Penetration Tester Job Description Template
An effective description can help you hire the best fit for your job. Check out our tips to provide details that skilled professionals are looking for.
Penetration Tester Job Description Template
A penetration tester, also known as a pen tester or ethical hacker, is a cybersecurity professional who identifies security vulnerabilities in systems, networks, and applications. This role is vital for safeguarding information security and protecting organizations from potential cyberattacks by assessing risks and recommending security measures.
Hiring a skilled penetration tester on Upwork can provide your company with the expertise needed to identify weaknesses and implement solutions effectively to thwart security breaches.
Job Overview
A penetration tester conducts comprehensive security assessments to identify and exploit vulnerabilities within an organization’s systems, applications, and networks. This role requires expertise in penetration testing methodologies, programming languages such as Python, and operating systems like Linux and Windows. Pen testers collaborate with stakeholders to enhance security measures and safeguard information systems from cyber threats. The ideal candidate will hold certifications such as OSCP or CEH and have experience in scripting, vulnerability assessment, and remediation. By proactively identifying and addressing security flaws, penetration testers play a critical role in maintaining robust cybersecurity.
Key Responsibilities
- Performing security assessments. Conduct detailed penetration testing on web applications, networks, and computer systems to uncover vulnerabilities and security flaws.
- Analyzing vulnerabilities. Assess identified vulnerabilities and recommend remediation strategies to strengthen security measures.
- Developing reports. Create comprehensive reports detailing findings, methodologies, and actionable insights for stakeholders.
- Collaborating with teams. Work closely with security analysts, systems administrators, and other team members to implement solutions and enhance security systems.
- Conducting social engineering tests. Simulate phishing attacks and other social engineering techniques to assess organizational security readiness.
- Utilizing tools and frameworks. Leverage tools such as Metasploit and programming languages like Python for security testing and scripting.
- Maintaining certifications. Stay updated with industry certifications, such as OSCP, CEH, and CompTIA, to ensure expertise in the latest methodologies and tools.
- Testing physical security. Evaluate physical security measures to ensure comprehensive protection against unauthorized access.
- Providing remediation advice. Offer actionable recommendations to address security threats and improve application security and network security.
Qualifications and Skills
- Education. Bachelor’s degree in computer science, information technology, or a related field; a master’s degree is advantageous.
- Certifications. Certifications such as Offensive Security Certified Professional (OSCP), Certified Ethical Hacker (CEH), or CompTIA certifications are highly valued.
- Technical expertise. Proficiency in scripting, operating systems (Linux and Windows), and programming languages like Python.
- Analytical skills. Strong problem-solving skills to identify and mitigate security vulnerabilities effectively.
- Experience. 3-5 years of experience in penetration testing, vulnerability assessments, and cybersecurity roles.
- Communication skills. Excellent report writing and verbal communication skills to articulate findings and recommendations.
- Tools and methodologies. Familiarity with penetration testing tools like Metasploit and frameworks for ethical hacking.
- Teamwork. Ability to collaborate with cross-functional teams and stakeholders to implement security solutions.
- Knowledge of security policies. Understanding of information security policies, network protocols, and industry standards.
About Our Company
At [company name], we’re a forward-thinking organization dedicated to strengthening cybersecurity and safeguarding sensitive information. Our team of experts values innovation, collaboration, and data-driven strategies to address security vulnerabilities and security issues to improve overall protection. We prioritize continuous learning and certifications, empowering our team to stay ahead of industry trends and tackle complex challenges. Join us to make a meaningful impact in the world of cybersecurity and advance your career as a penetration tester.
What does a penetration tester do?
A penetration tester identifies and exploits security vulnerabilities in computer systems, networks, and web applications. By using methodologies like ethical hacking, penetration testers simulate cyberattacks to assess an organization’s security measures and uncover weaknesses. They collaborate with stakeholders to conduct audits, analyze vulnerabilities, and recommend remediation strategies to enhance information security and protect against future cyber threats. This role requires expertise in programming languages, operating systems, and penetration testing tools, as well as a commitment to continuous improvement and certifications.
Penetration tester duties and responsibilities
Penetration testers are essential for identifying and mitigating security risks. Their key duties include:
- Conducting security testing. Performing penetration testing on applications, networks, and systems to uncover security flaws and vulnerabilities.
- Analyzing results. Evaluating findings from security assessments and providing actionable recommendations for improvement.
