Talent badge filter
Skills filter
Petar A.
$50/hr
100% Job Success
Start of list.
End of list.
Petar A. has worked .
✅ Professional Penetration Tester ✅ 3500+ Hours ✅ Top Rated Plus Freelancer Security Researcher and Penetration Tester recognized by the U.S. Department of Defense, AT&T, Sony, and Semrush for the responsible disclosure of 40+ vulnerabilities via HackerOne. Since 2022, an active member of the Synack Red Team - an elite tier of offensive security specialists vetted through rigorous technical and background screening. Every engagement concludes with a comprehensive technical report built to satisfy the specific penetration testing controls required for HIPAA, ISO 27001, SOC2, and PCI-DSS. I provide a high-level executive summary for stakeholders alongside deep-dive technical findings, fully reproducible Proofs-of-Concept (PoC), and prioritized remediation steps to ensure your team can effectively close every gap before your audit. Specializing in black and gray box testing of live web applications, cloud environments, and networks, covering all common attack vectors, business logic flaws, and discovering previously undisclosed vulnerabilities (0days) to prevent high-impact data breaches. Service Description: 1) Web Application Penetration Testing (OWASP Top 10, PTES, ASVS, Business Logic Testing) 2) Mobile Application Penetration Testing (OWASP Top 10, MASVS, MASTG, PTES) 3) Network Penetration Testing (Active Directory, Entra ID, Internal & External Network) 4) API Security Testing - REST, GraphQL, SOAP, gRPC, Webhooks (OWASP API Top 10) 5) Cloud Security Testing - AWS/Azure/GCP/OCI/Alibaba/IBM/DigitalOcean/SaaS/IaaS/PaaS 6) Cloud-Native & Container Security (Kubernetes, Docker, OpenShift, EKS/AKS/GKE) 7) LLM Security Testing (OWASP LLM Top 10, Prompt Injection, Data Poisoning) Tools used in engagements: BurpSuite Professional | Custom Python scripts | BloodHound | Impacket Framework | Responder | Metasploit | Mimikatz | Nuclei | Nmap | FRIDA | Android Studio | Postman Identify and secure your attack surface before threat actors do ! Message me to discuss your project requirements.
Pankaj R.
$25/hr
100% Job Success
Start of list.
End of list.
Pankaj R. has worked .
I am a Cybersecurity Specialist with hands-on experience in malware removal, website security, vulnerability assessment, penetration testing, server security, incident response, and security hardening. I help businesses identify, investigate, remove, and prevent malware infections across websites, servers, WordPress, Joomla, Laravel, Linux environments, hosting platforms, and cloud infrastructure. My focus is not just removing infected files. I investigate how the compromise happened, identify persistence mechanisms and backdoors, clean the environment, secure the system, and provide recommendations to prevent reinfection. MALWARE REMOVAL AND CLEANUP I can investigate and remove: PHP malware and backdoors WordPress malware Joomla malware Laravel malware JavaScript injections Malicious redirects SEO spam Casino and pharmaceutical spam Google cloaking malware Fake CAPTCHA malware Phishing pages Malicious iframes Web shells PHP shells Encoded malware Base64 and eval injections gzinflate and obfuscated PHP malware Remote payload loaders Malicious cron jobs Systemd persistence Suspicious scheduled tasks Injected .htaccess files Injected .user.ini files Malicious Composer/autoload injections Database-injected malware Malicious admin users Unauthorized accounts Suspicious SSH activity Cryptominers Malicious ELF binaries Server-level malware Web-based backdoors Persistent malware WORDPRESS SECURITY WordPress malware removal WordPress security audit WordPress malware investigation WordPress backdoor detection Malicious plugin detection Malicious theme detection Hidden administrator detection WordPress database cleanup WordPress file integrity checks WordPress hardening WordPress firewall configuration WordPress login protection XML-RPC security File permission hardening Security plugin configuration Post-cleanup security monitoring LINUX SERVER SECURITY Linux malware investigation Linux server hardening Root-level malware investigation Suspicious process analysis ELF malware investigation Cron persistence analysis Systemd persistence analysis SSH security Unauthorized user investigation File integrity analysis Network connection analysis Listening port investigation