Talent badge filter
Skills filter
Chakradhar C.
$50/hr
100% Job Success
$70K+ earned
Start of list.
End of list.
Chakradhar C. has worked .
✅ Top Rated Plus Expert ✅ 1000+ Hours ✅ Professional Penetration Tester Senior Penetration Tester with more than 7+ years of rich industry experience in Web, Mobile, API, and Network Penetration Testing. I have successfully completed 500+ Web application Pentests, 200+ Mobile Application Penetration Tests, 300+ API Penetration Tests, 100+ External Network Penetration Tests and 30+ Internal Penetration Tests. I am also a Security researcher acknowledged by Yahoo (among other notable companies like SolarEdge, Imgur, Artsy, etc.) for disclosing a number of vulnerabilities via the HackerOne bug bounty platform. My core competency is Blackbox, Greybox Testing on Web, API, Mobile, and Network applications. I am familiar with all attacks and mitigations and am well-versed in OWASP, NIST, and PTES Frameworks. My Pentesting reports include clear documentation of the vulnerabilities found along with the remediations to make sure the client is 100% satisfied. I am also certified in AWS, and Azure and have a very keen knowledge of Cloud Security and cloud administration. ✅ I have conducted Penetration Tests, Vulnerability Assessments and delivered professional reports to companies around the world complying with the following: ►OWASP Web Security Top 10 Vulnerability ►OWASP API Security Top 10 Vulnerability ►OWASP Mobile Security Top 10 Vulnerability ►External Network Penetration Testing ►Internal Network Penetration Testing ►Payment Card Industry Data Security Standard (PCI DSS) ►System and Organization Controls 2 (SOC2) ►General Data Protection Regulation (GDPR) ►Common Vulnerability Scoring System (CVSS) ►Open Source Security Testing Methodology Manual (OSSTMM) My Certs include: ►CompTIA Pentest+ (Expired) ►AWS Solutions Architect (Expired) ►Azure Administrator (Expired) Tools: Burp Suite, Nikto, Nmap, Zap, Metasploit, Nessus, W3af, Ffuf, Dirb, etc... I am available 24/7. If you are interested in cooperation, drop me a line :)
Afaq H.
$30/hr
100% Job Success
$4K+ earned
Offers consultations
Start of list.
End of list.
Afaq H. has worked .
🔐 𝐀𝐛𝐨𝐮𝐭 𝐌𝐞 Looking for a top-class, confidential, and results-driven penetration testing (pentesting) expert at reasonable rates? You’re in the right place. I am a Cybersecurity Specialist currently securing PureHealth, the UAE's largest healthcare group, where I work across security audits, infrastructure assessments, and enterprise risk management. Before this, I served as Manager, Cybersecurity at Nayatel, where I led offensive security initiatives and supervised comprehensive security assessments across corporate, financial, telecom, education, and government sectors. I hold the OSCP+ certification and have built a Top Rated reputation on Upwork through independent penetration testing and security consulting engagements. Beyond my technical work, I am a public speaker, trainer, and content creator, sharing practical cybersecurity knowledge with a community of 9,000+ followers. 💼 𝐖𝐡𝐲 𝐂𝐥𝐢𝐞𝐧𝐭𝐬 𝐓𝐫𝐮𝐬𝐭 𝐌𝐞 𝐏𝐫𝐨𝐯𝐞𝐧 𝐈𝐧𝐝𝐮𝐬𝐭𝐫𝐲 𝐄𝐱𝐩𝐞𝐫𝐭𝐢𝐬𝐞: I have personally conducted or overseen 85+ penetration tests in the past year, covering Web Apps, Mobile Apps (iOS & Android), APIs, Networks, Cloud Infrastructure, Active Directory, and AI-driven systems. 𝐃𝐞𝐞𝐩 𝐁𝐮𝐬𝐢𝐧𝐞𝐬𝐬 𝐔𝐧𝐝𝐞𝐫𝐬𝐭𝐚𝐧𝐝𝐢𝐧𝐠: I don’t just run automated scans; I analyze business logic vulnerabilities and perform manual blackbox testing to uncover real-world risks that automated tools miss. 𝐂𝐥𝐢𝐞𝐧𝐭-𝐅𝐢𝐫𝐬𝐭 𝐂𝐨𝐥𝐥𝐚𝐛𝐨𝐫𝐚𝐭𝐢𝐨𝐧: I maintain transparent communication throughout the engagement, ensuring you understand every finding, its impact, and how to fix it. 