Information Security Projects on Upwork
Find and secure information security projects on Upwork with Vollna. Our advanced filters, real-time alerts, and analytics help you bid smarter and work more efficiently.
Signup for free
to get access to all filter attributes and instant notifications when new jobs are posted.
Setup filter
Get access to over 30+ filter attributes, setup instant notifications, integrate with your CRM and marketing tools, and more.
Start free trial
287 projects
published for past 72 hours.
| Job Title | Budget | Published | |||
|---|---|---|---|---|---|
|
Microsoft 365 / Azure Security Specialist
Applied
|
not specified | 11 minutes ago |
3
|
||
|
We're a digital agency and tech services company hiring an experienced Microsoft 365 and Azure security specialist to join our team and strengthen our security capabilities. This is an ongoing contractor role (or potential full-time team member).
RESPONSIBILITIES: -Handle Microsoft 365 and Azure AD security assessments and audits -Conduct threat assessments and security hardening for client environments -Implement security best practices across M365 deployments -Build and maintain security documentation and playbooks -Advise clients on email security, Conditional Access, and DLP policies -Stay current on M365 security threats and Microsoft updates -Mentor junior team members on security concepts REQUIRED EXPERIENCE: -3+ years of hands-on Microsoft 365 / Azure AD security -Proven experience with incident response and breach remediation -Strong expertise in Exchange Online, Azure AD (Entra ID), and -Conditional Access -Understanding of email security threats, phishing, and malware -Ability to read and interpret M365 audit logs and security alerts -Strong communication skills (will work with clients directly) PREFERRED QUALIFICATIONS: -Microsoft Certified: Security Administrator (SC-900 or higher) -Certified Information Security Auditor (CISA) -AZ-500 (Azure Security Engineer) -CEH or equivalent ethical hacking certification -Experience in regulated industries (healthcare, finance, legal) -Background in security audits or compliance (SOC 2, ISO 27001) POSITION TYPE: -Contractor Role: 10-20 hours/week, ongoing (retainer-based) Or: Full-time employee hire -Flexible based on candidate preference
Budget:
not specified
11 minutes ago
|
|||||
|
Linux Server Security Investigation
Applied
|
$20
|
1 hour ago |
3
|
||
|
Below is the simple requirement.
[1] Check the source of unauthorised certain database table being deleted [2] Check the source of unauthorised certain database table being modified with a different contents. Date that this happened: 12 September 2026 / 13th September 2026. Deliverables • Identify source of unauthorised database access. • Block/remove source of unauthorised database access. • Identify and remove the backdoor files.
Fixed budget:
20 USD
1 hour ago
|
|||||
|
Linux Server Security Investigation
Applied
|
$20
|
1 hour ago |
3
|
||
|
Below is the simple requirement.
[1] Check the source of unauthorised certain database table being deleted [2] Check the source of unauthorised certain database table being modified with a different contents. Date that this happened: 12 September 2026 / 13th September 2026. Deliverables • Identify source of unauthorised database access. • Block/remove source of unauthorised database access. • Identify and remove the backdoor files.
Fixed budget:
20 USD
1 hour ago
|
|||||
|
Penetration Tester, IT Audit ,GRC and Compliance
Applied
|
$10 - $40
/ hr
|
1 hour ago |
3
|
||
|
Penetration Testing – Perform web, API, network, cloud, mobile, Active Directory, wireless, and segmentation testing across enterprise environments.
Security Architecture & Assessment: Design and review secure architectures across networks, applications, APIs, cloud environments, identity management, Zero Trust, and data protection. Security Testing: Conduct authorized testing of applications, APIs, networks, cloud platforms, mobile solutions, identity environments, wireless systems, and network segmentation. AI and Generative AI Security: Assess AI applications, language models, retrieval systems, AI agents, and integrations for security, privacy, and operational risks. Compliance and IT Audit: Perform gap assessments, control testing, audit-readiness activities, and compliance support across major security and privacy frameworks. Identity and Zero Trust Evaluation: Review authentication, authorization, privileged access, role-based access, and non-human identity controls. Risk and Vulnerability Management: Identify, prioritize, document, and monitor vulnerabilities and control gaps based on risk and business impact. Reporting and Remediation: Develop audit documentation, risk registers, management reports, remediation plans, and validation-testing results.
Hourly rate:
10 - 40 USD
1 hour ago
|
|||||
|
CMMC Level 2 Compliance Consultant / Cybersecurity Expert
Applied
|
$2,000
|
4 hours ago |
5
|
||
|
We are looking for an experienced cybersecurity compliance consultant to help our company prepare for CMMC Level 2 requirements.
The consultant should have practical experience helping companies assess their current cybersecurity environment, identify compliance gaps, implement required security controls, prepare documentation, and become ready for an independent assessment. The work will include reviewing our current IT and security environment, performing a gap assessment, developing a remediation plan, assisting our technical team with implementation, preparing policies and procedures, developing the System Security Plan, organizing compliance evidence, and performing a readiness review. Experience with CMMC Level 2, NIST cybersecurity requirements, CUI environments, Microsoft cloud environments, identity and access management, endpoint security, logging, vulnerability management, incident response, and security documentation is preferred. We are looking for someone with real implementation experience, not simply someone who provides templates or general compliance advice. When applying, please describe your previous experience helping companies with CMMC Level 2 readiness, your cybersecurity compliance background, and your general approach to a project like this. This may become an ongoing engagement as we work through assessment, remediation, implementation, documentation, and final readiness.
