Certified CCSFP & Risk Advisory Consultant with over 5+
years of hands-on experience in providing strategic
guidance and tactical implementation of cybersecurity
frameworks for a diverse clientele including NBFCs,
Nationalized Banks, Fin-techs, and Stock Brokers.
Proficient in navigating regulatory requirements such as
ISO, PCI DSS, SOC Type 1 and 2, HIPAA, RBI, UIDAI, NPCI, and IRDAI to ensure compliance
and mitigate risks. Skilled in conducting Third-Party Risk
Management (TPRM) audits, having audited over 200+
vendors with a keen focus on enhancing security postures
Vulnerability Assessment
Risk Management
Information Security Audit
Information Security Consultation
ISO 27001
PCI DSS
SOC 2
Security Policies & Procedures Documentation
Ethical Hacking
ISO 27018
ISO 27017
Policy Writing
Cybersecurity Management
Cyber Threat Intelligence
John M.
Bengaluru, India
$89/hr
5.0
48 jobs
🔢 As an Upwork Top 1% Expert Vetted 👑 OSCP+, Certified Ethical Hacker and an Experienced Penetration Tester with 10+ years of experience Penetration Testing Web SaaS and Mobile based applications and networks, every flaw tells a story; I write the ending and specialize in helping my clients strengthen their cybersecurity defenses.
An average Cybersecurity Incident in your business can you cost you anywhere between $120,000+ to $1.24+ million and even a 10%+ reduction in risk can save your business nearly $124,000+ and hiring a full time in-house team can cost you $100,000+ per employee per year. That is why you need an expert like me to protect your business and reduce your business risk.
What makes me stand out from other freelancers is the fact that I am also a Cybersecurity Architect, capable of architecting solutions to enhance the security of your organisation and preserving the security and integrity of your data.
I have always been passionate about solving technical problems for my clients through Pen Testing and I don't rest till I get to the root of the problem and solve it.
What I can offer?
I can help you secure your business by providing the following services:
✅ Web/Mobile Application Penetration Testing,
✅ Secure Source Code Analysis,
✅ Network Penetration Testing,
✅ Secure Architecture Review,
✅ API Security Testing,
✅ SOC 2, ISO 27001, PCI DSS, AMAZON SP and Compliance-Oriented Penetration Test Reports
✅ Secure Code Review,
✅ CASA Assessment,
✅ Red Team Assessment,
✅ Phishing Simulations & Assessment.
Why Choose Me?
🧑🏼💼 Client-Centric Approach: Your security is my top priority. I work closely with your team to understand your objectives and deliver tailored services that align with your business goals. Trust and transparency are the cornerstones of my practice, and I am committed to helping you navigate the complex landscape of cybersecurity with confidence and achieve compliance.
📐 Comprehensive Security Assessments: I conduct detailed SOC Type 2 / ISO compliant evaluations to identify vulnerabilities in your network, applications, and infrastructure.
✂️ Tailored Solutions: Every organization is unique. I customize my approach to meet your specific security needs and industry standards.
🎬 Actionable Recommendations: Post-assessment, I provide clear, concise, and practical remediation steps to address identified vulnerabilities.
🔁 Ongoing Support: Cybersecurity is an ongoing process. I offer continuous support and re-assessment to ensure your defenses remain robust against evolving threats
🌏 Holistic Approach: I don't just patch vulnerabilities; I architect comprehensive security solutions that align with business goals. My focus extends beyond the technical to encompass risk management and organizational resilience.
🗨️ Collaborative Communicator: I bridge the gap between technical jargon and business language, fostering understanding across teams. Effective communication is key to successful security implementation.
🏫 Continuous Learning: The threat landscape evolves, and so do I. Whether it's a new attack vector or an emerging technology, count me in. Learning is my superpower.
🙋♂️ Key Skills:
✔️ Penetration Testing & Vulnerability Assessment: I thrive on dissecting systems, identifying weaknesses, and recommending robust solutions. Armed with tools like Kali Linux, Metasploit, Nmap, and Wireshark, I delve into web applications, networks, and APIs. But here's the twist—I don't stop at discovery; I offer a free retest after remediation to ensure vulnerabilities stay sealed.