🧠𝐂𝐞𝐫𝐭𝐢𝐟𝐢𝐜𝐚𝐭𝐢𝐨𝐧𝐬 My credentials speak for my commitment and technical depth: OSCP+ | OSCP | Pentest+ | PT1 | CRTA | CSA 🧰 𝐓𝐞𝐜𝐡𝐧𝐢𝐜𝐚𝐥 𝐄𝐱𝐩𝐞𝐫𝐭𝐢𝐬𝐞 & 𝐓𝐨𝐨𝐥𝐬 My VAPT (Vulnerability Assessment & Penetration Testing) approach aligns with OWASP Top 10, NIST, and ISO 27001 standards. I use expensive industry-leading tools such as Burp Suite Professional, Nessus, Nexpose, Acunetix, and a wide array of custom scripts for blackbox testing and post-exploitation analysis. 🧾 𝐑𝐞𝐩𝐨𝐫𝐭𝐢𝐧𝐠 & 𝐒𝐮𝐩𝐩𝐨𝐫𝐭 You’ll receive a comprehensive report containing: 👉 Clear vulnerability descriptions 👉 Business risk ratings 👉 Step-by-step remediation guidance After delivery, I don’t disappear. I work with you until every vulnerability is fixed, offering unlimited retesting and validation. 🌐 𝐋𝐞𝐭’𝐬 𝐂𝐨𝐧𝐧𝐞𝐜𝐭 Whether you’re looking for a web app pentest, mobile app security audit, or a full-scale red team assessment, I bring a blend of technical precision, real-world insight, and business focus to every engagement. Send me a message today and 𝐥𝐞𝐭’𝐬 𝐣𝐮𝐦𝐩 𝐨𝐧 𝐚 𝐪𝐮𝐢𝐜𝐤 𝐙𝐨𝐨𝐦 𝐜𝐚𝐥𝐥 to discuss how I can help secure your systems, protect your business, and give you complete peace of mind. ==================== ✅ Keywords: Vulnerability Assessment | Penetration Testing | VAPT | Cybersecurity Expert | Web Application Penetration Testing (WAPT) | Mobile Application Penetration Testing (MAPT) | API Penetration Testing | Network Security Testing | Application Security Testing | Ethical Hacking | Security Assessment | Security Testing | Web App Security | API VAPT | Mobile App Security | OWASP Top 10 | Cybersecurity Testing | System Security Audit | Application Vulnerability Assessment | Information Security | Server Security Hardening | Risk Assessment | Penetration Tester | Security Audit Report | Cyber Risk Management | Vulnerability Scan | Security Compliance Testing | Security Analyst | Cloud Security Assessment | Security Configuration Review | Data Protection Testing | Infrastructure Security Testing | Web Security Audit | Bug Bounty | Red Team Assessment | White Hat Hacker | Burp Suite | OWASP ZAP | Metasploit | Nmap | Nikto | Wireshark | MobSF | Postman | Kali Linux | Nessus | Acunetix | OpenVAS | Invicti | Parrot OS | Hydra
Julian M.
$25/hr
100% Job Success
$30K+ earned
Start of list.
End of list.
Julian M. has worked .
As a CREST/Offensive Security (OSCP) Certified Penetration Tester, OffSec Web Expert (OSWE) and cybersecurity professional with 5 years of experience and more than 100 successful penetration tests completed, my purpose is to protect businesses and individuals from the ever-increasing cyber threats that we face in today's digital age. I believe that everyone deserves the peace of mind that comes with knowing their digital assets are secure and their data protected, and I'm passionate about using my expertise to make that a reality. With extensive experience in offensive security, I specialize in conducting Web Application, Mobile Application, Internal/External infrastructure, and Wireless infrastructure vulnerability assessments and penetration testing exercises. By working closely with organizations, I develop tailored solutions that meet their unique needs and help them achieve their security goals. But my work isn't just about technical expertise - it's about empowering businesses and individuals to achieve their objectives with confidence. I'm committed to building strong relationships with the organizations I collaborate with, so that I can truly understand their needs and work collaboratively to create effective solutions. My focus is always on providing value to those I work with. ✅ I have conducted Penetration Test, Vulnerability Assessment and delivered professional reports to companies complying with: ► CREST standards ► Offensive Security (OSCP) standards ► OWASP Top 10 Vulnerability ► OWASP API Security Top 10 Vulnerability ► OWASP Mobile Security Top 10 Vulnerability ► CWE Top 25 Most Dangerous Software Errors ► ISO 27001 Penetration Testing ► General Data Protection Regulation (GDPR) ► Common Vulnerability Scoring System (CVSS)
Ahmed P.
