Hire the best Penetration Testers in New York

Check out Penetration Testers in New York with the skills you need for your next job.
  • $30 hourly
    I am currently a fourth year student at the Rochester Institute of Technology set to graduate in 2026 with a BS/MS in Computing Security, as well as a previous information security intern for Factory Mutual, Wegmans, and AmTrust Financial. I have extensive experience in Information Technology, Information Security, Systems Administration, and Cybersecurity. Previous work I have done for clients: - Full corporate network penetration testing and remediation recommendations, finding vulnerabilities across servers, desktops, point-of-sale systems, routers, and IOT devices (such as security cameras) - Search engine enumeration of domain, identifying easily accessible file footprint and highlighting sensitive metadata - Security Information and Event Management tool implementation at all steps of the process, from importing data sources to creating alerts and triage documentation - Red team engagement with custom tooling and break scheduling for competition use
    Featured Skill Penetration Testing
    Security Policies & Procedures Documentation
    Information Gathering
    Information Security
  • $44 hourly
    Passionate Cyber and Information Security professional with a master's degree and proven expertise in risk management, data privacy, and software security. Adept at handling complex projects, collaborating with cross-functional teams, and implementing effective security solutions. My goal is to use my skills in vulnerability and risk management to obtain experience in an entry level position.
    Featured Skill Penetration Testing
    Risk Management
    Vulnerability Assessment
  • $300 hourly
    Hi! I'm Harish Prasanna, New York City-based​ with a Masters in Digital Forensics and Cybersecurity & Bachelors in Computer Science and Engineering. My passion is Web/Software Development with extra emphasis on Security and Open Source. I have worked on a wide array of languages for the Web/Mobile/Desktop and have developed in multiple fields including ML, AI, Chatbots, NLP, Data Visualization, Data ETL & Representation, Cybersecurity, Smart Contracts and more. Contact me for projects that involve cyber security, web development, software development, networking, digital forensics or just about any idea that you have been tinkering within the recent past! Looking forward to work with you!
    Featured Skill Penetration Testing
    Network Security
    HTML5
    Web Design
    Elasticsearch
    PHP
    Data Recovery
    Amazon Web Services
    Python
  • $100 hourly
    Experience Information Security professional with prior experience as technical support, system administration, and network administration. Experienced in load balancing, app firewall, vulnerability assessments(Nessus, InsightVM, etc), penetration testing, tripwire, Varonis DatAdvantage, active directory,etc.
    Featured Skill Penetration Testing
    Enterprise Architecture
    Web Application Security
    Financial Audit
    Risk Assessment
    Vulnerability Assessment
  • $50 hourly
    Hello, my name is Timothy. I'm a AWS DevOps Engineer. I specialize in Serverless applications on Amazon Web Services (AWS). My expertise is centered around core AWS services such as Lambda, Amazon ECS (*on Fargate or EC2), DynamoDB, API-Gateway, CloudFront, Amazon Route 53, Fastly CDN, and the many other services that compliment them to enable a production-ready environment. Recent Projects: ⦁ Three-Tier Network VPC on AWS ⦁ Synapse Matrix server deployment with Docker and EC2 (Video & Audio calls enabled) ⦁ Migration from Vercel to Amazon ECS (on EC2) ⦁ Fastly and AWS log & metric aggregation with Datadog ⦁ Datadog SIEM ⦁ Custom AWS Lambda Authorizer ⦁ Fastly CDN integration ⦁ Custom Fastly log aggregation and parsing with AWS (Lambda, DynamoDB, Firehose, etc.) ⦁ Application deployment on Amazon ECS (on Fargate) ⦁ CI/CD from GitHub to Amazon ECS with semantic versioning ⦁ AWS Secrets Manager and Parameter Store for Lambda and Amazon ECS parameters ⦁ RSS Aggregator
    Featured Skill Penetration Testing
    Maerix Synapse
    AWS Fargate
    Docker
    Amazon API Gateway
    Amazon DynamoDB
    AWS CloudFront
    AWS Lambda
    Amazon ECS
    Linux System Administration
    Amazon Web Services
    Python
    JavaScript
    Node.js
  • $110 hourly