- Creating detailed reports. Documenting methodologies, findings, and remediation strategies for stakeholders and decision-makers.
- Collaborating with teams. Working with cybersecurity professionals, IT teams, and stakeholders to implement security measures and improve systems.
- Simulating attacks. Conducting ethical hacking exercises, including phishing simulations and other social engineering tests, to assess organizational readiness.
- Staying updated. Keep abreast of industry trends, emerging threats, and the latest penetration testing methodologies.
- Training team members. Providing guidance to colleagues on best practices in cybersecurity and vulnerability assessment.
- Testing security tools. Evaluating the effectiveness of existing security tools and frameworks, recommending upgrades or replacements as needed.
- Enhancing physical security. Assessing physical security measures to ensure comprehensive protection against unauthorized access.
Penetration Testers you can meet on Upwork
- $45/hr$45 hourly
Vikas G.
- 4.8
- (3 jobs)
Chandigarh, CHANDIGARHPenetration Testing
Google Chrome ExtensionServerBrowser ExtensionApplication SecurityVulnerability AssessmentOWASPWeb App Penetration TestingWordPress Malware RemovalBash ProgrammingLinuxInformation SecurityWebsite SecurityJavaScriptPHPI help companies find and fix real security vulnerabilities before attackers do. I’m an experienced Application Security Engineer & Penetration Tester with a strong background in web and API security testing, vulnerability research, and custom security tooling. I work with startups and established teams to identify high-impact security flaws, provide clear remediation guidance, and strengthen overall security posture without slowing development. My approach goes beyond automated scans, I focus on manual testing, logic flaws, vulnerability chaining, and realistic attack scenarios that reflect how systems are actually exploited in the wild. Whether you need a one-time security assessment or ongoing security support, I deliver clear findings, reproducible PoCs, and actionable fixes that engineering teams can immediately work with. What I Do Best Web Application Penetration Testing - OWASP Top 10 coverage - Authentication & authorization flaws - Business logic vulnerabilities - Input validation & injection flaws (XSS, SQLi, SSTI, etc.) API Penetration Testing - REST & JSON APIs - Broken object level authorization (BOLA) - Auth bypasses, IDORs, mass assignment - Token handling & access control issues Security & Vulnerability Assessments - Manual testing + targeted automation - Risk-based findings (not noise) - Clear severity and remediation guidance Reconnaissance & OSINT - Attack surface discovery - Subdomain & asset enumeration - Exposure identification before attackers How I Work - Manual testing first, scanners second - Clear, developer-friendly reports - Proof-of-concepts that actually reproduce - Secure-by-design recommendations - Respect for deadlines and business context I treat security as a collaboration, not a checkbox exercise. Tools & Technical Skills Scripting & Automation - Python, PHP, JavaScript, Bash Security Tooling - Burp Suite, custom scripts, manual exploitation techniques Platforms & Systems - Linux, servers, web infrastructure Security Knowledge - OWASP Top 10, vulnerability assessment, application security testing Why Clients Hire Me - You want real vulnerabilities, not false positives - You need clear explanations, not generic reports - You care about security that fits your product and timeline - You want someone who thinks like an attacker and communicates like an engineer Let’s Work Together If you’re looking for a reliable security professional who values quality, transparency, and fair business, feel free to reach out. I’m happy to discuss your requirements and recommend the right level of testing for your product. - $99/hr$99 hourly
Sammy B.
