I am a cybersecurity specialist with expertise in SIEM engineering, EDR deployment, SOC operations, and security automation.
I deploy and tune Splunk, QRadar, Elastic, Wazuh, LogScale, NG SIEM, CrowdStrike, and SentinelOne, write the detection rules that go on top, and automate the triage so alerts turn into answers instead of backlog.
Five plus years in live security operations, including MSSP environments serving clients across the globe.
SIEM ENGINEERING & DEPLOYMENT
- Splunk, IBM QRadar, Elastic SIEM, CrowdStrike NG SIEM and LogScale, Wazuh
- Platform setup, sizing, and log source onboarding
- Parsers, custom detection rules, correlation searches, dashboards
- SIEM to SIEM migrations
EDR & XDR
- CrowdStrike Falcon, SentinelOne, Microsoft Defender, Darktrace
- Agent rollout and policy tuning
- Threat hunting mapped to MITRE ATT&CK
SOC OPERATIONS & INCIDENT RESPONSE
- Alert triage through containment and root cause
- Alert tuning and gap analysis to cut false positives
- Digital forensics with Volatility, Autopsy, Wireshark
- Malware analysis to build detection signatures
SOAR & AUTOMATION
- Playbooks in Splunk SOAR (Phantom), IBM QRadar SOAR (Resilient), Cortex XSOAR, Cortex XSIAM, n8n, Tines
- Python, PowerShell, and Bash for the glue nobody sells a product for
- Recent build cut handling time on repetitive alerts by around 60 percent
AI FOR SECURITY OPERATIONS
- LLM agents that do the first pass on alerts and draft investigation notes
- Automated CVE advisory generation from vendor feeds
- STIX 2.1 threat intel pipelines feeding OpenCTI
VULNERABILITY ASSESSMENT & COMPLIANCE
- Vulnerability assessment with Rapid7 Nexpose and Nessus
- SOC 2 and ISO 27001 control mapping and evidence collection
I ask what your detection gaps actually are before recommending anything. You get working content in your environment and documentation that outlives the contract.
Message me with what you are running and what is breaking. Happy to discuss and jump on a quick call
Splunk
Python
Cyber Threat Intelligence
Cybersecurity Tool
Digital Forensics
Cryptography
SOC 1
Elasticsearch
ELK Stack
CrowdStrike
n8n
Linux
Kali Linux
Security Operation Center
Network Security
Rizwan Ahmad B.
Islamabad, Pakistan
$35/hr
5.0
96 jobs
I am an IT, Cybersecurity, and AI professional with **15+ years of experience** designing, developing, deploying, and managing enterprise IT and security solutions. I have successfully delivered **100+ enterprise projects**, with **3,000+ Upwork hours, 81+ completed jobs, 100% Job Success, Top Rated status, and $100K+ in Upwork earnings**.
My current focus is on **AI engineering, application development, product development, and AI-powered cybersecurity**, while continuing to work extensively with **Wazuh, SIEM, XDR, SOC automation, network security, and infrastructure**.
### 🤖 AI Engineering & Application Development
I work extensively with both **open-source and cloud-based AI technologies**, building practical AI solutions rather than simply integrating APIs.
* LLM application development and integration
* Open-source LLMs including **Llama, Qwen, DeepSeek, Gemma**, and other models
* OpenAI / ChatGPT and cloud AI platforms
* **RAG (Retrieval-Augmented Generation)** architectures
* Vector databases and semantic search
* Embeddings and knowledge-base systems
* **AI Agents and Agentic workflows**
* Multi-agent systems
* AI orchestration and **LLM orchestration layers**
* Prompt engineering and structured AI workflows
* AI-powered automation and decision-making
* AI integration with enterprise applications and APIs
* AI-powered cybersecurity and SOC use cases
* Model evaluation, optimization, and deployment
* Self-hosted and private AI environments
* Docker-based AI deployments and GPU environments
I particularly enjoy building the **orchestration layer between LLMs, enterprise data, security platforms, APIs, tools, and automation**, turning AI models into practical production systems.