$65/hr
100% Job Success
$7K+ earned
Available now
Offers consultations
Start of list.
End of list.
Penetration Tester | Ethical Hacker | Red Team | Web & Network Security Need a Penetration Tester or Ethical Hacker to identify security vulnerabilities before attackers find them? I am a Cybersecurity Specialist and Penetration Tester specializing in Penetration Testing, Ethical Hacking, Red Teaming, Web Application Security, Network Security, Active Directory Security, API Security, Vulnerability Assessment, and Adversary Emulation. I help businesses find, validate, and clearly document security vulnerabilities across web applications, APIs, networks, cloud environments, and Active Directory infrastructure. My Cybersecurity and Penetration Testing services include: • Penetration Testing and Ethical Hacking • Web Application Penetration Testing • Network Penetration Testing • API Penetration Testing • Active Directory Penetration Testing • Red Team Operations and Adversary Emulation • Vulnerability Assessment and Security Testing • AWS and Cloud Security Testing • EDR Testing and Security Control Validation • Phishing Simulations and Social Engineering Assessments • Incident Response Support • OWASP Top 10 Security Testing • Security Assessment and Vulnerability Reporting • Threat Detection and TTP Research I have led 12+ Active Directory-focused CTF events with 120+ participants and have experience automating offensive security workflows, evaluating security solutions, building security test environments using Atomic Red Team and AWS Lambda, and executing controlled attack campaigns. I also have experience assessing APIs, web applications, enterprise networks, Active Directory environments, cloud infrastructure, and AI systems. Certifications: • PNPT - Practical Network Penetration Tester • CRTO - Certified Red Team Operator • CompTIA Security+ • CCNA My core skills include Penetration Testing, Cybersecurity, Ethical Hacking, Red Teaming, Network Security, Web Security, Application Security, Active Directory, Vulnerability Assessment, Vulnerability Management, API Security, Cloud Security, AWS Security, EDR, Adversary Emulation, OWASP, Incident Response, Threat Detection, Security Testing, and Offensive Security. If you need a Penetration Tester, Ethical Hacker, Red Team Specialist, or Cybersecurity Consultant for a security assessment, I can help identify vulnerabilities and provide clear actionable remediation recommendations.
Assumed Breach
Associated with
Assumed Breach
GM Salman A M.
$30/hr
100% Job Success
$10K+ earned
Available now
Start of list.
End of list.
GM Salman A M. has worked .
🚨 If your application, SaaS platform, or cloud environment has never undergone a professional security assessment, you may have unknown vulnerabilities that attackers can exploit. I’m a Certified Penetration Tester and Ethical Hacker providing Vulnerability Assessment and Penetration testing (VAPT) services for web applications, APIs, cloud infrastructure, mobile apps, SaaS platforms, and network environments. My goal is not just to find vulnerabilities — but to help you understand real security risks and fix them effectively. I perform manual penetration testing supported by professional security tools to identify exploitable weaknesses such as authentication flaws, privilege escalation paths, injection vulnerabilities, and business logic issues. You will receive a clear and actionable security report that helps developers resolve issues and allows management to understand the real business impact. 🎯 My Services - Vulnerability Assessment & Penetration Testing (VAPT) - Web Application Penetration Testing (OWASP Top 10) - API Penetration Testing (REST, GraphQL, authentication flaws, IDOR, injection) - Cloud Infrastructure Security (AWS, Azure — misconfigurations, IAM, exposed services) - Network Penetration Testing (internal & external) - Mobile Application Security (Android & iOS) - SaaS Platform Security & Penetration Testing (multi-tenant logic, RBAC, privilege escalation) - CMS Security (WordPress, Laravel, custom apps) - Retesting after remediation 📋 What You Will Receive A clear, structured security report designed for both technical teams and business stakeholders, including: • Executive summary for management and decision-makers • Detailed vulnerability findings with severity ratings • CVSS scoring and risk prioritization • Proof-of-concept evidence (screenshots, request/response captures) • Business impact explanation for each issue • Step-by-step remediation guidance for developers • Retesting validation after fixes are applied • Reporting that can support ISO 27001 and SOC 2 compliance preparation 🏆 Certifications - Certified Ethical Hacker Practical — EC-Council - eLearnSecurity Junior Penetration Tester (eJPT) — INE - Certified API Penetration Tester — APISec University - IBM Cybersecurity Analyst - Cisco Verified Ethical Hacker - ISO 27001:2022 Lead Auditor 🛠️ Tools I work with Burp Suite Pro, OWASP ZAP, Nmap, Nessus, Metasploit, MobSF, Wireshark, Postman, and custom Python/Bash scripts and so on. Whether you're preparing for a security review, compliance audit, or investor due diligence, I can help you understand your attack surface and security risks. 📩 Send me your scope or asset list and I’ll help you determine the best testing approach.