Fixed budget:
2,000 USD
4 hours ago
|
|||||
|
Meta Appeals Specialist — Help Reinstate Suspended Instagram/Facebook Accounts
Applied
|
not specified | 4 hours ago |
4
|
||
|
I'm looking for a lawyer or specialist experienced with the Digital Services Act (DSA) and social media account appeals to help me challenge an unfair account suspension by Meta.
Background: One of my Instagram account (@xxx), active since 2020 with no prior violations, was suspended on 10 September 2026 and as a consequence, has also blocked my personal FB and my personal IG account — both unrelated to any violation I'm aware of. The last content posted on xxx was in October 2025 and I havent posted any scam or money guaranteed, is a page where i post about crypto, trading, and how I am navigating this market, I havent had any violation or flag since the beginning. Then this august I posted a real on my own personal account tagging the xxx page where I share how I made a good amount of profit trading gold and I was going to use those to finance the creation of an app — no false claims, no scam, no solicitation of funds. Trough my personal account I have also access to a meta business suite where we are advertising on a different project, which I am now not able to access anymore. What I need help with: - Reviewing my case and advising on the strongest legal/procedural path forward - Filing and/or strengthening a dispute with the Appeals Centre Europe (the certified DSA out-of-court dispute settlement body) - Drafting or reviewing formal correspondence to Meta if needed - General guidance on my rights as an EU/Italian citizen under the DSA regarding platform account suspensions Please share relevant experience with similar cases (platform bans, DSA disputes, Appeals Centre Europe submissions) when applying.
Budget:
not specified
4 hours ago
|
|||||
|
Help Suzie
Applied
|
not specified | 6 hours ago |
1
|
||
|
Hi Emanuel,
I need a hacker to figure out what is going on? So I think I am being scammed online for months now. They have slowly, slowly taken lioe 7500£ as I am in the Uk with apple gift cards. My problem is this person is taking it to another level as I keep blocking him and he keeps coming back with another nee mobile number?! My issue is it started and still is a love scam but now he keep insisting on that he is a famous singer and he is so madly in love that he is leaving his label for me?! Ha ha. Wait the sweetest thing is he talked me into download an app called Trust its a bitcoin app and the crazy label of his sent me all of his money in Bitcoin. I have no clue on how bitcoin works and how u can take cash out of it, but he keeps coming insisting that I take it out in a bitcoin cash machine but it charges huge fees and u have to pay that fee in advance like 32000£ ? Is this true and Is there no other way to cash this bitcoin out cheaper. I am also afraid of the tax in Uk liabilities as if u take it out in cash I would liable to pay tax after it?? No? Can u help?
Budget:
not specified
6 hours ago
|
|||||
|
Cyber Security Consultant
Applied
|
$10 - $30
/ hr
|
15 hours ago |
3
|
||
|
About Us
Marketing Sweet is an Australian based digital marketing company, we work with clients to build, manage, and protect their digital presence. As our client portfolio expands, so does our responsibility to keep their websites and platforms secure, and that's where you come in. We're looking for a Cyber Security Consultant to join our team and assist with the the security side of our website and platform management. This is a hands-on role for someone who genuinely enjoys solving problems, staying ahead of threats, and making systems more resilient. About the Role As our Cyber Security Consultant, you'll be responsible for assessing, implementing, and maintaining security protections across a range of client websites and platforms. You'll work closely with our development and marketing teams to ensure every site we manage is secure by design and stays that way. What You'll Be Doing Implementing and managing security protections across client websites Conducting security assessments and identifying vulnerabilities before they become problems Monitoring and maintaining the security posture of websites hosted on GitHub and Vercel Managing access controls, permissions, and deployment security across GitHub repositories and Vercel projects Responding to and remediating security incidents as they arise Keeping documentation, processes, and security protocols up to date Staying current on emerging threats and recommending proactive improvements Collaborating with the wider team to build security into everyday workflows, not just bolt it on afterward What We're Looking For A positive, pragmatic attitude — you solve problems calmly, communicate clearly, and don't catastrophize Proven experience implementing protection and increasing security on websites — this isn't a theory-only role, we need someone who's done the work Based in Adelaide — this is an in-office role at our North Adelaide location, so local candidates only Familiarity with website management on GitHub and Vercel — you're comfortable navigating repositories, deployments, and platform settings on both Nice to Have (Not Required) Comfortable web development skills using React and Next.js Familiarity with database systems such as Redis and MongoDB If you don't tick every box here but have the core security experience and the right attitude, we'd still love to hear from you. How to Apply If this sounds like you, we'd love to see your application. Please submit your resume along with a brief cover note outlining your experience in cyber security.