Suspicious outbound connection analysis Process and service investigation Log analysis Server compromise investigation Incident response Post-compromise security hardening WEB APPLICATION SECURITY I perform security assessments and vulnerability testing for websites and web applications, including: Vulnerability Assessment and Penetration Testing OWASP Top 10 Web application security testing API security testing Authentication testing Authorization testing Session security Access control testing SQL Injection Cross-Site Scripting CSRF SSRF File upload vulnerabilities Command injection Path traversal Security misconfiguration Broken access control API vulnerabilities Business logic vulnerabilities Information disclosure Security headers SSL/TLS configuration Authentication and authorization weaknesses SECURITY TOOLS AND TECHNOLOGIES Burp Suite Burp Suite Professional OWASP ZAP Nmap Nessus OpenVAS HCL AppScan Splunk ELK Kibana CrowdStrike Falcon Microsoft Defender Cloudflare Wordfence Sucuri Linux Windows Server Apache Nginx cPanel Plesk WHM Cloudways Hostinger DigitalOcean AWS Azure INCIDENT RESPONSE When a website or server is compromised, I can perform a structured investigation to determine: What was compromised How the attacker gained access Which files were modified Which accounts were created Whether backdoors are present Whether persistence mechanisms exist Whether credentials may have been compromised What malicious processes are running What external IPs or domains were contacted Whether other websites or accounts are affected Whether the attacker still has access I can analyze logs, processes, file modifications, cron jobs, system services, network connections, database entries, application files, and suspicious artifacts to build a clear picture of the compromise. SECURITY HARDENING After malware removal or a security assessment, I can harden the environment by addressing: File permissions User privileges SSH configuration Web server configuration PHP configuration Firewall rules Security headers CMS configuration Plugin and theme security Database security Admin account security Authentication controls Cloudflare configuration WAF rules Rate limiting Bot protection DDoS protection Backup security Logging and monitoring Vulnerability management CLOUDFLARE SECURITY I also provide Cloudflare security and protection services, including: Cloudflare WAF Cloudflare Firewall Rules Custom WAF Rules DDoS Protection Bot Management Bot Fight Mode Rate Limiting Security Rules Origin IP Protection SSL/TLS DNS Security CDN configuration Cache security Country and IP filtering API protection Cloudflare Zero Trust Cloudflare Tunnel Security Event analysis Malicious traffic mitigation MALWARE INVESTIGATION PROCESS My approach generally
Youssef E.
$25/hr
100% Job Success
$10K+ earned
Available now
Start of list.
End of list.
Youssef E. has worked .
I find the vulnerabilities in your web apps, APIs, and networks before attackers do, then hand your team a clear, reproducible penetration testing report they can act on. GXPN and GCIH certified. Top Rated on Upwork with 100% Job Success across web application, API, and network security engagements. No scanner dump and no jargon wall. Every finding comes with a severity rating (CVSS), working proof of concept, and a concrete fix your developers can ship. What I test: - Web application penetration testing (OWASP Top 10, PTES, NIST) - API security testing (REST, GraphQL, auth/OAuth, IDOR, broken access control) - SaaS and multi-tenant assessments (Supabase / Firebase data-isolation testing) - Network and external perimeter penetration testing - Source code / secure code review How I work: authorized testing only, on systems you own or have permission to test. Everything is documented over Upwork so you get a written record of every finding, not a verbal hand-wave. I retest after you patch to confirm the holes are actually closed. Credentials: GXPN (GIAC Advanced Penetration Tester & Exploit Researcher), GCIH (GIAC Certified Incident Handler), SANS CTF winner, and an active national/international CTF competitor (web, reverse, crypto, forensics). I also handle WordPress malware removal and incident response. See my Project Catalog for a fixed-price option.
Syed Jan Muhammad Z.
$30/hr
100% Job Success
$2K+ earned
Available now
Offers consultations
Start of list.
End of list.
Syed Jan Muhammad Z. has worked .