Hoang Nhan L.
$25/hr
100% Job Success
Available now
Start of list.
End of list.
Hoang Nhan L. has worked .
✅ As a CREST/Offensive Security (OSCP) Certified Penetration Tester and Cyber Security Consultant, I have deep knowledge of Security Assessment Methodology to identify vulnerabilities in Network, API, Web, and Mobile Applications. ✅ I have conducted Penetration Test, Vulnerability Assessment and delivered professional reports to companies in the world complying with: ► CREST standards ► Offensive Security (OSCP) standards ► OWASP Top 10 Vulnerability ► OWASP API Security Top 10 Vulnerability ► OWASP Mobile Security Top 10 Vulnerability ► Application Security Verification Standard 4.0 (ASVS 4.0) ► CWE Top 25 Most Dangerous Software Errors ► ISO 27001 Penetration Testing ► Payment Card Industry Data Security Standard (PCI DSS) ► General Data Protection Regulation (GDPR) ► Common Vulnerability Scoring System (CVSS) ► Open Source Security Testing Methodology Manual (OSSTMM) ✅ I have some cybersecurity certifications including: ► CREST Registered Penetration Tester (CRT) ► CREST Practitioner Security Analyst (CPSA) ► Offensive Security Certified Professional (OSCP) ✅ The deliverable will be a professional Penetration Testing/Vulnerability Assessment report which includes: ► Executive Summary ► Assessment Methodology ► Type of Tests ► Risk Level Classifications ► Result Summary ► Table of Findings ► Detailed Findings. Each finding listed within the report will contain CVSS score, Issue Description, Proof of Concept, Remediation, and Reference sections. ► Tool List (Acunetix, Nessus, BurpSuite Professional, Nmap, Netsparker, Metasploit Framework, OpenVAS, Mimikatz, SQLmap, Nikto, Zaproxy, Gobuster, etc.) ✅ Please contact me if you have any question. ✅ Thank you and have a good day!
$15/hr
89% Job Success
Available now
Start of list.
End of list.
Sahil D. has worked .
I fix cloud environments that are down, insecure, or failing an audit — mostly AWS, with real Azure administration work alongside it (roughly 60/40 across my recent projects) — and build the infrastructure so they don't get there again. 15 years running production workloads at scale: multi-AZ VPC architecture on AWS, VNet/resource group administration on Azure, EKS/ECS deployments, Terraform with remote state locking, and CI/CD pipelines with automated rollback. I've led SOC 2 Type 2 audits to zero major findings, cut MTTR by 30% with alarm-tied incident runbooks, and reduced cloud spend by 20% through right-sizing and Spot/Reserved Instance strategy. What I actually do: → AWS infrastructure design and hardening — VPC, EKS/ECS, RDS Aurora Multi-AZ, disaster recovery with sub-15-minute RTO → Azure administration — VNet configuration, resource group and subscription management, AD identity/access administration, Azure SQL and storage account setup → Terraform infrastructure-as-code — modular design, remote state, policy-as-code with OPA → CI/CD pipeline builds — GitHub Actions, CodePipeline, Azure DevOps, Jenkins, blue/green and canary deploys → DevSecOps and compliance engineering — SOC 2 Type 2, HIPAA risk assessments, PCI DSS, ISO 27001 readiness, security baked into the pipeline not bolted on after → Incident response and observability — CloudWatch, Azure Monitor, Prometheus/Grafana, PagerDuty, runbook automation Certified AWS Solutions Architect – Professional, Microsoft Certified: Azure Administrator Associate (AZ-104), and CISA. I've worked directly with fintech platforms (PCI DSS environments for banking clients including Zest.ai,BNZ, KiwiBank, ANZ, Westpac), healthcare SaaS (HIPAA PHI audits), and high-traffic e-commerce and payment platforms. If your infrastructure is down, insecure, or you're staring down an audit deadline — on AWS, Azure, or both — tell me what's actually broken. I'll tell you honestly what it takes to fix it.