Hourly rate:
10 - 30 USD
15 hours ago
|
|||||
|
Senior Azure DevOps Engineer for Secure SDLC, CI/CD & Compliance Hardening
Applied
|
$35 - $60
/ hr
|
22 hours ago |
5
|
||
|
Job Description
Overview We are looking for an experienced Azure DevOps and DevSecOps consultant to help improve the development, deployment, and governance processes for an existing SaaS application running in Microsoft Azure. This is an active production application. We recently completed an internal review and identified several opportunities to improve code governance, deployment controls, testing automation, environment management, and overall software development lifecycle practices. The ideal consultant is highly hands-on and comfortable working directly within Azure DevOps, Azure, source control, CI/CD pipelines, and production environments. Scope of Work 1. Source Control & Pull Request Governance Review and improve repository configuration and branch protection controls. Expected outcomes: Pull request based workflow Required code reviews Reviewer approval policies Comment resolution requirements Prevention of direct commits to protected branches Branch policy enforcement Repository security review 2. CI/CD Pipeline Review Review existing build and deployment pipelines. Expected outcomes: Automated build validation Automated testing before merge Pull request validation Merge protection when validation fails Recommendations for pipeline improvements 3. Production Deployment Controls Review production deployment practices and permissions. Expected outcomes: Review of deployment permissions Review of role-based access controls Production approval workflows Improved separation of duties Recommendations for release governance 4. Environment Architecture Review Review the current application hosting model and recommend best practices. Areas of focus: Development environment Test or staging environment Production environment Deployment promotion process Configuration management Secret management Application deployment strategy 5. Development Lifecycle Improvements Provide recommendations and implementation assistance for: Secure software development lifecycle practices Code review governance Testing requirements Change management Release management Deployment approval processes 6. Documentation & Audit Readiness Help document implemented controls and identify any remaining gaps. Expected deliverables: Current-state assessment Recommended improvements Implemented enhancements Documentation of controls Prioritized roadmap for future improvements Required Skills Please apply only if you have substantial experience with: Azure DevOps Azure Repositories Azure Pipelines Azure App Services CI/CD implementation DevSecOps Infrastructure security Access control and permissions management Secure software development practices Preferred Experience Experience in one or more of the following areas is a plus: Information security programs Security audits Secure development programs Regulatory or compliance-focused environments Software governance and release management Deliverables At the conclusion of the engagement, we would like: A review of the current environment A list of improvements implemented A list of recommended next steps Documentation of key controls A practical roadmap for continued improvement To Apply Please provide: A brief summary of similar Azure DevOps or DevSecOps engagements you have completed. Examples of CI/CD improvements you have implemented. Experience improving deployment governance and production controls. Experience working with secure software development practices. A short description of how you would approach this engagement.
Hourly rate:
35 - 60 USD
22 hours ago
|
|||||
|
Internal ISO 42001 auditor
Applied
|
$20 - $50
/ hr
|
22 hours ago |
4
|
||
|
My Business needs a internal audit be conducted objectively and impartially.
The Internal Audit must be conducted by someone independent of our external auditor (Advantage Partners). As such, I am looking for an independent auditor to help with our ISO 42001. Here are requirements for ISO 27001 - that our external auditor shared. We are doing 42001 not 27001 but the information there is still relevant. https://www.vanta.com/collection/iso-27001/iso-27001-internal-audit
Hourly rate:
20 - 50 USD
22 hours ago
|
|||||
|
ISO 27001 Lead Implementer
Applied
|
$15 - $50
/ hr
|
1 day ago |
4
|
||
|
Looking for an experienced ISO 27001 implementation specialist to fulfil in a short time frame.
The client is a small/medium-sized SAAS company looking to implement an audit and prepare for ISO 27001 certification. I'm looking for someone with strong practical implementation experience who can take responsibility for the specialist side of the work. This would initially be a project-based engagement, with the possibility of further implementation projects if the collaboration works well. Scope of work The project is expected to involve: Initial gap assessment ISMS implementation Information security risk assessment and treatment Statement of Applicability (SoA) Development/adaptation of policies and procedures Evidence and documentation requirements Internal audit preparation Management review preparation Certification audit preparation Ongoing guidance throughout the implementation I would manage the client relationship, communication and project coordination, while you would provide the specialist ISO 27001 expertise and lead the relevant technical implementation work. Ideal background I'm looking for someone who has actually taken organisations through ISO 27001 implementation, rather than someone whose experience is primarily theoretical. Ideally you have: Multiple completed ISO 27001 implementations Experience implementing an ISMS from scratch ISO 27001 Lead Implementer certification Experience with SMEs/startups Experience with SaaS or technology companies is a strong plus Experience with Vanta, Drata, Secureframe or similar platforms is a plus Strong English communication Comfortable working independently with clients What I'm particularly interested in I'd like to work with someone who has a structured and efficient implementation methodology. To apply Please provide: Number of ISO 27001 implementations you've personally completed. Your specific role in those implementations. Your ISO 27001 certifications. Typical company size and industries you've worked with. Whether you've worked with SaaS/technology companies. GRC/compliance platforms you're familiar with. Your typical fee/rate for an SME implementation. A brief example of a recent implementation you've led. Please focus your proposal on your practical implementation experience rather than sending a generic ISO 27001 consulting proposal. Client's questions:
Hourly rate:
15 - 50 USD
1 day ago
|
|||||
|
Fractional Security & GRC Consultant — Google Workspace / Audit Readiness
Applied
|
$5 - $15
/ hr
|
1 day ago |
5
|
||
|
We are a growing professional services company looking for an experienced Security & GRC consultant to help establish and maintain a practical, right-sized security and compliance program.
