- Hourly: $20.00 - $80.00
- Expert
- Est. time: Less than 1 month, Less than 30 hrs/week
Looking for a google workspace security expert to review/analyze/identify source of issues and enhance security We have 2FA enforced on our google workspace but continuing to see phishing emails being sent from our user emails Need some help reviewing our google workspace email settings and making sure all our email settings are optimized to avoid spoofing, emails ending up in spam etc. Hoping to do this over a screen sharing session asap. Also audit current security settings and make recommendations on updates The initial review call will be a 1 hour review/resolve session and that may be enough but if any additional work, it can be done off call
- Hourly
- Expert
- Est. time: Less than 1 month, Less than 30 hrs/week
I need penetration testing performed to help ensure we have no vulnerabilities with the latest AI advancements.
- Hourly
- Expert
- Est. time: Less than 1 month, Less than 30 hrs/week
We are seeking a US-based company to manage our software, focusing on security monitoring, backups, disaster recovery, patch management, network security, and deployments. The ideal candidate will have experience in software management and security, ensuring our systems are secure and efficient. This is a part-time role with a project scale of small, expected to last less than a month.
- Hourly: $30.00 - $65.00
- Intermediate
- Est. time: 1 to 3 months, Less than 30 hrs/week
## IT and Workflow Consultant for Small CPA Firm We own a growing tax and accounting firm with 1–5 employees and 3+contractors. I am looking for an IT consultant to review our current technology, security, and workflow and recommend practical improvements. We currently use Microsoft Windows, Google Workspace, Dropbox, Google Sheets, WhatsApp, tax software, and a VPN. The consultant should review: * Passwords and user access * VPN configuration and security * Network security and design * Google Workspace administration * Dropbox administration and permissions * Employee and contractor access * Data backup and recovery * Email accounts and shared company addresses * Current workflow and communication methods * Sales, client onboarding, document collection, and tax-return workflow * Whether we should improve our current tools or adopt a new workflow system The goal is to document our current process, identify security and efficiency issues, and create a simple future-state plan. ### Required Skills * Business with 1–9 Employees * Dropbox Administration * Google Workspace Administration * Microsoft Windows * Network Administration * Network Security * VPN Configuration and Security * Workflow Optimization Experience working with accounting, tax, legal, or other professional-services firms is preferred. I will leave you a stellar 5/5 review !!! ;-)
- Hourly
- Intermediate
- Est. time: 1 to 3 months, Less than 30 hrs/week
Small IT team seeking an experienced tech writer to assist with creating standard ISO27001 framework policies. The focus is on policy documentation, not certification. Ideal candidates will have a strong understanding of technical writing and experience with ISO standards.
- Hourly: $30.00 - $55.00
- Expert
- Est. time: 3 to 6 months, Not sure
We are looking for a Data Loss Prevention SME to assist with various DLP project rollouts, consulting, implementation, and configuration. From initial strategy to full implementation. functionality. In some cases maintenance/operational work will be required.
- Fixed price
- Expert
- Est. budget: $450.00
We are a new logistics company building our website, and we are looking for a Website Security & Compliance Specialist to partner with our internal team. Our designer (Toni) is handling all layout, pages, and visual development — your role focuses strictly on the security, access control, and compliance‑sensitive portions of the site. What we need: We need someone who can review the site structure, secure employee‑only pages, configure protected document access, secure multiple reporting forms, and ensure the website meets the data‑protection expectations required for Amazon DSP compliance. You will collaborate with our designer as needed, but you will not be responsible for design or page creation. Deliverables include: Secure access controls for employee‑only pages Protected employee handbook download Anonymous reporting form security Urgent reporting workflow security Secure form configuration + email routing Google Workspace integration General website security hardening Compliance review + risk assessment Skills required: Information Security, IT Compliance, Secure Form Configuration, Access Control, Authentication Systems, Google Workspace Integration, and Website Security Hardening. How we work: We communicate clearly, respond quickly, and keep responsibilities separated. Toni will lead the full website build, and you will focus on the backend security and compliance requirements. We value transparency, collaboration, and professionals who can explain what they need in order to complete their part of the project. What we’re looking for: Someone experienced, reliable, and comfortable partnering with another professional. This is a focused, security‑driven role — perfect for someone who specializes in compliance workflows and secure website infrastructure.