    Seasoned cybersecurity expert with executive presence, extensive engineering capabilities, and a strong focus on offensive security challenges. Proficient in deploying security programs from policy development to hands-on implementation of comprehensive tool stacks. Highly motivated and adept at leading cybersecurity teams, developing training, and mentoring others. Skilled in tackling complex cybersecurity challenges, excelling in offensive security, and effectively communicating technical concepts in English and Spanish. Highly experienced in penetration testing for large domain environments and financial institutions. Certifications and Trainings: • January 2024 – Certificate #ADLID8313 Certified Red Team Professional (CRTP) Altered Security • February 2023 – Attacking & Defending Azure By Nikhil Mittal. Altered Security • June 2021 – Enterprise Attacker Emulation and C2 Implant Development By John Strand @Wild West Hackin’ Fest • August 2018 - Applied Data Science and Machine Learning for Cyber Security @BlackHat2018 • June 2018 – License # 6786 GIAC Web Application Penetration Tester (GWAPT) SANS SEC542 • March 2018 – Certificate # ECC91614970119 Certified EC-Council Instructor (CEI) • March 2018 – Certificate # ECC30215408965 EC-Council Certified Ethical Hacker (CEH) • February 2018 – Certificate # ECC71193024028 EC-Council Certified Incident Handler (ECIH) • January 2018 – Certificate # ECC52595515682 EC-Council Certified Network Defender (CND) • November 2016 – Certificate # 5838720 ITIL® Foundation Certificate in IT Service Management • June 2016 – Offensive Security Penetration Testing with Kali Linux (PWK) • March 2016 – License #133 GIAC Continuous Monitoring and Security Operations (GMON) SANS SEC511 • April 2015 – License #36727 GIAC Security Essentials (GSEC) SANS SEC401 • August 2014 – Certificate # FCNSP-2014-20681 Fortinet FCNSP Certified • May 2014 – Certificate # FCNSA-2014-19373 Fortinet FCNSA Certified • June 2013 – Cisco Certified Academy Instructor • June 2012 – Cisco ID # CSCO11636078 CCNA Security Certified • July 2009 – Cisco ID # CSCO11636078 CCNA Certified
    Featured Skill Penetration Testing
    Training
    Information Security Awareness
    Information Security
    Information Security Consultation
    Red Team Assessment
    System Security
    Cybersecurity Management
  • $560 hourly
    We have just spun off our security arm from our general Level 4 support entity. Security specialists that think outside-of-the-box to keep you, your business, and your data - safe. I have no problem disclosing our hourly rate. If it looks high to you then move along. If you care about your customers, your business, you, your family getting hacked and extorted then lets talk
    Featured Skill Penetration Testing
    Security Analysis
    Windows Server
    AWS Amplify
    Fortinet
    FortiGate Firewall
    Web Application Firewall
    Apache Administration
    Web API
  • $55 hourly
    Summary Results-driven Cybersecurity Analyst with over 5 years of experience in Security Operations Center (SOC) operations, threat detection, and incident response. Skilled in using SIEM platforms (Splunk, QRadar, Elastic Security), EDR solutions, and network forensic tools to monitor, analyze, and remediate security incidents. Expertise in malware analysis, phishing investigations, log correlation, and cloud security (AWS, Azure, GCP). Proven ability to handle 500+ monthly security events and reduce incident response times by 30%. Familiar with industry standards such as MITRE ATT&CK, NIST 800-53 and 800-171, ISO 27001, HIPAA, GDPR, and PCI DSS. Passionate about proactively defending against cyber threats and improving SOC response workflows.
    Featured Skill Penetration Testing
    Incident Response Readiness Assessment
    Ethical Hacking
    Cybersecurity Tool
    Cybersecurity Monitoring
    Information Security Awareness
    Vulnerability Assessment
    Threat Detection
    Cyber Threat Intelligence
    Information Security
  • $45 hourly
    Highly analytical and detail-oriented Application Security Analyst with 3.5+ years of experience in risk assessment, cloud security, and incident response to identify, diagnose, and resolve complex security issues to ensure secure application development. Skilled at defensive strategies, policy maintenance, and penetration testing.
    Featured Skill Penetration Testing
    Compliance
    Security Analysis
    OWASP
    Security Testing
    Cloud Security
    Web App Penetration Testing