Our environment is relatively simple: a remote workforce, company-managed endpoints, Google Workspace / Google Admin, and agents primarily working inside client-provided systems rather than applications we host ourselves. Our immediate need is to prepare for a customer security review and an independent third-party security assessment against an appropriate recognized framework, along with third-party vulnerability/penetration testing. We are looking for someone who can help us: - Assess our current security posture and recommend the most appropriate assessment/framework for our size and customer requirements - Prepare us for independent third-party validation - Help implement and document endpoint, identity, MFA, encryption, DLP, patching, logging, monitoring, and access-management controls - Review and advise on Google Workspace, Google Admin, and managed ChromeOS security controls - Help select and implement an appropriate EDR/AV solution - Establish lightweight security policies, procedures, and evidence collection - Set up annual security training and completion tracking - Coordinate with independent auditors/assessors and VAPT providers - Help respond to customer security questionnaires and due-diligence requests After the initial project, we would ideally retain this person as our fractional security/GRC resource for ongoing support, periodic control reviews, documentation updates, customer security reviews, and keeping us audit-ready as we grow. We are not looking to build an unnecessarily complex enterprise security program. We want someone experienced enough to understand strong security practices while keeping the approach practical and proportional for a small, growing business. Ideal Experience - Security/GRC consulting for startups, SMBs, BPOs, or contact centers - NIST CSF 2.0 - SOC 2 - ISO 27001 - Google Workspace / Google Admin / ChromeOS - Endpoint security, EDR, DLP, vulnerability management - Preparing organizations for independent security assessments - Fractional security lead / vCISO experience is a plus Client's questions:
Hourly rate:
5 - 15 USD
1 day ago
|
|||||
|
MBA Assignment Humanization for Turnitin
Applied
|
$10 - $30
|
1 day ago |
-
|
||
|
I have already drafted the full MBA paper on digital transformation and information security, but it still reads too much like it was generated by a machine. I need every section—Introduction, main Body, and Conclusion—rewritten in a way that feels authentically human while preserving the formal, professional tone expected at graduate level.
The core objective is to ensure the text passes Turnitin’s AI-detection algorithms without sacrificing clarity, logical flow, or academic rigor. Facts, citations, and technical vocabulary related to both digital transformation initiatives and modern information-security practices must remain intact; I simply want them expressed through natural sentence variation, nuanced transitions, and a clear writer’s voice. Deliverable: • A polished, human-sounding version of the entire assignment (all three sections) returned in editable Word or Google Docs format, ready for final citation checks. I will run the revised document through Turnitin once I receive it, so please structure your rewrite with that standard in mind. Skills: Research, Proofreading, Technical Writing, Management, Research Writing, Content Writing, Academic Writing, Writing Tutoring
Fixed budget:
10 - 30 USD
1 day ago
|
|||||
|
Experienced ISO 27001 Consultant for Startup Certification
Applied
|
not specified | 1 day ago |
1
|
||
|
We are a startup seeking an experienced ISO/IEC 27001 consultant to lead us through the practical work required to achieve certification. We need someone who can assess our current position, establish an appropriate information security management system (ISMS), guide implementation and support us through the independent certification audit process.
Proven delivery experience is essential. Please apply only if you have personally helped businesses achieve ISO 27001 certification and can substantiate your role and the outcomes. We value clear advice, practical implementation and documentation that a small team can maintain. SCOPE OF WORK 1. Initial assessment and certification roadmap • Review our business activities, systems, suppliers, existing policies and security practices. • Define an appropriate ISMS and certification scope with our team. • Complete a gap assessment against ISO/IEC 27001:2022, including applicable amendments. • Produce a prioritised roadmap with milestones, responsibilities, dependencies, estimated effort and a realistic certification timeline. 2. ISMS development and risk management • Establish or improve the information security risk assessment methodology, risk register and risk treatment plan. • Prepare the Statement of Applicability with clear control selection and exclusion justifications. • Develop tailored policies, procedures and registers relevant to our agreed scope. • Define security responsibilities, objectives, document control and evidence requirements. 3. Practical implementation and evidence • Work with our team to implement the agreed processes and controls, identifying technical tasks that require our staff or other specialists. • Address relevant areas such as access management, supplier security, incident response, business continuity, asset management and staff awareness. • Establish an organised evidence register and help us demonstrate that the ISMS operates in practice. • Provide staff guidance and training appropriate to our size and needs. 4. Internal audit and readiness • Coordinate an objective internal audit with appropriate independence from the work being audited. • Help us prepare and conduct management review. • Identify gaps, track corrective actions and assess readiness for external certification. 5. Certification audit support • Help us evaluate suitable accredited certification bodies and understand their scope, costs and scheduling. • Support Stage 1 and Stage 2 audit preparation, audit queries and responses to findings. • Clearly distinguish your consultancy role from the independent certification body's responsibility for certification decisions. 