Hire the Best Security Consultants

Clients rate our Security Consultants
Rating is 4.7 out of 5.
4.7/5
Based on 463 client reviews
John M.

Bengaluru, India

$34/hr
5.0
48 jobs

๐Ÿ”ข As an Upwork Top 1% Expert Vetted ๐Ÿ‘‘ OSCP+, Certified Ethical Hacker and an Experienced Penetration Tester with 10+ years of experience Penetration Testing Web SaaS and Mobile based applications and networks, every flaw tells a story; I write the ending and specialize in helping my clients strengthen their cybersecurity defenses. An average Cybersecurity Incident in your business can you cost you anywhere between $120,000+ to $1.24+ million and even a 10%+ reduction in risk can save your business nearly $124,000+ and hiring a full time in-house team can cost you $100,000+ per employee per year. That is why you need an expert like me to protect your business and reduce your business risk. What makes me stand out from other freelancers is the fact that I am also a Cybersecurity Architect, capable of architecting solutions to enhance the security of your organisation and preserving the security and integrity of your data. I have always been passionate about solving technical problems for my clients through Pen Testing and I don't rest till I get to the root of the problem and solve it. What I can offer? I can help you secure your business by providing the following services: โœ… Web/Mobile Application Penetration Testing, โœ… Secure Source Code Analysis, โœ… Network Penetration Testing, โœ… Secure Architecture Review, โœ… API Security Testing, ย ย  โœ… SOC 2, ISO 27001, PCI DSS, AMAZON SP and Compliance-Oriented Penetration Test Reports โœ… Secure Code Review, โœ… CASA Assessment, โœ… Red Team Assessment, โœ… Phishing Simulations & Assessment. Why Choose Me? ๐Ÿง‘๐Ÿผโ€๐Ÿ’ผ Client-Centric Approach: Your security is my top priority. I work closely with your team to understand your objectives and deliver tailored services that align with your business goals. Trust and transparency are the cornerstones of my practice, and I am committed to helping you navigate the complex landscape of cybersecurity with confidence and achieve compliance. ๐Ÿ“ Comprehensive Security Assessments: I conduct detailed SOC Type 2 / ISO compliant evaluations to identify vulnerabilities in your network, applications, and infrastructure. โœ‚๏ธ Tailored Solutions: Every organization is unique. I customize my approach to meet your specific security needs and industry standards. ๐ŸŽฌ Actionable Recommendations: Post-assessment, I provide clear, concise, and practical remediation steps to address identified vulnerabilities. ๐Ÿ” Ongoing Support: Cybersecurity is an ongoing process. I offer continuous support and re-assessment to ensure your defenses remain robust against evolving threats ๐ŸŒ Holistic Approach: I don't just patch vulnerabilities; I architect comprehensive security solutions that align with business goals. My focus extends beyond the technical to encompass risk management and organizational resilience. ๐Ÿ—จ๏ธ Collaborative Communicator: I bridge the gap between technical jargon and business language, fostering understanding across teams. Effective communication is key to successful security implementation. ๐Ÿซ Continuous Learning: The threat landscape evolves, and so do I. Whether it's a new attack vector or an emerging technology, count me in. Learning is my superpower. ๐Ÿ™‹โ€โ™‚๏ธ Key Skills: โœ”๏ธ Penetration Testing & Vulnerability Assessment: I thrive on dissecting systems, identifying weaknesses, and recommending robust solutions. Armed with tools like Kali Linux, Metasploit, Nmap, and Wireshark, I delve into web applications, networks, and APIs. But here's the twistโ€”I don't stop at discovery; I offer a free retest after remediation to ensure vulnerabilities stay sealed. โœ”๏ธ Network Security: I've designed and implemented secure network architectures, ensuring data confidentiality, integrity, and availability. Firewalls, intrusion detection systems, and VPNsโ€”my toolkit covers it all. โœ”๏ธ Cloud Security: Proficient in securing cloud environments especially Amazon Web Services (AWS) & Oracle Cloud Infrastructure (OCI). I stress-test cloud deployments ensuring they withstand real-world attacks. โœ”๏ธ Secure Coding Practices: I advocate for secure coding principles using tools like SonarQube and collaborate with development teams to build resilient applications. Prevention beats cure, every time. โ›๏ธTools I Use โ˜‘๏ธ Penetration Testing: Nmap, Metasploit, Burp Suite Professional, Wireshark, SQLmap, Kali Linux โ˜‘๏ธ Programming & Scripting Skills: Python, Bash, PowerShell, JavaScript, Java and C# โ˜‘๏ธ Security Frameworks & Standards: OWASP, NIST, CASA, CIA Triad, PCI-DSS ๐Ÿซฑ๐Ÿฝโ€๐Ÿซฒ๐Ÿฝ Let's Connect: Ready to enhance your business/organization's security? Let's chat! Reach out to me here on Upwork, and let's build a safer digital future together. ๐ŸŸข Press '...' button and then โ€˜Send Messageโ€™ button in the top right-hand corner โœ‰๏ธ ๐Ÿšซ No hacking service - I do not provide any hacking services, and I will not engage in any activities that involve gaining unauthorized access to any accounts, systems, or social media platforms. Requests for such services will be declined.