- 5.0
- (43 jobs)
Los Angeles, CAPenetration Testing
Cloud SecurityNetwork SecurityCybersecurity MonitoringSOC 2HIPAAPCICertified Information Systems Security ProfessionalISO 27001Security InfrastructureCompliance ConsultationWeb Application SecurityInformation Security AuditVulnerability AssessmentSecurity Policies & Procedures DocumentationI help organizations of all sizes build, mature, and manage their cloud security and compliance programs. With over 15 years of experience in cybersecurity, I’ve led security initiatives for Fortune 100 companies like Warner Bros., EA Sports, Pfizer, State Farm Insurance, and Goldman Sachs. Today, I work with fast-growing SaaS companies, healthcare organizations, and mid-sized businesses to help secure their cloud environments and achieve compliance goals. My expertise includes: Cloud security architecture and hardening across AWS, Azure, and GCP SOC 2, ISO 27001, HIPAA, and GDPR compliance readiness Cloud risk assessments, gap analysis, and remediation planning Penetration testing and vulnerability management Security program development as a virtual CISO (vCISO) SIEM deployment, configuration, and log monitoring (Splunk, ELK, and cloud-native tools) Security policy and procedure development Incident response planning and tabletop exercises DevSecOps integration and CI/CD pipeline security Certifications include CISSP, CISA, GPEN, GMON, GCCC, CEH, AWS Certified Solutions Architect, CHFI, CWSP, ITIL Foundation, and PMP. I focus on delivering practical, business-aligned security outcomes that reduce risk, meet audit requirements, and build trust with your customers and stakeholders. If you’re looking for help with cloud security, regulatory compliance, or security program leadership, let’s connect. Keywords: cloud security, AWS security, Azure security, GCP security, SOC 2 compliance, ISO 27001 consultant, virtual CISO, vCISO, cybersecurity risk assessment, NIST CSF, CIS Controls, penetration testing, vulnerability management, SIEM deployment, Splunk consultant, ELK Stack security, cloud compliance, HIPAA security, GDPR compliance, cloud incident response, DevSecOps, secure CI/CD, security policies and procedures, cloud security audit, remote security consultant, cloud penetration tester, security roadmap, cloud vulnerability assessment. - $75/hr$75 hourly
Md Azizur R.
- 4.9
- (31 jobs)
Dhaka, DHAKAPenetration Testing
Secure SDLCSecurity AnalysisCloud SecurityISO 27001Security EngineeringSecurity Policies & Procedures DocumentationSecurity TestingSource Code ScanningInformation SecurityApplication SecurityCybersecurity ManagementNetwork SecurityDatabase SecurityVulnerability AssessmentI help organizations become audit-ready, secure, and compliant - without overengineering or slowing down business. With 17+ years in cybersecurity, I operate as a Fractional CISO (vCISO), bridging technical execution, risk governance, and compliance across fast-growing SaaS companies, fintech, and enterprise environments. I specialize in building end-to-end security programs aligned with: ISO/IEC 27001 SOC 2 NIS2 Directive HIPAA 🎯 What I Deliver 🔐 Compliance & Audit Readiness SOC 2 Type I & II end-to-end readiness ISO 27001 ISMS design, implementation & audit support NIS2 gap assessment & full implementation roadmap HIPAA compliance for SaaS, VoIP, and cloud platforms 🛡️ Security Leadership (vCISO) Security strategy aligned with business goals Risk management (NIST CSF, CIS Controls) Board-level reporting (Risk vs Cost vs Impact) Vendor & third-party risk management ⚙️ Technical & Cloud Security AWS / GCP / Azure security architecture & hardening DevSecOps & Secure SDLC (SAST, DAST, IAST integration) Application & API security testing Identity & Access Management (IAM / PAM) 🔍 Offensive Security & Assurance Penetration testing (Web, mobile and Network) Red team simulation & threat modeling Secure code review & vulnerability management 🧠 Why Clients Hire Me I don’t just deliver policies - I deliver working security programs I translate technical risk into business decisions I align compliance with real-world architecture (AWS, SaaS, DevOps) I help you pass audits AND actually be secure 🏆 Credentials CISM • CISA • CEH • ECSA • LPT (Master) ISO 27001 Lead Implementer (BSI) AWS Security Specialty • Azure Security (AZ-500) 💡 Engagement Model Fractional CISO (ongoing advisory) Compliance programs (SOC 2 / ISO 27001 / NIS2 / HIPAA) Security assessments & remediation Audit readiness & evidence preparation 🚀 Let’s Talk If you're preparing for an audit, scaling securely, or need a CISO-level partner without full-time cost, I can help you get there efficiently.
- $45/hr$45 hourly
Vikas G.