### 🛡️ Cybersecurity, SIEM & XDR
My cybersecurity background complements my AI engineering work, allowing me to build **AI-powered security and SOC solutions**.
* **Wazuh SIEM / XDR**
* Elasticsearch / OpenSearch
* Kibana / OpenSearch Dashboards
* Grafana
* Suricata IDS/IPS
* SIEM architecture and deployment
* SOC monitoring and alerting
* Security automation and response
* Threat detection and correlation
* Log collection, parsing, normalization, and enrichment
* Security analytics and AI-assisted alert triage
* Compliance monitoring and reporting
* SOC 2 readiness
* Security operations and incident response workflows
* Vulnerability and security monitoring
I have extensive hands-on experience designing and customizing **Wazuh-based SIEM/XDR environments**, integrating multiple security and infrastructure data sources, and developing automation and AI capabilities around security operations.
### 🌐 Network & System Administration
My infrastructure background includes enterprise network and system administration:
* Windows Server & Linux
* Active Directory
* Network administration
* Routing & Switching
* Firewalls and VPNs
* Cisco, Juniper, Fortinet and other network/security technologies
* Network monitoring and troubleshooting
* Proxmox and virtualization
* Docker & Portainer
* pfSense
* TrueNAS and storage infrastructure
* Cloud infrastructure and VPS environments
### ☁️ Cloud & DevOps
* AWS
* Microsoft Azure
* Cloudflare
* Hetzner
* OVH
* Contabo
* Docker / containerized deployments
* Infrastructure automation
* Secure cloud architecture
* Monitoring and observability
* CI/CD and application deployment
### 🚀 Product & Technology Development
In addition to engineering, I work on **product architecture, product management, and technical solution design**, particularly where AI, cybersecurity, cloud infrastructure, and enterprise applications intersect.
I can help you with:
**AI Product Development → LLM Integration → RAG → AI Agents → Orchestration → Application Development → Cybersecurity → SIEM/XDR → Cloud Infrastructure**
### ⭐ Why Work With Me?
I bring a combination of **AI engineering, cybersecurity, software/application development, network engineering, system administration, and product thinking**.
Whether you need to **build an AI application, develop an AI agent, implement RAG, integrate LLMs, create an orchestration layer, deploy Wazuh/SIEM/XDR, automate SOC operations, secure infrastructure, or develop a complete enterprise solution**, I can help design and implement it end-to-end.
**My goal is simple: build solutions that are intelligent, secure, scalable, and production-ready.**
Intrusion Prevention System
Network Security
Network Monitoring
Information Security
Docker
Kibana
PfSense
System Administration
Elasticsearch
Linux System Administration
System Monitoring
Kubernetes
OpenVPN
VMware Administration
Security Management
Affan Z.
Karachi, Pakistan
$12/hr
5.0
2 jobs
I’m a Cybersecurity Specialist with a strong focus on both IT and OT (Operational Technology) environments, providing end-to-end security solutions designed to protect critical infrastructure from evolving threats. With hands-on experience in blue teaming, OT simulation environments, and industrial cybersecurity, I deliver tailored strategies that strengthen defenses, improve visibility, and ensure compliance.
Core Services:
Risk Assessments: Identify, evaluate, and prioritize risks across IT/OT systems to minimize vulnerabilities and operational impact.
SOC/SIEM Setup: Design and implement Security Operations Centers (SOC) and Security Information and Event Management (SIEM) systems for proactive threat detection and incident response.
Threat Detection & Response: Deploy advanced monitoring and threat hunting techniques to detect, analyze, and contain threats before they impact operations.
Digital Forensics & Incident Investigation: Conduct forensic analysis to trace security incidents, preserve evidence, and recommend mitigation strategies.
Vulnerability Testing: Perform penetration testing and vulnerability assessments to uncover security gaps across networks, endpoints, and industrial control systems (ICS).
Compliance Reporting (PECA): Deliver audit-ready reports for regulatory standards like PECA, ensuring that your organization meets cybersecurity compliance requirements.