  • Vulnerability Assessment
  • Penetration Testing
  • Network Penetration Testing
  • Security Testing
  • Security Assessment & Testing
  • Information Security
  • Application Security
  • Web Application Security
  • Network Security
  • System Security
  • Web App Penetration Testing
  • Website Security
  • Black Box Testing
  • OWASP
  • Risk Assessment
Travis N.

Palm Valley, Florida

$85/hr
4.4
13 jobs

I'm a Cloud Engineering and DevOps Consultant who specializes in security. With 10+ years of experience across Fortune 100 enterprises, startups, healthcare, and SMBs, I build cloud infrastructure and CI/CD pipelines that are secure by design โ€” not bolted on after an audit fails. If you need someone to architect your AWS or GCP environment, automate deployments with Terraform, and make sure the whole stack holds up to HIPAA, SOC 2, or PCI scrutiny, that's exactly what I do. My Core Areas of Expertise: - Secure Cloud Architecture (AWS, GCP, Azure): Designing production cloud environments with security baked in, hardened VPCs, multi-account structures, least-privilege IAM, KMS, AWS WAF, GCP Security Command Center, and guardrails that scale with the business. - Infrastructure as Code: Terraform and CloudFormation modules with built-in security controls, policy-as-code (OPA, Sentinel, Checkov), and drift detection. Reusable, peer-reviewed, and CI-tested. - Secure CI/CD Pipelines: GitHub Actions, Azure DevOps, GitLab CI, and AWS CodePipeline with integrated SAST, SCA, secret scanning, and container image scanning. Pipelines that ship fast and safely. - Containers & Kubernetes Security: Docker, ECS, EKS, GKE, image hardening, runtime security, network policies, and admission controls. - DevSecOps & Compliance Automation: Automating controls for HIPAA, SOC 2 Type II, PCI DSS 4.0.1, and HITRUST. I've taken multiple organizations through audits with zero findings by making compliance a build artifact, not a quarterly fire drill. - Zero Trust & Network Security: Identity-based micro-segmentation, Cloudflare deployments, site-to-site VPNs, and secure networking for distributed teams. - Observability & Incident Response: CloudWatch, Datadog, security event monitoring, and runbooks that turn alerts into action. Why work with me? Most consultants either build cloud infrastructure or audit it. I do both, which means the environments I deliver are production-ready and audit-ready on day one. From greenfield AWS builds to debugging deployment issues on AI-assisted web apps, my goal is to leave your stack automated, secure, and easy for your team to own going forward. Let's connect to discuss how we can modernize your cloud, automate your deployments, and keep your data locked down.

