Hi I am Daniel Hayes a experienced penetration tester specializing in red teaming, with a strong focus on adversary emulation. I have been ethically hacking for over five years and working as a cybersecurity consultant for three. I have successfully breached multi-million and billion-dollar organizations worldwide. As a former penetration tester for one of the top seven professional services firms globally, I have extensive experience working with different organizations from various industries to ensure their cybersecurity needs are met.
Services I Perform (But not limited to)
- Web Application Penetration Testing (Black Box / White Box)
- External Penetration Testing (Black Box / White Box)
- Internal Penetration Testing (Black Box / White Box)
- Red Teaming / Adversary Simulation
- Compliance and Regularly Frameworks (NIST, SOC2, HIPAA, Etc)
I look forward to helping you keep your organization safe from any threat!
Penetration Testing
Network Penetration Testing
Web App Penetration Testing
Michael H.
Baltimore, Maryland
$125/hr
5.0
115 jobs
Stop relying on automated scans. I find the vulnerabilities they miss.
I’m a senior penetration tester and vulnerability researcher with deep experience across enterprise networks, web apps / APIs and cloud platforms.
Most testers just run automated tools and hand you a generic report. I simulate how an attacker actually thinks, perform thorough testing, and deliver professional, tailored reporting suitable not just for your own remediation efforts but also for audit / compliance.
Benefits of manual testing:
- Chaining multiple low/medium findings to show more significant impact
- Breaking multi-tenant isolation
- Bypassing auth controls (JWT, OAuth, misconfigurations)
- Identifying cost-amplification / abuse vectors (e.g., billing attacks in serverless environments)
- ZERO false positives (and wasted time trying to remediate non-issues)
- REAL severity scoring (not just CVSS or ratings with no connection to actual impact/risk for your systems and data)
What I Deliver
- Manual, attacker-style testing (not just scans)
- Clear, prioritized findings with real business impact
- Proof-of-concept exploits where it matters
- Practical remediation guidance your devs can use immediately
- Optional retesting to verify fixes
Common Engagements
- SaaS / multi-tenant application security testing
- API and authentication testing (JWT, OAuth, session flaws)
- Cloud security reviews (GCP, AWS, Azure, O365)
- DevOps security reviews (Gitlab/hub, BitBucket, etc.)
- Pre-SOC2 / investor readiness assessments
- High-intensity black-box pentests
Why Clients Hire Me
- I go beyond the scan—I find what others miss
- I understand both offense and architecture
- I communicate clearly with both engineers and leadership
- I’ve worked on MANY real-world, high-impact systems
I also help organizations:
- Investigate breaches
- Contain active threats
- Recover compromised systems
(Note: I do not assist with social media account recovery.)
Penetration Testing
Security Assessment & Testing
Ethical Hacking
Network Penetration Testing
Network Security
Vulnerability Assessment
Web App Penetration Testing
Security Analysis
Security Engineering
Web Application Security
Certified Information Systems Security Professional
OWASP
White Box Testing
Security Infrastructure
Incident Management
Ahmed P.
Carbondale, Illinois
$50/hr
5.0
9 jobs
Cybersecurity professional specializing in Red Teaming, Network Security, and Adversary Emulation. Skilled in bypassing EDR solutions, executing stealthy attacks, and assessing enterprise security postures. Led 12+ Active Directory-focused CTF events with 120+ participants, automated offensive security workflows, and evaluated vendor security solutions. Focused on TTP research, OPSEC evasion, and improving threat detection.
I have worked on building test environments using Atomic Red Team and AWS Lambda, running attack campaigns, and securing APIs, web applications, and AI models.
As the founder of Assumed Breach, I provide services such as penetration testing, red team operations, phishing simulations, and incident response.
I am certified in PNPT, CRTO, and Security+, bringing expertise in offensive security.
Penetration Testing
Network Penetration Testing
Vulnerability Assessment
System Security
Application Security
Windows Server
Linux System Administration
Linux
Cisco Certified Network Associate
Python
Scripting
Computing & Networking
Web Application Security
Web Application
Dwight G.
Ashburn, Virginia
$85/hr
5.0
13 jobs
I am a mid level to senior cybersecurity professional with 7+ years of hands-on experience delivering penetration testing, vulnerability assessments, risk analysis, and compliance-driven security programs for commercial, enterprise, and government environments.
I help organizations find real security gaps, reduce risk, and meet regulatory requirements—without unnecessary complexity or vendor lock-in.
Team Gala_Layo's background spans offensive security (Red Team), defensive controls, cloud security, identity & access management, and governance frameworks including NIST, ISO 27001, HIPAA, PCI-DSS, FedRAMP, and CMMC etc...I specialize in translating technical findings into executive-ready risk insights that drive action.
I am the President and Technical Lead at Gala_Layo, a cybersecurity firm trusted by federal agencies, regulated industries, and high-risk organizations.
