your fractional vCISO and fix that, fast.
With 10+ years building and running security programs — and a technical foundation in infrastructure, endpoint, identity, and network security — I've helped SaaS, healthcare, fintech, and managed services companies go from zero compliance posture to full audit readiness.
🎯 What I deliver:
• 📋 Compliance programs — SOC 2 (Type 1 & 2), ISO 27001:2022, ISO 42001 (AI Governance), ISO 27701 (Privacy), ISO 22301 (BCM), HIPAA, PCI DSS, GDPR, FedRAMP, CIS Controls — gap assessments, implementation, evidence collection, and audit preparation from start to finish
• 🛡️ Fractional vCISO — security program design, policy & procedure library, risk register, vendor risk management, board-level reporting, AI/SaaS third-party risk, and supply chain risk
• 🔑 Identity & Access Management — Microsoft Entra ID, Conditional Access, Privileged Access Management, MFA deployment, JML processes, and password manager deployment (Keeper, 1Password, Bitwarden, ITGlue)
• 💻 Endpoint & device management — Microsoft Intune (end-to-end), IBM MaaS360, Cisco Meraki MDM, system hardening, BitLocker, Windows hardening, Microsoft 365 Business Premium configuration
• 🛰️ Security operations — SIEM deployment & tuning (Splunk, QRadar, Microsoft Sentinel, Wazuh, Elastic/ELK), MDR (BlackPoint, Huntress, Sentinel Suite, TrendMicro), DFIR, vulnerability management, threat intelligence
• ⚙️ Compliance automation — Vanta, Drata, Secureframe, GRC engineering
• ☁️ Cloud security — AWS, Azure, GCP
• 📐 Framework alignment — NIST CSF 2.0, NIST SP 800-53, ISO 27005/31000, COBIT, CIS Controls
🔧 Why my compliance work is different:
Most compliance consultants work from a checklist. I've actually built what I audit — I've deployed MDM solutions, run enterprise vulnerability management programs, managed SAST and application security pipelines, operated MDR platforms, and hardened endpoints and infrastructure across managed services client bases. That technical depth means the controls I design actually work in the real world, not just on paper. When your auditor asks hard questions, I already know the answers.
📌 My track record includes:
• ✔ Built and operated end-to-end ISMS as fractional vCISO — from policy library to enterprise risk register
• ✔ Leading ISO 27001 ISMS lifecycle, ISO 27005 risk assessments, and ISO 27701 (PIMS) implementation at enterprise level
• ✔ Deployed and managed MDM solutions (Intune, MaaS360, Meraki) and EDR/MDR platforms across MSP client bases
• ✔ Designed and executed enterprise-wide vulnerability management programs, AppSec pipelines (SAST), and security awareness programs
• ✔ Led AI/SaaS third-party risk assessments and board-level security reporting
🔄 How I engage:
Scoping call → gap assessment → prioritized roadmap → implementation → audit support. Open to short engagements (policy review, gap assessment, security posture assessment, endpoint hardening) or long-term fractional vCISO retainers.
📩 Message me with your target framework, environment, or challenge — I'll send back a clear path forward within 24 hours.
Information Security
PCI DSS
ISO 27001
NIST Cybersecurity Framework
NIST SP 800-53
GDPR
HIPAA
Incident Management
Risk Management
Cloud Security
SOC 2
Data Privacy
Governance, Risk Management & Compliance
Gap Analysis
Policy Development
Microsoft Endpoint Manager
Microsoft Intune
Wafa A.
Islamabad, Pakistan
$15/hr
5.0
27 jobs
💪 Top Rated
I help startups, SaaS companies, and enterprises identify security vulnerabilities before attackers do. With 5+ years of cybersecurity experience, I specialize in manual penetration testing, application security, API security, cloud security, compliance assessments, and privacy audits.
I have worked with organizations across the United States, United Kingdom, Germany, and Canada, delivering security assessments aligned with international standards and industry best practices. My assessments have uncovered critical vulnerabilities including Account Takeover, Remote Code Execution (RCE), IDOR, Authentication & Authorization flaws, Business Logic vulnerabilities, SSRF, XSS, CSRF, SQL Injection, Sensitive Data Exposure, Security Misconfigurations, and Insecure API Implementations.
