Hire the Best WebApp Pentesters
in India

More than 3,000 reviews on G2
Rating is 4.5 out of 5.
4.5/5
of Upwork by G2 peer reviewers
Ankit Kumar R.

Ghazipur, India

$7/hr
5.0
3 jobs

Hi, Iโ€™m Ankit a Penetration Tester and Ethical Hacker with hands-on experience in Vulnerability Assessment & Penetration Testing (VAPT) for web applications, networks, and APIs. I help businesses identify security vulnerabilities, OWASP Top 10 risks, and misconfigurations before attackers exploit them ๐—ช๐—ต๐—ฎ๐˜ ๐—œ ๐—ฐ๐—ฎ๐—ป ๐—›๐—ฒ๐—น๐—ฝ ๐—ฌ๐—ผ๐˜‚ ๐—ช๐—ถ๐˜๐—ต- โ–ช Web Application Penetration Testing (OWASP Top 10) โ–ช Network & Infrastructure Penetration Testing โ–ช Vulnerability Assessment & Penetration Testing (VAPT) โ–ช Dark Web Monitoring & Threat Intelligence โ–ช Bug Bountyโ€“style Security Audits โ–ช Malware & Exploit Analysis ๐—ง๐—ผ๐—ผ๐—น๐˜€ & ๐—ง๐—ฒ๐—ฐ๐—ต๐—ป๐—ถ๐—พ๐˜‚๐—ฒ๐˜€ ๐—œ ๐—จ๐˜€๐—ฒ- Kali Linux | Metasploit | Burp Suite | Nmap | Nessus | Wireshark SQL Injection | XSS | CSRF | Privilege Escalation | Brute Force Testing ๐—ช๐—ต๐—ฎ๐˜ ๐—ฌ๐—ผ๐˜‚โ€™๐—น๐—น ๐—š๐—ฒ๐˜- โ–ช Detailed vulnerability reports with risk severity โ–ช Clear proof-of-concept (PoC) screenshots/videos โ–ช Step-by-step remediation guidance โ–ช Ethical, confidential, and professional testing ๐—ช๐—ต๐˜† ๐—–๐—น๐—ถ๐—ฒ๐—ป๐˜๐˜€ ๐—›๐—ถ๐—ฟ๐—ฒ ๐— ๐—ฒ- โ–ช Real-world attack simulations โ–ช Clear communication & fast delivery โ–ช Security-first mindset โ–ช Trusted ethical hacking practices If security matters to you, letโ€™s ๐˜๐—ฒ๐˜€๐˜ ๐—ถ๐˜ ๐—ฏ๐—ฒ๐—ณ๐—ผ๐—ฟ๐—ฒ ๐—ต๐—ฎ๐—ฐ๐—ธ๐—ฒ๐—ฟ๐˜€ ๐—ฑ๐—ผ. #CyberSecurity #EthicalHacking #PenetrationTesting #VulnerabilityAssessment #VAPT #WebApplicationSecurity #NetworkSecurity #InformationSecurity #SecurityTesting #OWASPTop10 #BugBounty #DarkWebMonitoring #DarkWebInvestigation #ThreatIntelligence #MalwareAnalysis #KaliLinux #BurpSuite #Nmap #Nessus #RiskAssessment

  • Penetration Testing
  • Ethical Hacking
  • Vulnerability Assessment
  • Web Application Security
  • Network Security
  • Cybersecurity Management
  • Information Security
  • Security Testing
  • Internet Security
  • Security Analysis
  • Information Security Audit
  • Computer Network
  • Cloud Security
  • OWASP
  • API Testing
  • IT Compliance Audit
  • Threat Detection
  • Incident Response Readiness Assessment
Nimit J.

