Talent badge filter
Skills filter
Select talent location
Select talent time zones
$50/hr
100%
Job Success
Start of list.
End of list.
Petar A.
has worked
.
✅ Professional Penetration Tester ✅ 3500+ Hours ✅ Top Rated Plus Freelancer
Security Researcher and Penetration Tester recognized by the U.S. Department of Defense, AT&T, Sony, and Semrush for the responsible disclosure of 40+ vulnerabilities via HackerOne. Since 2022, an active member of the Synack Red Team - an elite tier of offensive security specialists vetted through rigorous technical and background screening.
Every engagement concludes with a comprehensive technical report built to satisfy the specific penetration testing controls required for HIPAA, ISO 27001, SOC2, and PCI-DSS. I provide a high-level executive summary for stakeholders alongside deep-dive technical findings, fully reproducible Proofs-of-Concept (PoC), and prioritized remediation steps to ensure your team can effectively close every gap before your audit.
Specializing in black and gray box testing of live web applications, cloud environments, and networks, covering all common attack vectors, business logic flaws, and discovering previously undisclosed vulnerabilities (0days) to prevent high-impact data breaches.
Service Description:
1) Web Application Penetration Testing (OWASP Top 10, PTES, ASVS, Business Logic Testing)
2) Mobile Application Penetration Testing (OWASP Top 10, MASVS, MASTG, PTES)
3) Network Penetration Testing (Active Directory, Entra ID, Internal & External Network)
4) API Security Testing - REST, GraphQL, SOAP, gRPC, Webhooks (OWASP API Top 10)
5) Cloud Security Testing - AWS/Azure/GCP/OCI/Alibaba/IBM/DigitalOcean/SaaS/IaaS/PaaS
6) Cloud-Native & Container Security (Kubernetes, Docker, OpenShift, EKS/AKS/GKE)
7) LLM Security Testing (OWASP LLM Top 10, Prompt Injection, Data Poisoning)
Tools used in engagements:
BurpSuite Professional | Custom Python scripts | BloodHound | Impacket Framework | Responder | Metasploit | Mimikatz | Nuclei | Nmap | FRIDA | Android Studio | Postman
Identify and secure your attack surface before threat actors do ! Message me to discuss your project requirements.
$25/hr
100%
Job Success
Start of list.
End of list.
Pankaj R.
has worked
.
I am a Cybersecurity Specialist with hands-on experience in malware removal, website security, vulnerability assessment, penetration testing, server security, incident response, and security hardening.
I help businesses identify, investigate, remove, and prevent malware infections across websites, servers, WordPress, Joomla, Laravel, Linux environments, hosting platforms, and cloud infrastructure.
My focus is not just removing infected files. I investigate how the compromise happened, identify persistence mechanisms and backdoors, clean the environment, secure the system, and provide recommendations to prevent reinfection.
MALWARE REMOVAL AND CLEANUP
I can investigate and remove:
PHP malware and backdoors
WordPress malware
Joomla malware
Laravel malware
JavaScript injections
Malicious redirects
SEO spam
Casino and pharmaceutical spam
Google cloaking malware
Fake CAPTCHA malware
Phishing pages
Malicious iframes
Web shells
PHP shells
Encoded malware
Base64 and eval injections
gzinflate and obfuscated PHP malware
Remote payload loaders
Malicious cron jobs
Systemd persistence
Suspicious scheduled tasks
Injected .htaccess files
Injected .user.ini files
Malicious Composer/autoload injections
Database-injected malware
Malicious admin users
Unauthorized accounts
Suspicious SSH activity
Cryptominers
Malicious ELF binaries
Server-level malware
Web-based backdoors
Persistent malware
WORDPRESS SECURITY
WordPress malware removal
WordPress security audit
WordPress malware investigation
WordPress backdoor detection
Malicious plugin detection
Malicious theme detection
Hidden administrator detection
WordPress database cleanup
WordPress file integrity checks
WordPress hardening
WordPress firewall configuration
WordPress login protection
XML-RPC security
File permission hardening
Security plugin configuration
Post-cleanup security monitoring
LINUX SERVER SECURITY
Linux malware investigation
Linux server hardening
Root-level malware investigation
Suspicious process analysis
ELF malware investigation
Cron persistence analysis
Systemd persistence analysis
SSH security
Unauthorized user investigation
File integrity analysis
Network connection analysis