6. Handover and maintenance • Provide editable documentation, an evidence index and a clear handover. • Set out ongoing responsibilities and a practical schedule for reviews, internal audits, improvement and surveillance audit preparation. EXPERIENCE REQUIRED • A demonstrable track record of personally delivering successful ISO 27001 certification projects. • At least two relevant project examples explaining the organisation's size and sector, standard/version, your responsibilities and the certification outcome. • Verifiable references or appropriately redacted supporting evidence, shared with client permission. • Strong working knowledge of ISO/IEC 27001:2022 and practical ISMS implementation. • Experience working with startups or small teams. • Excellent written documentation, communication and project management skills. Relevant ISO 27001 Lead Implementer and/or Lead Auditor qualifications are highly desirable. Please identify the qualification and issuing organisation. Qualifications should be supported by practical delivery experience. PROPOSAL REQUIREMENTS Please include: • Two comparable projects you personally delivered and how the results can be verified. • Your recommended approach and what you would deliver during the initial assessment. • A realistic indicative timeline, assumptions and expected involvement from our team. • Your hourly rate and/or proposed milestone fees, with consultancy, certification-body fees and any optional software costs identified separately. • Your availability, time zone and the person who would perform the work. • Any proposed subcontractors, certification-body relationships or referral arrangements. We will agree the final scope, schedule and commercial terms after the initial assessment is defined. Any additional services or tools must be scoped and approved in advance. Our objective is accredited ISO 27001 certification supported by a working, maintainable ISMS. The independent certification body makes the certification decision. Please explain your approach and evidence of experience clearly; generic proposals will not be prioritised. Client's questions:
Budget:
not specified
1 day ago
|
|||||
|
DuraWell - Comprehensive Medical Coordinator App
Applied
|
~6 - 157 USD
|
1 day ago |
-
|
||
|
DuraWell – Healthcare Journey Platform
I am looking for an experienced mobile app developer/development team to build DuraWell, a healthcare journey coordination platform connecting patients, doctors and hospitals. DuraWell is not intended to be just another doctor-booking app. The long-term vision is to coordinate the patient's complete treatment journey, especially when patients travel from one city/state to another for medical care. Core journey: Home → Doctor/Hospital Discovery → Appointment → Medical Records → Travel → Accommodation → Local Transport → Hospital → Investigation → Treatment → Discharge → Return Home → Follow-up I need a real, functional, scalable and deployable product, not only a UI prototype. 1. Patient App Registration & Profile - Mobile OTP/email login - Patient profile - Family/dependent profiles - Emergency contact - Basic health information - Allergies, conditions, medications and medical history Medical Records Secure upload and organization of: - Prescriptions - Lab reports - X-rays/CT/MRI reports - Discharge summaries - Previous medical records - Referral letters - PDF/images Records should be categorized, dated, viewable and securely stored. 2. Doctor Discovery Patients should be able to search/filter doctors by: - Specialty/sub-specialty - City - Hospital - Experience - Availability - Consultation type Doctor profiles should include qualifications, specialty, experience, hospital affiliation, consultation fee, availability and location. 3. Hospital Discovery Search hospitals by: - City - Specialty - Treatment/service - Location - Hospital type Hospital profiles should show departments, doctors, services, facilities, emergency services, address and contact information. 4. Appointment Booking Required: - Doctor/hospital appointment booking - Date/time slot selection - Confirmation - Cancellation/rescheduling - Appointment history - Reminders and notifications Architecture should support future hospital/API integrations. 5. DuraWell Patient Journey This is the core feature. After selecting a doctor/hospital, DuraWell should create a structured treatment journey. Example: Doctor Selected → Appointment → Records Prepared → Travel → Accommodation → Hospital Visit → Investigation → Consultation → Admission → Treatment → Discharge → Return Home → Follow-up Patients should see progress through a simple timeline/checklist. Example: ✓ Doctor selected ✓ Appointment booked ✓ Records uploaded → Travel → Hospital visit → Investigation → Treatment → Discharge → Follow-up The journey system should be modular so additional services can be added later. 6. Travel, Accommodation & Transport For patients travelling to another city, future modules should support: Travel - Destination - Travel dates - Airport/railway station information - Travel assistance Accommodation - Nearby hotels/accommodation - Distance from hospital - Location - Price/category filtering - Future booking integration Local Transport - Airport/railway station → hotel - Hotel → hospital - Hospital → diagnostic centre - Return transportation These modules can initially be designed for future API/partner integration. 7. Maps & Hospital Navigation Integrate Google Maps or equivalent for: - Hospital/doctor locations - Nearby services - Distance and routes - Navigation Future versions may include hospital department/OPD navigation and indoor navigation. 8. Doctor Dashboard Doctors should eventually be able to: - Manage profile - Manage appointments - View appointment calendar - Manage authorized patient information - Access permitted medical records - Manage follow-ups - Receive notifications 9. Hospital Dashboard Hospitals should be able to manage: - Hospital profile - Departments - Doctors - Appointments - Patient journeys - Patient arrival information - Services - Basic analytics 10. Admin Dashboard Web-based admin panel for managing: - Patients/users - Doctors - Hospitals - Appointments - Medical documents - Verification - Partners/services - Notifications - Complaints/support - Analytics - Roles and permissions 11. Notifications Support: - Push notifications - Appointment reminders - Journey updates - Follow-up reminders - Important alerts Firebase Cloud Messaging or equivalent can be used. 12. Payments Architecture should be payment-ready for future: - Consultation payments - Platform services - Partner services Possible gateways: Razorpay, Cashfree, PhonePe or another suitable Indian gateway. 13. AI – Future Development AI is part of the long-term vision but does not need to be fully implemented in the first MVP. Future possibilities: - Medical document organization - Medical-record summarization - Patient journey assistant - Intelligent reminders - Healthcare navigation - Patient FAQ assistant - Personalized journey support - Doctor/hospital discovery assistance The architecture should allow future AI integration. AI must not independently provide unsafe medical diagnosis/treatment decisions. 14. Security & Privacy Because DuraWell will handle healthcare information, security is critical. Required: - Secure authentication - Encrypted communication - Secure database - Role-based access - Patient consent - Secure document storage - Backup strategy - Audit logging where appropriate - Protection against common security vulnerabilities The developer should consider applicable Indian healthcare/data-protection requirements. 