Strengths & Skills:
Expertise in blue teaming, threat hunting, and real-world OT attack simulations
Knowledge of ICS/SCADA security frameworks (e.g., NIST, IEC 62443)
Experience with leading SIEM platforms (Splunk, Wazuh, QRadar, etc.)
Strong understanding of MITRE ATT&CK for Enterprise and ICS
Familiar with network segmentation, secure remote access, and zero-trust architectures
Rapid incident triage, root cause analysis, and remediation planning
Projects & Accomplishments:
Led the deployment of an enterprise-grade SIEM system integrated with OT monitoring tools, reducing mean time to detect (MTTD) by 45%.
Conducted risk assessments for critical manufacturing plants, helping them achieve PECA cybersecurity compliance.
Simulated advanced persistent threat (APT) scenarios in OT environments to test the resilience of ICS networks.
Developed customized threat detection rules tailored to industrial environments.
Education:
Bachelor’s degree in Cybersecurity
Professional certifications
System Security
Penetration Testing
Cybersecurity Management
Vulnerability Assessment
Security Infrastructure
Cloud Security
Security Assessment & Testing
IT Compliance Audit
Cyber Threat Intelligence
System Administration
Digital Forensics
Security Operation Center
Abu B.
Lahore, Pakistan
$40/hr
4.8
9 jobs
I build the detections that catch real attacks and the automations that handle the noise, so your analysts stop drowning in false positives.
5+ years in security operations: threat detection, incident response, detection engineering, and SOAR. Currently SOC Analyst & Incident Responder for a US healthcare technology company, working daily in Microsoft Sentinel and Defender across a regulated environment.
WHAT I CAN DO FOR YOU
SIEM ENGINEERING & DETECTION CONTENT
Deploy and tune Microsoft Sentinel end to end, data connectors, CEF collectors, analytics rules, watchlists, and custom KQL detections mapped to MITRE ATT&CK. I onboard messy log sources (AWS, Palo Alto, Cisco Meraki, Windows and Linux servers, employee endpoints) and write detections that fire on real threats instead of burying your team in alerts. Also work in OpenSearch, ELK, and Wazuh.
SOAR & SECURITY AUTOMATION
Playbooks in Azure Logic Apps and n8n that cut manual analyst effort. One example: automated IP blocking pushed across Cloudflare, Microsoft Defender, and CrowdStrike, but only after the IP clears automated reputation checks against AbuseIPDB, VirusTotal, and Sentinel threat intelligence, so legitimate traffic never gets cut off. Another correlates live software inventory against newly disclosed CVEs to flag exposed assets automatically.
LOG PIPELINE & PLATFORM INTEGRATION
I built the full ingestion layer for a commercial ITDR product, 7+ sources pulled via API, parsed and normalized through Logstash and Filebeat into OpenSearch, enriched with MISP and OpenCTI threat intelligence, containerized in Docker for reproducible deployment.
INCIDENT RESPONSE & THREAT HUNTING
Triage, scoping, containment, remediation, root cause analysis, and post-incident reporting. Proactive hunting driven by ATT&CK-based hypotheses rather than guesswork.
OFFENSIVE SECURITY BACKGROUND
A year of network and web application penetration testing against OWASP methodology, plus social engineering and phishing assessments. I know what attacks look like from the other side, which is why my detections hold up.
CERTIFICATIONS
Microsoft SC-200 (Security Operations Analyst Associate)
SANS SEC504 (Hacker Tools, Techniques & Incident Handling)
Practical Threat Hunting (Applied Network Defense)
AZ-500 in progress.
WHO I WORK BEST WITH
Startups and mid-size companies that need a SIEM stood up properly the first time. MSSPs that need detection content written. Security teams buried in alerts who need automation built around them.
Tell me what your stack looks like and what's hurting most right now, and I'll tell you honestly whether I'm the right person for it.
