Web Penetration Testing(OWASP Top 10 methodology) | Network Penetration testing | OWASP API Security | Mobile Vulnerability Assessment(iOS and Android) | Source Code Reviews(.Net, Java, PHP) | Vulnerability Assessment and Penetration Testing | SIEM team (Cloud(AWS and Azure) Security, File Integrity Monitoring and Event Monitoring, Endpoint Security and Encryption, Data Loss Prevention, Network Access Control, Threat Monitoring (Email Traffic and Malware Analysis), Privileged Access and Identity Management)
Have 7+ years of experience in both black box and white box testing penetration testing. Perform VAPT (Vulnerability Assessment and Penetration Testing) services for web applications, networks, mobile; source code reviews; malware analysis; server hardening; and security analysis etc. Conduct penetration testing in a systematic approach. Follow the standard methodology of the industry like OWASP Testing Guide v4(OTGv4); SANS top 25; NIST SP 800-115; PCI DSS to perform penetration testing so that client can concentrate on their professions without worrying about security threats.
Web Application Testing: Do web application penetration testing with the latest methodology like OWASP Top-10, SANS Top-25. Perform both manual and automated penetration testing for vulnerabilities like Injection flaws(such as SQL, NoSQL, OS, and LDAP injection etc),Broken Authentication, Sensitive Data Exposure,XML External Entities (XXE), Broken Access Control,Security Misconfiguration, Cross-site scripting(XSS), Insecure Deserialization, Using Components with Known Vulnerabilities,Insufficient Logging & Monitoring. Also, perform source code reviews for many technologies like Java, NET, PHP etc.
Approach for Manual Web-Application Penetration Testing: Conduct manual testing with following controls:
* Configuration and Deployment Management Testing
* Identity Management Testing
* Authentication Testing
* Authorization Testing
* Session Management Testing
* Input Validation Testing
* Testing for Error Handling
* Testing for weak Cryptography
* Business Logic Testing
* Client Side Testing
Tools that use for Automated Web Penetration Testing: Acunetix, Burp-Suite, Netsparker, Nexpose, Nikto, IBM AppScan, HP fortify, W3af etc.
Network penetration testing: Provide both external and internal network Penetration Testing so that your Network Infrastructure is secured from the real world attacks. Do both manual and automated network penetration testing.
Approach for Manual Network Penetration Testing: Manually check for IDS/IPS, Server, Networks switch, Network Router, VPN, Firewalls, Anti-virus, Password etc.
Tools that use for automated network penetration testing: OpenVas, Wireshark, Nessus, Metasploit, Armitage, Scapy etc.
Mobile Application Penetration Testing: Perform mobile applications application penetration testing with the latest OWASP methodology(MSTG). Performed both manual and automated penetration testing for vulnerabilities like Weak Server Side Controls, Insecure Data Storage, Insufficient Transport Layer Protection, Unintended Data Leakage, Poor Authorization and Authentication, Broken Cryptography, Client Side Injection, Security Decisions Via Untrusted Inputs, Improper Session Handling, Lack of Binary Protections.
Tools: Burp-Suite, HP fortify, Dex2Jar, Apktool, framework-res.apk, iNalyzer.
Source Code Reviews: Perform source code reviews for both front and back-end languages. Perform source code reviews standard methodology like OWASP top 10. Do manual and automated source code reviews for various web based security vulnerabilities like SQL injection, Cross site scripting (XSS), CSRF, RFI,LFI, Authentication bypass etc.
Tools: CheckMarx, IBM Appscan source for analysis, Microfocus HP Fortify.
Security Analysis and Server Hardening: Regularly check and maintain your systems, servers to ensure that they comply with the standards. Do hardening application checks the item automatically on a daily basis and monitors all critical networks and server components. We support various frameworks like CIS benchmarking for Desktops & Web Browsers, Mobile Devices, Network Devices, Servers – Operating Systems, Virtualization Platforms & Cloud etc.
Social Engineering: Have experience in social engineering vectors: Vishing, Phishing, Smishing, Impersonation. Used the following social engineering cycle to conduct social engineering:
Gather Information: Here Information gathered from company websites, social media and other publications.
Plan Attack: Next step is outline how intends to execute the attack
Acquire Tools: After planning, next include computer programs that an attacker will use when launching the attack.
Attack: Exploit the weaknesses in the target system.
Use acquired knowledge: Information gathered during the social engineering tactics is used in attacks such as password guessing.
