You will get a thorough security assessment of your Web App or Cloud Architecture

Fotios B.Status: Offline
Fotios B. Fotios B.
4.9
Top Rated

Let a pro handle the details

Buy Assessments & Penetration Testing services from Fotios, priced and ready to go.
Fotios B.Status: Offline
Fotios B. Fotios B.
4.9
Top Rated

Let a pro handle the details

Buy Assessments & Penetration Testing services from Fotios, priced and ready to go.

Project details

You will get is an original and well thought out IT Security consultation, that will fully leverage my skills and experience while being tailored around your particular requirements. It will be delivered in a professionally written document (in both doc and pdf format).

I am an IT Security specialist with 15+ years of hands on design and development experience in real world systems (both Linux and Windows platforms) as well as in PoCs created as part of Cybersecurity related academic research projects. The breadth and depth of skills and expertise I possess is very significant and can help me discover not just the specific issues with a particular solution or technology but also have a better grasp of the big picture and the long term effects of certain architectural and solution deployment choices. I have good experience with all three major cloud service providers: GCP, AWS and Azure and I have developed and deployed real world solutions on all of them, some even involving HSM services (AWS)

Please also note that I am recommended by the head of Privacy Engineering @ Android on my LinkedIn page (check my Upwork profile here to find it).
Cybersecurity Expertise
Audit, Cyber Threat Intelligence, Risk Assessment
Technology Type
Firewall, IaaS, Computer Network, Database, Operating System, SaaS, Web Application, CRM, Email System, ERP
Cybersecurity Regulation
GDPR, ISO, HIPAA, NIST Cybersecurity Framework, PCI DSS

What's included $150

These options are included with the project scope.

$150
  • Delivery Time 1 day
    • Application Audit
4.9
76 reviews
95% Complete
5% Complete
1% Complete
(0)
1% Complete
(0)
1% Complete
(0)

JD

James D.
5.00
Jun 25, 2026
IT Professional for AI and Cybersecurity Alex is exceptional, met every milestone and always kept me informed throughout the milestones

RV

Raul V.
5.00
Apr 2, 2026
Help needed to publish App in the Microsoft Store Another great project with Alex! He is prompt, reliable and knowledgeable of his craft.

GW

George W.
5.00
Mar 4, 2026
Configure Backup Solution for Google Workspace Drive Fantastic communication, thorough work, trustworthy, affordable, great English!
I will recommend Alex to my clients who need his level of expertise.

RV

Raul V.
5.00
Feb 9, 2026
MS Word & Excel Add-in development We have worked with Alex several times over the past few years. He is a true professional developer with good communication skills and always goes the extra mile to make sure the project is successful. He has a thorough understanding of Microsoft 365 inner workings and helped us develop a Microsoft 365 add-in with Intune & SSO security. Will definitely hire Alex again for future projects.

JP

Joshua P.
5.00
Sep 22, 2025
PPT Add on that exports data Second great project
Highly recommend
Fotios B.Status: Offline

About Fotios

Fotios B.Status: Offline
IT Commando
100% Job Success
4.9  (76 reviews)
Blumenau, Brazil - 4:30 pm local time
Coding AIs have made the average human developer obsolete for low-end, commonly used software like typical three-tier web apps, e-commerce sites, basic CRUD tools, simple desktop apps, etc. because they can generate the needed structures and code faster and cheaper than most freelancers.

However, AIs, still largely fail on projects that actually require true engineering judgment and real world experience. Novel architectures, large codebases, systems with unusual requirements or high-stakes IT security related work, expose the hard to bridge gap between semantics and pragmatics. LLMs excel at pattern-matching prima facie meaning from training data but they cannot sustain long-term logical coherence, invent pragmatic solutions for projects with requirements that never appeared (or appeared very little) in the subject matter, or keep the thread of a system design alive, when context buffers fill and earlier decisions and actions fade from their memory. They may get into loops of repeatedly choosing the wrong high-level logic, the wrong tech stack and the wrong security model, even through they can implement any single function to perfection. Those limits, in both resources and the very nature of LLMs as reasoning tools, can turn complex projects into a series of wrong turns that drift the outcome more and more off course.