New Delhi, India

$30/hr
4.9
26 jobs

๐ŸŒŸ Top Rated๐ŸŒŸ ๐Ÿ›ก๏ธ Penetration Testing Expert | Certified Cybersecurity Professional ๐Ÿง  OSCP & ๐Ÿ… CREST Certified | ๐Ÿšจ 8+ years in VAPT (Vulnerability Assessment and Penetration Testing) | โœ… 300+ Web, Mobile, API & Network Pentests Note: PLEASE don't contact for unethical jobs such as Insta/Facebook/Gmail/Crypto Hacking & Recovery!!! โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” ๐ŸŽ“ About Me โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” Hi, Iโ€™m Nimit Jain โ€” a cybersecurity professional specializing in penetration testing (pentesting) and VAPT services. With 8+ years of hands-on experience, Iโ€™ve successfully tested and secured 300+ assets for Fortune 500 companies, startups, and regulated sectors. My core expertise covers web application penetration testing, mobile app security (Android/iOS), API security, thick client testing, and network infrastructure pentesting. I identify real-world risks and deliver actionable remediation aligned with compliance standards. โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” ๐Ÿ† Key Certifications โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” โœ… OSCP (Offensive Security Certified Professional) โœ… CREST Registered Penetration Tester (CRT) โœ… CREST Practitioner Security Analyst (CPSA) โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” ๐ŸŒŸ Client Testimonials โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” ๐ŸŒŸ โ€œWorking with Nimit was excellent. His penetration testing expertise helped us uncover critical issues and strengthen our security posture. Clear communication and reliable delivery.โ€ ๐ŸŒŸ โ€œHighly skilled in VAPT and pentesting, Nimit gave us valuable insights into our application security. Professional, detail-oriented, and easy to work with.โ€ ๐ŸŒŸ "Nimit was fantastic throughout; worked with tight deadlines and delivered a very good service. Highly recommend !" โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” ๐ŸŒ Penetration Testing Expertise โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” ๐Ÿ”น Web Applications: Secured against OWASP Top 10 vulnerabilities ๐Ÿ”น Mobile Apps: Pentested Android & iOS for real-world exploits ๐Ÿ”น APIs: Conducted API VAPT for secure integrations ๐Ÿ”น Thick Clients: Enterprise-grade security assessments ๐Ÿ”น Network Security: Infrastructure pentests to expose misconfigurations Industry Focus: โœ”๏ธ Banking, Financial Services & Insurance (BFSI) โœ”๏ธ Healthcare & Pharma โœ”๏ธ E-Commerce Platforms โœ”๏ธ Manufacturing & Critical Infrastructure โœ”๏ธ Government & Public Sector โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” ๐Ÿ“œ Compliance & Standards โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” Expert in ISO 27001, HIPAA, GDPR, PCI DSS, and FDA compliance. Methodologies include OWASP, NIST, and SANS guidelines, ensuring high-quality penetration testing reports for audits and certifications. โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” ๐Ÿ”ฌ Research & CVEs โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” ๐Ÿ›ก๏ธ CVE-2019-12744 โ€“ Remote Code Execution ๐Ÿ›ก๏ธ CVE-2019-12745 โ€“ Cross-Site Scripting (XSS) ๐Ÿ›ก๏ธ CVE-2019-12801 โ€“ Cross-Site Scripting (XSS) ๐Ÿ›ก๏ธ CVE-2019-12932 โ€“ Cross-Site Scripting (XSS) โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” ๐Ÿš€ Advanced Skills โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” โœ”๏ธ Red & Blue Teaming engagements โœ”๏ธ Cloud Security Pentesting (AWS, Azure, GCP) โœ”๏ธ Social Engineering & Phishing Simulations โœ”๏ธ Advanced API & Mobile Application VAPT โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” ๐Ÿค Why Work With Me โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” โœ… 8+ years of penetration testing experience across industries โœ… Proven track record securing 300+ assets โœ… Compliance-aligned VAPT reports for SOC2, PCI DSS, HIPAA audits โœ… Clear communication & timely delivery โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” ๐ŸŽฏ Get in Touch โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ” I help businesses strengthen their security posture through end-to-end penetration testing (VAPT). Whether itโ€™s a web app pentest, API security test, or network infrastructure VAPT, I deliver actionable findings that make your systems resilient. ๐Ÿ“ž FREE Consultation Available Daily ๐Ÿ•— 8:00 AM IST โ€“ 11:00 PM IST (1:30 AM โ€“ 3:30 PM EST)

  • Penetration Testing
  • Network Penetration Testing
  • Application Security
  • Vulnerability Assessment
  • Information Security
  • Web App Penetration Testing
  • Security Analysis
  • Security Testing
  • Security Assessment & Testing
  • Information Security Consultation
  • Website Security
  • Network Security
  • Information Security Audit
  • Ethical Hacking
  • Kali Linux
Kunal N.