15. Suggested Technology I am open to recommendations. Possible stack: Mobile: Flutter / React Native Backend: Node.js/NestJS or equivalent Database: PostgreSQL/MySQL Cloud: AWS/Google Cloud/Azure Authentication: OTP/Firebase Auth Notifications: Firebase Cloud Messaging Maps: Google Maps API Developer should recommend the best architecture considering scalability, security and cost. 16. MVP – Phase 1 The first objective is a genuine working MVP. Core MVP: Register → Patient Profile → Doctor/Hospital Search → Profile → Appointment → Medical Records → Treatment Journey → Journey Status → Notifications The MVP must be functional, testable and deployable, not merely a design prototype. 17. Deliverables Selected developer/team should provide: - UI/UX design - Android application - Backend - Database - APIs - Admin dashboard - Authentication - Medical-record system - Appointment system - Patient journey system - Notifications - Maps - Payment-ready architecture - Testing - Deployment - Production build - Complete source code - API/database documentation - Post-launch bug fixing Complete source code and agreed intellectual property must be handed over to the project owner. 18. Proposal Requirements Please provide a detailed bid containing: 1. MVP cost 2. Estimated full-platform cost 3. Module-wise cost if possible 4. Development timeline 5. Proposed technology stack 6. Team size and roles 7. Relevant previous projects 8. Maintenance/support cost 9. Post-launch bug-fixing period 10. Confirmation of source-code/IP ownership I am looking for a long-term technology partner, not someone who only creates a prototype. The long-term vision is to build a scalable healthcare ecosystem connecting patients, doctors, hospitals, diagnostics, travel, accommodation, transportation, telemedicine and AI. Please submit your best technical approach, realistic MVP quotation, timeline and relevant portfolio. Skills: Node.js, Database Development, UI / User Interface, Backend Development, Healthcare Sales, Flutter, Google Firebase, Android App Development, API Development, Medical App Development
Fixed budget:
600 - 15,000 INR
1 day ago
|
|||||
|
Security Camera Monitoring Specialist
Applied
|
$6,500
|
1 day ago |
5
|
||
|
We need a reliable freelancer to monitor security cameras and quickly identify potential security issues. You will review footage, assess suspicious activity, and communicate concerns to staff and law enforcement when needed. This role requires strong attention to detail, clear communication, and the ability to stay alert during monitoring shifts. Experience with security systems and reporting incidents is important. Please apply if you are comfortable handling real-time security monitoring and responding to potential threats.
Fixed budget:
6,500 USD
1 day ago
|
|||||
|
TikTok Impersonation, Fraud & OSINT Investigation
Applied
|
not specified | 1 day ago |
1
|
||
|
I am seeking a professional OSINT / digital forensics investigator for an ongoing social media impersonation and suspected fraud matter involving my public identity and business.
BACKGROUND I am a business owner and TikTok creator publicly known as Supreme Empress Cherita. I have been dealing with an ongoing and serious impersonation problem since 2024 involving multiple TikTok accounts. This is not a recent or isolated incident. Different accounts have impersonated me at different times over approximately two years. AS OF RIGHT NOW, there are FOUR ACTIVE TikTok accounts that are openly impersonating me and are still using my name. However, these are not the only accounts that have been involved. There have been additional TikTok accounts that previously used my identity, name, photographs, videos, content, or other identifying information. Some of those accounts later changed their names/usernames to something completely different and removed my videos and other content from their profiles. Because those accounts changed their identities and removed my content, they may no longer appear at first glance to be impersonating me. However, I have reason to believe some may be connected to the same ongoing activity. I would therefore like the investigation to consider both the FOUR CURRENTLY ACTIVE ACCOUNTS and the historical impersonation activity dating back to 2024 where evidence remains lawfully and reasonably available. CURRENT TAKEDOWN PROCESS I have already hired a separate professional takedown service that is working with TikTok to have the four currently active impersonation accounts removed. I am NOT hiring an investigator primarily to perform account takedowns. The takedown process is already underway. Because of that, the four currently active accounts could disappear at any time. Preserving publicly available evidence from those accounts before they are removed is extremely important. WHAT HAS BEEN HAPPENING This situation goes beyond someone simply copying my TikTok profile. The impersonators have allegedly used my name, public identity, business identity, photographs, videos, and content while pretending to be me. They have also allegedly communicated with people while representing themselves as me and directed people away from TikTok to communicate or conduct transactions through other services. The information I have collected includes: • Four currently active TikTok accounts openly impersonating me • Information concerning additional TikTok accounts that previously impersonated me but later changed their names/usernames and removed my content • Current and previous usernames that I have been able to document • Phone numbers, including numbers that appear to be TextFree/VoIP numbers • Email addresses created to resemble my legitimate email address, sometimes differing from my real email address by only one letter • WhatsApp contact information • Signal contact information • Cash App/payment information • Apple Pay/payment information • Screenshots of conversations and communications involving the impersonators • Screenshots and other evidence concerning impersonation accounts • My legitimate TikTok account for comparison • Other information and evidence collected from the impersonators and from people they have contacted Some of the impersonators appear to have attempted to obtain money from people while pretending to be me. MY PRIMARY OBJECTIVE I am looking for an INVESTIGATION, not simply account removal. My primary goal is to determine WHO is actually behind this activity. I want to determine whether: • The four currently active TikTok accounts are connected to one another • The older accounts that previously impersonated me are connected to the current accounts • The different phone numbers, emails, usernames, payment identifiers, and other information are connected • The activity appears to originate from one person, multiple