Hire the Best Penetration Testers
in the United States

Clients rate our Penetration Testers
Rating is 4.9 out of 5.
4.9/5
Based on 133 client reviews
Daniel H.

Fayetteville, North Carolina

$40/hr
5.0
14 jobs

Hi I am Daniel Hayes a experienced penetration tester specializing in red teaming, with a strong focus on adversary emulation. I have been ethically hacking for over five years and working as a cybersecurity consultant for three. I have successfully breached multi-million and billion-dollar organizations worldwide. As a former penetration tester for one of the top seven professional services firms globally, I have extensive experience working with different organizations from various industries to ensure their cybersecurity needs are met. Services I Perform (But not limited to) - Web Application Penetration Testing (Black Box / White Box) - External Penetration Testing (Black Box / White Box) - Internal Penetration Testing (Black Box / White Box) - Red Teaming / Adversary Simulation - Compliance and Regularly Frameworks (NIST, SOC2, HIPAA, Etc) I look forward to helping you keep your organization safe from any threat!

  • Penetration Testing
  • Network Penetration Testing
  • Web App Penetration Testing
Thomas W.

Colorado Springs, Colorado

$125/hr
5.0
6 jobs

"Top Rated Plus" cybersecurity consultant and published author with 25+ years of experience specializing in penetration testing. Clients hire me when they need senior-level testing that includes clear scoping, reporting that drives remediation, and efficient execution. I’ve led red team and penetration testing work for Fortune 100 enterprises, government agencies, and startups. My assessments are designed to simulate realistic attacker behavior, prioritize what matters most, and produce results that are easy for technical teams to reproduce and fix. Areas of expertise: * Web application testing (OWASP Top 10, authentication/session flaws, access control, input validation, SSRF, IDOR, RCE) * API testing (token/session handling, authorization boundaries, input validation, business logic, fuzzing where appropriate) * Internal and external network testing (Windows, Linux, hybrid) with segmentation and control validation * Active Directory testing (enumeration, privilege escalation simulation, attack path validation) * AWS and Azure security reviews (misconfigurations, IAM privilege analysis, exposure discovery, logging and monitoring validation) * Compliance-aligned testing and guidance (PCI DSS, HIPAA, CIS, NIST and more) What you can expect: * Strong communication, documented scope, and no surprises * Findings prioritized by real-world impact, not just scanner output * Executive summary plus actionable remediation steps your team can use immediately * Optional live debrief and remediation testing Certifications: CISSP, CCSP, ISSMP, AWS Security Specialty, AWS Solutions Architect, CCNP Security, and more. Published author of multiple penetration testing books and a frequent security conference speaker.

  • Penetration Testing
  • Security Assessment & Testing
  • Ethical Hacking
  • Information Security
  • Network Penetration Testing
  • Network Security
  • Vulnerability Assessment
  • Cloud Security
  • Cybersecurity Management
  • Red Team Assessment
  • OWASP
  • Certified Information Systems Security Professional
  • Kali Linux
  • Web Testing
  • Application Security
Chase M.

Pittsburgh, Pennsylvania

$100/hr
5.0
3 jobs

I'm a senior penetration tester and security consultant based in Pittsburgh. By day, I lead security assessments for U.S. critical infrastructure. On the side, I help startups and growth-stage companies with penetration testing and virtual CISO (vCISO) work. Background: 15 years in offensive security. Former Senior Security Analyst at Bishop Fox. Former penetration tester at Carnegie Mellon's CERT Division. I've also taught graduate-level ethical hacking at Carnegie Mellon. I've responsibly disclosed critical vulnerabilities to Google, Netflix, Spotify, eBay, Dropbox, and others. I am also the founder of a vCISO consultancy and a penetration testing company. What I do best: Web and API penetration testing, cloud security assessments (AWS/Azure/GCP), and helping companies get audit-ready for SOC 2, ISO 27001, HIPAA, and CMMC, without overcomplicating it. Certs: CISSP, OSCP, CREST CPSA, AWS CCP. MS in Information Security from Carnegie Mellon. I work directly with clients. No subcontracting, no handoffs. If that fits what you're looking for, send me a message.

  • Penetration Testing
  • Ethical Hacking
  • Network Security
  • Kali Linux
  • Security Analysis
  • Security Engineering
  • ISO 27001
  • Security Infrastructure
  • Wireless Security
  • Amazon Web Services
Ameen K.