Tools: SET(Kali-Linux); GetGoPhish
Web Application Security
Network Security
Vulnerability Assessment
Penetration Testing
Information Security
Internet Security
Security Analysis
Software QA
Network Penetration Testing
Website Security
Information Security Audit
Web Testing
Steffin S.
Kozhikode, India
$30/hr
4.8
208 jobs
Need a Web Application or API penetration test that goes beyond automated scanner output?
I’m an OSCP, OSEP, OSWP and CREST CPSA-certified Penetration Tester with 100% Job Success, Top Rated status, 190+ completed Upwork engagements and experience delivering 400+ penetration tests and security assessments.
I help SaaS companies, startups, e-commerce platforms and enterprise teams identify real, exploitable security weaknesses before product launches, major releases and compliance reviews.
My approach is manual-first. I investigate vulnerabilities that automated scanners often miss, including authentication weaknesses, authorization bypasses, IDOR/BOLA, privilege escalation, tenant-isolation failures, business-logic flaws, race condition flaws and chained attack scenarios.
CORE SERVICES
• Web Application Penetration Testing
• API Security Testing
• Mobile Application Penetration Testing
• External and Internal Network Penetration Testing
• Active Directory and Infrastructure Assessments
• Thick Client Application Testing
• Security Retesting and Remediation Verification
WHAT YOU RECEIVE
• A professional executive and technical report
• Reproducible proof-of-concept evidence
• Risk ratings and CVSS scoring where applicable
• Clear business-impact explanations
• Developer-focused remediation guidance
• Retesting after fixes are implemented
Reports can support SOC 2, ISO 27001, PCI DSS, Amazon SP-API, vendor-security reviews and internal audits.
Redacted Web Application and API penetration-testing report samples are available upon request.
Send me your application type, number of user roles, approximate API endpoints or hosts, testing environment and preferred timeline. I will help you define the appropriate scope, methodology and deliverables.
Web Application Security
Application Security
Information Security
Penetration Testing
Network Security
Security Assessment & Testing
Security Testing
Vulnerability Assessment
System Security
Web App Penetration Testing
Website Security
Black Box Testing
Network Penetration Testing
OWASP
Risk Assessment
Aaryan S.
Rohtak, India
$30/hr
5.0
45 jobs
If your SaaS product handles user data, processes payments, or is heading toward SOC 2 or ISO 27001 — your attack surface needs to be tested before your auditor finds it for you.
I'm Aaryan Saharan, an independent penetration tester with 4+ years of hands-on experience across web, API, Android, and iOS targets. I hold CEH v13 and PhD-CSA credentials, and I work with the same tools used by enterprise security teams: Burp Suite Pro, Invicti Enterprise, Nuclei, Trivy, and Garak for AI/LLM attack surfaces.
What I test:
— Web applications (OWASP Top 10, business logic flaws, multi-tenant isolation)
— REST & GraphQL APIs (auth bypass, mass assignment, injection, rate limiting)
— Mobile apps — Android & iOS (insecure storage, certificate pinning, reverse engineering)
— AI/LLM applications (prompt injection, model extraction, OWASP Top 10 for LLMs)
— Cloud & container environments (misconfiguration, privilege escalation via Prowler & Trivy)
My methodology follows OWASP, PTES, NIST, and MITRE ATLAS — so findings map directly to the frameworks your compliance team already speaks.
Every engagement includes:
— A clear scope document before work begins
— Real-time Jira-integrated ticket tracking (so your dev team sees findings as they're discovered)
— A professional PDF report with CVSS-scored findings, reproduction steps, and fix guidance
— A re-test to verify patches hold
I work with funded startups, scale-ups, and product teams running release-based or continuous security programs. If you need a one-time pre-launch test or an ongoing retainer, I can scope either.
Let's talk about what you're building — and what an attacker would see when they look at it.
Web Application
Penetration Testing
Vulnerability Assessment
Ethical Hacking
Website Security
Mobile App Testing
Information Security Audit
Security Assessment & Testing
AWS Application
Cloud Security
SaaS
Source Code Scanning
White Box Testing
Black Box Testing
Security Analysis
Web Application Audit
AI Security
WebAPITesting
Jeel V.
Surat, India
$16/hr
5.0
15 jobs
Hi, I’m Jeel Vekariya, a Cybersecurity Expert with 5+ years of hands-on experience helping businesses, startups, SaaS companies, and organizations identify vulnerabilities, reduce security risks, and protect their applications and infrastructure.