Security Testing
Intrusion Detection System
Microsoft Azure
Automation
Security Operation Center
System Deployment
Cybersecurity Monitoring
Information Security Threat Mitigation
Threat Detection
Cyber Threat Intelligence
Cloud Security
Information Security
ISO 27001
SOC 2
Incident Response Plan
Network Security
Security Engineering
ELK Stack
Digital Forensics
Task Automation
Muhammad S.
Lahore, Pakistan
$25/hr
4.7
12 jobs
I am a Cloud Engineer and Cybersecurity Specialist with 5+ years of professional experience, delivering customized and scalable security solutions to leading corporations and medium-sized businesses. I specialize in cloud architecture, cloud security, and cybersecurity operations, ensuring robust protection, compliance, and operational efficiency across complex infrastructures. My expertise includes cloud-native technologies, incident response, threat detection, SIEM management, and secure deployments on platforms such as AWS and Google Cloud. I bring a proactive approach to securing cloud environments and strengthening the overall security posture of organizations.
What I Offer:
✅ Cloud Engineering & Security: Design, deploy, and secure cloud infrastructure using AWS, Azure, and Google Cloud, with expertise in VPC, EC2, IAM, and Kubernetes.
✅ SOC Operations: Set up and maintain SOC environments for continuous monitoring, threat detection, and real-time incident response.
✅ Incident Response: Rapid response to security incidents, minimizing damage and ensuring business continuity.
✅ Cloud Cost Optimization: Analyze and optimize cloud resources to improve performance and reduce costs without compromising security.
Key Tools & Technologies:
✅ Cloud Platforms: AWS (VPC, EC2, IAM, RDS, Lambda), Azure (Azure Active Directory, Azure Monitor), Google Cloud (Cloud SOC, GKE)
✅ Cloud Security: AWS Security Hub, Azure Security Center, Google Cloud IAM
✅ SOC Tools: Splunk, IBM QRadar, ArcSight, Wazuh, Rapid7 InsightIDR
✅ Infrastructure as Code (IaC): Terraform, CloudFormation
✅ Containerization: Docker, Kubernetes
✅ Incident Response: Wireshark, TheHive, Cortex XSOAR
✅ Endpoint Security: CrowdStrike, Carbon Black, Symantec Endpoint Protection
I am committed to delivering top-tier cloud engineering and SOC solutions tailored to your specific needs. Whether it’s architecting secure cloud environments, optimizing SOC workflows, or responding to incidents, I provide proactive and results-driven support.
Let’s collaborate to secure your digital infrastructure and elevate your business to the next level!
Cybersecurity Management
Penetration Testing
Vulnerability Assessment
Information Security
Digital Forensics
Incident Response Plan
Ethical Hacking
WordPress Malware Removal
Teaching
Information Security Awareness
Information Security Governance
Python Script
Bug Bounty
Disaster Recovery Plan
Ransomware Simulation Assessment
Amad S.
Rawalpindi, Pakistan
$50/hr
5.0
5 jobs
I'm a DevOps Engineer, Cloud Architect, and Platform Engineer with over 6 years of experience designing, automating, securing, and operating cloud-native infrastructure for startups, SaaS companies, enterprises, and telecom organizations. My expertise spans the entire software delivery lifecycle, from infrastructure design and provisioning to deployment automation, observability, security, disaster recovery, and production operations. I specialize in building resilient, highly available, and scalable platforms across AWS, Microsoft Azure, and Google Cloud Platform (GCP), enabling organizations to deliver software faster while maintaining security, reliability, and operational excellence.
Cloud Infrastructure & Infrastructure as Code
I design and provision production-grade cloud infrastructure using Terraform, AWS CloudFormation, and Ansible, following Infrastructure as Code (IaC) best practices to deliver consistent, repeatable, and version-controlled environments. My experience includes architecting secure cloud foundations with VPCs/VNets, subnets, routing, IAM, load balancers, NAT gateways, storage, managed databases, Kubernetes clusters, and networking components across AWS, Azure and GCP. I build modular and reusable Terraform modules, automate multi-environment deployments, implement remote state management, and integrate infrastructure provisioning into CI/CD pipelines to accelerate deployments while ensuring governance, scalability, and compliance.