Booth, Texas

$60/hr
5.0
17 jobs

I'm a USA based consultant with 10+ years experience in penetration testing. I’ve led and executed over 500 assessments across diverse environments—web applications, internal/external networks, red/purple teams, cloud infrastructures, social engineering, mobile platforms, and even physical security. I’ve had the privilege of consulting for some of the biggest Fortune 500 companies, including PayPal, Berkshire Hathaway, TikTok, Meta, Tesla, Saudi Aramco, and more, delivering actionable insights to strengthen their security postures. Additionally, I spent over 9 months working alongside leading financial and social media companies, optimizing and expanding network infrastructures with 100,000+ devices, ensuring streamlined and secure operations at scale. Whether you're a small business or an enterprise, I bring proven expertise to identify vulnerabilities, mitigate risks, and secure what matters most. Let’s build a stronger, more resilient security framework together! 🔢 My stats are: ✅ Saved tens of thousands of dollars for Forbes 500 clients by identifying critical vulnerabilities ✅ Professional certifications (OSCP, GCPN,Security+) ✅ Top 10 in HackTheBox Team Global Rank ✅ Won 2022 DEF CON 30 CTF Competition ✅ Supporting all time zones ✅ Long-term engagements ✅ USA based ✅ Active LLC ✅ Active Liability insurance 🔢Core Competencies: 1. Network Penetration Testing 2. Web Application Penetration Testing 3. Social Engineering (Phishing, Vishing) 4. Cloud (Azure/AWS ) Penetration Testing 5. Security Training 6. Defensive Solution Configurations/Reviews (Security Engineering) 7. Malware Analysis 8. Cyber Risk Analysis 9. API Penetration Testing 10. Mobile Penetration Testing 11. External Network Penetration Testing 12. Vulnerability Assessment Testing ✅I love finding vulnerabilities. Whether those vulnerabilities exist in your firewall configuration, your employee training, or under your security fence, I will identify, triage, and alert you of threats before an attacker turns them into the next front page news story. 🔢Working with me, you will: ✅ Customized approach: I understand that every client's needs are unique, and I tailor my approach to meet your specific requirements. This ensures that you get the most comprehensive and effective security testing possible. ✅ Timely delivery: I understand that time is of the essence when it comes to security testing, and I always deliver my reports on time, without compromising on quality. ✅ Complete manual testing for your application and immediate notification if any high-impact issues are found. ✅ Unlimited retesting for the fixed issues and unlimited revisions ✅ Able to find critical bug classes that are often missed by automated pentests. 🔢NOTE: If you want to see my past reports I have done with previous clients know that reports contains sensitive information, NDA is signed for most of them especially from Gov & Forbes 500 clients. Disclosing information like that is breach of client privacy. However, I can share sample report with sensitive information hidden. Skills: Penetration Testing: Extensive experience conducting penetration tests, red team exercises, and purple team engagements across various platforms, including but not limited to, web applications, APIs, wireless, physical, network infrastructure, cloud environments (AWS & Azure), and other devices. Security Tools: Proficient in utilizing a wide range of security tools such as Burp Suite, Metasploit, C2 frameworks, Mythic, Sliver, bloodhound, etc. for penetration tests and red team operations. Defensive and Monitoring Technologies: Familiarity with defensive and monitoring technologies, including Intrusion Prevention Systems (IPS), Intrusion Detection Systems (IDS), Web Application Firewalls (WAF), and Security Information and Event Management (SIEM) solutions. Programming and Scripting: Proficient in scripting languages such as Python and Bash. Skilled in modifying and executing exploits and proof-of-concepts (POCs) to evade defensive countermeasures and emulate threat actor tactics, techniques, and procedures (TTPs). Cybersecurity Compliance: Familiar with security compliance requirements and industry standards, including MITRE ATT&CK, Cyber Kill Chain, HIPAA, NIST Cybersecurity Framework, and OWASP. Communication and Collaboration: Excellent communication and reporting skills to effectively communicate technical issues to both technical and non-technical stakeholders. Proven ability to work independently and collaboratively in a team environment.

  • Penetration Testing
  • Information Security
  • Network Penetration Testing
  • Web App Penetration Testing
  • Compliance
  • Cloud Security
  • Security Testing
  • NIST Cybersecurity Framework
  • Red Team Assessment
  • OWASP
Anthony G.

Kings County, New York

$75/hr
4.4
116 jobs

As a seasoned freelance programmer with a strong foundation in security and Unix systems, I bring a wealth of expertise to the realm of software development. With a passion for tackling complex challenges, I specialize in full-stack development, reverse engineering, and imparting knowledge through tutoring. Technical Proficiency: - Programming Languages: Proficient in a diverse range of languages including Python, Java, Ruby, Perl, C, JavaScript, and more! - Security Expertise: Extensive experience in identifying and mitigating security vulnerabilities. Adept at conducting penetration testing, threat modeling, and implementing robust security measures. - Unix Mastery: In-depth understanding of Unix-based systems, with a focus on Linux. Capable of optimizing system performance and ensuring the security and stability of Unix environments. Full Stack Development: - Frontend: Skilled in crafting responsive and user-friendly interfaces using HTML, CSS, and JavaScript frameworks such as React and Angular. Backend: Experienced in developing scalable server-side applications with proficiency in Node.js, Django, and Flask. Database Management: Proficient in designing and implementing databases using MySQL, PostgreSQL, and MongoDB. Reverse Engineering: - Binary Analysis: Expertise in reverse engineering and analyzing binaries to uncover vulnerabilities and enhance software security. Tutoring and Mentorship: - Educational Background: Possessing a comprehensive understanding of programming fundamentals, security concepts, and Unix systems, I am adept at conveying complex ideas in an accessible manner. - Mentorship: Committed to fostering the growth of aspiring developers through personalized guidance, code reviews, and hands-on mentorship. Additional Skills: - DevOps: Proficient in implementing CI/CD pipelines, containerization (Docker), and orchestration (Kubernetes) for streamlined development and deployment processes. - Networking: Knowledgeable in networking protocols, firewall configurations, and VPN setups to ensure robust and secure communication. - Cloud technologies: AWS, GCP, and Azure. Professional Approach: - Problem Solver: Known for my analytical mindset and creative problem-solving skills, I thrive in dynamic environments and excel at finding innovative solutions to intricate challenges. - Collaborative Team Player: Effective in cross-functional collaborations, I communicate technical concepts to both technical and non-technical stakeholders, fostering a cohesive and productive working atmosphere. With a commitment to continuous learning and a track record of delivering high-quality solutions, I am well-equipped to contribute to projects requiring a versatile and experienced freelance programmer with a focus on security and Unix environments.