✔️ Network Security: I've designed and implemented secure network architectures, ensuring data confidentiality, integrity, and availability. Firewalls, intrusion detection systems, and VPNs—my toolkit covers it all.
✔️ Cloud Security: Proficient in securing cloud environments especially Amazon Web Services (AWS) & Oracle Cloud Infrastructure (OCI). I stress-test cloud deployments ensuring they withstand real-world attacks.
✔️ Secure Coding Practices: I advocate for secure coding principles using tools like SonarQube and collaborate with development teams to build resilient applications. Prevention beats cure, every time.
⛏️Tools I Use
☑️ Penetration Testing: Nmap, Metasploit, Burp Suite Professional, Wireshark, SQLmap, Kali Linux
☑️ Programming & Scripting Skills: Python, Bash, PowerShell, JavaScript, Java and C#
☑️ Security Frameworks & Standards: OWASP, NIST, CASA, CIA Triad, PCI-DSS
🫱🏽🫲🏽 Let's Connect: Ready to enhance your business/organization's security? Let's chat! Reach out to me here on Upwork, and let's build a safer digital future together.
🟢 Press '...' button and then ‘Send Message’ button in the top right-hand corner ✉️
🚫 No hacking service - I do not provide any hacking services, and I will not engage in any activities that involve gaining unauthorized access to any accounts, systems, or social media platforms. Requests for such services will be declined.
Vulnerability Assessment
Penetration Testing
Network Penetration Testing
Security Testing
Security Assessment & Testing
Information Security
Application Security
Web Application Security
Network Security
System Security
Web App Penetration Testing
Website Security
Black Box Testing
OWASP
Risk Assessment
ISO 27001
SOC 2
SOC 2 Report
PCI DSS
IT Compliance Audit
Prashant D.
Bengaluru, India
$25/hr
4.9
13 jobs
6+ years as an Offensive Security Researcher, OSCP and CEH v12 certified, I help startups, SaaS companies, and enterprises think like an attacker before real attackers do through hands-on Penetration Testing, Red Teaming, and Vulnerability Assessment (VAPT) across web, mobile, API, network, and cloud environments.
My approach is simple: real offensive security isn't a scanner dump it's manual exploitation, chained attack paths, and a prioritized, developer-ready remediation plan mapped to your actual business risk.
With a strong software engineering background, I read source code, trace data flows, and reason about architecture catching business-logic flaws, privilege-escalation chains, and design weaknesses that automated tools always miss.
🎯 PENETRATION TESTING & VAPT
Full-scope Vulnerability Assessment and Penetration Testing (VAPT) across the OWASP Top 10, OWASP API Security Top 10, and PTES/OSSTMM methodologies: broken access control, IDOR, SSRF, SQLi/NoSQLi/command/template injection, XSS, CSRF, insecure deserialization, auth/session flaws, privilege escalation, and business-logic abuse.
Web App Pentesting: React, Angular, Vue, Next.js, Node.js, Django/Flask/FastAPI, Spring, Laravel, Rails, .NET, Go
Mobile Pentesting: Android & iOS per OWASP MASVS/MASTG, static + dynamic analysis, reverse engineering, insecure storage, API/backend abuse
API Pentesting: REST, GraphQL, SOAP auth bypass, rate-limit abuse, mass assignment, BOLA/BFLA
Network Pentesting: internal/external, Active Directory attacks (Kerberoasting, pass-the-hash, lateral movement, privilege escalation), segmentation testing
Every finding is manually verified (zero false positives), CVSS-scored, and delivered with an executive summary + technical deep dive + exact remediation steps, plus a free retest.