  • Vulnerability Assessment
  • Google Cloud Platform
  • System Administration
  • Cybersecurity Management
  • DevOps
  • CI/CD
  • PCI DSS
  • SaaS
  • System Security
  • Management Skills
  • Real Time Stream Processing
  • Report
  • Report Writing
  • System Deployment
Nandy B.

Lehigh County, Pennsylvania

$85/hr
5.0
280 jobs

๐Ÿ—ฝ U.S. and ๐Ÿ Canada -only clients โ˜‘๏ธ Upwork Expert-Vetted ๐ŸŒŸ | 100% Job Success โœ… | 10,000+ hours ๐Ÿ’ป on 200+ projects Hi there! ๐Ÿ‘‹ Iโ€™m an Upwork veteran with over 10,000 hours delivered, 200+ successful projects, and $1M+ earned helping U.S. companies secure and scale their cloud and hybrid environments. โ˜๏ธ I specialize in Azure, Microsoft 365, and security-focused systems โ€” delivering: โ€ข Secure infrastructure using Zero Trust, IaC (Terraform/Bicep), and DevSecOps pipelines โ€ข Incident response, forensics, and breach containment across regulated industries โ€ข Compliance-ready solutions aligned to SOC 2, HIPAA, ISO 27001, and NIST 800-53 As a certified consultant, I work directly with technical teams to deliver secure cloud transformation, implement controls, and respond to threats โ€” fast. I also collaborate with Microsoftโ€™s internal dev teams, giving me early-access insights and practical fixes 3โ€“4 release cycles ahead of public rollout. Why Choose Me? โœ… $1M+ in security projects delivered across healthcare, fintech, crypto, and gov sectors ๐Ÿ” Architected Azure landing zones, GitOps pipelines, and zero trust cloud environments ๐Ÿšจ Led incident response and forensic investigations for Fortune 500 and defense clients ๐Ÿ“Š Built compliance workflows and policy-as-code enforcement for audit success ๐Ÿช™ Secured crypto CI/CD pipelines and smart contract environments with GitHub, Checkov, GHAS ๐Ÿง  Career Highlights: โ–ช Delivered security modernization and audit readiness for global government contractors and Fortune 500 companies โ–ช Led compliance remediation and data protection initiatives across healthcare, fintech, and public sector clients โ–ช Migrated global users to Microsoft 365 with security-first design โ€” Exchange, Purview, Intune, Defender โ–ช Built hybrid identity strategies (Entra ID, ADFS, GoDaddy 365, Azure AD B2C, custom policy support) โ–ช Managed VMware-to-Azure hardening with conditional access, audit enforcement, and security baselines ๐Ÿ”ง Solutions I Deliver: โ€ข Azure Infra Security: Terraform, Bicep, Azure Policy, RBAC, Defender for Cloud โ€ข DevSecOps: GitHub Actions, tfsec, Checkov, Trivy, GHAS, pipeline reviews โ€ข Microsoft 365 Hardening: Defender, Purview, Compliance Center, Intune, Exchange โ€ข Compliance & Audits: SOC 2, ISO 27001, HIPAA, GDPR, NIST, CIS Benchmarks โ€ข Incident Response & Forensics: Malware analysis, reverse engineering, breach recovery โ€ข Crypto Security: CI/CD for smart contracts, wallet infra hardening, Web3 audits โ€ข Reverse-engineered malware to identify attack vectors and harden systems post-breach โ€ข Hardened Microsoft Exchange Online and Defender for Email in phishing-prone orgs โ€ข Integrated Azure Sentinel analytics with dashboards for cross-cloud visibility ๐Ÿค Retainer & Advisory Support: โ€ข Ongoing guidance for CISOs, security architects, and compliance teams โ€ข Monthly retainers for SOC 2 evidence collection, security tool reviews, and policy automation โ€ข Rapid-response engagements for forensics, malware recovery, and breach root cause analysis ๐Ÿงฐ Platforms & Tools: โ€ข Azure, Microsoft 365, Azure Sentinel, Microsoft Defender (all modules), Intune โ€ข Terraform, Bicep, GitHub, Azure DevOps, GitOps, GHAS โ€ข Splunk, FTK, EnCase, Wireshark, Autopsy, Cisco ASA/Firepower โ€ข Checkov, Trivy, Aqua Security, smart contract security tooling โ€ข Compliance: SOC 2, HIPAA, ISO 27001, CIS, NIST, GDPR ๐Ÿ“… Letโ€™s set up a free 30-minute consultation to explore how I can help you with security transformation, compliance readiness, or urgent recovery โ€” no fluff, just fast, proven results. I bring the calm in chaos โ€” whether you're planning secure growth or cleaning up after a breach, Iโ€™ll steady the course and deliver results. ๐Ÿ“Œ Helped a fintech client pass SOC 2 in under 60 days ๐Ÿ“Œ Responded to ransomware, restored 95% of systems in 48 hours ๐Ÿ“Œ Hardened crypto wallet infra securing $100M+ in assets Thanks again for stopping by. You can invite me to your job post or simply send a message to arrange a quick discovery call โ€” I respond fast, and weโ€™ll keep everything inside Upwork. โ€” Nandy Bo ๐Ÿ—ฃ๏ธโ ๐™„๐™ฉ ๐™๐™–๐™จ ๐™—๐™š๐™š๐™ฃ ๐™– ๐™ฅ๐™ก๐™š๐™–๐™จ๐™ช๐™ง๐™š ๐™ฉ๐™ค ๐™ฌ๐™ค๐™ง๐™  ๐™ฌ๐™ž๐™ฉ๐™ ๐™‰๐™–๐™ฃ๐™™๐™ฎ ๐™™๐™ช๐™ง๐™ž๐™ฃ๐™œ ๐™ฉ๐™๐™š ๐™ฉ๐™ง๐™–๐™ฃ๐™จ๐™ž๐™ฉ๐™ž๐™ค๐™ฃ ๐™ค๐™› ๐˜พ๐™–๐™ก๐™ก๐™˜๐™ค๐™ข. ๐™‰๐™–๐™ฃ๐™™๐™ฎ ๐™ž๐™จ ๐™ซ๐™š๐™ง๐™ฎ ๐™œ๐™š๐™ฃ๐™ช๐™ž๐™ฃ๐™š, ๐™๐™ค๐™ฃ๐™š๐™จ๐™ฉ ๐™–๐™ฃ๐™™ ๐™๐™š๐™ก๐™ฅ๐™›๐™ช๐™ก ๐™ž๐™ฃ ๐™ฃ๐™–๐™ฉ๐™ช๐™ง๐™š. ๐™ƒ๐™š ๐™–๐™ก๐™จ๐™ค ๐™๐™–๐™จ ๐™– ๐™ซ๐™š๐™ง๐™ฎ ๐™ž๐™ฃ-๐™™๐™š๐™ฅ๐™ฉ๐™ ๐™ ๐™ฃ๐™ค๐™ฌ๐™ก๐™š๐™™๐™œ๐™š ๐™ค๐™› ๐™„๐™ ๐™ฌ๐™๐™ž๐™ก๐™š ๐™ข๐™–๐™ž๐™ฃ๐™ฉ๐™–๐™ž๐™ฃ๐™ž๐™ฃ๐™œ ๐™– ๐™ซ๐™š๐™ง๐™ฎ ๐™—๐™ง๐™ค๐™–๐™™ ๐™ฅ๐™ง๐™ค๐™—๐™ก๐™š๐™ข-๐™จ๐™ค๐™ก๐™ซ๐™ž๐™ฃ๐™œ ๐™ค๐™ช๐™ฉ๐™ก๐™ค๐™ค๐™ . ๐™๐™๐™š๐™จ๐™š ๐™›๐™š๐™–๐™ฉ๐™ช๐™ง๐™š๐™จ ๐™ข๐™–๐™ ๐™š ๐™๐™ž๐™ข ๐™ฃ๐™ค๐™ฉ ๐™ค๐™ฃ๐™ก๐™ฎ ๐™– ๐™ฅ๐™ก๐™š๐™–๐™จ๐™ช๐™ง๐™š ๐™ฉ๐™ค ๐™ฌ๐™ค๐™ง๐™  ๐™ฌ๐™ž๐™ฉ๐™ ๐™—๐™ช๐™ฉ ๐™–๐™ก๐™จ๐™ค ๐™ซ๐™š๐™ง๐™ฎ ๐™ž๐™ฃ๐™จ๐™ฅ๐™ž๐™ง๐™–๐™ฉ๐™ž๐™ค๐™ฃ๐™–๐™ก. โž โ€” ๐™…๐™ค๐™ง๐™™๐™ค๐™ฃ ๐˜ฝ๐™ž๐™ก๐™ก - ๐™ˆ๐™–๐™ฃ๐™–๐™œ๐™ž๐™ฃ๐™œ ๐˜ฟ๐™ž๐™ง๐™š๐™˜๐™ฉ๐™ค๐™ง - ๐˜พ๐™–๐™ก๐™ก๐™˜๐™ค๐™ข ๐™„๐™ฃ๐™ฉ๐™š๐™ง๐™ฃ๐™–๐™ฉ๐™ž๐™ค๐™ฃ๐™–๐™ก

