Expert-Vetted on Upwork (Top 1% of security professionals). If you're building on the cloud and want to find the security gaps attackers would exploit — before they do — I can help.
I’m a cybersecurity consultant and founder of Exfiltra, helping startups and enterprises secure their applications, cloud infrastructure, and DevOps pipelines.
I have worked with organizations generating $6B+ in annual revenue and helped companies strengthen security across cloud environments, applications, and compliance programs.
I personally lead security engagements and, when needed, bring in specialists from my team at Exfiltra to support larger or complex projects.
Most clients hire me when they want to:
✔ Secure Azure / AWS / GCP environments
✔ Perform professional penetration testing
✔ Implement DevSecOps and secure CI/CD pipelines
✔ Prepare for SOC 2, ISO 27001, HIPAA, FedRAMP, or CMMC
✔ Improve security posture using industry frameworks
CORE EXPERTISE
AZURE & CLOUD SECURITY
• Azure security architecture reviews
• Microsoft Defender for Cloud & Sentinel
• Identity security (Entra ID / Conditional Access)
• Cloud configuration reviews and CIS Benchmark hardening
APPLICATION SECURITY & PENETRATION TESTING
• Web application penetration testing
• API security testing
• Mobile application security testing
• Network and cloud penetration testing
• Assessments aligned with OWASP Top 10 and OWASP ASVS
DEVSECOPS & SECURITY AUTOMATION
• Secure CI/CD pipelines (Azure DevOps / GitHub Actions)
• Infrastructure as Code security (Terraform / Bicep)
• SAST and DAST integration in pipelines
SECURITY TOOLS
• Snyk
• Semgrep
• OWASP ZAP
• Burp Suite
• Wazuh
• CrowdStrike
• Microsoft Sentinel
AI & LLM SECURITY
• AI application threat modeling
• Prompt injection and model abuse testing
• Secure architecture for AI-powered applications
WHY CLIENTS WORK WITH ME
• Upwork Expert-Vetted (Top 1% of freelancers)
• Founder of Exfiltra – a cybersecurity services company
• Supported by a team of security specialists for larger engagements
• Contributor to OWASP ZAP
• Experience securing environments for organizations generating $6B+ in revenue
• Background in both software engineering and cybersecurity
• Security research involving organizations like the U.S. Department of Defense
NOT A GOOD FIT IF
• You want to hack or recover social media accounts
• You want enterprise-grade security but are not willing to invest in it
If your goal is to build secure systems instead of reacting to breaches later, feel free to invite me to your job or send a message describing your project.
Web Application Security
Application Security
Network Security
Kali Linux
Security Assessment & Testing
Penetration Testing
Information Security Consultation
Vulnerability Assessment
Information Security
Ethical Hacking
Cloud Security
Web App Penetration Testing
Security Management
System Security
AI Security
Secure SDLC
Security Testing
Website Security
Database Security
Cybersecurity Management
John M.
Bengaluru, India
$34/hr
5.0
48 jobs
🔢 As an Upwork Top 1% Expert Vetted 👑 OSCP+, Certified Ethical Hacker and an Experienced Penetration Tester with 10+ years of experience Penetration Testing Web SaaS and Mobile based applications and networks, every flaw tells a story; I write the ending and specialize in helping my clients strengthen their cybersecurity defenses.
An average Cybersecurity Incident in your business can you cost you anywhere between $120,000+ to $1.24+ million and even a 10%+ reduction in risk can save your business nearly $124,000+ and hiring a full time in-house team can cost you $100,000+ per employee per year. That is why you need an expert like me to protect your business and reduce your business risk.
What makes me stand out from other freelancers is the fact that I am also a Cybersecurity Architect, capable of architecting solutions to enhance the security of your organisation and preserving the security and integrity of your data.
I have always been passionate about solving technical problems for my clients through Pen Testing and I don't rest till I get to the root of the problem and solve it.
What I can offer?
I can help you secure your business by providing the following services:
✅ Web/Mobile Application Penetration Testing,
✅ Secure Source Code Analysis,
✅ Network Penetration Testing,
✅ Secure Architecture Review,
✅ API Security Testing,
✅ SOC 2, ISO 27001, PCI DSS, AMAZON SP and Compliance-Oriented Penetration Test Reports
✅ Secure Code Review,
✅ CASA Assessment,
✅ Red Team Assessment,
✅ Phishing Simulations & Assessment.