My Services
Penetration Testing
• Web Application Penetration Testing (OWASP Top 10)
• Mobile Application Security Testing (Android & iOS)
• REST & GraphQL API Security Testing
• External & Internal Network Penetration Testing
• Authentication & Authorization Testing
• Business Logic Testing
• Secure Code Review (SAST)
• Cloud Security Assessments (AWS, Azure & GCP)
Privacy & Tracking Audits
I perform non-destructive privacy and tracking audits to evaluate how websites collect, process, and share user data without making any changes to production environments.
My privacy audits include:
• Tracking & Analytics Review (Google Analytics, Meta Pixel, LinkedIn Insight Tag, etc.)
• Cookie & Consent Compliance Assessment
• Third-Party Script & Tag Analysis
• Privacy & Data Collection Review
• Browser Storage Review (Cookies, Local Storage & Session Storage)
• Sensitive Data Leakage Detection
• Tracking Request Analysis
• GDPR Privacy Assessment
• Actionable Privacy & Security Recommendations
Important: I do not modify, delete, or update website code, tracking configurations, analytics settings, or production systems. My work is strictly read-only and results in a detailed report highlighting privacy concerns, security risks, and practical recommendations for improvement.
Compliance & Security Frameworks
• CASA Tier 2 Security Testing
• CMMC Level 2
• NIST SP 800-171
• NIST SP 800-53
• ISO 27001
• SOC 2
• GDPR
Security Automation
I develop custom security automation solutions that help organizations reduce manual effort and improve their security posture.
Automation services include:
• Vulnerability Management Automation
• Security Testing Automation
• Compliance Reporting Automation
• Security Workflow Automation
• Custom Security Scripts & Tools
Technical Toolkit
Security Tools
• Burp Suite Professional
• OWASP ZAP
• Nmap
• Nessus
• Metasploit
• SonarQube
• Veracode
• Appknox
• Bandit
Infrastructure & Cloud Security
• Cloudflare
• Imperva WAF
• Firewall Configuration
• Identity & Access Management (IAM)
• Access Control Management
• Database Security
Programming & Automation
• Python
• Bash
• Node.js
• Java
Why Clients Hire Me
✅ 5+ Years of Professional Cybersecurity Experience
✅ Manual Security Testing Not Just Automated Scanner Reports
✅ Clear, Actionable Reports with Risk Ratings and Remediation Guidance
✅ Independent Security Consultant (No Agency, No Subcontracting)
✅ Strong Communication Throughout the Engagement
✅ Flexible Across Multiple Time Zones (Including EST Overlap)
Deliverables
Every assessment includes:
• Executive Summary
• Technical Findings with Evidence
• Risk Severity (CVSS/OWASP where applicable)
• Step-by-Step Reproduction
• Screenshots & Proof of Concept
• Practical Remediation Recommendations
• Optional Re-Testing After Fixes
Due to client confidentiality, I do not publicly share full penetration testing reports. However, I can demonstrate redacted professional reports during a screen-sharing meeting or after an NDA is signed.
Whether you need a comprehensive penetration test, a privacy and tracking audit, an application security assessment, or compliance guidance, I'm here to help you strengthen your security posture and reduce risk.
Let's discuss your project.
Compliance
Computer Network
Information Security
Network Penetration Testing
Penetration Testing
Testing
Software Testing
Malware Removal
Digital Forensics
Web App Penetration Testing
Security Testing
Cloud Testing
Cloud Security
SOC 2
IT Compliance Audit
AI Compliance
GDPR Compliance Review
SOC 2 Report
Compliance Consultation
How it works
Post a job for freePost a job
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a PCI Compliance Specialist in Pakistan on Upwork?
You can hire a PCI Compliance Specialist in Pakistan on Upwork in four simple steps:
Create a job post tailored to your PCI Compliance Specialist project scope. We'll walk you through the process step by step.
Browse top PCI Compliance Specialist talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top PCI Compliance Specialist profiles and interview.
Hire the right PCI Compliance Specialist for your project from Upwork, the world's largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a PCI Compliance Specialist?
Rates charged by PCI Compliance Specialists on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a PCI Compliance Specialist in Pakistan on Upwork?
As the world's work marketplace, we connect highly-skilled freelance PCI Compliance Specialists and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream PCI Compliance Specialist team you need to succeed.
Can I hire a PCI Compliance Specialist in Pakistan within 24 hours on Upwork?
Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive PCI Compliance Specialist proposals within 24 hours of posting a job description.
Find more freelancers
Top cities for PCI Compliance Specialists in Pakistan