Listening port investigation
Suspicious outbound connection analysis
Process and service investigation
Log analysis
Server compromise investigation
Incident response
Post-compromise security hardening
WEB APPLICATION SECURITY
I perform security assessments and vulnerability testing for websites and web applications, including:
Vulnerability Assessment and Penetration Testing
OWASP Top 10
Web application security testing
API security testing
Authentication testing
Authorization testing
Session security
Access control testing
SQL Injection
Cross-Site Scripting
CSRF
SSRF
File upload vulnerabilities
Command injection
Path traversal
Security misconfiguration
Broken access control
API vulnerabilities
Business logic vulnerabilities
Information disclosure
Security headers
SSL/TLS configuration
Authentication and authorization weaknesses
SECURITY TOOLS AND TECHNOLOGIES
Burp Suite
Burp Suite Professional
OWASP ZAP
Nmap
Nessus
OpenVAS
HCL AppScan
Splunk
ELK
Kibana
CrowdStrike Falcon
Microsoft Defender
Cloudflare
Wordfence
Sucuri
Linux
Windows Server
Apache
Nginx
cPanel
Plesk
WHM
Cloudways
Hostinger
DigitalOcean
AWS
Azure
INCIDENT RESPONSE
When a website or server is compromised, I can perform a structured investigation to determine:
What was compromised
How the attacker gained access
Which files were modified
Which accounts were created
Whether backdoors are present
Whether persistence mechanisms exist
Whether credentials may have been compromised
What malicious processes are running
What external IPs or domains were contacted
Whether other websites or accounts are affected
Whether the attacker still has access
I can analyze logs, processes, file modifications, cron jobs, system services, network connections, database entries, application files, and suspicious artifacts to build a clear picture of the compromise.
SECURITY HARDENING
After malware removal or a security assessment, I can harden the environment by addressing:
File permissions
User privileges
SSH configuration
Web server configuration
PHP configuration
Firewall rules
Security headers
CMS configuration
Plugin and theme security
Database security
Admin account security
Authentication controls
Cloudflare configuration
WAF rules
Rate limiting
Bot protection
DDoS protection
Backup security
Logging and monitoring
Vulnerability management
CLOUDFLARE SECURITY
I also provide Cloudflare security and protection services, including:
Cloudflare WAF
Cloudflare Firewall Rules
Custom WAF Rules
DDoS Protection
Bot Management
Bot Fight Mode
Rate Limiting
Security Rules
Origin IP Protection
SSL/TLS
DNS Security
CDN configuration
Cache security
Country and IP filtering
API protection
Cloudflare Zero Trust
Cloudflare Tunnel
Security Event analysis
Malicious traffic mitigation
MALWARE INVESTIGATION PROCESS
My approach generally
$25/hr
100%
Job Success
$10K+ earned
Available now
Start of list.
End of list.
Youssef E.
has worked
.
I find the vulnerabilities in your web apps, APIs, and networks before attackers do, then hand your team a clear, reproducible penetration testing report they can act on.
GXPN and GCIH certified. Top Rated on Upwork with 100% Job Success across web application, API, and network security engagements.
No scanner dump and no jargon wall. Every finding comes with a severity rating (CVSS), working proof of concept, and a concrete fix your developers can ship.
What I test:
- Web application penetration testing (OWASP Top 10, PTES, NIST)
- API security testing (REST, GraphQL, auth/OAuth, IDOR, broken access control)
- SaaS and multi-tenant assessments (Supabase / Firebase data-isolation testing)
- Network and external perimeter penetration testing
- Source code / secure code review
How I work: authorized testing only, on systems you own or have permission to test. Everything is documented over Upwork so you get a written record of every finding, not a verbal hand-wave. I retest after you patch to confirm the holes are actually closed.
Credentials: GXPN (GIAC Advanced Penetration Tester & Exploit Researcher), GCIH (GIAC Certified Incident Handler), SANS CTF winner, and an active national/international CTF competitor (web, reverse, crypto, forensics).
I also handle WordPress malware removal and incident response. See my Project Catalog for a fixed-price option.
$30/hr
100%
Job Success
$2K+ earned
Available now
Offers consultations
Start of list.
End of list.
Syed Jan Muhammad Z.
has worked
.