- 4.8
- (3 jobs)
Chandigarh, CHANDIGARHPenetration Testing
Google Chrome ExtensionServerBrowser ExtensionApplication SecurityVulnerability AssessmentOWASPWeb App Penetration TestingWordPress Malware RemovalBash ProgrammingLinuxInformation SecurityWebsite SecurityJavaScriptPHPI help companies find and fix real security vulnerabilities before attackers do. I’m an experienced Application Security Engineer & Penetration Tester with a strong background in web and API security testing, vulnerability research, and custom security tooling. I work with startups and established teams to identify high-impact security flaws, provide clear remediation guidance, and strengthen overall security posture without slowing development. My approach goes beyond automated scans, I focus on manual testing, logic flaws, vulnerability chaining, and realistic attack scenarios that reflect how systems are actually exploited in the wild. Whether you need a one-time security assessment or ongoing security support, I deliver clear findings, reproducible PoCs, and actionable fixes that engineering teams can immediately work with. What I Do Best Web Application Penetration Testing - OWASP Top 10 coverage - Authentication & authorization flaws - Business logic vulnerabilities - Input validation & injection flaws (XSS, SQLi, SSTI, etc.) API Penetration Testing - REST & JSON APIs - Broken object level authorization (BOLA) - Auth bypasses, IDORs, mass assignment - Token handling & access control issues Security & Vulnerability Assessments - Manual testing + targeted automation - Risk-based findings (not noise) - Clear severity and remediation guidance Reconnaissance & OSINT - Attack surface discovery - Subdomain & asset enumeration - Exposure identification before attackers How I Work - Manual testing first, scanners second - Clear, developer-friendly reports - Proof-of-concepts that actually reproduce - Secure-by-design recommendations - Respect for deadlines and business context I treat security as a collaboration, not a checkbox exercise. Tools & Technical Skills Scripting & Automation - Python, PHP, JavaScript, Bash Security Tooling - Burp Suite, custom scripts, manual exploitation techniques Platforms & Systems - Linux, servers, web infrastructure Security Knowledge - OWASP Top 10, vulnerability assessment, application security testing Why Clients Hire Me - You want real vulnerabilities, not false positives - You need clear explanations, not generic reports - You care about security that fits your product and timeline - You want someone who thinks like an attacker and communicates like an engineer Let’s Work Together If you’re looking for a reliable security professional who values quality, transparency, and fair business, feel free to reach out. I’m happy to discuss your requirements and recommend the right level of testing for your product. - $99/hr$99 hourly
Sammy B.
- 5.0
- (43 jobs)
Los Angeles, CAPenetration Testing
Cloud SecurityNetwork SecurityCybersecurity MonitoringSOC 2HIPAAPCICertified Information Systems Security ProfessionalISO 27001Security InfrastructureCompliance ConsultationWeb Application SecurityInformation Security AuditVulnerability AssessmentSecurity Policies & Procedures DocumentationI help organizations of all sizes build, mature, and manage their cloud security and compliance programs. With over 15 years of experience in cybersecurity, I’ve led security initiatives for Fortune 100 companies like Warner Bros., EA Sports, Pfizer, State Farm Insurance, and Goldman Sachs. Today, I work with fast-growing SaaS companies, healthcare organizations, and mid-sized businesses to help secure their cloud environments and achieve compliance goals. My expertise includes: Cloud security architecture and hardening across AWS, Azure, and GCP SOC 2, ISO 27001, HIPAA, and GDPR compliance readiness Cloud risk assessments, gap analysis, and remediation planning Penetration testing and vulnerability management Security program development as a virtual CISO (vCISO) SIEM deployment, configuration, and log monitoring (Splunk, ELK, and cloud-native tools) Security policy and procedure development Incident response planning and tabletop exercises DevSecOps integration and CI/CD pipeline security Certifications include CISSP, CISA, GPEN, GMON, GCCC, CEH, AWS Certified Solutions Architect, CHFI, CWSP, ITIL Foundation, and PMP. I focus on delivering practical, business-aligned security outcomes that reduce risk, meet audit requirements, and build trust with your customers and stakeholders. If you’re looking for help with cloud security, regulatory compliance, or security program leadership, let’s connect. Keywords: cloud security, AWS security, Azure security, GCP security, SOC 2 compliance, ISO 27001 consultant, virtual CISO, vCISO, cybersecurity risk assessment, NIST CSF, CIS Controls, penetration testing, vulnerability management, SIEM deployment, Splunk consultant, ELK Stack security, cloud compliance, HIPAA security, GDPR compliance, cloud incident response, DevSecOps, secure CI/CD, security policies and procedures, cloud security audit, remote security consultant, cloud penetration tester, security roadmap, cloud vulnerability assessment. - $75/hr$75 hourly
Md Azizur R.