    Web Application Security
    DevOps
    Vulnerability Assessment
    Application Security
  • $45 hourly
    PROFESSIONAL SUMMARY Security Operations Analyst with 2+ years of experience monitoring and responding to security incidents. Proficient in SIEM and EDR tools to analyze threats, manage vulnerabilities, and ensure regulatory compliance. Known for clear documentation and effective communication in high-pressure environments, consistently enhancing threat response and security posture. RELEVANT PROJECTS Enterprise Vulnerability Management Implementation Relevant Projects * Designed and deployed a comprehensive vulnerability management program using industry-standard tools such as Tenable Nessus, Tanium, and CrowdStrike. * Developed automated vulnerability scanning and remediation tracking mechanisms, reducing mean time to resolution (MTTR) by 35%. * Implemented security controls aligned with NIST & CIS frameworks, increasing overall security compliance. Network Security Monitoring System Development Relevant Projects
    Featured Skill Penetration Testing
    Risk Assessment
    CIS Control Assessment
    NIST Cybersecurity Framework
    Threat Detection
    Vulnerability Assessment
    Intrusion Prevention System
    Intrusion Detection System
    Splunk
    Network Security
    System Administration
    Computing & Networking
    Computer Network
    Information Security
    Government Reporting Compliance
  • $55 hourly
    IT Systems Engineer | Azure • Microsoft 365 • SharePoint • Device Imaging & Deployment I'm an experienced IT Systems Engineer with a strong background in Microsoft cloud solutions, device provisioning, and enterprise migrations. I specialize in: 🔹 Windows imaging and device builds for new users (ideal for onboarding and remote setups) 🔹 Migrating on-premise file servers to SharePoint Online 🔹 Seamless migrations to Microsoft 365 (Exchange, OneDrive, Teams, SharePoint) 🔹 Deploying and configuring devices in Azure AD and Microsoft Intune 🔹 Creating secure and scalable networks within Microsoft Azure Whether you're a small business looking to modernize your infrastructure, or an agency in need of backend IT support — I'm here to help with fast, reliable service. Let's work together to make your IT environment more efficient, secure, and cloud-ready.
    Featured Skill Penetration Testing
    Microsoft Intune
    Microsoft Azure
    IT Support
    Software Testing
    Testing
    Information Technology
    Military
  • $100 hourly
    Over 14 years of experience in Software/Web Development , Mobile App Development , Automation Test developing, Automation Framework design, API/Web Services testing and Mobile application testing, Penetration, Security and Performance testing. Extensive experienced in Cloud Computing/ DevOps (both AWS and MS Azure ). Advance knowledge in AI testing, LLM Prompt Engineering. Digital Marketing and SEO expert.
    Featured Skill Penetration Testing
    Digital Marketing
    LLM Prompt Engineering
    DevOps Engineering
    AWS Application
    Cloud Computing
    Performance Testing
    Security Testing
    Cyber Threat Intelligence
    QA Automation
    Artificial Intelligence
    Mobile App
    Web Development
    Software QA
    Quality Assurance
  • $50 hourly
    Passionate Cybersecurity and IT Support Specialist with hands-on experience from Fullstack Academy’s Cyber Bootcamp and a 28-year Navy career. I offer services in vulnerability assessment, incident response, and tech support. I’m here to help small businesses and organizations protect their systems, solve tech issues, and stay secure — reliably and efficiently. Let’s work together!
    Featured Skill Penetration Testing
    Information Security Awareness
    Cyber Threat Intelligence
    Help Desk Technology International ServicePRO
    Microsoft Active Directory
    Windows Server
    Office 365
    Splunk
    Linux
    Technical Support
    Incident Response Plan
    Network Security
    Cybersecurity Monitoring
    Government Reporting Compliance
    Python
  • $60 hourly