👏𝐀𝐩𝐩𝐫𝐞𝐜𝐢𝐚𝐭𝐞𝐝
STEX is grateful for your significant contribution to the information security of the project and we recommend you as an IT security professional. Please continue your useful work and do not tire of making the Internet better! - 𝐎𝐥𝐚𝐟 𝐇𝐚𝐧𝐬𝐞𝐧 - 𝐁𝐮𝐬𝐢𝐧𝐞𝐬𝐬 𝐃𝐞𝐯𝐞𝐥𝐨𝐩𝐦𝐞𝐧𝐭 𝐌𝐚𝐧𝐚𝐠𝐞𝐫 𝐨𝐧 𝐒𝐓𝐄𝐗
🙋♂️𝐀𝐛𝐨𝐮𝐭 𝐌𝐞
✅ 8+ years of Industry Experience in Penetration Testing of Web, Mobile, API's, Cloud and network
✅ Experienced Security Professional; Trusted by Enterprises & Startups
✅ CEH (Practical) & CRTP Certified
✅ Identified 1000+ vulnerabilities in infrastructure and applications
🏆𝐍𝐨𝐭𝐚𝐛𝐥𝐞 𝐚𝐜𝐡𝐢𝐞𝐯𝐞𝐦𝐞𝐧𝐭𝐬
✅ Discoverer of CVE-2024-3121
✅ Recognized by LinkedIn, Stex, GlobalSign other enterprise platforms
💡𝐖𝐡𝐲 𝐌𝐞?
✅Beyond Automated Testing - Unique in depth and manual RSER penetration testing methodology, beyond automated scans to reduce false positives.
✅ Collaborative Approach - Actively collaborate with your development team to help fix the vulnerabilities
✅Controlled Testing - Testing in a safe and controlled environment, aligned with OWASP TOP 10 and PTES Standards.
✅Professional Reporting - Clear, professional, technical and detailed reporting with evidence of exploitation and remediation guidance for each vulnerability.
✅Executive Summary Report - Unique high-level summary crafted for executives and investors, translating technical findings into business risks and actionable insights.
✅Pentest Letter of Attestation (LoPT) - A formal proof of testing confirming your system has undergone professional penetration testing. Ideal for clients, partners, or compliance verification.
🙌Let’s connect! I can show you how I deliver thorough, transparent testing, produce reports that meet industry standards, and work closely with your team to fix vulnerabilities efficiently.
$10/hr
97%
Job Success
Available now
Offers consultations
Start of list.
End of list.
Faizan I.
has worked
.
Hi
Availability 40+ hour/week
I help SaaS, AI, web, mobile, and eCommerce teams release stable, user-ready products through Software QA, Manual Testing, Test Automation, API Testing, Mobile App Testing, Web App Testing, Regression Testing, Functional Testing, and clear Bug Reporting.
I work as a Software QA Engineer / QA Automation Engineer who can test your product from both the user side and the technical side. My goal is simple: give your team clear test coverage, clean reports, real evidence, and practical release feedback before your customers find problems.
My core QA services include:
✅ Manual Testing
• Web App Testing
• Mobile App Testing
• Functional Testing
• Regression Testing
• Smoke Testing
• Sanity Testing
• Exploratory Testing
• Usability Testing
• User Acceptance Testing
• Cross-Browser Testing
• Responsive Testing
• Test Case Design
• Test Plan Creation
• QA Documentation
✅ QA Automation
• Playwright Testing
• Cypress Testing
• Selenium Automation
• Appium Testing
• End-to-End Testing
• Regression Automation
• UI Automation
• CI/CD Testing
• GitHub Actions test support
• Stable automation for repeated test journeys
✅ API & Backend Validation
• API Testing with Postman
• REST API Testing
• Swagger and Open API validation
• Authentication testing
• Request and response validation
• Negative test cases
• Data validation
• Frontend and backend result comparison
✅ Mobile QA Testing
• Android App Testing
• iOS App Testing
• Real-device testing
• Emulator and simulator testing
• Onboarding, login, payment, chat, wallet, push notification, and subscription testing
• Mobile UI, responsiveness, crash, and performance checks
✅ AI & Modern QA Testing
• AI Testing
• AI SaaS Testing
• LLM Testing
• Chatbot Testing
• Prompt-based testing
• AI output validation
• Edge-case testing for AI-generated responses
• Accuracy, consistency, and usability checks for AI products
Tools I work with:
Playwright, Cypress, Selenium, Appium, Postman, Swagger, Jira, Trello, ClickUp, TestRail, Qase, Zephyr, BrowserStack, LambdaTest, GitHub, GitHub Actions, Chrome DevTools, Android Studio, Xcode, and CI/CD pipelines.