I specialize in Vulnerability Assessment & Penetration Testing (VAPT), Ethical Hacking, Offensive Security, Application Security, API Security, Mobile Security, Network Security, Cloud Security, and Security Research.
My approach is simple:
Find the vulnerability → Validate the risk → Explain the impact → Recommend the fix → Retest
━━━━━━━━━━━━━━━━━━━━
WHAT I CAN HELP YOU WITH
✦ Web Application Penetration Testing
➤ OWASP Top 10 Testing
➤ Authentication & Authorization Testing
➤ IDOR / BOLA & Broken Access Control
➤ SQL Injection (SQLi)
➤ Cross-Site Scripting (XSS)
➤ CSRF & SSRF
➤ File Upload & Path Traversal
➤ Remote Code Execution (RCE)
➤ Command Injection
➤ Business Logic Vulnerabilities
➤ Session & JWT Security
➤ Security Misconfiguration
✦ API Security Testing
➤ REST API Penetration Testing
➤ GraphQL Security Testing
➤ OWASP API Security Top 10
➤ API Authentication & Authorization
➤ OAuth & JWT Security Testing
➤ BOLA / IDOR Testing
➤ Rate Limiting & Abuse Testing
➤ API Gateway Security
➤ Business Logic Testing
✦ Mobile Application Security
➤ Android & iOS Penetration Testing
➤ Mobile API Security Testing
➤ Static & Dynamic Analysis
➤ Authentication & Authorization Testing
➤ Secure Data Storage Testing
➤ SSL/TLS Security Testing
➤ MobSF, Frida & JADX Analysis
✦ Network & Infrastructure Security
➤ Internal & External Network Penetration Testing
➤ Vulnerability Assessment
➤ Network Security Assessment
➤ Firewall Security Review
➤ Server Security Testing
➤ Linux & Windows Security Testing
➤ Active Directory Security Assessment
➤ Privilege Escalation Testing
✦ Cloud & Infrastructure Security
➤ AWS Security Assessment
➤ Microsoft Azure Security Assessment
➤ Google Cloud (GCP) Security Review
➤ IAM & Access Control Review
➤ Cloud Configuration Assessment
➤ Docker & Kubernetes Security
➤ Infrastructure Security Testing
➤ Security Hardening
✦ Application & Specialized Security
➤ Source Code Review
➤ Secure Code Review
➤ SAST / DAST
➤ Software Composition Analysis (SCA)
➤ AI & LLM Security Testing
➤ Red Team Security Assessments
➤ Security Configuration Review
➤ OSINT & Cybersecurity Research
━━━━━━━━━━━━━━━━━━━━
HOW I WORK
➤ Understand your application, infrastructure, and scope
➤ Review the attack surface and potential entry points
➤ Perform manual and automated security testing
➤ Validate vulnerabilities and reduce false positives
➤ Assess technical and business impact
➤ Provide reproducible Proof of Concept (PoC)
➤ Explain the vulnerability in clear language
➤ Provide practical remediation recommendations
➤ Retest fixes after remediation
I don't simply provide automated scanner results. I focus on finding meaningful security issues and giving your team information they can actually use to fix them.
━━━━━━━━━━━━━━━━━━━━
SECURITY REPORTS & DELIVERABLES
✔ Executive Summary
✔ Detailed Technical Findings
✔ Vulnerability Description
✔ CVSS-Based Severity Rating
✔ Proof of Concept
✔ Screenshots & Evidence
✔ Steps to Reproduce
✔ Business Impact
✔ Remediation Recommendations
✔ Prioritized Findings
✔ Retesting Support
My reports are designed to be useful for both developers and business stakeholders, making it easier to understand the issue, its impact, and how to resolve it.