What I Do Best
============
Penetration Testing & Ethical Hacking
---------------------------------------------
* Network, web application, API, wireless, and cloud penetration testing
* OWASP Top 10, SANS Top 25, manual exploitation & validation
* Tooling: Metasploit, Burp Suite Pro, Nessus, Nmap, OpenVAS, Aircrack-ng, Wireshark
* Actionable reports with proof-of-concept, risk scoring, and remediation guidance
Vulnerability & Risk Assessments
---------------------------------------
* NIST-aligned security risk assessments
* Vulnerability scanning & continuous risk scoring
* Risk registers, POA&M development, and control gap analysis
* STIGS
Tools: Tenable.sc, Qualys, Rapid7, ServiceNow GRC, RegScale
Cloud & Identity Security
------------------------------
* AWS & Azure security posture reviews
* IAM, MFA, SSO, and privileged access reviews
* WAF and cloud security configuration audits
Tools: Okta, Azure AD (Entra ID), Auth0, CyberArk
Governance, Risk & Compliance (GRC)
----------------------------------------------
* NIST RMF, NIST CSF 2.0, ISO 27001, HIPAA, PCI-DSS
* FedRAMP, CMMC, FFIEC, GSA compliance support
* Policy, SOP, and incident response plan authoring
* Change Control Advisory Board (CAB) experience
AI & Emerging Technology Security
-------------------------------------------
* Secure-by-Design and MLSecOps advisory
* AI risk assessments & Responsible AI impact analysis
* Prompt injection & LLM threat modeling
* Integration of AI into security workflows safely and responsibly
Industries Served
---------------------
* Government & Federal Contractors
* Healthcare & Life Sciences
* Financial Services
* Cloud & SaaS
* Critical Infrastructure
* Small & Mid-Sized Businesses (SMBs)
Tools & Technologies
-------------------------
* Operating Systems: Kali Linux, Ubuntu, Windows, macOS
* Languages: Python, JavaScript, Shell
* Security Tools: Nessus, Burp Suite, Metasploit, Rapid7, Qualys, Splunk
* Cloud: AWS, Azure
* Dev & Code: GitLab, VS Code, Snyk, SonarQube
* Virtualization: VMware, VirtualBox
Certifications & Education
-------------------------------
* Certified Ethical Hacker (CEH)
* CompTIA Security+
Security Clearance
------------------------
* Top Secret
Education
------------
* M.S. Information & Communications Technology – Information Systems Security
University of Denver (GPA 4.0, magna cum laude)
Why Clients Hire Me
------------------------
✔ Real-world offensive & defensive experience
✔ Clear, business-focused reporting (not scanner noise)
✔ Deep federal & regulatory knowledge
✔ Ability to explain complex risks to non-technical stakeholders
✔ Trusted advisor—not just a tool operator
Typical Projects
-------------------
* Penetration Testing & Red Team Engagements
* Vulnerability Assessments & Risk Registers
* NIST / ISO / HIPAA Readiness Assessments
* Cloud Security Reviews (AWS / Azure)
* Incident Response Planning & Tabletop Exercises
* AI & Emerging Tech Risk Assessments
Penetration Testing
Network Security
Vulnerability Assessment
NIST Cybersecurity Framework
Web Application Security
API Testing
Governance, Risk Management & Compliance
Risk Assessment
Zero Trust Architecture
Cloud Security Framework
Incident Response Readiness Assessment
User Identity Management
Compliance Testing
Information Security Audit
Cybersecurity Management
Thomas W.
Colorado Springs, Colorado
$150/hr
5.0
6 jobs
"Top Rated Plus" cybersecurity consultant and published author with 25+ years of experience specializing in penetration testing. Clients hire me when they need senior-level testing that includes clear scoping, reporting that drives remediation, and efficient execution.
I’ve led red team and penetration testing work for Fortune 100 enterprises, government agencies, and startups. My assessments are designed to simulate realistic attacker behavior, prioritize what matters most, and produce results that are easy for technical teams to reproduce and fix.
Areas of expertise:
* Web application testing (OWASP Top 10, authentication/session flaws, access control, input validation, SSRF, IDOR, RCE)
* API testing (token/session handling, authorization boundaries, input validation, business logic, fuzzing where appropriate)
* Internal and external network testing (Windows, Linux, hybrid) with segmentation and control validation
* Active Directory testing (enumeration, privilege escalation simulation, attack path validation)
* AWS and Azure security reviews (misconfigurations, IAM privilege analysis, exposure discovery, logging and monitoring validation)
* Compliance-aligned testing and guidance (PCI DSS, HIPAA, CIS, NIST and more)
What you can expect:
* Strong communication, documented scope, and no surprises
* Findings prioritized by real-world impact, not just scanner output
* Executive summary plus actionable remediation steps your team can use immediately
* Optional live debrief and remediation testing
Certifications: CISSP, CCSP, ISSMP, AWS Security Specialty, AWS Solutions Architect, CCNP Security, and more. Published author of multiple penetration testing books and a frequent security conference speaker.
Penetration Testing
Security Assessment & Testing
Ethical Hacking
Information Security
Network Penetration Testing
Network Security
Vulnerability Assessment
Cloud Security
Cybersecurity Management
Red Team Assessment
OWASP
Certified Information Systems Security Professional
Kali Linux
Web Testing
Application Security
Ameen K.