Techtweek Infotech LLC
Associated with
Techtweek Infotech LLC
Benjamin V.
$50/hr
100% Job Success
$1M+ earned
Offers consultations
Start of list.
End of list.
ALGO is an engineering partner for organisations building technically demanding systems with advanced technologies. Our specialist capabilities span AI & Machine Learning, blockchain, immersive technologies, IoT, robotics, Game Tech, and algorithmic & quantitative systems. What differentiates ALGO is that we go beyond the specialist technology itself. We combine deep technical expertise with the end-to-end engineering required to turn ideas, requirements and prototypes into complete systems that work reliably in the real world. Our engineering capabilities include software development, data, cloud and DevOps, cybersecurity, QA, UX, integration, monitoring and operations. We can support the complete journey from architecture and development through integration, testing, deployment and operation. Clients can engage ALGO to deliver a complete solution or to add specialist engineering capability alongside their internal teams and existing technology partners. ALGO combines the production discipline of a systems integrator with the specialisation, agility, flexibility, direct accountability and senior attention of an engineering partner. Specialist technology. End-to-end engineering. Systems built for the real world.
ALGO ® 🏅 With Expert-Vetted Talent (Top 1%)
Associated with
ALGO ® 🏅 With Expert-Vetted Talent (Top 1%)
$3M+
earned
Hachani L.
$35/hr
100% Job Success
Available now
Offers consultations
Start of list.
End of list.
Hachani L. has worked .
What Makes Me Different ? (Top 10% on Upwork and 100% Job Success Rate since 2022) | 🛡️ 7+ Years in CyberSecurity, Application Security and Penetration Testing, Securing Multinational Companies. Experience across Technology , Travel-tech, banking, insurance, Healthcare, oil & gas, Technology and government. Experience Product Security, QA, DevSecOps, AWS security hardening, SAST/DAST pipelines, secure code review, infrastructure security, and vulnerability remediation across modern application stacks. 💼 Services Include : - Application Security & Penetration Testing - SOC 2 Type II Readiness Evidence & Hardening and Support - AWS Security 📜 My Industry Penetration Testing | Application Security certifications : OSCP – Offensive Security Certified Professional OSWE – Offensive Security Web Expert ECIR – Certified Incident Responder 🏆 My Recent Multinational Cybersecurity Project Experience 🔐 Financial & Banking Sector 🌍 Technology & Digital Platforms 🛡️ Insurance Sector 🛢️ Energy & Oil Sector 🏛️ Government & Public Sector 🏥 Healthcare Sector 🎓 Education & Universities Sector Penetration Testing | OSCP | OSWE | OSCE | OSEP | Web App Security | Network Security Testing | Mobile App Penetration Testing | API Security Testing | Security Assessment | Ethical Hacking | Application Security Testing | Bug Bounty | Red Team Assessment | White Hat Hacker | Vulnerability Scan | System Security Audit | Cloud Security Assessment | Security Compliance Testing | Risk Assessment | Cybersecurity Expert | Application Vulnerability Assessment | Server Hardening | Information Security | Security Audit Report | Cyber Risk Management | Secure Coding Review | Source Code Review | CI/CD Security Testing | Container Security (Docker/Kubernetes) | Cloud Security Testing | Threat Modeling | OWASP Top 10 | OWASP WSTG | SAST (Static Analysis Security Testing) | DAST (Dynamic Analysis Security Testing) | SAST (SAST Application Security Testing) | Mobile App Security | Web Security Audit | Security Configuration Review | Data Protection Testing | Infrastructure Security Testing | Application Security Automation | Burp Suite | OWASP ZAP | Metasploit | Nmap | Nikto | Wireshark | MobSF | Postman | Kali Linux | Nessus | Acunetix | OpenVAS | Invicti | Parrot OS | Hydra | web security | Nessus | Active Directory security Audit
Wafa A.