━━━━━━━━━━━━━━━━━━━━
TOOLS & TECHNOLOGIES
Web & API: Burp Suite Pro, OWASP ZAP, Postman
Network: Nmap, Nessus, Metasploit, Wireshark
Mobile: MobSF, Frida, JADX, Objection
Cloud: AWS, Microsoft Azure, GCP
Containers: Docker, Kubernetes
Operating Systems: Kali Linux, Linux, Windows Server
━━━━━━━━━━━━━━━━━━━━
CORE SECURITY EXPERTISE
✔ Vulnerability Assessment & Penetration Testing
✔ Web Application Security
✔ API Security
✔ Mobile Application Security
✔ Network & Infrastructure Security
✔ Cloud Security
✔ Active Directory Security
✔ Authentication & Authorization
✔ IDOR / BOLA
✔ SQL Injection & XSS
✔ SSRF & CSRF
✔ Business Logic Testing
✔ Privilege Escalation
✔ Secure Code Review
✔ AI / LLM Security
✔ Red Teaming
✔ OWASP Security Testing
━━━━━━━━━━━━━━━━━━━━
WHY CLIENTS WORK WITH ME
➤ 5+ years of cybersecurity experience
➤ Top Rated Upwork Freelancer
➤ 100% Job Success
➤ Manual + automated security testing
➤ Clear and professional security reports
➤ Practical remediation guidance
➤ Developer-friendly findings
➤ Professional communication
➤ On-time delivery
➤ Confidential and authorized testing
My goal is not only to find vulnerabilities. I want to help you understand the risk, fix the problem, and improve your overall security posture.
➔ Let's discuss your security requirements and find the vulnerabilities before attackers do.
Web Application Security
Application Security
Penetration Testing
Vulnerability Assessment
Ethical Hacking
Mobile App Testing
API Testing
Network Penetration Testing
Cloud Security
Cyber Threat Intelligence
Red Team Assessment
WordPress Security
Information Security
Web App Penetration Testing
Cybersecurity Management
Nimit J.
New Delhi, India
$30/hr
4.9
32 jobs
🌟 Top Rated🌟
🛡️ Penetration Testing Expert | Certified Cybersecurity Professional
🧠 OSCP & 🏅 CREST Certified | 🚨 8+ years in VAPT (Vulnerability Assessment and Penetration Testing) | ✅ 300+ Web, Mobile, API & Network Pentests
Note: PLEASE don't contact for unethical jobs such as Insta/Facebook/Gmail/Crypto Hacking & Recovery!!!
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🎓 About Me
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Hi, I’m Nimit Jain — a cybersecurity professional specializing in penetration testing (pentesting) and VAPT services. With 8+ years of hands-on experience, I’ve successfully tested and secured 300+ assets for Fortune 500 companies, startups, and regulated sectors.
My core expertise covers web application penetration testing, mobile app security (Android/iOS), API security, thick client testing, and network infrastructure pentesting. I identify real-world risks and deliver actionable remediation aligned with compliance standards.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🏆 Key Certifications
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ OSCP (Offensive Security Certified Professional)
✅ CREST Registered Penetration Tester (CRT)
✅ CREST Practitioner Security Analyst (CPSA)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🌟 Client Testimonials
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🌟 “Working with Nimit was excellent. His penetration testing expertise helped us uncover critical issues and strengthen our security posture. Clear communication and reliable delivery.”
🌟 “Highly skilled in VAPT and pentesting, Nimit gave us valuable insights into our application security. Professional, detail-oriented, and easy to work with.”
🌟 "Nimit was fantastic throughout; worked with tight deadlines and delivered a very good service. Highly recommend !"
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🌐 Penetration Testing Expertise
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🔹 Web Applications: Secured against OWASP Top 10 vulnerabilities
🔹 Mobile Apps: Pentested Android & iOS for real-world exploits
🔹 APIs: Conducted API VAPT for secure integrations
🔹 Thick Clients: Enterprise-grade security assessments
🔹 Network Security: Infrastructure pentests to expose misconfigurations
Industry Focus:
✔️ Banking, Financial Services & Insurance (BFSI)
✔️ Healthcare & Pharma
✔️ E-Commerce Platforms
✔️ Manufacturing & Critical Infrastructure
✔️ Government & Public Sector
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
📜 Compliance & Standards
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Expert in ISO 27001, HIPAA, GDPR, PCI DSS, and FDA compliance. Methodologies include OWASP, NIST, and SANS guidelines, ensuring high-quality penetration testing reports for audits and certifications.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🔬 Research & CVEs
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🛡️ CVE-2019-12744 – Remote Code Execution
🛡️ CVE-2019-12745 – Cross-Site Scripting (XSS)
🛡️ CVE-2019-12801 – Cross-Site Scripting (XSS)
🛡️ CVE-2019-12932 – Cross-Site Scripting (XSS)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🚀 Advanced Skills
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✔️ Red & Blue Teaming engagements
✔️ Cloud Security Pentesting (AWS, Azure, GCP)
✔️ Social Engineering & Phishing Simulations
✔️ Advanced API & Mobile Application VAPT
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🤝 Why Work With Me
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ 8+ years of penetration testing experience across industries
✅ Proven track record securing 300+ assets
✅ Compliance-aligned VAPT reports for SOC2, PCI DSS, HIPAA audits
✅ Clear communication & timely delivery
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🎯 Get in Touch
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
I help businesses strengthen their security posture through end-to-end penetration testing (VAPT). Whether it’s a web app pentest, API security test, or network infrastructure VAPT, I deliver actionable findings that make your systems resilient.