people, or a coordinated group • There are cross-platform connections between the different identifiers • The person or people responsible can reasonably be identified through lawful OSINT and investigative methods I understand that identifying an anonymous account operator cannot be guaranteed. I am looking for a professional investigator who will distinguish between what can actually be proven, what is strongly supported by evidence, and what is merely possible. CROSS-PLATFORM INVESTIGATION I would like the investigator to examine lawful and publicly available connections involving, where applicable: • TikTok accounts • Current usernames • Previous usernames where discoverable • Aliases • Phone numbers • TextFree/VoIP numbers • Email addresses • Look-alike email addresses • WhatsApp information • Signal information • Cash App/payment identifiers • Apple Pay/payment information • Profile photographs • Reused photographs • Reused videos • Posting patterns • Communication patterns • Profile/account histories • Historical information dating back to 2024 where lawfully and reasonably available • Publicly available metadata where legitimately available • Cross-platform profiles and identifiers • Other lawful digital indicators that could establish connections between the accounts For example, if the same username, alias, phone number, email address, payment identifier, photograph, video, wording, contact information, posting behavior, or another identifier appears across multiple accounts or platforms, I would like that connection investigated and documented. OLDER ACCOUNTS THAT CHANGED THEIR IDENTITIES The older accounts are particularly important to me. Some accounts that previously impersonated me later changed their names/usernames to something completely different and removed my videos/content. I would like the investigator to determine, where reasonably possible, whether historical or publicly available evidence can document that these accounts previously impersonated me and whether those accounts can be connected to the currently active accounts or the same operator(s). Because this activity has been occurring since 2024, recurring patterns across accounts and time periods may also be relevant. EVIDENCE PRESERVATION The four currently active TikTok accounts are already subject to professional takedown requests. I therefore need the investigator to tell me how quickly evidence from the currently active profiles can be preserved before those accounts potentially disappear. I would like appropriate publicly available evidence documented, including relevant URLs, usernames, profile information, dates/times where available, screenshots, and other relevant information that may assist in establishing what existed before removal. QUESTIONS I NEED ANSWERED BEFORE HIRING 1. Can you investigate ALL FOUR currently active TikTok impersonation accounts together rather than analyzing only one profile? 2. Can you examine additional accounts that previously impersonated me but later changed their names/usernames and removed my videos/content? 3. Since this has been occurring since 2024, can you examine historical information that remains lawfully and reasonably available for connections between older and current accounts? 4. Can you determine whether the older accounts appear connected to any of the four currently active accounts? 5. Can you examine the associated phone numbers, including possible TextFree/VoIP numbers, for lawful and publicly available connections to usernames, accounts, services, aliases, or identities? 6. Can you examine the look-alike email addresses for connections to other publicly available accounts, usernames, websites, profiles, aliases, or identities? 7. Can you examine the WhatsApp and Signal information I have collected for lawful investigative leads or connections? 8. Can you examine Cash App/payment identifiers, Apple Pay information, and other payment information for publicly available connections to names, usernames, aliases, accounts, or other identifiers? 9. Can you perform cross-platform analysis to determine whether the activity appears to involve the same individual, multiple individuals, or a coordinated group? 10. Can you examine usernames, previous usernames where discoverable, aliases, posting behavior, profile history, reused content, connections, and publicly available metadata where legitimately available? 11. Can you compare activity and identifiers from 2024 to the present for recurring patterns that could connect accounts? 12. If attribution is realistically possible using lawful and publicly available information, can you attempt to identify the actual person or people responsible? 13. Can you preserve evidence from all four currently active TikTok accounts BEFORE they are removed? 14. Can you document whatever evidence remains concerning older accounts that changed their names and removed my content? 15. Will you document HOW accounts or identifiers are connected rather than simply providing an opinion? 16. Will I receive a WRITTEN INVESTIGATIVE REPORT containing the findings and supporting evidence? 17. Will that report clearly distinguish between CONFIRMED findings, strongly supported connections, and POSSIBLE/unconfirmed connections? 18. If a possible individual is identified, will the report explain the evidence supporting that attribution? 19. If conclusive identification is not possible, will the report still document useful evidence, connections, and investigative leads that could potentially be provided to an attorney or law enforcement? 20. If conclusive identification would require private records from TikTok, a telecommunications/VoIP provider, email provider, payment company, or another service, will the report explain what additional information or appropriate legal process would likely be required? 21. Because the four currently active accounts are pending removal, how quickly could evidence preservation begin? 