  • Solution Architecture Consultation
  • Cloud Implementation
  • Information Security
  • Cloud Security
  • Microsoft Endpoint Manager
  • Risk Assessment
  • Cloud Engineering Consultation
  • Microsoft Azure
  • Office 365
  • Email Security
  • Microsoft Exchange Online
  • Digital Forensics
  • Incident Response Readiness Assessment
  • Information Security Audit
Muhammad R.

Islamabad, Pakistan

$40/hr
4.8
13 jobs

I break into systems for a living, then build the defenses that keep the next person out. Seven years, 60+ assessments, both sides of the fence. CPTS-certified penetration tester and security engineer. Head of Cybersecurity at AC Sรผppmayer GmbH in Germany, former Application Security Engineer at Tap Payments โ€” a regulated FinTech processing live payment traffic. Founder of Triox Cyber Security, delivering third-party security work for technology companies, FinTechs, and mid-market enterprises across Europe, the Gulf, and North America. Most security freelancers do offense or defense. I do both, in the same engagement, which means the detection logic I write is built from attacks I have actually run โ€” not from a vendor template. โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ OFFENSIVE SECURITY Web application and API penetration testing Mobile application assessment โ€” iOS and Android Cloud security review โ€” AWS, Azure, GCP Internal and external network penetration testing Active Directory attack path assessment Wireless assessment OWASP Top 10, OWASP MASVS, and PTES-aligned methodology Fully manual testing supported by tooling โ€” never an automated scan with a cover page. Every engagement delivers an executive summary written for leadership, CVSS-scored findings, complete reproduction steps, prioritized and developer-ready remediation guidance, and a free retest once fixes are in place. โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ SECURITY ENGINEERING & DEFENSE Splunk SIEM deployment, tuning, and detection engineering SOC build-out and MITRE ATT&CK detection coverage XDR deployment and configuration IDS/IPS, firewall, and WAF architecture and hardening Cloud and infrastructure hardening โ€” CIS benchmark alignment Honeypot and deception deployment Vulnerability management and secure SDLC programs Breaches are rarely missed for lack of logs. They are missed because nobody was watching the right ones. I make sure the right ones are watched, and that your team knows what to do when they fire. โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ TYPICAL ENGAGEMENTS Pre-launch penetration test on a web application or API External and internal network penetration test Mobile application security assessment Cloud configuration and IAM review Active Directory attack path assessment and hardening Splunk SIEM or SOC deployment from the ground up Infrastructure hardening and security architecture review Remediation support following a failed audit or third-party pentest Ongoing retainer โ€” quarterly testing with continuous detection tuning โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ HOW I WORK You work directly with the engineer performing the test. No sales layer, no junior handoff, no findings written by someone who never touched your environment. Scope and rules of engagement are agreed in writing before anything starts. Critical findings are reported the day they are found, not held for the final report. Retesting after remediation is included โ€” a finding is not closed until it is proven closed. Reports are written to survive an auditor, a client security questionnaire, and a developer's sprint planning, because in regulated FinTech they have to survive all three. โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ Years of delivery for technology, FinTech, and enterprise clients. Working comfortably across English, the German market, and Arabic-speaking clients in the GCC. NDA and formal contracting standard. If you have a compliance deadline, a customer demanding a pentest report, a product going live with unknown exposure, or a SOC producing noise instead of alerts โ€” send me your scope. I will tell you honestly whether I am the right fit, and if I am not, I will tell you that too.