👏𝐀𝐩𝐩𝐫𝐞𝐜𝐢𝐚𝐭𝐞𝐝 STEX is grateful for your significant contribution to the information security of the project and we recommend you as an IT security professional. Please continue your useful work and do not tire of making the Internet better! - 𝐎𝐥𝐚𝐟 𝐇𝐚𝐧𝐬𝐞𝐧 - 𝐁𝐮𝐬𝐢𝐧𝐞𝐬𝐬 𝐃𝐞𝐯𝐞𝐥𝐨𝐩𝐦𝐞𝐧𝐭 𝐌𝐚𝐧𝐚𝐠𝐞𝐫 𝐨𝐧 𝐒𝐓𝐄𝐗 🙋‍♂️𝐀𝐛𝐨𝐮𝐭 𝐌𝐞 ✅ 8+ years of Industry Experience in Penetration Testing of Web, Mobile, API's, Cloud and network ✅ Experienced Security Professional; Trusted by Enterprises & Startups ✅ CEH (Practical) & CRTP Certified ✅ Identified 1000+ vulnerabilities in infrastructure and applications 🏆𝐍𝐨𝐭𝐚𝐛𝐥𝐞 𝐚𝐜𝐡𝐢𝐞𝐯𝐞𝐦𝐞𝐧𝐭𝐬 ✅ Discoverer of CVE-2024-3121 ✅ Recognized by LinkedIn, Stex, GlobalSign other enterprise platforms 💡𝐖𝐡𝐲 𝐌𝐞? ✅Beyond Automated Testing - Unique in depth and manual RSER penetration testing methodology, beyond automated scans to reduce false positives. ✅ Collaborative Approach - Actively collaborate with your development team to help fix the vulnerabilities ✅Controlled Testing - Testing in a safe and controlled environment, aligned with OWASP TOP 10 and PTES Standards. ✅Professional Reporting - Clear, professional, technical and detailed reporting with evidence of exploitation and remediation guidance for each vulnerability. ✅Executive Summary Report - Unique high-level summary crafted for executives and investors, translating technical findings into business risks and actionable insights. ✅Pentest Letter of Attestation (LoPT) - A formal proof of testing confirming your system has undergone professional penetration testing. Ideal for clients, partners, or compliance verification. 🙌Let’s connect! I can show you how I deliver thorough, transparent testing, produce reports that meet industry standards, and work closely with your team to fix vulnerabilities efficiently.
Faizan I.
$10/hr
97% Job Success
Available now
Offers consultations
Start of list.
End of list.
Faizan I. has worked .
Hi Availability 40+ hour/week I help SaaS, AI, web, mobile, and eCommerce teams release stable, user-ready products through Software QA, Manual Testing, Test Automation, API Testing, Mobile App Testing, Web App Testing, Regression Testing, Functional Testing, and clear Bug Reporting. I work as a Software QA Engineer / QA Automation Engineer who can test your product from both the user side and the technical side. My goal is simple: give your team clear test coverage, clean reports, real evidence, and practical release feedback before your customers find problems. My core QA services include: ✅ Manual Testing • Web App Testing • Mobile App Testing • Functional Testing • Regression Testing • Smoke Testing • Sanity Testing • Exploratory Testing • Usability Testing • User Acceptance Testing • Cross-Browser Testing • Responsive Testing • Test Case Design • Test Plan Creation • QA Documentation ✅ QA Automation • Playwright Testing • Cypress Testing • Selenium Automation • Appium Testing • End-to-End Testing • Regression Automation • UI Automation • CI/CD Testing • GitHub Actions test support • Stable automation for repeated test journeys ✅ API & Backend Validation • API Testing with Postman • REST API Testing • Swagger and Open API validation • Authentication testing • Request and response validation • Negative test cases • Data validation • Frontend and backend result comparison ✅ Mobile QA Testing • Android App Testing • iOS App Testing • Real-device testing • Emulator and simulator testing • Onboarding, login, payment, chat, wallet, push notification, and subscription testing • Mobile UI, responsiveness, crash, and performance checks ✅ AI & Modern QA Testing • AI Testing • AI SaaS Testing • LLM Testing • Chatbot Testing • Prompt-based testing • AI output validation • Edge-case testing for AI-generated responses • Accuracy, consistency, and usability checks for AI products Tools I work with: Playwright, Cypress, Selenium, Appium, Postman, Swagger, Jira, Trello, ClickUp, TestRail, Qase, Zephyr, BrowserStack, LambdaTest, GitHub, GitHub Actions, Chrome DevTools, Android Studio, Xcode, and CI/CD pipelines. What you will get: • Clear test cases based on your requirements • Structured bug reports with steps, screenshots, videos, logs, severity, priority, expected result, and actual result • Fast QA updates during testing • Practical feedback on usability, layout, responsiveness, and product behavior • Regression testing before release • API and UI