Tools: Burp Suite Pro, OWASP ZAP, Nmap, Metasploit, Cobalt Strike, Nuclei, sqlmap, Nessus, ffuf, BloodHound, Mimikatz, Hashcat, John the Ripper, Wireshark
🕵️ RED TEAMING & ADVERSARY SIMULATION
End-to-end Red Team engagements simulating real-world TTPs mapped to MITRE ATT&CK: initial access, phishing simulation, C2 infrastructure, privilege escalation, lateral movement, persistence, and data exfiltration testing people, process, and technology together, not just systems. Purple Team collaboration to strengthen detection and response (SOC/EDR/SIEM evasion & tuning).
☁️ CLOUD SECURITY (AWS, Azure & GCP)
IAM and least-privilege reviews, network segmentation, exposed storage (S3/Blob/GCS), privilege-escalation paths, and CIS Benchmark hardening. Cloud penetration testing and CSPM assessments using Prowler, ScoutSuite, and Pacu.
⚙️ DEVSECOPS & INFRASTRUCTURE SECURITY
Security embedded into CI/CD (GitHub Actions, GitLab CI, Jenkins), container/Kubernetes security (Trivy, Grype, RBAC, Pod Security Standards), and IaC security review for Terraform/CloudFormation/Ansible (Checkov, tfsec). SAST, DAST, SCA, and secrets scanning integration (Semgrep, Snyk, SonarQube, Gitleaks, TruffleHog).
🤖 AI / LLM SECURITY
Offensive testing of AI/ML and LLM-powered features against the OWASP Top 10 for LLM Applications and MITRE ATLAS: prompt injection, jailbreaks, model DoS, sensitive-data leakage, insecure output handling, and excessive agency in agentic systems.
🧠 SECURITY ENGINEERING & RESEARCH
Secure code review, threat modeling (STRIDE, attack trees), reverse engineering (Java/bytecode, anti-tamper analysis), malware analysis fundamentals, and security architecture design.
🤝 HOW I WORK:
1️⃣ Free scoping call to define objectives, rules of engagement, and scope
2️⃣ Testing/assessment with clear, regular communication
3️⃣ A prioritized report Executive Summary + technical detail + exact fixes
4️⃣ Free retest and debrief once your team remediates
Every engagement is handled under strict confidentiality, signed Rules of Engagement, and full written authorization. I don't oversell if you don't need a service, I'll tell you honestly.
Keywords: penetration testing, ethical hacking, VAPT, red teaming, purple team, OSCP, CEH, offensive security, web app pentest, mobile pentest, API pentest, network pentest, Active Directory pentest, cloud security, AWS pentest, Azure pentest, GCP pentest, DevSecOps, cybersecurity consultant, vulnerability assessment, security audit, ISO 27001, SOC 2, GDPR compliance, MITRE ATT&CK, OWASP Top 10, secure code review, threat modeling, AI security, LLM security.
📩 Message me with your project details, and I'll respond with a clear, no-pressure scoping plan.
Vulnerability Assessment
Web Application Security
Penetration Testing
Information Security
OWASP
API
Cloud Security
DevOps
Kubernetes
IT Compliance Audit
ISO 27001
SOC 2
Network Security
Risk Assessment
NIST Cybersecurity Framework
Information Security Audit
Information Security Governance
Governance, Risk Management & Compliance
Information Security Consultation
Sourabh G.
Bengaluru, India
$10/hr
4.2
6 jobs
I help startups, SaaS companies, fintech organizations, enterprises, and government clients identify security vulnerabilities before attackers do.
I have worked on cybersecurity engagements for Dubai-based banking clients and am currently involved in cybersecurity projects for a Singapore-based organization, helping secure enterprise applications, APIs, cloud infrastructure, and modern SaaS platforms.
My expertise includes Web Application Penetration Testing, API Security Testing, SaaS Security, Cloud Security (AWS, Azure & GCP), Mobile Application Security, Vulnerability Assessment & Penetration Testing (VAPT), Secure Architecture Reviews, and Security Automation.
Unlike automated vulnerability scanners, I perform manual penetration testing to uncover real-world attack paths, business logic flaws, broken authentication, privilege escalation, insecure APIs, and security weaknesses that automated tools often miss.
If you're looking for an experienced Cybersecurity Consultant, Penetration Tester, VAPT Specialist, API Security Expert, SaaS Security Consultant, or Cloud Security Engineer who focuses on real business risk not just scanner output—I'd be happy to discuss your project and help secure your applications and infrastructure.