  • Penetration Testing
  • Network Penetration Testing
  • Web App Penetration Testing
  • Ethical Hacking
  • Security Testing
  • Security Engineering
  • Website Security
  • Network Security
  • Digital Forensics
  • Cybersecurity Tool
  • Cybersecurity Management
  • Cybersecurity Monitoring
  • System Security
  • Application Security
  • PCI DSS
Elizabeth G.

Lagos, Nigeria

$15/hr
5.0
15 jobs

๐ŸŸข๐€๐•๐€๐ˆ๐‹๐€๐๐‹๐„ ๐“๐Ž ๐’๐“๐€๐‘๐“ ๐ˆ๐Œ๐Œ๐„๐ƒ๐ˆ๐€๐“๐„๐‹๐˜ Many coaches and course creation have valuable knowledge, strong offers, and great ideas, yet their Kajabi setup still feels incomplete. pages don't flow naturally, automation feel disconnected, course arears become overwhelming, and potential buyers lose confidence before they even reach checkout. In many cases, the problem is not the offer itโ€™s the experience surrounding it. I work with coaches, consultants, educators and digital entrepreneurs who need more than just a basic Kajabi setup. My focus is creating organized, conversion-focused systems that feel intentional, easy to navigate, and professionally structured for both the client and their audience. Kajabi can do a lot, but without proper structure, even a strong program can end up looking unfinished. I help clients build streamlined sales funnels, polished landing pages, organized course arears, membership platforms, webnar pipelines, and automations that make sense while guiding visitors naturally toward taking action. Hereโ€™s what I help clients with: โœ” Kajabi Website Design โœ” Kajabi Sales Funnels & Pipelines โœ” Kajabi Landing Pages โœ” Kajabi Course Upload & Structuring โœ” Membership & Community Setup โœ” Email Automation & Sequences โœ” Checkout Pages & Offers โœ” Webinar Funnel Setup โœ” Canva-to-Kajabi Page Design โœ” Kajabi Migration & Redesign My approach is not just about making pages look good. I pay close attention to customer journey, mobile responsiveness, user experience, navigation flow, and backend organization so the entire platform feels smooth, professional, and easy to manage long after launch. A lot of course creators struggle with abandoned checkouts, confusing navigation, low engagement, disconnected automations, and funnels that simply do not convert the way they should. These small issues quietly affect trust and sales. Thatโ€™s why I focus on creating Kajabi systems that are clean, strategic, scalable, and built around how real users actually interact with online programs. To get started, send me an invite or message here on Upwork with a brief overview of your project. If you already have a clear idea, we can also schedule a quick consultation to map out the best way to structure your Kajabi setup. Key Tools: Kajabi, Kajabi design, Virtual assistant kajabi, Kajabi website designer, Kajabi sales page, Kajabi website, kajabi deisgn, Kajabi specialist, kajabi sales page, kajabi landing page, kajabi website designer, kajabi website design, kajabi website builder, kajabi designer, kajabi web designer, kajabi sales funnel, kajabi va, kajabi course, kajabi.