  • Java
  • JavaScript
  • C++
  • Python
  • Ruby
  • SQL
  • Perl
  • C
  • HTML
  • Assembly Language
Ahmed P.

Carbondale, Illinois

$65/hr
5.0
11 jobs

Penetration Tester | Ethical Hacker | Red Team | Web & Network Security Need a Penetration Tester or Ethical Hacker to identify security vulnerabilities before attackers find them? I am a Cybersecurity Specialist and Penetration Tester specializing in Penetration Testing, Ethical Hacking, Red Teaming, Web Application Security, Network Security, Active Directory Security, API Security, Vulnerability Assessment, and Adversary Emulation. I help businesses find, validate, and clearly document security vulnerabilities across web applications, APIs, networks, cloud environments, and Active Directory infrastructure. My Cybersecurity and Penetration Testing services include: • Penetration Testing and Ethical Hacking • Web Application Penetration Testing • Network Penetration Testing • API Penetration Testing • Active Directory Penetration Testing • Red Team Operations and Adversary Emulation • Vulnerability Assessment and Security Testing • AWS and Cloud Security Testing • EDR Testing and Security Control Validation • Phishing Simulations and Social Engineering Assessments • Incident Response Support • OWASP Top 10 Security Testing • Security Assessment and Vulnerability Reporting • Threat Detection and TTP Research I have led 12+ Active Directory-focused CTF events with 120+ participants and have experience automating offensive security workflows, evaluating security solutions, building security test environments using Atomic Red Team and AWS Lambda, and executing controlled attack campaigns. I also have experience assessing APIs, web applications, enterprise networks, Active Directory environments, cloud infrastructure, and AI systems. Certifications: • PNPT - Practical Network Penetration Tester • CRTO - Certified Red Team Operator • CompTIA Security+ • CCNA My core skills include Penetration Testing, Cybersecurity, Ethical Hacking, Red Teaming, Network Security, Web Security, Application Security, Active Directory, Vulnerability Assessment, Vulnerability Management, API Security, Cloud Security, AWS Security, EDR, Adversary Emulation, OWASP, Incident Response, Threat Detection, Security Testing, and Offensive Security. If you need a Penetration Tester, Ethical Hacker, Red Team Specialist, or Cybersecurity Consultant for a security assessment, I can help identify vulnerabilities and provide clear actionable remediation recommendations.

  • Penetration Testing
  • Network Penetration Testing
  • Vulnerability Assessment
  • System Security
  • Application Security
  • Windows Server
  • Linux System Administration
  • Linux
  • Cisco Certified Network Associate
  • Python
  • Scripting
  • Computing & Networking
  • Web Application Security
  • Web Application

How it works

Post a job for freePost a job

Tell us what you need. Create your own job post or generate one with AI then filter talent matches.

Hire top talent fast

Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.

Collaborate easily

Use Upwork to chat or video call, share files, and track project progress right from the app.

Payment simplified

Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.

Don't just take our word for it

How do I hire a Penetration Tester in the United States on Upwork?

You can hire a Penetration Tester in the United States on Upwork in four simple steps:

  • Create a job post tailored to your Penetration Tester project scope. We'll walk you through the process step by step.
  • Browse top Penetration Tester talent on Upwork and invite them to your project.
  • Once the proposals start flowing in, create a shortlist of top Penetration Tester profiles and interview.
  • Hire the right Penetration Tester for your project from Upwork, the world's largest work marketplace.

At Upwork, we believe talent staffing should be easy.

How much does it cost to hire a Penetration Tester?

Rates charged by Penetration Testers on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.

Why hire a Penetration Tester in the United States on Upwork?

As the world's work marketplace, we connect highly-skilled freelance Penetration Testers and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Penetration Tester team you need to succeed.

Can I hire a Penetration Tester in the United States within 24 hours on Upwork?

Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Penetration Tester proposals within 24 hours of posting a job description.