My Cybersecurity Services
Penetration Testing
✔ Web Application Penetration Testing
✔ API Penetration Testing (REST & GraphQL)
✔ SaaS Security Assessments
✔ Mobile Application Security Testing
✔ Network Penetration Testing
✔ External Attack Surface Assessment
✔ Internal Security Assessments
✔ Cloud Security Assessments
✔ Infrastructure Security Reviews
Vulnerability Assessment (VAPT)
I manually identify and validate vulnerabilities including:
• SQL Injection (SQLi)
• Cross-Site Scripting (XSS)
• Broken Access Control
• IDOR
• Privilege Escalation
• Authentication Bypass
• Authorization Issues
• SSRF
• CSRF
• XXE
• Remote Code Execution (RCE)
• API Security Vulnerabilities
• Business Logic Vulnerabilities
• Security Misconfigurations
• Sensitive Data Exposure
• Session Management Issues
Every vulnerability is manually validated to eliminate false positives and provide practical remediation guidance.
SaaS & API Security
I specialize in securing modern SaaS applications by testing:
• Authentication Systems
• Authorization Controls
• Multi-Tenant Security
• JWT & OAuth Security
• REST APIs
• GraphQL APIs
• API Rate Limiting
• Business Logic
• Role-Based Access Control (RBAC)
• Session Management
• Secure Architecture
AI-Assisted Security Engineering
I leverage AI to improve security testing efficiency while maintaining human-led validation.
Services include:
• AI-Assisted Penetration Testing
• LLM-Assisted Secure Code Review
• Security Automation
• AI-Based Vulnerability Analysis
• Automated Security Reporting
• Python Security Automation
• Security Research Automation
Security Assessment Methodology
Every assessment includes:
✔ Reconnaissance
✔ Manual Penetration Testing
✔ Automated Validation
✔ Exploit Verification
✔ Attack Path Analysis
✔ Risk Prioritization
✔ Developer-Friendly Remediation
✔ Executive Reporting
Security Reports Include
• Executive Summary
• Technical Findings
• CVSS Severity Ratings
• Screenshots & Evidence
• Proof of Concept (PoC)
• Business Impact Analysis
• Step-by-Step Remediation
• Developer Guidance
Security Tools
Burp Suite Professional
Nmap
Metasploit
Nessus
Qualys
Nuclei
OWASP ZAP
Wireshark
Postman
Kali Linux
Python
Bash
PowerShell
Docker
Git
Cloud Security
Amazon Web Services (AWS)
Microsoft Azure
Google Cloud Platform (GCP)
Docker
Kubernetes
IAM Security
Cloud Infrastructure Reviews
Security Standards & Compliance
OWASP Top 10
OWASP API Security Top 10
NIST Cybersecurity Framework (CSF)
ISO 27001
PCI-DSS
SOC 2
GDPR
CIS Benchmarks
MITRE ATT&CK
Certifications
• CISSP – Certified Information Systems Security Professional
• CISM – Certified Information Security Manager
• CEH – Certified Ethical Hacker
• ISO 27001 Lead Auditor
Vulnerability Assessment
Web App Penetration Testing
Web Application Security
Network Penetration Testing
Network Security
OWASP
Cybersecurity Tool
Mobile App Development
Kotlin
Web Application
Node.js
Code Review
Information Security Audit
Penetration Testing
Cybersecurity Monitoring
AI-Generated Code
Mahesh T.
Bengaluru, India
$40/hr
5.0
128 jobs
🔐 Certified Penetration Tester | AWS & Azure Cloud Security | Incident Response Expert 🔐
I’m a results-driven cybersecurity specialist with 14+ years of experience securing cloud infrastructure, web applications, and enterprise environments. I help companies prevent breaches, mitigate risks, and ensure compliance through advanced security architecture and real-world offensive security skills.
