If your website is compromised, blacklisted, or showing gambling links, you need more than just a developer you need an Incident Responder. With half a decade of experience serving in a Government Computer Security Incident Response Team (CSIRT), I specialize in identifying, neutralizing, and preventing complex cyber threats.
I have handled hundreds of high-stakes cases involving Web Defacement, Malware Infestation (including Japanese/Gambling SEO Spam), and Data Breaches. My approach combines government-grade security standards with a deep understanding of full-stack development.
🛡️ Why Hire Me?
- Former Gov-CSIRT Specialist: 5 years of experience in emergency incident response and forensic analysis.
- Malware & Virus Removal: 100% success rate in cleaning backdoors, shells, and malicious redirects.
- Vulnerability Expert: I don’t just fix the symptoms; I find the root cause (SQL Injection, XSS, Outdated Templates) and patch it.
💻 Technical Expertise:
- Security: Penetration Testing (OWASP), Malware Analysis, Security Hardening, OSINT.
- Development: Full-stack expertise in Laravel, Node.js, PHP, and WordPress.
- E-commerce: Expert in securing and optimizing WooCommerce (Fixing outdated templates & database issues).
"Security is not a product, but a process." Let's secure your digital assets with professional-grade protection. Whether you need an emergency clean-up or a proactive security audit, I am ready to help.
Penetration Testing
Information Security
Web Development
WordPress Landing Page
Security Testing
SEO Backlinking
Cybersecurity Monitoring
WordPress Development
Android App Development
Website Security
Web Application
App Development
Miftahul R.
Jakarta, Indonesia
$3/hr
5.0
2 jobs
I like to explore and find vulnerability software. Still learning and upgrade skill in cyber security area especially in web security testing.
Penetration Testing
Linux
Security Operation Center
Linux System Administration
Cloud Security
Fatur R.
Masamba, Indonesia
$6/hr
5.0
2 jobs
Experienced bug bounty hunter with a strong track record of finding and reporting critical vulnerabilities in web applications. I specialize in web application penetration testing, with a primary focus on vulnerabilities such as XSS, SQL Injection, IDOR, Authentication Bypass, Business Logic Flaws, and CSRF.
I've been actively involved in various bug bounty programs (both private and public), successfully discovering and reporting numerous valid vulnerabilities to companies ranging from startups to enterprises. Every finding is documented in a clear, reproducible, and actionable report — complete with proof of concept, risk impact, and mitigation recommendations.
What I offer:
✅ Web application penetration testing (manual + automated)
✅ Vulnerability assessment & security audits
✅ Professional security report writing that's easy for dev teams to act on
✅ Bug bounty program participation (private/public)
✅ Retesting & verification after patches are applied
I understand the importance of clear, responsive communication with clients — including regular progress updates and ethical disclosure coordination. I follow responsible disclosure principles and always ensure testing stays within the agreed scope.
Let's discuss your security testing needs — I'm ready to help secure your application against vulnerabilities before they can be exploited by malicious actors.
React
Tailwind CSS
Mushlih M.
Banjarbaru, Indonesia
$30/hr
4.7
30 jobs
A Cyber Security Consultant with over 7 years of experience in penetration testing and vulnerability assessment across Web, Mobile Apps, Networks, and Infrastructure. I am certified as an Offensive Security Certified Professional (OSCP), CREST Registered Penetration Tester (CRT), CREST Practitioner Security Analyst (CPSA), and Burp Suite Certified Practitioner (BSCP).
Penetration Testing
Security Assessment & Testing
Information Security
Network Security
Vulnerability Assessment
Python
Security Testing
Cybersecurity Management
Application Security
Kali Linux
Website Security
Cloud Security
Web Testing
Reverse Engineering
OWASP
Alvin F.
Jakarta, Indonesia
$15/hr
5.0
1 jobs
Introducing Alvin Ferdiansyah, a Cyber Security Consultant with proven professional years of experience in the field. With a top industry certification, Alvin specializes in offensive security, focusing mainly on web applications and infrastructure. He's passionate about learning, often diving into bug write ups to pick up new tricks. His favorite moments come about when he can give his best and uncover impactful vulnerability holes in his work.
My expertise lies in delivering end-to-end security assessments, from reconnaissance and manual exploitation to in-depth analysis and detailed reporting. I’ve led and contributed to both black-box and grey-box testing engagements, working directly with development and security teams to provide impactful recommendations and reduce attack surface.
Over the past years, I’ve conducted security testing across a wide range of environments including financial systems, e-commerce websites, CMS, SaaS platforms, banking sector, cloud hosted infrastructures, insurance and health care companies, and custom software developed by various software houses.
Certifications:
- CREST Registered Penetration Tester (CRT)
- OffSec Certified Professional (OSCP)
- PortSwigger Burp Suite Certified Practitioner (BSCP)
- CREST Practitioner Security Analyst (CPSA)
- Web application Penetration Tester eXtreme (eWPTX)
- Mobile Application Penetration Tester (eMAPT)
Core Capabilities:
- Web Application Penetration Testing: Manual exploitation of OWASP Top 10 vulnerabilities (XSS, IDOR, SQLi, SSRF, CSRF, auth bypass, etc.)