Pune, India

$20/hr
5.0
4 jobs

I help startups, SaaS companies, and enterprises identify critical security vulnerabilities before they become costly breaches, compliance issues, or business disruptions. As an Application Security Consultant and Penetration Tester, I specialize in uncovering real-world security weaknesses across web applications, APIs, network infrastructure, cloud environments, and modern technology platforms. My goal is not only to identify vulnerabilities but also to help organizations understand their security risks, prioritize remediation efforts, and strengthen their overall security posture. I have worked on security assessments involving enterprise applications, banking platforms, healthcare systems, cloud infrastructures, and business-critical applications. My experience includes identifying authentication flaws, access control weaknesses, business logic vulnerabilities, network misconfigurations, cloud security gaps, API security issues, and attack paths that automated scanners frequently miss. Core Security Services โ€ข Web Application Penetration Testing (OWASP Top 10 & Business Logic Testing) โ€ข API Security Testing (REST & GraphQL) โ€ข Network & Infrastructure Security Testing โ€ข Cloud Security Assessments (AWS) โ€ข Red Team Operations & Adversary Simulation โ€ข AI / LLM Security Testing โ€ข Vulnerability Assessment & Risk Analysis โ€ข Security Architecture Review โ€ข Email Security Implementation (SPF, DKIM & DMARC) What You Can Expect โ€ข Comprehensive Manual Security Testing โ€ข Detailed Vulnerability Reports โ€ข Proof-of-Concept Validation โ€ข Risk-Based Prioritization โ€ข Clear Remediation Guidance โ€ข Remediation Validation & Retesting โ€ข Executive and Technical Reporting Tools & Technologies โ€ข Burp Suite Professional โ€ข Nmap โ€ข Metasploit Framework โ€ข Nessus โ€ข OWASP ZAP โ€ข Wireshark โ€ข SQLMap โ€ข AWS Security Tools โ€ข Kali Linux Long-Term Security Partnership Many organizations engage me beyond a single penetration test. I work with clients on recurring security assessments, monthly security reviews, remediation verification, secure development guidance, and continuous security improvement initiatives. Whether you need a one-time security assessment or a long-term security partner, I focus on delivering actionable security insights that help protect your applications, infrastructure, customers, and reputation. If you are looking for a security professional who can think like an attacker and provide practical, business-focused security recommendations, I would be happy to discuss your project.

  • Penetration Testing
  • Network Penetration Testing
  • Web Application Security
  • Vulnerability Assessment
  • Ethical Hacking
  • OWASP
  • API Testing
  • Metasploit
  • Cloud Security
  • Cybersecurity Tool
  • Security Testing
  • Network Security
  • Application Security
  • Red Team Assessment
  • Information Security
Mahesh T.

Bengaluru, India

$40/hr
5.0
126 jobs

๐Ÿ” Certified Penetration Tester | AWS & Azure Cloud Security | Incident Response Expert ๐Ÿ” Iโ€™m a results-driven cybersecurity specialist with 13+ years of experience securing cloud infrastructure, web applications, and enterprise environments. I help companies prevent breaches, mitigate risks, and ensure compliance through advanced security architecture and real-world offensive security skills. ๐ŸŽฏ What I Do: โœ”๏ธ Cloud Security Hardening โ€“ AWS (IAM, EC2, S3, VPC, RDS, Route 53) & Azure (VNET, NSGs, Azure Security Center, Defender) โœ”๏ธ Penetration Testing โ€“ Full-scope internal/external pentests, web/app/API testing, business logic abuse, OWASP Top 10 โœ”๏ธ Vulnerability Assessments โ€“ Nessus, OpenVAS, Nmap, custom exploit validation, CVSS scoring & prioritization โœ”๏ธ Threat Detection & Response โ€“ Wazuh setup, real-time event correlation, SIEM deployment, log analysis โœ”๏ธ Security Architecture โ€“ Designing scalable, secure cloud solutions with strong IAM, encryption, and DR practices โœ”๏ธ Cloudflare Optimization โ€“ Harden DNS, implement WAF rulesets, rate-limiting, Zero Trust setup โœ”๏ธ Incident Response โ€“ Triage, forensics, log collection, remediation and recovery plans (NIST, MITRE ATT&CK aligned) ๐Ÿ“Œ Security Tools I Work With: - **Offensive Security**: Burp Suite, Metasploit, Nmap, Hydra, SQLmap - **Defensive Tools**: Wazuh, AWS GuardDuty, Azure Sentinel, Nessus, Suricata - **Languages/Scripting**: Bash, PowerShell, HTML/JavaScript (for attack emulation & automation) - **Frameworks/Standards**: OWASP, MITRE ATT&CK, NIST CSF, CIS Benchmarks ๐Ÿ›ก๏ธ Certifications: - AWS Certified Security โ€“ Specialty - Microsoft Certified: Azure Security Engineer Associate - Licensed Penetration Tester (LPT) | Certified Penetration Testing Professional (CPENT) - CEH, CCSK ๐Ÿ“ˆ Highlights: - $200K+ earned, 97% Job Success on Upwork - 9,300+ hours across 90+ successful projects - Trusted by startups, fintechs, and regulated industries (HIPAA, GDPR, SOC2) Iโ€™m known for delivering real-world, **actionable security results** โ€” not just checkbox audits. If youโ€™re looking to **secure your infrastructure, detect threats faster, or simulate real-world attacks**, letโ€™s connect!

