- Fixed price
- Expert
- Est. budget: $300.00
Job Title: Urgent: Experienced SOC L2 Analyst or SOC Hiring Manager Needed for Student Career Session We are urgently seeking an experienced SOC Level 2 Analyst, Senior SOC Analyst, or current/former SOC hiring manager to lead a live career and industry discussion for a small group of students who recently completed a SOC Level 2 bootcamp. The session will be conducted through Zoom and will last approximately 90 minutes. The audience will consist of seven or fewer students, allowing time for direct questions and meaningful discussion. Topics to Cover The speaker should provide practical, honest insight into: What SOC analysts actually do during a typical shift The responsibilities of Tier 1 and Tier 2 SOC analysts The technical and professional skills needed to succeed in a SOC or MSSP The skills candidates must demonstrate during a SOC analyst interview How candidates should prepare for technical and behavioral interview questions What employers expect to see on a SOC analyst résumé Common résumé mistakes that prevent candidates from receiving interviews Common interview mistakes that cause candidates to be rejected Why many entry-level candidates struggle to land their first SOC analyst position Practical steps students can take to become stronger job candidates The session should also include time for student questions and answers. Preferred Qualifications The ideal speaker should have one or more of the following: Current experience as a SOC Level 2 Analyst, Senior SOC Analyst, SOC Lead, or SOC Manager Experience working in an enterprise SOC or Managed Security Service Provider (MSSP) Current or former responsibility for interviewing or hiring SOC analysts Strong knowledge of SOC investigations, incident response, SIEM, EDR, threat intelligence, ticketing, and escalation procedures Experience reviewing cybersecurity résumés and conducting technical interviews Strong communication skills and the ability to explain concepts clearly to early-career professionals Experience with tools such as Microsoft Sentinel, CrowdStrike Falcon, Microsoft Defender XDR, Splunk, Jira, or similar security platforms is highly preferred. Engagement Details Format: Live Zoom session Duration: 1 hour and 30 minutes Audience: Seven or fewer SOC Level 2 bootcamp graduates Project type: One-time speaking engagement Event Schedule: 8/14/2026 Compensation: Please submit your proposed fixed rate for the 90-minute session
- Fixed price
- Intermediate
- Est. budget: $24,000.00
We are looking consultant with Google Spaces and related information security expertise to support clients using our processes.
- Hourly: $20.00 - $65.00
- Intermediate
- Est. time: Less than 1 month, Less than 30 hrs/week
Manual Penetration Test for EdTech SaaS Web App (Required for University Vendor Approval) Cybersecurity & Compliance / Penetration Testing One-time project Estimated Budget:** Fixed price - $3,000-$5,000 (open to discussing scope adjustments to fit budget) We're a small software company (Drawbridge Inc.) that builds Eli Review, a peer-review writing platform used by students and instructors in higher education. We need a **manual penetration test** of our web application and API, primarily to satisfy a university customer's third-party vendor security review. We are **not** looking for an automated vulnerability scan with a report attached — we need a tester who manually assesses business logic, access control between user roles, and authentication/session handling, and can produce a report suitable for submission to a university information security office. What We Need Tested - Web application (single production or staging environment — we'll provide the URL and test accounts) - REST API supporting the application - Role-based access control: our app has student, instructor, and admin roles — we specifically want testing of whether one role can improperly access another's data (e.g., a student viewing another student's peer review submissions, or cross-course data leakage) - Authentication and session management (login flow, password reset, session handling) - LTI/LMS integration points (we'll clarify exact scope with finalists) What We'll Provide - Access to a staging environment (preferred) with test accounts across all user roles - Basic architecture documentation - A point of contact for questions during testing Deliverables - Full technical findings report (scope, methodology, findings with severity ratings, proof-of-concept evidence, remediation recommendations) - **An executive summary of findings** suitable for sharing with a university vendor risk review team (this is a hard requirement - we need something we can submit externally, not just an internal-only report) - Availability for a brief call to walk through findings Ideal Candidate - Demonstrated experience with **manual** web application penetration testing (not just automated scanning) — please reference specific methodologies or tools you use for testing business logic and access control - Relevant certifications preferred (OSCP, CREST, GWAPT, or similar) - please list any you hold - Experience with SaaS/multi-tenant applications a plus - Experience producing reports for higher-education or compliance contexts (HECVAT, SOC 2 support, FERPA-relevant environments) is a strong plus given our use case, but not required - Comfortable working within a fixed timeline and fixed-scope budget Timeline Looking to start as soon as possible and have a completed report within 2 weeks of kickoff. To Apply, Please Include 1. A brief description of your manual testing methodology (what you do beyond automated scanning) 2. 1-2 examples of past web app/API pentest engagements (sanitized/redacted is fine) - ideally similar in scope to a single web app + API 3. Relevant certifications 4. A proposed fixed price and estimated turnaround time for the scope described above 5. Whether you're able to provide an executive summary format suitable for external/university submission