📞 FREE Consultation Available Daily
🕗 8:00 AM IST – 11:00 PM IST (1:30 AM – 3:30 PM EST)
Application Security
Penetration Testing
Vulnerability Assessment
Information Security
Security Testing
Security Assessment & Testing
Information Security Consultation
Network Security
Kali Linux
Web App Penetration Testing
Network Penetration Testing
Security Analysis
Website Security
Information Security Audit
Ethical Hacking
Chakradhar C.
Guntur, India
$50/hr
5.0
76 jobs
✅ Top Rated Plus Expert ✅ 1000+ Hours ✅ Professional Penetration Tester
Senior Penetration Tester with more than 7+ years of rich industry experience in Web, Mobile, API, and Network Penetration Testing. I have successfully completed 500+ Web application Pentests, 200+ Mobile Application Penetration Tests, 300+ API Penetration Tests, 100+ External Network Penetration Tests and 30+ Internal Penetration Tests.
I am also a Security researcher acknowledged by Yahoo (among other notable companies like SolarEdge, Imgur, Artsy, etc.) for disclosing a number of vulnerabilities via the HackerOne bug bounty platform.
My core competency is Blackbox, Greybox Testing on Web, API, Mobile, and Network applications. I am familiar with all attacks and mitigations and am well-versed in OWASP, NIST, and PTES Frameworks. My Pentesting reports include clear documentation of the vulnerabilities found along with the remediations to make sure the client is 100% satisfied. I am also certified in AWS, and Azure and have a very keen knowledge of Cloud Security and cloud administration.
✅ I have conducted Penetration Tests, Vulnerability Assessments and delivered professional reports to companies around the world complying with the following:
►OWASP Web Security Top 10 Vulnerability
►OWASP API Security Top 10 Vulnerability
►OWASP Mobile Security Top 10 Vulnerability
►External Network Penetration Testing
►Internal Network Penetration Testing
►Payment Card Industry Data Security Standard (PCI DSS)
►System and Organization Controls 2 (SOC2)
►General Data Protection Regulation (GDPR)
►Common Vulnerability Scoring System (CVSS)
►Open Source Security Testing Methodology Manual (OSSTMM)
My Certs include:
►CompTIA Pentest+ (Expired)
►AWS Solutions Architect (Expired)
►Azure Administrator (Expired)
Tools: Burp Suite, Nikto, Nmap, Zap, Metasploit, Nessus, W3af, Ffuf, Dirb, etc...
I am available 24/7. If you are interested in cooperation, drop me a line :)
Web Application Security
Penetration Testing
Network Security
Vulnerability Assessment
Metasploit
Information Security
Information Security Audit
Mobile App Testing
Cloud Security
Web App Penetration Testing
Network Penetration Testing
How it works
Post a job for freePost a job
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Summa Linguae
How do I hire a Web Application Security Freelancer in India on Upwork?
You can hire a Web Application Security Freelancer in India on Upwork in four simple steps:
Create a job post tailored to your Web Application Security Freelancer project scope. We'll walk you through the process step by step.
Browse top Web Application Security Freelancer talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top Web Application Security Freelancer profiles and interview.
Hire the right Web Application Security Freelancer for your project from Upwork, the world's largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a Web Application Security Freelancer?
Rates charged by Web Application Security Freelancers on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a Web Application Security Freelancer in India on Upwork?
As the world's work marketplace, we connect highly-skilled freelance Web Application Security Freelancers and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Web Application Security Freelancer team you need to succeed.
Can I hire a Web Application Security Freelancer in India within 24 hours on Upwork?
Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive Web Application Security Freelancer proposals within 24 hours of posting a job description.
Find more freelancers
Top cities for Web Application Security Freelancers in India