- 4.9
- (31 jobs)
Dhaka, DHAKAPenetration Testing
Secure SDLCSecurity AnalysisCloud SecurityISO 27001Security EngineeringSecurity Policies & Procedures DocumentationSecurity TestingSource Code ScanningInformation SecurityApplication SecurityCybersecurity ManagementNetwork SecurityDatabase SecurityVulnerability AssessmentI help organizations become audit-ready, secure, and compliant - without overengineering or slowing down business. With 17+ years in cybersecurity, I operate as a Fractional CISO (vCISO), bridging technical execution, risk governance, and compliance across fast-growing SaaS companies, fintech, and enterprise environments. I specialize in building end-to-end security programs aligned with: ISO/IEC 27001 SOC 2 NIS2 Directive HIPAA 🎯 What I Deliver 🔐 Compliance & Audit Readiness SOC 2 Type I & II end-to-end readiness ISO 27001 ISMS design, implementation & audit support NIS2 gap assessment & full implementation roadmap HIPAA compliance for SaaS, VoIP, and cloud platforms 🛡️ Security Leadership (vCISO) Security strategy aligned with business goals Risk management (NIST CSF, CIS Controls) Board-level reporting (Risk vs Cost vs Impact) Vendor & third-party risk management ⚙️ Technical & Cloud Security AWS / GCP / Azure security architecture & hardening DevSecOps & Secure SDLC (SAST, DAST, IAST integration) Application & API security testing Identity & Access Management (IAM / PAM) 🔍 Offensive Security & Assurance Penetration testing (Web, mobile and Network) Red team simulation & threat modeling Secure code review & vulnerability management 🧠 Why Clients Hire Me I don’t just deliver policies - I deliver working security programs I translate technical risk into business decisions I align compliance with real-world architecture (AWS, SaaS, DevOps) I help you pass audits AND actually be secure 🏆 Credentials CISM • CISA • CEH • ECSA • LPT (Master) ISO 27001 Lead Implementer (BSI) AWS Security Specialty • Azure Security (AZ-500) 💡 Engagement Model Fractional CISO (ongoing advisory) Compliance programs (SOC 2 / ISO 27001 / NIS2 / HIPAA) Security assessments & remediation Audit readiness & evidence preparation 🚀 Let’s Talk If you're preparing for an audit, scaling securely, or need a CISO-level partner without full-time cost, I can help you get there efficiently. - $125/hr$125 hourly
Luciano F.
- 5.0
- (20 jobs)
Winter Garden, FLPenetration Testing
Network Penetration TestingJavaScriptPythonPHPWeb App Penetration TestingProject Risk ManagementCybersecurity ManagementSecurity TestingIncident ManagementAI SecurityRisk AssessmentVulnerability AssessmentThreat DetectionCyber Threat IntelligenceCI/CDAmazon GuardDutyInfrastructure as CodeNIST SP 800-53FedRAMPZero Trust ArchitectureCloud SecurityI help organizations reduce cybersecurity risk, secure products, meet compliance requirements, and build practical security capabilities. Certifications: CISSP | CCISO | CISM | CRISC | CEH | C|RAGE (Responsible AI Governance) | ISO/IEC 27001 I am an experienced Chief Information Security Officer, penetration tester, cybersecurity instructor, course creator, and founder of LufSec. I work with startups, SaaS companies, enterprise teams, and training organizations that need senior cybersecurity expertise without unnecessary complexity or full-time overhead. My services include: FRACTIONAL CISO AND SECURITY LEADERSHIP • Build or mature cybersecurity programs • Perform security, risk, and compliance assessments • Develop security strategies, roadmaps, policies, and metrics • Prepare organizations for SOC 2, ISO 27001, NIST, GDPR, CCPA, and customer security reviews • Evaluate security architecture, vendors, cloud environments, and operational controls • Support executive teams, boards, auditors, customers, and investors • Implement vulnerability management, incident response, DevSecOps, security awareness, and third-party risk programs PENETRATION TESTING AND APPLICATION SECURITY • Web application penetration testing • API security testing • Cloud and infrastructure security assessments • Vulnerability validation and risk prioritization • OWASP Top 10 testing • Authentication, authorization, session, business-logic, and access-control testing • Executive and technical reports with clear remediation guidance • Retesting and remediation support AI AND LLM SECURITY • AI application and agent security assessments • Prompt injection and indirect prompt injection testing • LLM red teaming and adversarial testing • Sensitive-data exposure and unsafe tool-use analysis • AI governance, acceptable-use policies, and enterprise guardrails • Secure adoption of ChatGPT, Claude, Microsoft Copilot, and other AI assistants • AI security workshops