- Hourly: $45.00 - $50.00
- Expert
- Est. time: More than 6 months, Less than 30 hrs/week
This is not a full-time position. Workload will vary depending on client projects. Required Qualifications Minimum 10 years of hands-on IT experience Must reside in the United States Previous MSP or IT consulting experience preferred Excellent verbal and written English communication Ability to communicate directly with business clients Strong troubleshooting and problem-solving skills Able to work independently with minimal supervision Strong documentation skills Professional, dependable, and responsive. Microsoft Microsoft 365 Administration Microsoft 365 Business Premium Exchange Online SharePoint Online OneDrive Microsoft Teams Azure Microsoft Entra ID (Azure AD) Microsoft Intune Conditional Access Multi-Factor Authentication (MFA) Microsoft Defender. Windows Server 2016/2019/2022 Active Directory Group Policy DNS DHCP Hyper-V Remote Desktop Services Cybersecurity Endpoint Security Microsoft Security Best Practices Security Hardening Vulnerability Remediation Backup & Disaster Recovery Incident Response Email Security Phishing Protection Cloud & Backup Azure Microsoft 365 Backup OneDrive Backup SharePoint Backup Disaster Recovery Planning Remote Management NinjaOne (Preferred) Bitdefender GravityZone (Preferred) ConnectWise (Plus) Datto (Plus)
- Hourly: $25.00 - $50.00
- Intermediate
- Est. time: 1 to 3 months, Hours to be determined
We are seeking an experienced MSP engineer or technical consultant to support the integration of newly acquired managed service providers into our operating environment. This is a project-based contract role with engagements typically lasting 60 to 90 days. Successful candidates may be invited to participate in future acquisition integration projects on an ongoing basis. About the Role Your primary responsibility will be to review, validate, and standardize technical documentation from acquired MSPs and client environments. You will work closely with our internal Integration and Service Operations teams to bring documentation, asset records, network diagrams, vendor information, and operational procedures into alignment with our standards. This role is ideal for a former MSP Systems Administrator, Senior Engineer, Service Manager, or Technical Consultant who enjoys discovery, documentation, and process improvement. Responsibilities • Review existing MSP documentation for completeness and accuracy • Conduct interviews with technical staff and key stakeholders to gather missing information • Audit Microsoft 365, Azure, networking, security, backup, and endpoint management environments • Update and standardize documentation according to established SOPs and templates • Create or update network diagrams, asset inventories, vendor records, credential records, and support procedures • Identify documentation gaps, technical debt, and operational risks • Produce final documentation packages and handoff materials for operational teams • Participate in integration meetings and status updates as needed Required Experience • 2+ years working within a Managed Service Provider (MSP) • Strong understanding of Microsoft 365 and Azure environments • Experience documenting networks, systems, and operational procedures • Ability to work independently with minimal supervision • Strong written communication and organizational skills Preferred Experience • ITGlue, Liongard, ConnectWise Manage, Autotask, Datto RMM and similar platforms • MSP acquisition or integration experience • Network infrastructure documentation • Cybersecurity, data backup, and compliance documentation • Multi-site client environments Engagement Details • Contract / project-based • Typical engagements range from 60 to 90 days • Flexible hours • Remote work • U.S.-based preferred, but highly qualified international candidates will be considered • Potential for recurring opportunities throughout the year Please provide: - Summary of your MSP experience - Documentation platforms you have used (IT Glue, Hudu, etc.) - Examples of documentation projects you have completed - Experience supporting MSP mergers, acquisitions, or large clients
- Hourly: $50.00 - $75.00
- Intermediate
- Est. time: 1 to 3 months, Less than 30 hrs/week
About us: Luxe Intelligence is a Baltimore based AI consulting firm. We design and deliver custom AI agent systems for business clients, including regulated industries, with a growing security and government-adjacent practice. We design the system and own the client relationship. You build to spec. The kind of work: Real examples of project types on our roadmap: - Data matching and compliance checking agents that cross-reference large lists (10,000+ rows) with no shared ID, using fuzzy name matching, confidence scoring, and human review flags - Research agents that pull from defined sources and produce structured memos with citations, and say "unverified" instead of guessing - Workflow automations across webhooks, spreadsheets, CRMs, Slack, and email - Read and write-back integrations with systems of record like Salesforce - Deployments inside client cloud environments with audit logging and security review support Must haves: - Strong Python, including pandas and API work - Hands-on experience with LLM APIs (Anthropic, OpenAI): prompt design, structured outputs, cost control - Fuzzy matching or