Why Choose Me?
🧑🏼💼 Client-Centric Approach: Your security is my top priority. I work closely with your team to understand your objectives and deliver tailored services that align with your business goals. Trust and transparency are the cornerstones of my practice, and I am committed to helping you navigate the complex landscape of cybersecurity with confidence and achieve compliance.
📐 Comprehensive Security Assessments: I conduct detailed SOC Type 2 / ISO compliant evaluations to identify vulnerabilities in your network, applications, and infrastructure.
✂️ Tailored Solutions: Every organization is unique. I customize my approach to meet your specific security needs and industry standards.
🎬 Actionable Recommendations: Post-assessment, I provide clear, concise, and practical remediation steps to address identified vulnerabilities.
🔁 Ongoing Support: Cybersecurity is an ongoing process. I offer continuous support and re-assessment to ensure your defenses remain robust against evolving threats
🌏 Holistic Approach: I don't just patch vulnerabilities; I architect comprehensive security solutions that align with business goals. My focus extends beyond the technical to encompass risk management and organizational resilience.
🗨️ Collaborative Communicator: I bridge the gap between technical jargon and business language, fostering understanding across teams. Effective communication is key to successful security implementation.
🏫 Continuous Learning: The threat landscape evolves, and so do I. Whether it's a new attack vector or an emerging technology, count me in. Learning is my superpower.
🙋♂️ Key Skills:
✔️ Penetration Testing & Vulnerability Assessment: I thrive on dissecting systems, identifying weaknesses, and recommending robust solutions. Armed with tools like Kali Linux, Metasploit, Nmap, and Wireshark, I delve into web applications, networks, and APIs. But here's the twist—I don't stop at discovery; I offer a free retest after remediation to ensure vulnerabilities stay sealed.
✔️ Network Security: I've designed and implemented secure network architectures, ensuring data confidentiality, integrity, and availability. Firewalls, intrusion detection systems, and VPNs—my toolkit covers it all.
✔️ Cloud Security: Proficient in securing cloud environments especially Amazon Web Services (AWS) & Oracle Cloud Infrastructure (OCI). I stress-test cloud deployments ensuring they withstand real-world attacks.
✔️ Secure Coding Practices: I advocate for secure coding principles using tools like SonarQube and collaborate with development teams to build resilient applications. Prevention beats cure, every time.
⛏️Tools I Use
☑️ Penetration Testing: Nmap, Metasploit, Burp Suite Professional, Wireshark, SQLmap, Kali Linux
☑️ Programming & Scripting Skills: Python, Bash, PowerShell, JavaScript, Java and C#
☑️ Security Frameworks & Standards: OWASP, NIST, CASA, CIA Triad, PCI-DSS
🫱🏽🫲🏽 Let's Connect: Ready to enhance your business/organization's security? Let's chat! Reach out to me here on Upwork, and let's build a safer digital future together.
🟢 Press '...' button and then ‘Send Message’ button in the top right-hand corner ✉️
🚫 No hacking service - I do not provide any hacking services, and I will not engage in any activities that involve gaining unauthorized access to any accounts, systems, or social media platforms. Requests for such services will be declined.
Web Application Security
Application Security
Penetration Testing
Network Penetration Testing
Security Testing
Security Assessment & Testing
Vulnerability Assessment
Information Security
Network Security
System Security
Web App Penetration Testing
Website Security
Black Box Testing
OWASP
Risk Assessment
Ali H.
Kahuta, Pakistan
$20/hr
5.0
13 jobs
𝗛𝗔𝗥𝗗 · 𝗲𝗻 · 𝗖𝗢𝗗𝗘 - 𝐏𝐞𝐧𝐭𝐞𝐬𝐭 𝐲𝐨𝐮𝐫 𝐬𝐭𝐚𝐜𝐤. 𝐇𝐚𝐫𝐝𝐞𝐧 𝐲𝐨𝐮𝐫 𝐜𝐨𝐝𝐞.