validation together • Cross-browser and cross-device coverage • Automation support for repeated test journeys • Release-focused QA support for founders, developers, product managers, and agencies I focus on the areas that matter most in real products: login, signup, dashboard, checkout, payments, subscriptions, admin panels, role permissions, forms, search, filters, notifications, API responses, mobile screens, browser differences, and release blockers. I have experience testing SaaS platforms, AI products, mobile apps, eCommerce stores, dashboards, CRM systems, healthcare platforms, FinTech products, marketplaces, and business web applications. If you need a QA Engineer who can handle Manual Testing, QA Automation, API Testing, Web App Testing, Mobile App Testing, Regression Testing, AI Testing, and professional Bug Reporting, I can help you test your product properly before launch and support your team after release. SKILLS: Software Testing | QA Testing | Quality Assurance | Software QA | Manual Testing | Functional Testing | Regression Testing | Web App Testing | Mobile App Testing | Android App Testing | iOS App Testing | API Testing | Postman API Testing | End-to-End Testing | Test Case Design | Bug Reporting | Bug Tracking | Usability Testing | Test Automation | Automated Testing | Playwright Testing | Cypress Testing | Selenium Automation | Appium Testing | AI Testing | AI Test Automation | Generative AI Testing | LLM Testing | Performance Testing | Security Testing
$100/hr
84% Job Success
$10K+ earned
Available now
Offers consultations
Start of list.
End of list.
Hassan J. has worked .
Welcome to the profile of a renowned ethical hacker and bug bounty hunter, ranked among the top 400 hackers on Bugcrowd. With a remarkable portfolio that includes accolades from industry titans such as Samsung, Binance, cPanel, and F5, I bring unrivalled expertise and a track record of accomplishment to the table. What I Offer: Ethical Hacking Excellence: With extensive technical skills and an unwavering resolve to find vulnerabilities, I specialise in detecting and addressing security threats across a wide range of platforms and situations. Whether it's web apps or mobile apps, I have the expertise and knowledge to effectively strengthen your digital defences. Bug Bounty Mastery: As an experienced bug bounty hunter, I have gained the trust of major corporations by my careful methodology and unrelenting dedication to perfection. My contributions have been recognised by reputable businesses such as Samsung, Binance, cPanel, F5, and many others, demonstrating my ability to generate results that exceed expectations. Beyond bug finding, I provide full security consulting services that are tailored to your individual requirements. Whether you need strategic advice on On cyber security best practices or hands-on support in remediation efforts, I deliver practical insights to help you protect your assets and reduce any threats in advance. Why Choose Me: Trusted by Industry Leaders: My track record of accomplishment speaks for itself, with accolades from top-tier firms demonstrating my knowledge and professionalism. When you work with me, you will receive access to the same degree of expertise that has gained the trust of industry leaders globally. Proactive Approach: I believe in staying one step ahead of cyber threats by taking a proactive approach to security. By conducting extensive evaluations and executing effective mitigation measures, I assist customers in reducing potential hazards before they become full-fledged catastrophes. Collaborative collaboration: I see each client interaction as a collaborative collaboration with the goal of mutual success. I prioritise open communication, openness, and reactivity to guarantee that your individual demands and objectives are precisely satisfied. Let us strengthen your security posture: In an era of rising cyber dangers, investing in strong cyber security measures is critical for protecting your company's integrity and reputation. Partner with me to strengthen your defences, reduce potential risks, and remain ahead of the curve in today's ever-changing threat landscape. Contact me today to discuss how we help improve your security posture and secure what matters most to you.
Chakradhar C.
$50/hr
100% Job Success
$70K+ earned
Start of list.
End of list.
Chakradhar C. has worked .