What you will get:
• Clear test cases based on your requirements
• Structured bug reports with steps, screenshots, videos, logs, severity, priority, expected result, and actual result
• Fast QA updates during testing
• Practical feedback on usability, layout, responsiveness, and product behavior
• Regression testing before release
• API and UI validation together
• Cross-browser and cross-device coverage
• Automation support for repeated test journeys
• Release-focused QA support for founders, developers, product managers, and agencies
I focus on the areas that matter most in real products: login, signup, dashboard, checkout, payments, subscriptions, admin panels, role permissions, forms, search, filters, notifications, API responses, mobile screens, browser differences, and release blockers.
I have experience testing SaaS platforms, AI products, mobile apps, eCommerce stores, dashboards, CRM systems, healthcare platforms, FinTech products, marketplaces, and business web applications.
If you need a QA Engineer who can handle Manual Testing, QA Automation, API Testing, Web App Testing, Mobile App Testing, Regression Testing, AI Testing, and professional Bug Reporting, I can help you test your product properly before launch and support your team after release.
SKILLS:
Software Testing | QA Testing | Quality Assurance | Software QA | Manual Testing | Functional Testing | Regression Testing | Web App Testing | Mobile App Testing | Android App Testing | iOS App Testing | API Testing | Postman API Testing | End-to-End Testing | Test Case Design | Bug Reporting | Bug Tracking | Usability Testing | Test Automation | Automated Testing | Playwright Testing | Cypress Testing | Selenium Automation | Appium Testing | AI Testing | AI Test Automation | Generative AI Testing | LLM Testing | Performance Testing | Security Testing
$100/hr
84%
Job Success
$10K+ earned
Available now
Offers consultations
Start of list.
End of list.
Hassan J.
has worked
.
Welcome to the profile of a renowned ethical hacker and bug bounty hunter, ranked among the top 400 hackers on Bugcrowd. With a remarkable portfolio that includes accolades from industry titans such as Samsung, Binance, cPanel, and F5, I bring unrivalled expertise and a track record of accomplishment to the table.
What I Offer:
Ethical Hacking Excellence: With extensive technical skills and an unwavering resolve to find vulnerabilities, I specialise in detecting and addressing security threats across a wide range of platforms and situations. Whether it's web apps or mobile apps, I have the expertise and knowledge to effectively strengthen your digital defences.
Bug Bounty Mastery: As an experienced bug bounty hunter, I have gained the trust of major corporations by my careful methodology and unrelenting dedication to perfection. My contributions have been recognised by reputable businesses such as Samsung, Binance, cPanel, F5, and many others, demonstrating my ability to generate results that exceed expectations.
Beyond bug finding, I provide full security consulting services that are tailored to your individual requirements. Whether you need strategic advice on On cyber security best practices or hands-on support in remediation efforts, I deliver practical insights to help you protect your assets and reduce any threats in advance.
Why Choose Me:
Trusted by Industry Leaders: My track record of accomplishment speaks for itself, with accolades from top-tier firms demonstrating my knowledge and professionalism. When you work with me, you will receive access to the same degree of expertise that has gained the trust of industry leaders globally.
Proactive Approach: I believe in staying one step ahead of cyber threats by taking a proactive approach to security. By conducting extensive evaluations and executing effective mitigation measures, I assist customers in reducing potential hazards before they become full-fledged catastrophes.
Collaborative collaboration: I see each client interaction as a collaborative collaboration with the goal of mutual success. I prioritise open communication, openness, and reactivity to guarantee that your individual demands and objectives are precisely satisfied.
Let us strengthen your security posture:
In an era of rising cyber dangers, investing in strong cyber security measures is critical for protecting your company's integrity and reputation. Partner with me to strengthen your defences, reduce potential risks, and remain ahead of the curve in today's ever-changing threat landscape.
Contact me today to discuss how we help improve your security posture and secure what matters most to you.
$50/hr
100%
Job Success
$70K+ earned
Start of list.
End of list.
Chakradhar C.
has worked
.
✅ Top Rated Plus Expert ✅ 1000+ Hours ✅ Professional Penetration Tester
Senior Penetration Tester with more than 7+ years of rich industry experience in Web, Mobile, API, and Network Penetration Testing. I have successfully completed 500+ Web application Pentests, 200+ Mobile Application Penetration Tests, 300+ API Penetration Tests, 100+ External Network Penetration Tests and 30+ Internal Penetration Tests.