Kubernetes, Containers & Platform Engineering
I have extensive hands-on experience architecting and managing modern cloud-native platforms using Kubernetes, Docker, Helm, Argo CD, GitHub Actions, Jenkins, GitLab CI/CD, and Azure DevOps. I build production-ready Kubernetes clusters across Amazon EKS, Azure AKS, Google GKE, and self-managed Kubernetes, implementing GitOps workflows, automated deployments, secrets management, ingress controllers, certificate automation, service discovery, autoscaling, and zero-downtime deployment strategies. Whether migrating legacy applications from virtual machines or Docker Compose to Kubernetes, modernizing monolithic applications into microservices, or building internal developer platforms, I focus on delivering secure, highly available, and maintainable solutions.
Cloud Networking & Security
My background in networking enables me to design secure, resilient cloud environments using VPC/VNet architecture, VPNs (IPSec/OpenVPN), DNS, reverse proxies (NGINX & Traefik), SSL/TLS automation, WAFs, IAM, RBAC, private networking, and disaster recovery strategies. I have extensive experience managing production databases including PostgreSQL, MySQL, MongoDB, Redis, Elasticsearch, RabbitMQ, and Kafka, implementing high availability, replication, backup, recovery, and performance optimization for mission-critical applications.
Observability & Site Reliability Engineering
I believe every production platform should be fully observable and measurable. I implement comprehensive monitoring and observability solutions using Prometheus, Grafana, Loki, OpenTelemetry, ELK/OpenSearch, CloudWatch, and Azure Monitor to provide deep visibility into infrastructure and application health. My experience includes centralized logging, distributed tracing, custom dashboards, proactive alerting, SLI/SLO implementation, incident response, capacity planning, root cause analysis, and performance optimization—helping organizations improve reliability while minimizing downtime.
MLOps & AI Infrastructure
I help organizations build scalable cloud infrastructure for AI and machine learning workloads by provisioning secure environments, containerizing ML applications, deploying inference services on Kubernetes, and automating end-to-end MLOps pipelines. My experience includes GPU-enabled infrastructure, scalable object storage, model deployment automation, CI/CD for machine learning, and cloud-native ML platform operations. I focus on building reproducible, reliable, and production-ready environments that allow data science teams to move models from experimentation to production efficiently.
What distinguishes me is my ability to combine deep technical expertise with a strategic engineering mindset. I don't simply deploy infrastructure, I build platforms that emphasize automation, scalability, security, resilience, and operational excellence. I take ownership from architecture and implementation through optimization, monitoring, cost management, and long-term operations. By leveraging Infrastructure as Code, GitOps, DevSecOps, and platform engineering best practices, I help organizations accelerate software delivery while maintaining reliability and security.
Whether you need to modernize infrastructure, migrate to the cloud, scale Kubernetes, automate with Terraform, enhance observability, implement MLOps or optimize production operations, I deliver secure, scalable, and reliable cloud solutions.
Kubernetes
Terraform
Amazon Web Services
Microsoft Azure
Docker
MLOps
Prometheus
Grafana
Linux System Administration
Cloud Architecture
Google Cloud Platform
MLflow
Kubeflow
Apache Airflow
Python
Ansible
Bash Programming
CI/CD
DevOps Engineering
Git
How it works
Post a job for freePost a job
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a Splunk Developer in Pakistan on Upwork?
You can hire a Splunk Developer in Pakistan on Upwork in four simple steps:
Create a job post tailored to your Splunk Developer project scope. We'll walk you through the process step by step.
Browse top Splunk Developer talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top Splunk Developer profiles and interview.
Hire the right Splunk Developer for your project from Upwork, the world's largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a Splunk Developer?
Rates charged by Splunk Developers on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a Splunk Developer in Pakistan on Upwork?
As the world's work marketplace, we connect highly-skilled freelance Splunk Developers and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Splunk Developer team you need to succeed.
Can I hire a Splunk Developer in Pakistan within 24 hours on Upwork?
Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Splunk Developer proposals within 24 hours of posting a job description.