for technical and non-technical teams CYBERSECURITY TRAINING AND CUSTOM COURSE DEVELOPMENT • Customized corporate cybersecurity workshops • Instructor-led remote and onsite training • Cybersecurity course design and curriculum development • Hands-on labs, demonstrations, assessments, and instructor materials • Executive, technical, and non-technical audience training • Topics including penetration testing, web hacking, AI security, cloud security, IoT security, secure development, governance, and compliance WHY CLIENTS HIRE ME • Active CISO-level leadership experience • More than two decades of cybersecurity experience • Strong combination of executive strategy and hands-on technical capability • Experience implementing security programs in SaaS and enterprise environments • Practical communication for executives, engineers, auditors, customers, and students • Published cybersecurity author, instructor, podcaster, and course creator • Founder of LufSec and host of Inside Cyber Minds • Native Portuguese speaker with professional English fluency I do not deliver generic reports, recycled policies, or theoretical presentations. My work is designed to produce a measurable outcome: reduced risk, stronger controls, clearer decisions, improved compliance readiness, actionable technical findings, or a workforce that knows how to operate securely. Send me a message with your environment, challenge, timeline, and expected outcome. I will help you determine the most effective scope and approach. - $75/hr$75 hourly
Khaled S.
- 5.0
- (7 jobs)
Dubai, DUBAIPenetration Testing
Web App Penetration TestingPCINetwork Penetration TestingPythonCode ReviewComputer NetworkInformation SecurityVulnerability AssessmentI have Experience in Penetration Testing(Network, Web Application, Desktop, Mobile, IVR and webservice), performed lots of Security Implementations related to Security Solutions such as SIEM, Two Factor Authentication, Firewalls,...etc. in Egypt and Large banks in Qatar. . I have experience in PCI Audits , did lot's of gap assessments and pre-audits on many banks and payment gateway. Also I wrote multiple articles in big security magazines like Hakin9 in Europe and Security Kaizen in Middle East, I'm currently having two 0day vulnerability and listed in multiple hall of fames including Microsoft. I have multiple certifications like OSCP, OSEP, OSWE And OSCE Job Experience: • Running PCI-DSS Gap Assessments, Pre-Audits, Final Audits in big payment gateways and large ISP's in Egypt • Performing Internal / External Network Penetration testing for large bank, ISP & other clients. • Performing Internal / External Application Penetration Testing “Web / Desktop” for large customers in Egypt and Qatar. • Performing advanced Penetration testing including Mobile,Web service, IOT and IVR PT in Egypt. • Supervising big Vulnerability Assessment projects in Egypt most required by PCI-DSS clients. • Performing large SIEM Solution implementations for ISPs, Banks, government sector & others in Egypt, Qatar • Implementing biggest Two Factor Authentication Solution implementation in the middle east. • Vulnerability Management Solutions for large customers in Egypt •End Point Protection implementation in large banks in Egypt • McAfee Next Generation FW deployments for large clients in Qatar. • McAfee Network Security Manager IPS deployments for large clients in Qatar. •Deploying Anti Fraud solutions at one of the biggest banks in Middle east. •Deploying Mobile Device Management solutions (Mobile Iron)at one of the biggest banks in Middle east. •One of the consultants responsible for securing the 4G Network(IMS Core,HSS,...etc.) at one of the biggest Mobile operators in Egypt. •Leading a team of 3 Engineers to perform mentioned activities previously. - $40/hr$40 hourly
Jawad Saqib B.
- 4.8
- (45 jobs)
Rawalpindi, PUNJABPenetration Testing
Code ReviewPythonSecurity AnalysisWebsite SecurityMobile App TestingSecurity EngineeringCloud SecurityNetwork SecuritySecurity Assessment & TestingCybersecurity ManagementMalware RemovalInformation SecurityVulnerability AssessmentInformation Security Consultation✅ Amongst the Top 1000 hackers worldwide Web Pentesting | Mobile App Pentesting | API Pentesting | Vulnerability Assessment | Python & Bash Automation I work with companies to make their digital assets secure and provide solutions to enhance their security parameters. I create cybersecurity content on hackingloops.com explaining the practicalities and how-tos of the vulnerability and exploitation Part-time bug bounty hunter at Bugcrowd & Intigriti. Feel free to contact me for your queries and security-related issues. - $75/hr$75 hourly
Payton G.