I am also a Security researcher acknowledged by Yahoo (among other notable companies like SolarEdge, Imgur, Artsy, etc.) for disclosing a number of vulnerabilities via the HackerOne bug bounty platform.
My core competency is Blackbox, Greybox Testing on Web, API, Mobile, and Network applications. I am familiar with all attacks and mitigations and am well-versed in OWASP, NIST, and PTES Frameworks. My Pentesting reports include clear documentation of the vulnerabilities found along with the remediations to make sure the client is 100% satisfied. I am also certified in AWS, and Azure and have a very keen knowledge of Cloud Security and cloud administration.
✅ I have conducted Penetration Tests, Vulnerability Assessments and delivered professional reports to companies around the world complying with the following:
►OWASP Web Security Top 10 Vulnerability
►OWASP API Security Top 10 Vulnerability
►OWASP Mobile Security Top 10 Vulnerability
►External Network Penetration Testing
►Internal Network Penetration Testing
►Payment Card Industry Data Security Standard (PCI DSS)
►System and Organization Controls 2 (SOC2)
►General Data Protection Regulation (GDPR)
►Common Vulnerability Scoring System (CVSS)
►Open Source Security Testing Methodology Manual (OSSTMM)
My Certs include:
►CompTIA Pentest+ (Expired)
►AWS Solutions Architect (Expired)
►Azure Administrator (Expired)
Tools: Burp Suite, Nikto, Nmap, Zap, Metasploit, Nessus, W3af, Ffuf, Dirb, etc...
I am available 24/7. If you are interested in cooperation, drop me a line :)
$25/hr
100%
Job Success
Available now
Start of list.
End of list.
Hoang Nhan L.
has worked
.
✅ As a CREST/Offensive Security (OSCP) Certified Penetration Tester and Cyber Security Consultant, I have deep knowledge of Security Assessment Methodology to identify vulnerabilities in Network, API, Web, and Mobile Applications.
✅ I have conducted Penetration Test, Vulnerability Assessment and delivered professional reports to companies in the world complying with:
► CREST standards
► Offensive Security (OSCP) standards
► OWASP Top 10 Vulnerability
► OWASP API Security Top 10 Vulnerability
► OWASP Mobile Security Top 10 Vulnerability
► Application Security Verification Standard 4.0 (ASVS 4.0)
► CWE Top 25 Most Dangerous Software Errors
► ISO 27001 Penetration Testing
► Payment Card Industry Data Security Standard (PCI DSS)
► General Data Protection Regulation (GDPR)
► Common Vulnerability Scoring System (CVSS)
► Open Source Security Testing Methodology Manual (OSSTMM)
✅ I have some cybersecurity certifications including:
► CREST Registered Penetration Tester (CRT)
► CREST Practitioner Security Analyst (CPSA)
► Offensive Security Certified Professional (OSCP)
✅ The deliverable will be a professional Penetration Testing/Vulnerability Assessment report which includes:
► Executive Summary
► Assessment Methodology
► Type of Tests
► Risk Level Classifications
► Result Summary
► Table of Findings
► Detailed Findings. Each finding listed within the report will contain CVSS score, Issue Description, Proof of Concept, Remediation, and Reference sections.
► Tool List (Acunetix, Nessus, BurpSuite Professional, Nmap, Netsparker, Metasploit Framework, OpenVAS, Mimikatz, SQLmap, Nikto, Zaproxy, Gobuster, etc.)
✅ Please contact me if you have any question.
✅ Thank you and have a good day!
$30/hr
100%
Job Success
$10K+ earned
Available now
Start of list.
End of list.
GM Salman A M.
has worked
.
🚨 If your application, SaaS platform, or cloud environment has never undergone a professional security assessment, you may have unknown vulnerabilities that attackers can exploit.
I’m a Certified Penetration Tester and Ethical Hacker providing Vulnerability Assessment and Penetration testing (VAPT) services for web applications, APIs, cloud infrastructure, mobile apps, SaaS platforms, and network environments. My goal is not just to find vulnerabilities — but to help you understand real security risks and fix them effectively.
I perform manual penetration testing supported by professional security tools to identify exploitable weaknesses such as authentication flaws, privilege escalation paths, injection vulnerabilities, and business logic issues.