- API Security: RESTful, Postman collections, JSON/XML/SOAP based APIs, token tampering, weak token implementation, etc.
- Mobile App Security Testing: Reverse engineering APKs, Frida based dynamic instrumentation, root detection bypass, certificate pinning bypass, insecure storage analysis (shared prefs, SQLite, internal files), .so/native lib analysis.
- Advanced tool usage (Burp Suite, Kali Linux, nmap, metasploit, nessus, etc)
- End2End encryption bypassed.
- Custom scripting in Python for automation, request manipulation, and response parsing
- Red Team Support: Custom payload development, client-side attacks, infrastructure enumeration, phishing simulation.
My testing process is rooted in proven frameworks of OWASP Testing Guide. Each engagement is tailored based on client objectives, risk appetite, and application architecture, but generally follows this structure:
- Scoping & Rules of Engagement
- Reconnaissance & Threat Modeling
- Vulnerability Discovery (automated + manual)
- Exploitation (controlled and risk-aware)
- Post-Exploitation Analysis (privilege escalation, data exposure)
- Reporting (technical + business impact, PoCs, remediation guidance)
- Retesting (to verify fixes and validate security posture)
This methodology ensures coverage, clarity, and repeatability, allowing stakeholders to clearly understand risk while prioritizing fixes effectively.
Deliverables You Can Expect:
- PDF report with detailed vulnerabilities, CVSS scores, descriptions, PoCs, and remediation steps
- CVSS Scoring and component details.
- Executive summary (1 page) for management
- Exploitable PoCs with step by step replication
- Clear technical and business impact descriptions
- Mitigation and recommendation strategies aligned to your environment
- OWASP/CWE mapping for risk classification
- Structured documentation, screenshots, logs, and retesting summaries
Why work with me?
- I don’t just find bugs. I help you understand their risk, context, and business impact.
- I offer fullcycle engagement: from scoping and execution to documentation and retesting.
- I respect deadlines, communicate transparently, and provide clean, organized results.
Let’s ensure your application stands secure against today’s threat landscape. I’m available to start as early as you need, and I’ll tailor the engagement to fit your testing scope and business needs.
Looking forward to the opportunity.
Alvin Ferdiansyah
Cybersecurity Consultant | Penetration Tester | OSCP, CREST CRT, CPSA, eWPTX, eMAPT, BSCP
Penetration Testing
Information Security
Network Penetration Testing
Vulnerability Assessment
Web App Penetration Testing
Red Team Assessment
Security Analysis
Linux
Kali Linux
Metasploit
OWASP
Mohammad Hussam A.
Jakarta, Indonesia
$80/hr
4.9
33 jobs
✅ Penetration tester and cybersecurity engineer acknowledged by leading tech companies for discovering high and critical vulnerabilities across their systems and applications.
I combine hands-on security testing with comprehensive content development and compliance consulting to help organizations build robust security programs.
After conducting thorough penetration testing engagements utilizing both manual and automated techniques, I deliver professional reports that outline every vulnerability discovered, include detailed proofs-of-concept, and provide actionable remediation guidance.
My technical writing translates complex security concepts into clear, practical content for both technical and non-technical audiences.
Let's get in touch and secure your business 🛡️
What I Offer:
🏆 7+ Years in Cybersecurity
🏆 Penetration Testing (Web, Network, Active Directory, API)
🏆 Vulnerability Research & 0-day Discovery
🏆 Security Compliance Consulting (ISO 27001, HIPAA)
🏆 Technical Content Development & Training Materials
🏆 Cybersecurity Training & Mentorship
🏆 CTF & Training Lab Development
🏆 Exploit Development & Reverse Engineering
Recognition & Achievements:
🏆 Acknowledged by: Yahoo, Nokia, ZTE, Swisscom, Synology, eLearnsecurity, Payoneer, Sophos, Xiaomi, Astrox
🏆 Ranked #17 on HackTheBox in Turkey and Egypt regions
🏆 CVE Discoveries: Ford Sync3, Astrox, GLib, libgepub, and more
🏆 Certifications: OSED, OSMR, eCPTX, CRTP
🏆 BSides Jakarta Chapter Lead
Available for weekend engagements and urgent security assessments.
Penetration Testing
Ethical Hacking
Network Penetration Testing
Network Security
Vulnerability Assessment
Web App Penetration Testing
Linux
Web Application Security
OWASP
Docker
Nessus
Security Testing
Kali Linux
Metasploit
Digital Forensics
How it works
Post a job for freePost a job
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a Penetration Tester in Indonesia on Upwork?
You can hire a Penetration Tester in Indonesia on Upwork in four simple steps:
Create a job post tailored to your Penetration Tester project scope. We'll walk you through the process step by step.
Browse top Penetration Tester talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top Penetration Tester profiles and interview.
Hire the right Penetration Tester for your project from Upwork, the world's largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a Penetration Tester?
Rates charged by Penetration Testers on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a Penetration Tester in Indonesia on Upwork?
As the world's work marketplace, we connect highly-skilled freelance Penetration Testers and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Penetration Tester team you need to succeed.
Can I hire a Penetration Tester in Indonesia within 24 hours on Upwork?
Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Penetration Tester proposals within 24 hours of posting a job description.