💼 SERVICES
🔒 𝐏𝐞𝐧𝐞𝐭𝐫𝐚𝐭𝐢𝐨𝐧 𝐓𝐞𝐬𝐭𝐢𝐧𝐠 for web and mobile apps, APIs, and auth flows
🔎 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐀𝐮𝐝𝐢𝐭𝐬 and 𝐒𝐞𝐜𝐮𝐫𝐞 𝐂𝐨𝐝𝐞 𝐑𝐞𝐯𝐢𝐞𝐰 (OWASP Top 10)
🛡️ 𝐀𝐏𝐈 and 𝐀𝐈/𝐋𝐋𝐌 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 hardening
⚙️ 𝐒𝐞𝐜𝐮𝐫𝐞 𝐖𝐞𝐛 and 𝐀𝐈 𝐃𝐞𝐯𝐞𝐥𝐨𝐩𝐦𝐞𝐧𝐭 (React, Node, SaaS, MVPs)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
𝟏𝟎𝟎% 𝐉𝐨𝐛 𝐒𝐮𝐜𝐜𝐞𝐬𝐬 | 𝐌𝐒 𝐂𝐲𝐛𝐞𝐫 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 (𝐏𝐈𝐄𝐀𝐒) | 𝟗+ 𝐲𝐞𝐚𝐫𝐬 in tech | Available now
I find and fix security holes in web applications, APIs, and AI systems. I bring an MS Cyber Security degree from PIEAS and 9+ years building production software, so I test like an attacker and fix like a developer. I look for problems at the code level, not just what an automated scanner prints out.
My MS thesis research found a novel denial of service attack in LoRaWAN IoT networks and built a working mitigation. Most security freelancers cannot read your source code. I can, because I spent years writing the kind of code I now test.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🎓 CREDENTIALS
→ 𝐌𝐒 𝐂𝐲𝐛𝐞𝐫 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 (PIEAS): cryptography, forensics, malware analysis, ethical hacking
→ 𝐂𝐄𝐇 training completed (EC-Council), certification in progress
→ 𝐂𝐇𝐅𝐈 in progress
→ MS thesis: LoRaWAN DoS attack and mitigation (NS-3, defended 2023)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🛡️ PROOF PROJECTS
→ 𝐇𝐞𝐚𝐥𝐭𝐡𝐜𝐚𝐫𝐞 𝐀𝐏𝐈: multi-tenant, JWT and OAuth, RBAC, rate limiting, 40+ endpoints
→ 𝐀𝐈 𝐜𝐡𝐚𝐭 𝐡𝐚𝐫𝐝𝐞𝐧𝐢𝐧𝐠: prompt injection filtering, rate limits, validated API before the LLM
→ 𝐘𝐨𝐮𝐫𝐊𝐞𝐲: AES-GCM encryption at rest, secp256k1 key management
→ 𝐇𝐚𝐦𝐚𝐡 𝐀𝐈 𝐭𝐨𝐨𝐥𝐬: secure AI API integration, JWT auth, input validation
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🔧 TOOLS
Security: Burp Suite, Nmap, Wireshark, Metasploit, Autopsy, IDA
Development: React, Node.js, TypeScript, Python, MySQL
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
⭐ TESTIMONIALS
"Ali has been impressive. Extremely dedicated, very dependable, and made a big effort to meet deadlines." (CRM Client)
"Ali was amazing with his skills, thoroughness, and problem solving. He learned a new specialized domain quickly." (Software Engineer Client)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Industries: Healthcare, SaaS, Fintech, IoT, AI and ML
Hours per week: More than 30
Response time: 0 to 4 hours
Languages: English (Fluent), Urdu (Native)
Web Application Security
Application Security
Penetration Testing
Vulnerability Assessment
Cybersecurity Management
Information Security
Security Assessment & Testing
Network Security
Ethical Hacking
Secure SDLC
AI Security
Cryptography
OWASP
React
Node.js
TypeScript
Next.js
Python
Flutter
AI Development
Usman A.
Islamabad, Pakistan
$32/hr
5.0
43 jobs
With 10+ years of experience across AI development, cybersecurity, and blockchain, I bring a combination most freelancers can't offer I think like an engineer and a hacker at the same time.
✦ CYBERSECURITY
Certified OSCP | CRTO | eWPTXv2 I've led hundreds of penetration tests and security assessments for startups, enterprises, and regulated financial institutions.