You will receive a clear and actionable security report that helps developers resolve issues and allows management to understand the real business impact.
🎯 My Services
- Vulnerability Assessment & Penetration Testing (VAPT)
- Web Application Penetration Testing (OWASP Top 10)
- API Penetration Testing (REST, GraphQL, authentication flaws, IDOR, injection)
- Cloud Infrastructure Security (AWS, Azure — misconfigurations, IAM, exposed services)
- Network Penetration Testing (internal & external)
- Mobile Application Security (Android & iOS)
- SaaS Platform Security & Penetration Testing (multi-tenant logic, RBAC, privilege escalation)
- CMS Security (WordPress, Laravel, custom apps)
- Retesting after remediation
📋 What You Will Receive
A clear, structured security report designed for both technical teams and business stakeholders, including:
• Executive summary for management and decision-makers
• Detailed vulnerability findings with severity ratings
• CVSS scoring and risk prioritization
• Proof-of-concept evidence (screenshots, request/response captures)
• Business impact explanation for each issue
• Step-by-step remediation guidance for developers
• Retesting validation after fixes are applied
• Reporting that can support ISO 27001 and SOC 2 compliance preparation
🏆 Certifications
- Certified Ethical Hacker Practical — EC-Council
- eLearnSecurity Junior Penetration Tester (eJPT) — INE
- Certified API Penetration Tester — APISec University
- IBM Cybersecurity Analyst
- Cisco Verified Ethical Hacker
- ISO 27001:2022 Lead Auditor
🛠️ Tools I work with
Burp Suite Pro, OWASP ZAP, Nmap, Nessus, Metasploit, MobSF, Wireshark, Postman, and custom Python/Bash scripts and so on.
Whether you're preparing for a security review, compliance audit, or investor due diligence, I can help you understand your attack surface and security risks.
📩 Send me your scope or asset list and I’ll help you determine the best testing approach.
$55/hr
100%
Job Success
$30K+ earned
Available now
Offers consultations
Start of list.
End of list.
Ehtisham F.
has worked
.
I help SaaS companies, dev teams, and startups find and fix security vulnerabilities before attackers do, through manual penetration testing, not automated scans. CRTO & CPTS Certified | 5+ years in offensive security | 49 projects completed | 94% Job Success Score
I've delivered 50+ security assessments for clients worldwide, helping them prevent an estimated $100,000+ in potential breach costs and meet compliance requirements under OWASP, ISO 27001, and SOC 2.
Services I provide:
Web Application Penetration Testing: OWASP Top 10, business logic flaws, RCE, SQLi, XSS, IDOR/BOLA, SSRF, tenant isolation issues in multi tenant SaaS
API Security Testing: REST, SOAP, and GraphQL. Broken auth, token misuse, injection, rate limit bypass
Mobile Application Penetration Testing: iOS and Android, static and dynamic analysis, insecure local storage, hardcoded secrets, cert/TLS handling
Cloud & SaaS Backend Security: AWS configuration review (IAM, S3, API Gateway), Supabase/Postgres Row Level Security review, service role and auth flow testing
Internal Network & Active Directory Pentesting: Kerberoasting, misconfigurations, lateral movement paths
External Network Pentesting: DNS leaks, open ports, exposed services, privilege escalation
Windows Desktop Application Testing: binary analysis, insecure storage, reverse engineering
OSINT & Recon Assessments: exposed employee, asset, and sensitive data discovery
Vulnerability Assessment & Retesting: gray box and white box methodologies, verified PoCs, prioritized remediation reports, post fix retest and attestation
I test against recognized standards (OWASP Testing Guide, NIST SP 800-115, PTES) and can produce reports suitable for SOC 2 Type I/II audit evidence.
Recent results:
Hardened a healthcare SaaS platform, closing gaps that would have caused HIPAA violations
Tested API endpoints for a fintech client, cutting the exposed attack surface by 43%
Found Active Directory misconfigurations that would have allowed full domain compromise
Helped a startup pass its security audit ahead of a $2.5M funding round
Why clients keep hiring me back:
Certified in offensive security (CRTO, CPTS) and red teaming. Deep manual testing, not just scanner output
Developer ready reports with CVSS scores and reproducible proof of concept steps
Retesting included after fixes, so you know the issue is actually closed
Fast communication, usually within a few hours
Comfortable embedding into a DevSecOps pipeline for ongoing coverage