entity resolution experience on real data - Cloud deployment on AWS, Azure, or GCP - Security-minded engineering as a habit, not an afterthought: secrets management, least-privilege access, encryption in transit and at rest, audit trails, human-in-the-loop review steps - Clear written English and documented handoffs Nice to have: - A real cybersecurity background: security engineering, compliance frameworks (SOC 2, NIST, FedRAMP awareness), or secure deployment in regulated environments - US citizenship with eligibility for a government security clearance, or an active clearance, is a plus and worth mentioning - Make.com or similar automation platforms - Salesforce API - Experience answering client security questionnaires How we work: Fixed-price milestones scoped from agreed hour estimates, paid on delivery and approval. NDA signed before any project details are shared. No client contact; all communication runs through Luxe. Some overlap with US Eastern hours. Every engagement starts with one small paid test milestone. Strong performance can grow into a larger ongoing role. To apply, answer these four things, and start your reply with the word CHARCOAL so we know you read this far: 1. Describe a fuzzy matching or entity resolution project you built. How big was the data, and how did you score confidence? 2. Describe an LLM-powered system you deployed into someone else's environment. What broke, and how did you fix it? 3. Estimate this: two lists, about 10,000 rows and 2,000 rows, no shared ID. Need matches, confidence scores, and a monthly flagged-items report. Roughly how many hours, broken down however makes sense to you? 4. Your hourly rate, your weekly available hours, and any security or clearance background.
- Hourly
- Expert
- Est. time: More than 6 months, 30+ hrs/week
About Us We are a cloud consulting and technology transformation company that helps organizations modernize applications, data platforms, analytics, and AI solutions on AWS. Our team works with customers across multiple industries to design, build, and operate secure cloud environments, enterprise data platforms, and AI-powered solutions. As we continue expanding into regulated industries, we are investing in a comprehensive HIPAA compliance program to support healthcare customers while maintaining strong security, governance, and operational standards. We are looking for an experienced consultant who has successfully guided technology organizations through HIPAA readiness and can help establish a practical, scalable compliance program. About the Engagement This is a hands-on consulting engagement where you will assess our current environment, identify compliance gaps, and lead the implementation of the processes, documentation, and security controls required to support HIPAA-regulated customers. You will work closely with company leadership, engineering, cloud, operations, and HR teams to build a compliance program that becomes part of our day-to-day operations rather than a one-time documentation exercise. What You'll Do • Assess how our services, internal operations, and cloud environments align with HIPAA requirements. • Identify areas where protected health information (PHI) could be created, received, accessed, maintained, or transmitted. • Conduct a comprehensive HIPAA Security Risk Analysis and develop a prioritized remediation roadmap. • Design practical governance, security, and operational processes that support long-term compliance. • Develop the policies, procedures, and documentation required for HIPAA readiness. • Review our cloud security architecture and recommend improvements aligned with HIPAA safeguards. • Establish processes for vendor management, Business Associate Agreements (BAAs), workforce training, and compliance monitoring. • Guide implementation efforts across technical and operational teams. • Provide executive-level recommendations and validate readiness once remediation activities are complete. What We're Looking For • Extensive experience leading HIPAA readiness or compliance programs for technology companies, SaaS providers, consulting firms, managed service providers, or Business Associates. • Strong understanding of the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. • Experience conducting HIPAA Security Risk Analyses and translating findings into practical implementation plans. • Knowledge of cloud security, governance, and modern infrastructure environments, preferably AWS. • Ability to work comfortably with both executive leadership and technical delivery teams. • Excellent communication and documentation skills. Preferred Experience • AWS cloud security and governance • Healthcare technology or digital health organizations • NIST Cybersecurity Framework and NIST guidance for implementing HIPAA security requirements • SOC 2 implementation or audit readiness • HITRUST familiarity • Certifications such as HCISPP, CISSP, CISM, CISA, CHPS, or similar Expected Deliverables By the end of the engagement, you should have delivered: • HIPAA applicability and scope assessment • HIPAA Security Risk Analysis • Compliance gap assessment • Prioritized remediation roadmap • HIPAA policy and procedure framework • Vendor and BAA management process • Workforce training recommendations • Compliance evidence repository structure • Executive readiness report with implementation recommendations Why Join This Project This is an opportunity to build a HIPAA compliance program from the ground up for a fast-growing cloud consulting organization. You'll work directly with leadership, influence company-wide security and governance practices, and establish a scalable framework that supports future healthcare customers.