  • Penetration Testing
  • Cloudflare
  • Kali Linux
  • Microsoft Azure
  • Security Testing
  • Vulnerability Assessment
  • Application Security
  • Security Analysis
  • Amazon Web Services
  • Information Security
  • Web App Penetration Testing
  • Security Assessment & Testing
  • Security Infrastructure
  • Information Security Consultation
John M.

Bengaluru, India

$34/hr
5.0
47 jobs

๐Ÿ”ข As an Upwork Top 1% Expert Vetted ๐Ÿ‘‘ Certified Ethical Hacker and an Experienced Penetration Tester with 10+ years of experience Penetration Testing Web SaaS and Mobile based applications and networks, every flaw tells a story; I write the ending and specialize in helping my clients strengthen their cybersecurity defenses. An average Cybersecurity Incident in your business can you cost you anywhere between $120,000+ to $1.24+ million and even a 10%+ reduction in risk can save your business nearly $124,000+ and hiring a full time in-house team can cost you $100,000+ per employee per year. That is why you need an expert like me to protect your business and reduce your business risk. What makes me stand out from other freelancers is the fact that I am also a Cybersecurity Architect, capable of architecting solutions to enhance the security of your organisation and preserving the security and integrity of your data. I have always been passionate about solving technical problems for my clients through Penetration Testing and I don't rest till I get to the root of the problem and solve it. What I can offer? I can help you secure your business by providing the following services: โœ… Web Application Penetration Testing, โœ… Secure Source Code Analysis, โœ… Mobile Application Penetration Testing, โœ… Network Penetration Testing, โœ… Secure Architecture Review, โœ… API Security Testing, ย ย  โœ… Secure Configuration Review, โœ… Secure Code Review, โœ… CASA Assessment, โœ… Red Team Assessment, โœ… Threat Modelling, โœ… Phishing Simulations & Assessment. Why Choose Me? ๐Ÿง‘๐Ÿผโ€๐Ÿ’ผ Client-Centric Approach: Your security is my top priority. I work closely with your team to understand your objectives and deliver tailored services that align with your business goals. Trust and transparency are the cornerstones of my practice, and I am committed to helping you navigate the complex landscape of cybersecurity with confidence and achieve compliance. ๐Ÿ“ Comprehensive Security Assessments: I conduct detailed SOC Type 2 / ISO compliant evaluations to identify vulnerabilities in your network, applications, and infrastructure. โœ‚๏ธ Tailored Solutions: Every organization is unique. I customize my approach to meet your specific security needs and industry standards. ๐ŸŽฌ Actionable Recommendations: Post-assessment, I provide clear, concise, and practical remediation steps to address identified vulnerabilities. ๐Ÿ” Ongoing Support: Cybersecurity is an ongoing process. I offer continuous support and re-assessment to ensure your defenses remain robust against evolving threats ๐ŸŒ Holistic Approach: I don't just patch vulnerabilities; I architect comprehensive security solutions that align with business goals. My focus extends beyond the technical to encompass risk management and organizational resilience. ๐Ÿ—จ๏ธ Collaborative Communicator: I bridge the gap between technical jargon and business language, fostering understanding across teams. Effective communication is key to successful security implementation. ๐Ÿซ Continuous Learning: The threat landscape evolves, and so do I. Whether it's a new attack vector or an emerging technology, count me in. Learning is my superpower. ๐Ÿ™‹โ€โ™‚๏ธ Key Skills: โœ”๏ธ Penetration Testing & Vulnerability Assessment: I thrive on dissecting systems, identifying weaknesses, and recommending robust solutions. Armed with tools like Kali Linux, Metasploit, Nmap, and Wireshark, I delve into web applications, networks, and APIs. But here's the twistโ€”I don't stop at discovery; I offer a free retest after remediation to ensure vulnerabilities stay sealed. โœ”๏ธ Network Security: I've designed and implemented secure network architectures, ensuring data confidentiality, integrity, and availability. Firewalls, intrusion detection systems, and VPNsโ€”my toolkit covers it all. โœ”๏ธ Cloud Security: Proficient in securing cloud environments especially Amazon Web Services (AWS) & Oracle Cloud Infrastructure (OCI). I stress-test cloud deployments ensuring they withstand real-world attacks. โœ”๏ธ Secure Coding Practices: I advocate for secure coding principles using tools like SonarQube and collaborate with development teams to build resilient applications. Prevention beats cure, every time. โ›๏ธTools I Use โ˜‘๏ธ Penetration Testing: Nmap, Metasploit, Burp Suite Professional, Wireshark, SQLmap, Kali Linux โ˜‘๏ธ Programming & Scripting Skills: Python, Bash, PowerShell, JavaScript, Java and C# โ˜‘๏ธ Security Frameworks & Standards: OWASP, NIST, CASA, CIA Triad, PCI-DSS ๐Ÿซฑ๐Ÿฝโ€๐Ÿซฒ๐Ÿฝ Let's Connect: Ready to enhance your business/organization's security? Let's chat! Reach out to me here on Upwork, and let's build a safer digital future together. ๐ŸŸข Press '...' button and then โ€˜Send Messageโ€™ button in the top right-hand corner โœ‰๏ธ ๐Ÿšซ No hacking service - I do not provide any hacking services, and I will not engage in any activities that involve gaining unauthorized access to any accounts, systems, or social media platforms. Requests for such services will be declined.