✅ Top Rated Plus Expert ✅ 1000+ Hours ✅ Professional Penetration Tester Senior Penetration Tester with more than 7+ years of rich industry experience in Web, Mobile, API, and Network Penetration Testing. I have successfully completed 500+ Web application Pentests, 200+ Mobile Application Penetration Tests, 300+ API Penetration Tests, 100+ External Network Penetration Tests and 30+ Internal Penetration Tests. I am also a Security researcher acknowledged by Yahoo (among other notable companies like SolarEdge, Imgur, Artsy, etc.) for disclosing a number of vulnerabilities via the HackerOne bug bounty platform. My core competency is Blackbox, Greybox Testing on Web, API, Mobile, and Network applications. I am familiar with all attacks and mitigations and am well-versed in OWASP, NIST, and PTES Frameworks. My Pentesting reports include clear documentation of the vulnerabilities found along with the remediations to make sure the client is 100% satisfied. I am also certified in AWS, and Azure and have a very keen knowledge of Cloud Security and cloud administration. ✅ I have conducted Penetration Tests, Vulnerability Assessments and delivered professional reports to companies around the world complying with the following: ►OWASP Web Security Top 10 Vulnerability ►OWASP API Security Top 10 Vulnerability ►OWASP Mobile Security Top 10 Vulnerability ►External Network Penetration Testing ►Internal Network Penetration Testing ►Payment Card Industry Data Security Standard (PCI DSS) ►System and Organization Controls 2 (SOC2) ►General Data Protection Regulation (GDPR) ►Common Vulnerability Scoring System (CVSS) ►Open Source Security Testing Methodology Manual (OSSTMM) My Certs include: ►CompTIA Pentest+ (Expired) ►AWS Solutions Architect (Expired) ►Azure Administrator (Expired) Tools: Burp Suite, Nikto, Nmap, Zap, Metasploit, Nessus, W3af, Ffuf, Dirb, etc... I am available 24/7. If you are interested in cooperation, drop me a line :)
Hoang Nhan L.
$25/hr
100% Job Success
Available now
Start of list.
End of list.
Hoang Nhan L. has worked .
✅ As a CREST/Offensive Security (OSCP) Certified Penetration Tester and Cyber Security Consultant, I have deep knowledge of Security Assessment Methodology to identify vulnerabilities in Network, API, Web, and Mobile Applications. ✅ I have conducted Penetration Test, Vulnerability Assessment and delivered professional reports to companies in the world complying with: ► CREST standards ► Offensive Security (OSCP) standards ► OWASP Top 10 Vulnerability ► OWASP API Security Top 10 Vulnerability ► OWASP Mobile Security Top 10 Vulnerability ► Application Security Verification Standard 4.0 (ASVS 4.0) ► CWE Top 25 Most Dangerous Software Errors ► ISO 27001 Penetration Testing ► Payment Card Industry Data Security Standard (PCI DSS) ► General Data Protection Regulation (GDPR) ► Common Vulnerability Scoring System (CVSS) ► Open Source Security Testing Methodology Manual (OSSTMM) ✅ I have some cybersecurity certifications including: ► CREST Registered Penetration Tester (CRT) ► CREST Practitioner Security Analyst (CPSA) ► Offensive Security Certified Professional (OSCP) ✅ The deliverable will be a professional Penetration Testing/Vulnerability Assessment report which includes: ► Executive Summary ► Assessment Methodology ► Type of Tests ► Risk Level Classifications ► Result Summary ► Table of Findings ► Detailed Findings. Each finding listed within the report will contain CVSS score, Issue Description, Proof of Concept, Remediation, and Reference sections. ► Tool List (Acunetix, Nessus, BurpSuite Professional, Nmap, Netsparker, Metasploit Framework, OpenVAS, Mimikatz, SQLmap, Nikto, Zaproxy, Gobuster, etc.) ✅ Please contact me if you have any question. ✅ Thank you and have a good day!
GM Salman A M.
$30/hr
100% Job Success
$10K+ earned
Available now
Start of list.
End of list.
GM Salman A M. has worked .