- Hourly: $35.00 - $75.00
- Expert
- Est. time: Less than 1 month, Less than 30 hrs/week
The National Financial Educators Council is developing a course on protecting learner personal information, Personally Identifiable Information (PII), and sensitive financial information in financial education and coaching settings. The course focuses on practical privacy and safeguard issues that may occur before, during, and after instruction or coaching. Topics include learner forms, documents, uploads, emails, online tools, screen sharing, coaching notes, digital records, and situations where private information may be collected, displayed, stored, recorded, or shared. Purpose of the SME Engagement The SME will review the course for accuracy, clarity, completeness, and practical application related to PII, learner data protection, privacy risk, information handling, and safeguard procedures. The goal is to ensure the course reflects responsible information-handling practices and gives educators and coaches clear steps they can apply in real-world settings. Scope of Work The SME will review lessons, examples, scenarios, activities, assessments, checklists, forms, and safeguard procedures related to: PII definitions and risk categories. Highly Sensitive PII, Sensitive PII, Identifying Information, and Personal Financial Information. Learner information risks in classroom, workshop, webinar, online course, and one-on-one coaching settings. Digital exposure risks, including uploads, email attachments, shared folders, screen sharing, screenshots, recordings, transcripts, chat, AI summaries, and online tools. Use of redacted materials, prefilled sample-safe forms, private reflection, summaries, ranges, and approved secure systems. Data minimization, documentation of safeguard actions, and escalation when learner information is exposed or mishandled. The SME will: Identify inaccurate, unclear, incomplete, outdated, or misleading content. Confirm whether examples and scenarios reflect realistic risks faced by educators, coaches, schools, nonprofits, financial institutions, workplace programs, and community programs. Evaluate whether the course provides practical guidance for reducing learner information exposure. Review the course framework: Recognize Risk, Reduce Exposure, Document Safeguards, Teach Responsibly, and Escalate When Needed. Assess whether the course clearly distinguishes group education risks from one-on-one coaching risks. Recommend improvements to lessons, scenarios, activities, pre-tests, post-training surveys, reflection prompts, knowledge checks, and tools. Deliverables 1. Course Review Notes Written comments identifying needed corrections, clarifications, or improvements. 2. PII Risk and Safeguard Gap Review A summary of missing or underdeveloped privacy risks, data-handling concerns, or safeguard procedures. 3. Scenario and Activity Review Feedback on educator scenarios, coaching scenarios, warm-ups, assessments, and learner activities. 4. Final Recommendation Summary A brief summary stating whether the course is ready for final editing or what revisions are still needed. SME Qualifications The SME should have experience in privacy, data protection, cybersecurity, compliance, financial services compliance, education privacy, learner data protection, information security, risk management, consumer protection, financial education, financial coaching, or related professional practice. Experience reviewing training materials, policies, procedures, controls, educational programs, coaching programs, or data-handling processes involving personal or financial information is preferred. Exclusions The SME is not being asked to provide formal legal advice unless separately qualified and engaged to do so. The SME is not responsible for rewriting the full course unless separately agreed. The primary role is to review, identify gaps, provide recommendations, and confirm whether the course appropriately addresses PII and learner data protection issues. Disclaimer The NFEC provides equal opportunity to all applicants. We select individuals based on their merit and value the unique abilities and talents everyone brings to our organization. The NFEC does not discriminate on the basis of race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, retaliation, parental status, military service, or other non-merit factors.