    With over 10 years of extensive experience in Information Technology and Cybersecurity, I specialize in delivering enterprise-grade IT security solutions, risk management, and secure infrastructure design. I have successfully led multiple mega and enterprise IT security projects for government and private sectors, including implementation, migration, and threat prevention. My expertise spans Information Security Risk Management, Network Security (FortiNet, Palo Alto, Cisco, Juniper), Cloud Security (AWS Certified Security Specialist), DevOps (Ansible, Docker, Kubernetes), and Operating Systems (RHEL, Windows Server, Solaris). I am well-versed in penetration testing, vulnerability compliance, and data protection technologies like DLP, SIEM, and encryption. Certified as CISSP, AWS Security Specialist, RHCE, PCNSE, and more, I provide end-to-end cybersecurity consulting—from risk assessments and system security plans aligned with NIST standards, to continuous threat monitoring and remediation strategies. I excel at creating strategic roadmaps, training teams, and delivering practical security solutions tailored to client needs, ensuring data integrity and regulatory compliance. Let’s connect to secure your infrastructure and elevate your security posture with proven expertise and dedication.
    Featured Skill Penetration Testing
    Antivirus & Security Software
    CI/CD
    Firewall
    Business Continuity Plan
    Risk Management
    Compliance
    Information Security Audit
    Information Security Awareness
    Information Security Governance
    Intrusion Prevention System
    Security Assessment & Testing
    Cloud Security
    Network Security
    System Security
  • $20 hourly
    I specialize in manual penetration testing, using a wide range of proven payloads and fuzzing techniques to target every entry point in your web application—be it parameters, URLs, headers, or hidden endpoints. Once manual tests identify potential weak spots, I augment the process with industry-grade automated tools to ensure comprehensive coverage and clarity. Although many automated tools exist to detect vulnerabilities, they often produce false positives and overlook context-specific threats. That’s where I come in. 🔐 Here’s What I Offer: ✅ Manual Web Application Penetration Testing — Exploit-focused testing across all input vectors and endpoints ✅ OWASP Top 10 Coverage & Beyond — XSS, SQLi, CSRF, IDOR, SSRF, LFI, RCE, logic flaws, and more ✅ Reconnaissance & Attack Surface Mapping — Subdomain enumeration, directory brute-forcing, hidden admin panels, exposed APIs ✅ WordPress Security Audits — Plugin/theme vulnerability checks, outdated component detection, multisite hardening ✅ Professional Reports — Full write-ups with screenshots, CVSS-based severity ratings, PoC payloads, and actionable remediation advice 💻 Tools I Use: Burp Suite, FFUF, WPScan, Nmap, Nikto, SQLmap, Axiom, Amass, custom scripts, and more. Whether you're a startup preparing for launch or an established business securing production systems, I can help you identify and fix vulnerabilities before real attackers do. 📩 Let’s talk and make your web app resilient from real-world threats.
    Featured Skill Penetration Testing
    Source Code Scanning
    Vulnerability Assessment
    Bug Bounty
    WordPress Security
    Web App Penetration Testing
  • $30 hourly
    I’m a developer with expertise in building scalable systems and personalized recommendation platforms for a variety of industries, including entertainment, literature, and dining. Whether you're looking to create data-driven solutions, optimize user experiences, or integrate complex APIs, I can help. Development of intelligent recommendation systems using Neo4j, Supabase, and PostgreSQL. API integrations with platforms like Spotify, TMDB, and Yelp for seamless data acquisition. Expertise in Python, data modeling, and graph databases. Full project lifecycle support from database design to frontend integration. Let’s collaborate to turn your ideas into impactful, user-centered applications.
    Featured Skill Penetration Testing
    ETL
    Data Extraction
    Data Mining
    Reverse Engineering
    Data Engineering
    Data Analysis
    Python
    Information Security
    Security Testing
  • Want to browse more freelancers?
    Sign up

How hiring on Upwork works

1. Post a job

Tell us what you need. Provide as many details as possible, but don’t worry about getting it perfect.

2. Talent comes to you

Get qualified proposals within 24 hours, and meet the candidates you’re excited about. Hire as soon as you’re ready.

3. Collaborate easily

Use Upwork to chat or video call, share files, and track project progress right from the app.

4. Payment simplified

Receive invoices and make payments through Upwork. Only pay for work you authorize.

Trusted by 5M+ businesses