- Hourly: $30.00 - $40.00
- Expert
- Est. time: More than 6 months, 30+ hrs/week
We're looking for an experienced Fractional Application Security Lead to oversee the security of our platform. This is an ongoing, part-time role requiring approximately 10–20 hours per week and reports directly to the CEO. Responsibilities: - Review every pull request before production - Review system architecture - Perform threat modeling for every new feature - Audit authentication and authorization - Review wallet and payment flows - Ensure secrets are stored correctly - Review AWS/cloud infrastructure - Review Firebase/Supabase (if used) - Review APIs - Review database permissions - Verify encryption - Ensure compliance with fintech best practices If you're interested, please include a brief summary of your relevant experience, examples of similar work, your availability, and your hourly rate. Screening Questions: 1. Please describe your experience securing fintech, financial services, banking, or payment platforms. 2. Describe your experience reviewing pull requests, system architecture, and cloud infrastructure from a security perspective. 3. Tell us about a significant security vulnerability you identified before it reached production. What was the issue, and how did you address it? 4. What experience do you have with authentication and authorization, API security, encryption, secrets management, and database permissions? 5. Why are you a good fit for this role, and what relevant experience would you bring to our team?
- Hourly: $50.00 - $100.00
- Intermediate
- Est. time: Less than 1 month, Less than 30 hrs/week
Overview We're looking for an experienced application security professional to review the codebase for a web app that handles sensitive borrower data (documents, personal information) before we launch it into user testing. We need someone to identify real vulnerabilities — not just run a scanner — and give us clear, prioritized recommendations we can act on before launch. The codebase ~13,000 lines total The repository contains 9,868 lines of first-party application code, measured as physical lines including comments and blank lines. Backend Python: 5,144 Frontend JSX/CSS/HTML: 3,954 Database migrations: 770 Tests: 3,027 So, including tests: 12,895 lines. Backend: Python/FastAPI (single app/ module), SQLAlchemy 2.0 + Alembic migrations, PostgreSQL in production (Heroku), SQLite in dev Frontend: React 18, vendored as UMD files (not an npm dependency), with Babel compiling frontend/app.jsx → static/app.js — no bundler, no runtime JS dependencies Integrations: Salesforce sync, Google Drive (file uploads/storage), SendGrid (magic-link login emails) Auth: passwordless/magic-link login, rate-limited via slowapi What we need reviewed Magic-link authentication — token generation, expiry, and replay protection Authorization checks across API routes — making sure users can only access their own data The Salesforce and Google Drive integrations — credential handling and data exposure risk File upload handling General exposure to OWASP Top 10-style risks Scope Manual source code review (not just an automated scan report) Written findings with severity ratings and concrete remediation steps Dynamic/penetration testing against a staging environment is a nice-to-have
- Hourly: $20.00 - $80.00
- Intermediate
- Est. time: 1 to 3 months, Hours to be determined
We are a boutique professional services firm seeking an experienced Microsoft Purview consultant to help us design and implement an AI data governance strategy within our Microsoft 365 environment. The ideal candidate will have deep expertise in Microsoft Purview, Microsoft 365 security and compliance, and AI data governance, and will be able to provide both strategic guidance and hands on implementation support. We are looking for a trusted advisor who can help us evaluate available Microsoft technologies, recommend practical solutions, and implement an AI governance framework that aligns with our firm's operational, security, and compliance objectives. Initially, we are seeking a consultant to assess our current Microsoft environment, explain the capabilities available through Microsoft Purview, identify any licensing considerations, and recommend a practical implementation roadmap for a small organization. If the engagement is a good fit, we anticipate continuing through implementation and ongoing advisory support. Areas of interest include: Microsoft Purview Microsoft Information Protection and Sensitivity Labels Data Loss Prevention (DLP) Information Governance and Records Management Retention Policies eDiscovery capabilities Microsoft Copilot governance AI governance and best practices Monitoring, auditing, and reporting We are particularly interested in understanding how Microsoft technologies can help organizations govern and protect information used with AI platforms, including Microsoft Copilot, ChatGPT, Codex, and similar tools, while maintaining appropriate administrative controls and information governance. Experience implementing Microsoft Purview for professional services organizations is preferred. Strong communication skills and the ability to explain technical concepts to business users are important.