$15/hr
100% Job Success
$4K+ earned
Start of list.
End of list.
Wafa A. has worked .
💪 Top Rated I help startups, SaaS companies, and enterprises identify security vulnerabilities before attackers do. With 5+ years of cybersecurity experience, I specialize in manual penetration testing, application security, API security, cloud security, compliance assessments, and privacy audits. I have worked with organizations across the United States, United Kingdom, Germany, and Canada, delivering security assessments aligned with international standards and industry best practices. My assessments have uncovered critical vulnerabilities including Account Takeover, Remote Code Execution (RCE), IDOR, Authentication & Authorization flaws, Business Logic vulnerabilities, SSRF, XSS, CSRF, SQL Injection, Sensitive Data Exposure, Security Misconfigurations, and Insecure API Implementations. My Services Penetration Testing • Web Application Penetration Testing (OWASP Top 10) • Mobile Application Security Testing (Android & iOS) • REST & GraphQL API Security Testing • External & Internal Network Penetration Testing • Authentication & Authorization Testing • Business Logic Testing • Secure Code Review (SAST) • Cloud Security Assessments (AWS, Azure & GCP) Privacy & Tracking Audits I perform non-destructive privacy and tracking audits to evaluate how websites collect, process, and share user data without making any changes to production environments. My privacy audits include: • Tracking & Analytics Review (Google Analytics, Meta Pixel, LinkedIn Insight Tag, etc.) • Cookie & Consent Compliance Assessment • Third-Party Script & Tag Analysis • Privacy & Data Collection Review • Browser Storage Review (Cookies, Local Storage & Session Storage) • Sensitive Data Leakage Detection • Tracking Request Analysis • GDPR Privacy Assessment • Actionable Privacy & Security Recommendations Important: I do not modify, delete, or update website code, tracking configurations, analytics settings, or production systems. My work is strictly read-only and results in a detailed report highlighting privacy concerns, security risks, and practical recommendations for improvement. Compliance & Security Frameworks • CASA Tier 2 Security Testing • CMMC Level 2 • NIST SP 800-171 • NIST SP 800-53 • ISO 27001 • SOC 2 • GDPR Security Automation I develop custom security automation solutions that help organizations reduce manual effort and improve their security posture. Automation services include: • Vulnerability Management Automation • Security Testing Automation • Compliance Reporting Automation • Security Workflow Automation • Custom Security Scripts & Tools Technical Toolkit Security Tools • Burp Suite Professional • OWASP ZAP • Nmap • Nessus • Metasploit • SonarQube • Veracode • Appknox • Bandit Infrastructure & Cloud Security • Cloudflare • Imperva WAF • Firewall Configuration • Identity & Access Management (IAM) • Access Control Management • Database Security Programming & Automation • Python • Bash • Node.js • Java Why Clients Hire Me ✅ 5+ Years of Professional Cybersecurity Experience ✅ Manual Security Testing Not Just Automated Scanner Reports ✅ Clear, Actionable Reports with Risk Ratings and Remediation Guidance ✅ Independent Security Consultant (No Agency, No Subcontracting) ✅ Strong Communication Throughout the Engagement ✅ Flexible Across Multiple Time Zones (Including EST Overlap) Deliverables Every assessment includes: • Executive Summary • Technical Findings with Evidence • Risk Severity (CVSS/OWASP where applicable) • Step-by-Step Reproduction • Screenshots & Proof of Concept • Practical Remediation Recommendations • Optional Re-Testing After Fixes Due to client confidentiality, I do not publicly share full penetration testing reports. However, I can demonstrate redacted professional reports during a screen-sharing meeting or after an NDA is signed. Whether you need a comprehensive penetration test, a privacy and tracking audit, an application security assessment, or compliance guidance, I'm here to help you strengthen your security posture and reduce risk. Let's discuss your project.