  • Kajabi
  • Landing Page
  • Sales Funnel
  • Web Design
  • Course Creation
  • Membership Plugin
  • Email Marketing
  • Marketing Automation
  • Zapier
  • HighLevel
  • ClickFunnels
  • Kartra
  • Leadpages
  • WordPress
  • Figma
  • Canva
  • Responsive Design
  • HTML
  • CSS
  • Website Migration
Ahmad J.

Lahore Cantt, Pakistan

$45/hr
5.0
42 jobs

Certified Cybersecurity & GRC Specialist for IT & OT/ICS Environments Building a company is hard enough โ€” security and compliance shouldnโ€™t slow you down. ๐Ÿš€I help industrial operators, critical infrastructure providers, and high-growth technology companies secure their environments and meet regulatory requirements โ€” without slowing down operations or product delivery. With a decade of experience spanning both IT and OT domains, including a background at Siemens and IEC 62443 Certified Expert credentials, I bring rare cross-domain depth: I understand SCADA, PLCs, and industrial protocols as well as I understand ISMS frameworks, cloud security, and compliance audits. - Governance, Risk & Compliance ISO 27001 ISMS design, implementation, and certification support SOC 2, GDPR, NIS2, and HIPAA readiness Risk assessments, gap analysis, and internal audits Security policies and procedures built for operational reality, not shelfware Security questionnaire and vendor assessment management (RFPs, enterprise due diligence) - OT / ICS / SCADA Security IEC 62443-aligned security programs for industrial control environments Purdue Model network architecture review and segmentation design OT asset inventory, network traffic analysis, and vulnerability assessment SCADA/HMI access control and configuration review OT/IT convergence risk assessments and gap analysis Vendor and protocol-specific security reviews (DNP3, Modbus, SNMP, and others) Security roadmaps tailored to plant, utility, and energy environments Cloud & Application Security AWS, Azure, and GCP security configuration and hardening Vulnerability Assessments and Penetration Testing (VAPT) Practical remediation planning that prioritizes business-critical risk Why Work With Me Most consultants specialize in IT compliance or OT security โ€” rarely both. I bridge that gap, which matters increasingly as industrial environments converge with cloud and enterprise IT. Clients get a single point of accountability across their full risk surface, from the plant floor to the cloud.๐Ÿ† What I Do for You โœ”๏ธImplement ISO 27001-compliant Information Security Management Systems (ISMS) โœ”๏ธPrepare you for SOC 2, ISO 27001, GDPR, HIPAA, and other regulatory requirements โœ”๏ธConduct risk assessments, gap analysis, and internal audits โœ”๏ธDevelop practical, startup-friendly security policies and procedures โœ”๏ธHandle security questionnaires (RFPs, enterprise clients, vendor assessments) โœ”๏ธSecure cloud environments (AWS, Azure, GCP) โœ”๏ธPerform Vulnerability Assessments and Penetration Testing (VAPT) โœ”๏ธIdentify, prioritize, and fix security gaps without slowing your team โœ”๏ธDesigned for High-Growth Companies ๐Ÿ‘จโ€๐Ÿ’ผI understand the challenges of scaling businesses: - Limited time and resources - Pressure to close enterprise deals - Increasing compliance demands - Need for fast, practical security solutions ๐Ÿ” Thatโ€™s why I focus on lightweight, scalable, and business-aligned security programs โ€” not unnecessary complexity. ๐Ÿ›  TECH STACK Governance: Vanta, Drata, Sprinto, Secureframe. Cloud: AWS, Azure, Google Cloud (GCP). ๐Ÿ“Š SECURITY AND COMPLIANCE FRAMWORKS SOC 2 | ISO 27001 | ISO 27017 | ISO 27018 | ISO 42001 | NIST 800-53 | NIST 800-171 | NIST CSF | NIST AI RMF | FedRAMP | CMMC | CMMI | PCI-DSS | HIPAA | HITRUST CSF | GDPR | TISAX | NERC | FFIEC | C5 | ENISA | CIS CSAT | IRAP | PIPEDA | TX-RAMP | StateRAMP | AZ-RAMP | NY DFS 23 NYCRR Part 500 | EU AI Act HOW I WORK Think of me as your outsourced security partner. You build, sell, and grow your business โ€” I handle your security, compliance, and risk management end-to-end. No jargon. No over-engineering. Just practical security that helps you move faster and win trust. ๐—œ๐—ณ ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ถ๐˜€ ๐—ฏ๐—น๐—ผ๐—ฐ๐—ธ๐—ถ๐—ป๐—ด ๐—ด๐—ฟ๐—ผ๐˜„๐˜๐—ต, ๐—บ๐—ฒ๐˜€๐˜€๐—ฎ๐—ด๐—ฒ ๐—บ๐—ฒ. ๐—œ'๐—น๐—น ๐˜๐—ฎ๐—ธ๐—ฒ ๐—ถ๐˜ ๐—ณ๐—ฟ๐—ผ๐—บ ๐—ต๐—ฒ๐—ฟ๐—ฒ. ๐—•๐—ผ๐—ผ๐—ธ ๐—ฎ ๐—ณ๐—ฟ๐—ฒ๐—ฒ ๐Ÿฒ๐Ÿฌ-๐—บ๐—ถ๐—ป๐˜‚๐˜๐—ฒ ๐—ฎ๐—ฑ๐˜ƒ๐—ถ๐˜€๐—ผ๐—ฟ๐˜† ๐—ฐ๐—ฎ๐—น๐—น. ๐—œ'๐—น๐—น ๐—บ๐—ฎ๐—ฝ ๐˜๐—ต๐—ฒ ๐—ณ๐—ฎ๐˜€๐˜๐—ฒ๐˜€๐˜ ๐—ฝ๐—ฎ๐˜๐—ต ๐—ณ๐—ผ๐—ฟ๐˜„๐—ฎ๐—ฟ๐—ฑ.