🚨 If your application, SaaS platform, or cloud environment has never undergone a professional security assessment, you may have unknown vulnerabilities that attackers can exploit. I’m a Certified Penetration Tester and Ethical Hacker providing Vulnerability Assessment and Penetration testing (VAPT) services for web applications, APIs, cloud infrastructure, mobile apps, SaaS platforms, and network environments. My goal is not just to find vulnerabilities — but to help you understand real security risks and fix them effectively. I perform manual penetration testing supported by professional security tools to identify exploitable weaknesses such as authentication flaws, privilege escalation paths, injection vulnerabilities, and business logic issues. You will receive a clear and actionable security report that helps developers resolve issues and allows management to understand the real business impact. 🎯 My Services - Vulnerability Assessment & Penetration Testing (VAPT) - Web Application Penetration Testing (OWASP Top 10) - API Penetration Testing (REST, GraphQL, authentication flaws, IDOR, injection) - Cloud Infrastructure Security (AWS, Azure — misconfigurations, IAM, exposed services) - Network Penetration Testing (internal & external) - Mobile Application Security (Android & iOS) - SaaS Platform Security & Penetration Testing (multi-tenant logic, RBAC, privilege escalation) - CMS Security (WordPress, Laravel, custom apps) - Retesting after remediation 📋 What You Will Receive A clear, structured security report designed for both technical teams and business stakeholders, including: • Executive summary for management and decision-makers • Detailed vulnerability findings with severity ratings • CVSS scoring and risk prioritization • Proof-of-concept evidence (screenshots, request/response captures) • Business impact explanation for each issue • Step-by-step remediation guidance for developers • Retesting validation after fixes are applied • Reporting that can support ISO 27001 and SOC 2 compliance preparation 🏆 Certifications - Certified Ethical Hacker Practical — EC-Council - eLearnSecurity Junior Penetration Tester (eJPT) — INE - Certified API Penetration Tester — APISec University - IBM Cybersecurity Analyst - Cisco Verified Ethical Hacker - ISO 27001:2022 Lead Auditor 🛠️ Tools I work with Burp Suite Pro, OWASP ZAP, Nmap, Nessus, Metasploit, MobSF, Wireshark, Postman, and custom Python/Bash scripts and so on. Whether you're preparing for a security review, compliance audit, or investor due diligence, I can help you understand your attack surface and security risks. 📩 Send me your scope or asset list and I’ll help you determine the best testing approach.
$55/hr
100% Job Success
$30K+ earned
Available now
Offers consultations
Start of list.
End of list.
Ehtisham F. has worked .
I help SaaS companies, dev teams, and startups find and fix security vulnerabilities before attackers do, through manual penetration testing, not automated scans. CRTO & CPTS Certified | 5+ years in offensive security | 49 projects completed | 94% Job Success Score I've delivered 50+ security assessments for clients worldwide, helping them prevent an estimated $100,000+ in potential breach costs and meet compliance requirements under OWASP, ISO 27001, and SOC 2. Services I provide: Web Application Penetration Testing: OWASP Top 10, business logic flaws, RCE, SQLi, XSS, IDOR/BOLA, SSRF, tenant isolation issues in multi tenant SaaS API Security Testing: REST, SOAP, and GraphQL. Broken auth, token misuse, injection, rate limit bypass Mobile Application Penetration Testing: iOS and Android, static and dynamic analysis, insecure local storage, hardcoded secrets, cert/TLS handling Cloud & SaaS Backend Security: AWS configuration review (IAM, S3, API Gateway), Supabase/Postgres Row Level Security review, service role and auth flow testing Internal Network & Active Directory Pentesting: Kerberoasting, misconfigurations, lateral movement paths External Network Pentesting: DNS leaks, open ports, exposed services, privilege escalation Windows Desktop Application Testing: binary analysis, insecure storage, reverse engineering OSINT & Recon Assessments: exposed employee, asset, and sensitive data discovery Vulnerability Assessment & Retesting: gray box and white box methodologies, verified PoCs, prioritized remediation reports, post fix retest and attestation I test against recognized standards (OWASP Testing Guide, NIST SP 800-115, PTES) and can produce reports suitable for SOC 2 Type I/II audit evidence. Recent results: Hardened a healthcare SaaS platform, closing gaps that would have caused HIPAA violations Tested API endpoints for a fintech client, cutting the exposed attack surface by 43% Found Active Directory misconfigurations that would have allowed full domain compromise Helped a startup pass its security audit ahead of a $2.5M funding round Why clients keep hiring me back: Certified in offensive security (CRTO, CPTS) and red teaming. Deep manual testing, not just scanner output Developer ready reports with CVSS scores and reproducible proof of concept steps Retesting included after fixes, so you know the issue is actually closed Fast communication, usually within a few hours Comfortable embedding into a DevSecOps pipeline for ongoing coverage