  • Penetration Testing
  • Network Penetration Testing
  • Security Testing
  • Security Assessment & Testing
  • Vulnerability Assessment
  • Information Security
  • Application Security
  • Web Application Security
  • Network Security
  • System Security
  • Web App Penetration Testing
  • Website Security
  • Black Box Testing
  • OWASP
  • Risk Assessment
Angu H.

Chennai, India

$35/hr
4.8
49 jobs

I am a Registered Penetration Tester & Ethical Hacker holding OSCP, CRTP, CEH, and CISSP certifications. I design custom tools and scripts for penetration testing and work extensively with Kali Linux. I perform comprehensive manual testing using Burp Suite, Metasploit, Nmap, SQLMap, Wireshark, and industry-standard frameworks. I safely develop, test, and modify exploits based on target environments. I currently work as a full-time security consultant specializing in penetration testing and vulnerability assessment across web applications, APIs, cloud infrastructure, and mobile platforms. I help organizations identify real, exploitable security risks through black-box, grey-box, and white-box testing methodologies. I have proven experience identifying critical and high-risk vulnerabilities across banking, telecom, insurance, government, SaaS, healthcare, and EdTech platforms. My work has led to multiple zero-day discoveries and CVE records in widely used products, including SHAREit, Upwork Time Tracker, and Avast Anti Virus. I bring 6+ years of hands-on experience as an information security professional. I have led and executed hundreds of penetration tests, VAPT engagements, red team operations, and security audits. My experience spans large enterprises with thousands of assets as well as startups seeking strong security foundations. I have deep expertise in assessing network security, cloud infrastructure (AWS, Azure), API security, web application security, and mobile application penetration testing (iOS and Android) across modern technology stacks. Core Competencies: โ€ข Web & Application Security: OWASP Top 10, authentication & authorization, access control, session management, business logic flaws, IDOR/BOLA, injection vulnerabilities โ€ข API Security: GraphQL, REST, OWASP API Top 10, OAuth/OIDC, SSO/SAML, token misuse, microservices โ€ข Cloud & Infrastructure: AWS (IAM privilege escalation, EC2/EKS, Lambda, S3, VPC, CloudTrail/GuardDuty), Azure, container/Kubernetes security โ€ข Specialized: AI/LLM security, mobile app security, thick client, admin panel security โ€ข Network: Internal AD testing, external penetration testing, lateral movement Working with me, you receive: โ˜… Actionable Deliverables: Detailed penetration test reports with executive summaries, risk severity classification (Critical/High/Medium/Low), CVSS scoring, proof of concept (PoC) with screenshots and logs, clear remediation recommendations, and impact analysis โ˜… Comprehensive Manual Testing: Complete hands-on security assessment (not automated scans) with immediate notification of high-impact exploitable issues โ˜… Customized Approach: Tailored testing for compliance needs (HECVAT, HIPAA, FERPA, Amazon SP-API,GDPR ,SOC2 ,ISO27001 ,PCIDSS), third-party security reviews, or proactive security hardening โ˜… Clear Communication: Developer-friendly reports and direct collaboration with engineering teams and non-security stakeholders โ˜… Timely Delivery: Comprehensive reports delivered on time without compromising quality โ˜… Unlimited Retesting: Vulnerability retest and fix validation included โ˜… Critical Bug Discovery: Proven ability to identify attack chains often missed by automated pentests My Track Record: โœ… Top-rated in information security and IT compliance โœ… Saved clients tens of thousands by identifying critical vulnerabilities before attackers โœ… Ranked Top 50 at multiple bug bounty programs โœ… Multiple CVE discoveries and responsible disclosures โœ… Professional certifications: OSCP, CISSP, CEH, CRTP โœ… Experience across SaaS, healthcare, EdTech, e-commerce, fintech, and enterprise โœ… Supporting all time zones for immediate-start and ongoing engagements Report Deliverables Include: โ–บ Executive Summary & Attestation Letter (for compliance documentation) โ–บ Assessment Methodology & Scope โ–บ Risk Severity Classification with CVSS scores โ–บ Detailed Findings: CVSS score, technical description, proof of exploitation (screenshots, request samples, logs), reproduction steps, impact analysis, and fix-ready remediation recommendations โ–บ Retest Report: Multiple validation rounds included My Expertise: โ˜… Web Application Penetration Testing (OWASP Top 10) โ˜… API Security Testing (REST, GraphQL, OWASP API Top 10) โ˜… Cloud Security Assessment (AWS, Azure - IAM, containers, serverless) โ˜… Mobile Application Penetration Testing (iOS, Android) โ˜… AI/LLM Security Testing โ˜… Internal Active Directory and External Network Penetration Testing โ˜… Vulnerability Assessment and Penetration Testing (VAPT) โ˜… Backend API and Microservices Security โ˜… Thick Client Penetration Testing โ˜… Security Audits for SaaS, Healthcare, EdTech, E-commerce โ˜… Third-Party Security Reviews and Compliance Testing โ˜… Production Environment Security Assessment โ˜… OSINT Assessment Sound like a fit? ๐ŸŸข Press '...' button and then 'Send Message' button in the top right-hand corner

  • Penetration Testing
  • Information Security
  • Vulnerability Assessment
  • Security Analysis
  • Network Security
  • Application Security
  • API Testing
  • Mobile App Testing
  • Web App Penetration Testing
  • Red Team Assessment
  • OWASP
  • Ethical Hacking
  • Security Assessment & Testing
  • Cybersecurity Management

How it works

Post a job for free Post a job

Tell us what you need. Create your own job post or generate one with AI then filter talent matches.

Hire top talent fast

Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.

Collaborate easily

Use Upwork to chat or video call, share files, and track project progress right from the app.

Payment simplified

Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.

Don't just take our word for it

How do I hire a WebApp Pentester in India on Upwork?

You can hire a WebApp Pentester in India on Upwork in four simple steps:

  • Create a job post tailored to your WebApp Pentester project scope. We'll walk you through the process step by step.
  • Browse top WebApp Pentester talent on Upwork and invite them to your project.
  • Once the proposals start flowing in, create a shortlist of top WebApp Pentester profiles and interview.
  • Hire the right WebApp Pentester for your project from Upwork, the world's largest work marketplace.

At Upwork, we believe talent staffing should be easy.

How much does it cost to hire a WebApp Pentester?

Rates charged by WebApp Pentesters on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.

Why hire a WebApp Pentester in India on Upwork?

As the world's work marketplace, we connect highly-skilled freelance WebApp Pentesters and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream WebApp Pentester team you need to succeed.

Can I hire a WebApp Pentester in India within 24 hours on Upwork?

Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive WebApp Pentester proposals within 24 hours of posting a job description.