🎯 What I Do:
✔️ Cloud Security Hardening – AWS (IAM, EC2, S3, VPC, RDS, Route 53) & Azure (VNET, NSGs, Azure Security Center, Defender)
✔️ Penetration Testing – Full-scope internal/external pentests, web/app/API testing, business logic abuse, OWASP Top 10
✔️ Vulnerability Assessments – Nessus, OpenVAS, Nmap, custom exploit validation, CVSS scoring & prioritization
✔️ Threat Detection & Response – Wazuh setup, real-time event correlation, SIEM deployment, log analysis
✔️ Security Architecture – Designing scalable, secure cloud solutions with strong IAM, encryption, and DR practices
✔️ Cloudflare Optimization – Harden DNS, implement WAF rulesets, rate-limiting, Zero Trust setup
✔️ Incident Response – Triage, forensics, log collection, remediation and recovery plans (NIST, MITRE ATT&CK aligned)
📌 Security Tools I Work With:
- **Offensive Security**: Burp Suite, Metasploit, Nmap, Hydra, SQLmap
- **Defensive Tools**: Wazuh, AWS GuardDuty, Azure Sentinel, Nessus, Suricata
- **Languages/Scripting**: Bash, PowerShell, HTML/JavaScript (for attack emulation & automation)
- **Frameworks/Standards**: OWASP, MITRE ATT&CK, NIST CSF, CIS Benchmarks
🛡️ Certifications:
- AWS Certified Security – Specialty
- Microsoft Certified: Azure Security Engineer Associate
- Licensed Penetration Tester (LPT) | Certified Penetration Testing Professional (CPENT)
- CEH, CCSK
📈 Highlights:
- $300K+ earned, 100% Job Success on Upwork
- 11,500+ hours across 110+ successful projects
- Trusted by startups, fintechs, and regulated industries (HIPAA, GDPR, SOC2)
I’m known for delivering real-world, **actionable security results** — not just checkbox audits. If you’re looking to **secure your infrastructure, detect threats faster, or simulate real-world attacks**, let’s connect!
Vulnerability Assessment
Cloudflare
Kali Linux
Microsoft Azure
Security Testing
Application Security
Security Analysis
Penetration Testing
Amazon Web Services
Information Security
Web App Penetration Testing
Security Assessment & Testing
Security Infrastructure
Information Security Consultation
API Testing
Cloud Security
SOC 2
ISO 27001
Dhabaleshwar D.
Bengaluru, India
$20/hr
5.0
1 jobs
What if your systems aren’t as secure as you think they are?
Hi, I’m Dhabaleshwar, a certified ethical hacker (CEH) and I’ve spent 5+ years digging into the hidden cracks of some of the most complex systems. It’s not just a job—it’s a mission. I’ve discovered vulnerabilities that others missed, cracked open security layers thought to be impenetrable, and saved businesses from potential disasters.
Imagine this: A global enterprise hires me after passing every standard penetration test. They feel confident, but something isn’t adding up. In just days, I find a zero-day vulnerability buried deep in their infrastructure—one that could have cost them millions. That’s the kind of impact I deliver.
I’ve completed 400+ penetration tests, discovered over 300 zero-day vulnerabilities, and earned a spot among India’s Top 15 Security Researchers in 2023. But what really sets me apart is my approach: I don’t just find vulnerabilities—I show you exactly how they can be exploited, how they can harm your business, and, most importantly, how to fix them.
What I Do Best
1- Thick Client Pentesting: I thrive in environments where others hesitate—proprietary protocols, layered logic, and thick client applications that demand a unique skill set.
2- API Security: REST, SOAP, GraphQL—you name it. I expose broken access controls, privilege escalation flaws, and injection vulnerabilities that others overlook.
3- Web & Mobile Applications Pentesting: From XSS and SSRF to insecure deserialization, I break down your app’s defenses, ensuring its resilience from the inside out.
4- Cloud & Container Security: AWS, GCP, Kubernetes, Docker—I don’t just find gaps; I close them.
5- LLM Pentesting: Language models like ChatGPT and other AI systems are powerful but vulnerable. I test for prompt injection, unauthorized data leakage, and logic bypasses, ensuring your AI solutions are both functional and secure.