My job is to guide and orchestrate the best of those AIs and their ecosystems (AIs like Claude, ChatGPT and Grok) through the decisions they cannot make correctly on their own. I often use more than one for the same project, sometimes in a mutual devil's advocate role. I draw up the basics of the architecture early and then iteratively fine-tune it, correct tech-stack choices before they compound into hard to untie tech knots, and keep the overall design coherent while the models handle the bulk of the tedious coding. I also integrate AI capabilities, e.g. fine tuned local LLMs, multi-agent pipelines, into production stacks making sure the models do not over-engineer, as they do have a tendency to.

Here are some specific AI driven design and implementation challenges I had to deal with:

- Project characteristics: AI-driven Windows endpoint protection (WFP kernel drivers, dual local LLaMA pipeline, ETW/Sysmon consumption, behavioral SOAR, cryptographically secured update channels). The LLM repeatedly proposed user-mode architectures that ignored kernel realities and secure update techniques.

- Multi-agent behavioral video surveillance pipelines (OpenCV, YOLO, Gemini/Claude). Models kept coming up with detection logic that failed under real camera noise, edge timing, and partial occlusion.

- Complex, often AI-assisted scraping and click bots. I routinely take on projects that coding AIs refuse to do because they get hung up on legal or TOS implications that, once examined against the pragmatics of the actual use case, simply do not apply. I have delivered residential IP proxies, stealth automation, adaptive auto-engagement headless browser farms for Facebook, Quora, Reddit, and similar work, all major coding LLMs will not even discuss.

In a recent project the client needed a Windows authentication & session-access system, integrating endpoints, Domain Controllers, smart cards, TPMs/HSMs, RDP tunnels and AD. Even Claude Opus 5.0 (currently the top-ranked coding LLM) could not produce an initial architecture that came close to satisfying the often implied requirements and constraints. Every early decision, like high level architecture, security model, protocols used and Windows APIs chosen, required near-manual intervention from me, before the model could usefully implement anything.

Critical cybersecurity is another domain where models require continuous human correction. HSM/TPM integration, hardware-token systems, top grade cryptography, root CAs, and flexible injection of SSO authentication to existing stacks, demand pragmatic trade-offs and threat models that the leading AIs need a lot of help to get right.

I led the development of the European Root Certification Authority for the EU Digital Tachograph (dtc.jrc.ec.europa.eu) while at the European Commission's Cybersecurity dept. I have hands-on experience with CloudHSM, KMS, TPMs, FEA-level security, and cryptographic protocol design under real regulatory and continent wide industry pressure.

Other skills: Kernel C/C++ development, WinUI 3/WPF, multi-LLM pipelines (Claude, local LLaMA, ONNX/NPU), LangChain/FAISS/OpenCV/YOLO, Node.js, Microsoft & Google APIs, MySQL/PostgreSQL/SQL Server, VSTO/Office.js, Puppeteer/Playwright, browser extensions, LAMP/Laravel, Azure AD/SSO, AWS & GCP, cryptography/steganography/HSM/TPM, programmatic PDF generation/editing, OAuth/Keycloak, VPN/TAP drivers, NDI streaming, reverse residential proxies.

I excel at doing the work the LLMs still cannot, and I make the LLMs offer the most under careful and informed human scrutiny. AIs are my friends and we work together to bring your vision to life.

Steps for completing your project

After purchasing the project, send requirements so Fotios can start the project.

Delivery time starts when Fotios receives requirements from you.

Fotios works on your project following the steps below.

Revisions may occur after the delivery date.

Requirements refinement

I interact with the client in several ways until the requirements are well fleshed out and with enough technical insight added to them.

Security Assessment & Penetration Testing

I will review the architecture, software components, and source code of your solution, and in the case of web apps or servers being security assessed, I will also perform penetration testing using several tools. I will interact with you as needed.

Review the work, release payment, and leave feedback to Fotios.