  • ISO 27001
  • Information Security Consultation
  • Security Policies & Procedures Documentation
  • Security Assessment & Testing
  • Incident Response Plan
  • Security Testing
  • Information Security
  • Risk Assessment
  • Network Penetration Testing
  • Technical Writing
  • IT Compliance Audit
  • Web App Penetration Testing
  • NIST SP 800-53
  • Ethical Hacking
  • GDPR

How it works

Post a job for freePost a job

Tell us what you need. Create your own job post or generate one with AI then filter talent matches.

Hire top talent fast

Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.

Collaborate easily

Use Upwork to chat or video call, share files, and track project progress right from the app.

Payment simplified

Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.

Don't just take our word for it

How do I hire a Security Consultant on Upwork?

You can hire a Security Consultant on Upwork in four simple steps:

  • Create a job post tailored to your Security Consultant project scope. Weโ€™ll walk you through the process step by step.
  • Browse top Security Consultant talent on Upwork and invite them to your project.
  • Once the proposals start flowing in, create a shortlist of top Security Consultant profiles and interview.
  • Hire the right Security Consultant for your project from Upwork, the worldโ€™s largest work marketplace.

At Upwork, we believe talent staffing should be easy.

How much does it cost to hire a Security Consultant?

Rates charged by Security Consultants on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.

Why hire a Security Consultant on Upwork?

As the worldโ€™s work marketplace, we connect highly-skilled freelance Security Consultants and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream Security Consultant team you need to succeed.

Can I hire a Security Consultant within 24 hours on Upwork?

Depending on availability and the quality of your job post, itโ€™s entirely possible to sign up for Upwork and receive Security Consultant proposals within 24 hours of posting a job description.