6- Red Teaming: Want to see how your defenses stand up to real-world attackers? I simulate advanced adversarial tactics, probing for weaknesses in your people, processes, and technologies.
7- Custom Exploitation: When security gets tough, I get creative—crafting tailored attack scenarios that demonstrate real-world impact.
Why Clients Work With Me
When businesses work with me, they’re not just ticking boxes—they’re securing their future. Clients trust me to:
i) Think Like an Attacker: I approach systems like someone trying to break in. No assumption is too small, no layer too secure.
ii) Prove the Impact: For every vulnerability I find, I provide actionable evidence—step-by-step scenarios, proof-of-concept exploits, and recommendations to fortify your defenses.
iii) Deliver Results That Matter: My detailed reports go beyond technical jargon. They tell you what’s wrong, why it matters, and exactly how to fix it.
Key Achievements
- 400+ Penetration Tests: From enterprise platforms to government systems, I’ve safeguarded industries against real-world threats.
- 300+ Zero-Days Discovered: From RCE to SQLi, XSS, BAC etc. I’ve found and fixed vulnerabilities that could have caused serious harm, keeping businesses safe from real threats.
- India’s Top 15 Security Researchers (2023): Recognized for uncovering 200+ vulnerabilities in critical government systems.
Tools & Methodologies
I leverage a wide range of tools, including Burp Suite Pro, Postman, Metasploit, Nmap, OWASP ZAP, Wireshark, Nessus, Acunetix etc. to uncover vulnerabilities with precision. For advanced needs, I write custom scripts in Python, Bash, and Java, ensuring a tailored approach. In LLM Pentesting, I use techniques like prompt engineering and adversarial logic testing, while Red Team engagements involve tools like Cobalt Strike, BloodHound, and Empire to simulate real-world threats.
Client Testimonials
"We thought our applications were secure—until Dhabaleshwar exposed what others missed. His insights have been invaluable."
"We had spent months trying to secure our API endpoints, but something always felt off. Dhabal not only found vulnerabilities we didn’t even know existed but also explained how they could be exploited in real-world scenarios. His detailed recommendations saved us from what could’ve been a disaster. He’s not just a pentester—he’s an ally."
"We trusted Dhabaleshwar to pentest our LLM-based AI platform, and his findings were eye-opening. He identified prompt injection vulnerabilities and even demonstrated how malicious actors could manipulate responses. His expertise in AI security is rare and invaluable."
Let’s Secure What Matters Most
If you’re looking for more than just a security check—you’re looking for someone who will care as much about your systems as you do—let’s talk. I’m here to uncover the vulnerabilities others miss, secure your systems, and ensure your business stays a step ahead of potential threats.
Click “Message” today to take the first step toward real security and peace of mind.
Vulnerability Assessment
Penetration Testing
Network Security
Information Security
Application Security
Code Review
Network Penetration Testing
WordPress Security
Website Security
How it works
Post a job for freePost a job
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a Vulnerability Assessment Specialist near Bengaluru, on Upwork?
You can hire a Vulnerability Assessment Specialist near Bengaluru, on Upwork in four simple steps:
Create a job post tailored to your Vulnerability Assessment Specialist project scope. We’ll walk you through the process step by step.
Browse top Vulnerability Assessment Specialist talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top Vulnerability Assessment Specialist profiles and interview.
Hire the right Vulnerability Assessment Specialist for your project from Upwork, the world’s largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a Vulnerability Assessment Specialist?
Rates charged by Vulnerability Assessment Specialists on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a Vulnerability Assessment Specialist near Bengaluru, on Upwork?
As the world’s work marketplace, we connect highly-skilled freelance Vulnerability Assessment Specialists and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Vulnerability Assessment Specialist team you need to succeed.
Can I hire a Vulnerability Assessment Specialist near Bengaluru, within 24 hours on Upwork?
Depending on availability and the quality of your job post, it’s entirely possible to sign up for Upwork and receive Vulnerability Assessment Specialist proposals within 24 hours of posting a job description.