- Hourly: $50.00 - $100.00
- Expert
- Est. time: 1 to 3 months, Less than 30 hrs/week
Fractional Microsoft Copilot & Copilot Studio Specialist (MSP) We are a SOC 2 Type II certified managed IT and cybersecurity provider serving small and mid-market organizations in regulated industries such as CMMC, HIPAA, SOC 2, and GLBA. We are running a company-wide initiative to put AI, primarily Microsoft 365 Copilot and Copilot Studio, into the day-to-day workflows of every team, and we need a hands-on specialist to help us ship real, in-use tools. This is execution work, not strategy slides. You will build grounded Copilot agents, coach our team leads, and leave us with production tools our staff actually use. ENGAGEMENT DETAILS Type: Fractional / contract Commitment: About 10 to 20 hours per week Term: About 90 days, renewable Location: Remote Start: Immediate Rate: Hourly. Please propose your rate. WHAT YOU WILL DO Audit our current Microsoft 365 Copilot and Copilot Studio footprint and identify high-value, high-frequency workflows to automate. Design and build grounded Copilot Studio agents against our line-of-business systems (AutoTask, IT Glue, Datto RMM, QuickBooks Online). Run structured discovery sessions with each team to select two deliverables each. Coach team leads and internal champions on prompt and agent design so the work sustains after your engagement ends. Help us establish lightweight AI governance suitable for a regulated-industry MSP, covering data boundaries and human-in-the-loop review. Deliver each solution with a documented before and after metric such as time saved, error reduction, or throughput. REQUIRED QUALIFICATIONS Demonstrated, hands-on experience building Microsoft Copilot Studio agents in a production Microsoft 365 tenant. Strong working knowledge of Microsoft 365 Copilot, grounding, and admin reporting. Ability to reason clearly about data boundaries, meaning grounded in-tenant versus ungrounded web usage, and why it matters for regulated data. Experience integrating or grounding agents against third-party and line-of-business systems. A portfolio or references showing shipped, in-use AI solutions rather than proofs of concept. NICE TO HAVE Background working with MSPs or IT service providers. Familiarity with compliance frameworks such as CMMC, HIPAA, SOC 2, and GLBA. Experience with Power Platform automation and pay-as-you-go Copilot credit management. Familiarity with AutoTask, IT Glue, Datto RMM, or QuickBooks Online. HOW WE WILL EVALUATE YOU As part of the interview, we will ask you to whiteboard, live, how you would automate one real workflow from our business. We want to see how you reason about grounding, data boundaries, and Copilot Studio orchestration, not a polished pitch. TO APPLY, PLEASE INCLUDE A short note on a Copilot or AI solution you shipped, the workflow it improved, and the measurable result. Your proposed hourly rate and weekly availability. Links or references to relevant agents, automations, or portfolio work.
- Hourly
- Intermediate
- Est. time: Less than 1 month, Less than 30 hrs/week
I’m working on an early-stage startup concept in the counter-drone / critical infrastructure security space. The product is not drone jamming, takedown, spoofing, or mitigation. The concept is a civilian-compliant drone incident management platform that helps data centers, utilities, ports, stadiums, prisons, refineries, airports, and industrial campuses detect, document, and respond to unauthorized drone activity. I’m looking to connect with a security integrator, physical security consultant, or security technology expert who understands how enterprise security systems are actually sold, installed, and operated. The product vision is a software/workflow layer that can eventually integrate with: CCTV / security camera systems Video management systems Access control systems Security operations centers Incident management tools Perimeter security systems RF/radar/acoustic drone detection sensors Alerting and dispatch workflows The goal is not to ask you to build the whole product. I’m looking for a practical partner/advisor who can help us understand how this would fit into real customer environments and how to eventually sell or pilot it through security integrators. I’d like help answering questions such as: Would data centers, utilities, ports, stadiums, prisons, or refineries care about this? Who inside the customer organization would own the budget? What security systems would this need to integrate with first? What would make this product credible to a security director? What would make this product sound unrealistic or risky? How do security integrators evaluate new software partners? What would a realistic 30-day pilot look like? What deliverables would a customer expect from a paid discovery project? Which industries would be easiest to enter first? What partnership structure would make sense for integrators? Deliverables I’m looking for: 1–2 advisory calls Feedback on target customer segments Feedback on pilot proposal and paid discovery offer Recommended integrations and must-have features Suggested partner strategy for security integrators List of objections customers/integrators may raise Optional written summary after the call Please let me know: Your background in physical security, security integration, SOC tools, CCTV, VMS, access control, perimeter security, or critical infrastructure security Whether you have experience selling to or supporting data centers, utilities, ports, stadiums, prisons, refineries, airports, or industrial sites Your availability for an initial advisory call Your hourly rate or fixed price for a concept review What information you would need from me before the call I’m looking for someone who can be direct and practical. The goal is to understand whether this product can realistically fit into existing security environments, what we should build first, and how to approach potential pilot customers or channel partners.