- Web Application & API Penetration Testing (OWASP Top 10, business logic flaws)
- Network Penetration Testing Internal & External
- Active Directory Security Assessments
- Red Team & Assume Breach Engagements
- Cloud Security Assessments
- MITRE ATT&CK–based adversary emulation
- Executive-ready reports, proof-of-concept evidence & free retests included
All testing is manual-first no scanner noise, only real exploitable findings.
✦ AI DEVELOPMENT
I've shipped full-scale AI products handling real users and real workflows. Here's what I build:
- AI video generation platforms custom avatar creation, script-to-video, multilingual dubbing, and export-ready outputs
- AI voice cloning & text-to-speech systems for content creators and media companies
- AI avatar & digital human platforms for marketing, training, and e-learning use cases
- Enterprise AI automation platforms natural language command execution, multi-task AI agents, and cross-department workflow automation
- AI chatbots & virtual assistants integrated with WhatsApp, Telegram, Slack, and web apps
- Custom LLM-powered tools document Q&A, internal knowledge bases, and AI copilots for SaaS products
- RAG (Retrieval-Augmented Generation) pipelines for accurate, context-aware AI responses
- AI content generation tools for social media, marketing copy, and video scripts
- End-to-end AI SaaS products with subscription billing, user dashboards, and API integrations
✦ BLOCKCHAIN & WEB3
- Smart contract development & security audits
- DeFi protocol builds and integrations
- Web3 application development with security-first architecture
- NFT platform development and token contract reviews
✦ WHY THIS COMBINATION MATTERS
When I build your AI product, I'm already thinking about how it gets attacked. When I audit your systems, I understand the modern tech stacks powering them. That dual perspective is rare and it raises the quality bar of everything I deliver.
If you want an AI builder who thinks like an attacker, or a security professional who ships real products — let's talk.
Web Application Security
Application Security
Ethical Hacking
Penetration Testing
AI Agent Development
LangChain
Retrieval Augmented Generation
React
Mobile App Development
Node.js
MERN Stack
Blockchain
Web3
Crypto Wallet Development
Ethereum
Solidity
Cryptocurrency
n8n
AI App Development
AI Chatbot
Luca F.
Valdagno, Italy
$100/hr
5.0
74 jobs
OSCP & CEH-certified Penetration Tester with 8+ years of hands-on experience in Web, Mobile (iOS/Android), API, and Cloud security testing. 65+ projects delivered, 100% Job Success Score, Top Rated on Upwork.
I help SaaS companies, healthcare platforms, FinTech, E-commerce and EdTech startups find real, exploitable vulnerabilities before attackers do, through manual penetration testing that goes far beyond automated scans.
— What makes my testing different —
I focus on real exploitation, not theoretical findings. Automated scanners miss business logic flaws, broken access control, and chained vulnerabilities. My OSCP-trained approach simulates how a motivated attacker would actually compromise your application, then documents the path so your developers can fix it for good.
Every engagement includes a free retest after remediation, so you know the fix worked.
— Core services —
• Web Application Penetration Testing (OWASP WSTG v4.2 methodology)
• Mobile App Security Testing for iOS & Android (OWASP MASVS / MASTG)
• API Security Testing — REST, GraphQL, OWASP API Top 10
• Cloud Security Reviews — AWS / GCP / Azure misconfiguration testing
• Source Code Security Review (PHP, Node.js, Python)
• AI / LLM Security — Prompt Injection, Data Leakage, OWASP LLM Top 10
• WordPress & PHP Application Hardening
• WAF Bypass Testing & Detection Engineering
— Tools & methodologies —
Burp Suite Professional, Frida, Nmap, sqlmap, Metasploit, OWASP ZAP, Nuclei, Genymotion, MobSF, OWASP WSTG, OWASP MASVS, MITRE ATT&CK, NIST SP 800-115.
— Industries I've worked with —
Healthcare & medical devices (compliance-grade pentest + documentation), EdTech mobile platforms (iOS app dynamic analysis with Frida, Keychain audit), SaaS startups (full-stack web + API testing), e-commerce (WAF bypass, payment flow security).
— Compliance support —
GDPR, PCI-DSS, ISO 27001, SOC 2, HIPAA — I provide the technical evidence and remediation documentation auditors expect.