Booth, Texas
$65/hr
5.0
17 jobs
I'm a USA based consultant with 10+ years experience in penetration testing. I’ve led and executed over 500 assessments across diverse environments—web applications, internal/external networks, red/purple teams, cloud infrastructures, social engineering, mobile platforms, and even physical security.
I’ve had the privilege of consulting for some of the biggest Fortune 500 companies, including PayPal, Berkshire Hathaway, TikTok, Meta, Tesla, Saudi Aramco, and more, delivering actionable insights to strengthen their security postures.
Additionally, I spent over 9 months working alongside leading financial and social media companies, optimizing and expanding network infrastructures with 100,000+ devices, ensuring streamlined and secure operations at scale.
Whether you're a small business or an enterprise, I bring proven expertise to identify vulnerabilities, mitigate risks, and secure what matters most. Let’s build a stronger, more resilient security framework together!
🔢 My stats are:
✅ Saved tens of thousands of dollars for Forbes 500 clients by identifying critical vulnerabilities
✅ Professional certifications (OSCP, GCPN,Security+)
✅ Top 10 in HackTheBox Team Global Rank
✅ Won 2022 DEF CON 30 CTF Competition
✅ Supporting all time zones
✅ Long-term engagements
✅ USA based
✅ Active LLC
✅ Active Liability insurance
🔢Core Competencies:
1. Network Penetration Testing
2. Web Application Penetration Testing
3. Social Engineering (Phishing, Vishing)
4. Cloud (Azure/AWS ) Penetration Testing
5. Security Training
6. Defensive Solution Configurations/Reviews (Security Engineering)
7. Malware Analysis
8. Cyber Risk Analysis
9. API Penetration Testing
10. Mobile Penetration Testing
11. External Network Penetration Testing
12. Vulnerability Assessment Testing
✅I love finding vulnerabilities. Whether those vulnerabilities exist in your firewall configuration, your employee training, or under your security fence, I will identify, triage, and alert you of threats before an attacker turns them into the next front page news story.
🔢Working with me, you will:
✅ Customized approach: I understand that every client's needs are unique, and I tailor my approach to meet your specific requirements. This ensures that you get the most comprehensive and effective security testing possible.
✅ Timely delivery: I understand that time is of the essence when it comes to security testing, and I always deliver my reports on time, without compromising on quality.
✅ Complete manual testing for your application and immediate notification if any high-impact issues are found.
✅ Unlimited retesting for the fixed issues and unlimited revisions
✅ Able to find critical bug classes that are often missed by automated pentests.
🔢NOTE: If you want to see my past reports I have done with previous clients know that reports contains sensitive information, NDA is signed for most of them especially from Gov & Forbes 500 clients. Disclosing information like that is breach of client privacy. However, I can share sample report with sensitive information hidden.
Skills:
Penetration Testing: Extensive experience conducting penetration tests, red team exercises, and purple team engagements across various platforms, including but not limited to, web applications, APIs, wireless, physical, network infrastructure, cloud environments (AWS & Azure), and other devices.
Security Tools: Proficient in utilizing a wide range of security tools such as Burp Suite, Metasploit, C2 frameworks, Mythic, Sliver, bloodhound, etc. for penetration tests and red team operations.
Defensive and Monitoring Technologies: Familiarity with defensive and monitoring technologies, including Intrusion Prevention Systems (IPS), Intrusion Detection Systems (IDS), Web Application Firewalls (WAF), and Security Information and Event Management (SIEM) solutions.
Programming and Scripting: Proficient in scripting languages such as Python and Bash. Skilled in modifying and executing exploits and proof-of-concepts (POCs) to evade defensive countermeasures and emulate threat actor tactics, techniques, and procedures (TTPs).
Cybersecurity Compliance: Familiar with security compliance requirements and industry standards, including MITRE ATT&CK, Cyber Kill Chain, HIPAA, NIST Cybersecurity Framework, and OWASP.
Communication and Collaboration: Excellent communication and reporting skills to effectively communicate technical issues to both technical and non-technical stakeholders. Proven ability to work independently and collaboratively in a team environment.
Penetration Testing
Information Security
Network Penetration Testing
Web App Penetration Testing
Compliance
Cloud Security
Security Testing
NIST Cybersecurity Framework
Red Team Assessment
OWASP
How it works
Post a job for freePost a job
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a Penetration Tester in the United States on Upwork?
You can hire a Penetration Tester in the United States on Upwork in four simple steps:
Create a job post tailored to your Penetration Tester project scope. We'll walk you through the process step by step.
Browse top Penetration Tester talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top Penetration Tester profiles and interview.
Hire the right Penetration Tester for your project from Upwork, the world's largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a Penetration Tester?
Rates charged by Penetration Testers on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a Penetration Tester in the United States on Upwork?
As the world's work marketplace, we connect highly-skilled freelance Penetration Testers and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Penetration Tester team you need to succeed.
Can I hire a Penetration Tester in the United States within 24 hours on Upwork?
Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Penetration Tester proposals within 24 hours of posting a job description.
Find more freelancers
Top states for Penetration Testers in the United States