- 4.9
- (13 jobs)
San Antonio, NMPenetration Testing
VoIPNetwork DesignAWS Systems ManagerNetwork SecurityAWS LambdaAWS CodeDeploySystem SecurityNetwork EngineeringVulnerability AssessmentCustomer ServiceNetwork AdministrationTechnical SupportData EntryVoIP AdministrationI bring over 15 years of progressive experience in IT, providing comprehensive technical solutions that drive business performance and security. My career has spanned multiple domains, giving me a broad yet deep expertise that allows me to align technology with organizational goals. IT Security Professional (5 years): Proven expertise in safeguarding enterprise environments through risk assessments, compliance alignment, vulnerability management, and incident response planning. Skilled in developing security frameworks that balance protection with operational efficiency. VoIP Engineer (7 years): Designed, implemented, and supported scalable VoIP solutions for enterprise clients. Experience includes SIP trunking, PBX integration, call center technologies, and troubleshooting voice quality issues to ensure reliable, cost-efficient communication. System Administrator (10 years): Extensive hands-on background managing Windows and Linux environments, Active Directory, virtualization platforms, storage, and cloud services. Adept at performance tuning, disaster recovery planning, and automation for seamless IT operations. Technical Support (15 years): Strong foundation in customer-facing IT support, with the ability to communicate complex technical concepts in simple terms. Recognized for building trust with stakeholders, reducing downtime, and ensuring user satisfaction. By combining security, infrastructure, communication, and end-user support expertise, I deliver holistic IT consulting that helps organizations reduce risks, optimize systems, and achieve scalable growth. My goal is to be a trusted partner, ensuring technology becomes a driver—not a barrier—to business success. - $150/hr$150 hourly
Luciana O.
- 5.0
- (231 jobs)
Boerne, TXPenetration Testing
PCI DSSNIST SP 800-53CMMCRisk AssessmentCloud SecurityInternet SecurityInformation Security AuditInformation Security AwarenessSecurity EngineeringSecurity AnalysisEmail SecurityInformation SecuritySecurity Policies & Procedures DocumentationCybersecurity ManagementI am the founder of BetterCyber Consulting, a cybersecurity consulting and managed services firm specializing in startups, small businesses, and mid-sized companies. As an Upwork Expert-Vetted Cybersecurity Consultant, I help businesses identify risks, implement security controls, and meet compliance requirements without unnecessary costs or complexity. My experience in cybersecurity includes positions at Fortune 100 companies like PayPal and Marathon Petroleum. I hold several security certifications and earned a master’s degree in Information Security Engineering from The SANS Technology Institute. I offer the following cybersecurity services: ● Technical Security Assessments – Security reviews for AWS, Azure, Google Cloud, Microsoft 365, Google Workspace, Slack, and more. ● Penetration Testing – Web, cloud, mobile, and on-premises security testing. ● Compliance Assessments – NIST 800-171 & 800-53, FedRAMP, ISO 27001, CIS Controls, CMMC, HIPAA, and SOC 2. ● Security Strategy & Architecture – Build scalable security programs. ● Incident Response & Threat Mitigation – Detect and respond to threats. ● Managed Security Services – Ongoing security monitoring and advisory. ● Virtual CISO (vCISO) Services – Security leadership for businesses without a full-time CISO. - $155/hr$155 hourly
Michael S.
- 5.0
- (41 jobs)
Norwalk, CTPenetration Testing
HIPAAEthical HackingLinux System AdministrationPCIPayment ProcessingMySQL ProgrammingMySQLC++PHPMy specialties are: - Understanding your requirements - Clearly communicating with you - Finding and implementing the best solution for you - Building easy to use and great looking custom software - Writing high-performance applications - Standing behind my work! Want to browse more talent?
Sign up
Join the world’s work marketplace

Post a job to interview and hire great talent.
Hire Talent
Find work you love with like-minded clients.
Find WorkEthical Hacking
Network Security
Cybersecurity Experts
Cloud Architects
Business Development Consultants
Certified AWS Cloud Architects
Network Engineering
Cloud Engineer
DevOps
YouTube Marketing
Web Development
Web Design
Vue.js
Virtual Assistant
User Experience Design
Translation