— How I work —
1. Send me your application URL or scope description, I'll review it and respond within 24 hours
2. Fixed-price or hourly proposal with clear deliverables, no surprises
3. Manual testing with detailed PoC for every finding
4. Executive summary + technical report (CVSS-scored, remediation-ready)
5. Free retest after your team applies the fixes
— Certifications —
• OSCP — Offensive Security Certified Professional
• CEH — Certified Ethical Hacker
• MSc in Information Systems & Network Security — University of Milan
Send me your application URL or a brief scope description, and within 24 hours you'll get a focused assessment and a clear, fixed-price estimate.
Web Application Security
Penetration Testing
Security Testing
Vulnerability Assessment
Web App Penetration Testing
Security Assessment & Testing
Cloud Security
Black Box Testing
Cybersecurity Management
Information Security Awareness
Kali Linux
Network Penetration Testing
OWASP
Risk Assessment
Information Security
WordPress Security
Bug Bounty
AI Security
Better Mobile Security Better
Red Team Assessment
Hien N.
Padova, Italy
$39/hr
5.0
3 jobs
LLM Security Engineer | AI Security | AppSec | DevSecOps | Cloud Security
I help startups, SaaS companies, and enterprises secure modern AI systems, web applications, cloud infrastructure, and digital assets — from development to production.
My work covers:
AI & LLM Security
• LLM application security assessments
• Prompt injection and jailbreak testing
• RAG pipeline security reviews
• Agentic workflow security
• Model abuse and data leakage testing
• AI threat modeling (STRIDE, MITRE ATLAS, OWASP LLM Top 10)
• Secure API integrations (OpenAI, Anthropic, vector databases)
Application & API Security
• Web application penetration testing
• API security assessments
• Authentication & authorization testing
• Business logic testing
• Secure architecture reviews
• Vulnerability discovery and remediation guidance
Incident Response & Malware Removal
• WordPress malware cleanup and security hardening
• Backdoor detection and persistence analysis
• Reinfection root cause analysis
• Webshell investigation
• Redirect/spam injection cleanup
• Post-compromise hardening and monitoring
DevSecOps & Cloud Security
• Secure CI/CD pipelines
• Infrastructure as Code (IaC) security
• Container and supply chain security
• Secrets management
• AWS & GCP security reviews
• Runtime detection engineering
• Security automation and secure SDLC improvements
Compliance & Security Governance
• Security assessments aligned with OWASP, NIST, ISO 27001, PCI DSS, GDPR, and SOC 2
• Threat modeling and risk analysis
• Security control validation
• Security architecture reviews
My background combines 7+ years of hands-on cybersecurity experience across application security, penetration testing, cloud security, DevSecOps, threat modeling, detection engineering, and adversarial machine learning research.
I work with clients across:
AI/ML platforms, SaaS, FinTech, E-commerce, Healthcare, Telecom, CMS/WordPress, and cloud-native environments.
Whether you need to secure your AI product, audit your application, clean a compromised website, or strengthen your cloud security posture, I can help you identify risks and implement practical fixes.
Available for short-term audits, incident response, and long-term security consulting.
Information Security
Cybersecurity Management
Python
NIST Cybersecurity Framework
Splunk
PCI DSS
Cloud Security
Vulnerability Assessment
Security Analysis
Kubernetes
Amazon Web Services
Security Assessment & Testing
CI/CD
Governance, Risk & Compliance Software
Information Security Audit
How it works
Post a job for freePost a job
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a Web Application Security Freelancer on Upwork?
You can hire a Web Application Security Freelancer on Upwork in four simple steps:
Create a job post tailored to your Web Application Security Freelancer project scope. We’ll walk you through the process step by step.
Browse top Web Application Security Freelancer talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top Web Application Security Freelancer profiles and interview.
Hire the right Web Application Security Freelancer for your project from Upwork, the world’s largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a Web Application Security Freelancer?
Rates charged by Web Application Security Freelancers on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a Web Application Security Freelancer on Upwork?
As the world’s work marketplace, we connect highly-skilled freelance Web Application Security Freelancers and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Web Application Security Freelancer team you need to succeed.
Can I hire a Web Application Security Freelancer within 24 hours on Upwork?
Depending on availability and the quality of your job post, it’s entirely possible to sign up for Upwork and receive Web Application Security Freelancer proposals within 24 hours of posting a job description.
Find more freelancers
Similar Web Application Security Freelancer Skills