22. What would the TOTAL PRICE be for the agreed scope? BUDGET AND AFFORDABILITY Affordability is extremely important to me. I am currently working with a limited budget, so I am specifically looking for the MOST AFFORDABLE way to have a meaningful and professional investigation completed. I understand that professional investigative work has a cost, and I am not asking for free services. However, I need an option that is reasonably priced and focuses first on the evidence and investigative steps most likely to produce useful results. I am NOT looking for an open-ended investigation, a large retainer, or unexpected additional charges. I would strongly prefer a FIXED PRICE for a clearly defined first phase so that I know exactly what I will be paying before any investigation begins. If everything described in this job cannot reasonably be completed within an affordable first phase, please recommend the MOST COST-EFFECTIVE approach for my situation rather than simply quoting me for the largest possible investigation. My immediate priority is preserving and investigating the four currently active TikTok accounts and cross-referencing the phone numbers, VoIP numbers, email addresses, usernames, WhatsApp/Signal information, payment information, and other evidence I already possess. Before hiring, I would like to know: • Exactly what will be investigated • How many accounts will be included • Which identifiers will be examined • Whether evidence preservation is included • Whether cross-platform correlation is included • Whether historical account research is included • Whether a written investigative report is included • The expected turnaround time • The TOTAL FIXED PRICE • Whether you can offer a lower-cost first phase focused on the strongest investigative leads • Any circumstances that could result in additional charges If investigating every historical account going back to 2024 immediately would substantially increase the cost, I am completely comfortable beginning with a smaller and more affordable first phase and expanding the investigation later only if the initial findings justify the additional expense. PRIORITIES FOR THE FIRST PHASE My priorities are: 1. Preserve publicly available evidence from the four currently active TikTok impersonation accounts before they disappear. 2. Investigate those four active accounts and the identifiers I already have associated with them. 3. Determine whether the four active accounts appear connected to one another. 4. Cross-reference the phone numbers, VoIP numbers, look-alike emails, WhatsApp/Signal information, payment identifiers, usernames, and other available evidence. 5. Attempt to identify the person or people responsible where the evidence reasonably permits. 6. Examine whether older accounts that changed their names and removed my content connect to the current accounts or the same operator(s). 7. Examine historical patterns dating back to 2024 where evidence remains available. 8. Produce a written investigative report documenting the evidence, methodology, findings, connections, and appropriate confidence level of the conclusions. IMPORTANT LIMITATIONS AND EXPECTATIONS I understand that an OSINT/private investigation cannot guarantee identification of an anonymous individual. I also understand that certain information held privately by TikTok, telecommunications/VoIP providers, email providers, payment companies, and other platforms may require subpoenas, warrants, court orders, or other appropriate legal process and may not be obtainable through OSINT. I am NOT requesting hacking, unauthorized access to accounts, password acquisition, unlawful surveillance, or any other unauthorized activity. I am seeking a lawful, professional OSINT/digital investigation based on information I already possess and other information that can legitimately be obtained. If the evidence reaches a point where further identification requires information that only a platform/provider possesses, I would like that limitation clearly documented so I understand what an attorney or law enforcement agency may need to pursue next. TIME SENSITIVITY This matter is time-sensitive because the four currently active impersonation accounts are already undergoing a professional takedown process. I would therefore like evidence preservation from those four accounts to begin as quickly as reasonably possible after an agreement is reached. Please respond with what you believe can realistically be accomplished, what you recommend for the most affordable and useful first phase, how quickly evidence preservation can begin, what deliverables I would receive, and the TOTAL FIXED COST before I proceed.
Budget:
not specified
1 day ago
|
|||||
|
Headscale/tailscale consultancy and audit
Applied
|
$25 - $80
/ hr
|
1 day ago |
5
|
||
|
We've setup a Headscale VPN that we need the setup checked for.
We're also struggling to roll it out to all VMs in our network. We're looking for an expert in Headscale (or the commercial Tailscale), not just an LLM monkey, with several years of networking experience. Client's questions:
Hourly rate:
25 - 80 USD
1 day ago
|
|||||
|
Microsoft 365 Security & ISO 27001 Gap Assessment, Entra ID, Defender & Licensing Review
Applied
|
$40
|
1 day ago |
3
|
||
|
We are looking for an experienced Microsoft Security professional to conduct a high-level assessment of our Microsoft 365 security environment and provide an ISO 27001 readiness/gap perspective.
The objective is to identify key security gaps, review the security capabilities available through our existing Microsoft licenses, and provide practical recommendations to improve our overall security posture. Scope of Work: - Review Microsoft 365 security configuration and overall security posture - Review Microsoft Entra ID security and identity/access controls - Review MFA and Conditional Access configuration - Review Microsoft Defender security capabilities and configuration - Review existing Microsoft security licenses and their utilization - Identify available security features that are currently underutilized or not configured - Conduct a high-level ISO 27001 readiness/gap assessment - Identify key security and compliance gaps - Provide prioritized recommendations and an action plan Expected Deliverable: A concise assessment report covering: 1. Current security posture 2. Key findings and identified gaps 3. Risk/priority level for major findings 4. Microsoft licensing/security feature recommendations 5. ISO 27001 readiness observations 6. Recommended corrective actions Ideal Candidate: - Strong experience with Microsoft 365 Security - Microsoft Entra ID - Microsoft Defender - Identity & Access Management - Cybersecurity assessments - ISO 27001 / Information Security Governance - Ability to provide practical, business-oriented recommendations
Fixed budget:
40 USD
1 day ago
|
|||||
|
IT / Security Engineer (Part-time, Endpoint Security)
Applied
|
$30 - $40
/ hr
|
1 day ago |
4
|
||
|
Endpoint security & automation on Fleet/osquery (~10-15 h/week)
We are an established international software development company with engineering teams across Asia and Europe, serving enterprise clients. Our device fleet is Linux-first (Ubuntu), alongside Windows and macOS. With AI tools now part of everyday engineering work, we want to strengthen our endpoint security and IT automation to match the security expectations of this new era. We have already adopted Fleet (fleetdm.com) with osquery as we replace ScaleFusion, and our IT lead has a detailed design ready. We're looking for an experienced engineer to help us validate the design and build out the remaining pieces alongside our team: privileged-access management (just-in-time admin), full-disk encryption with recovery-key escrow, application execution control (e.g., fapolicyd / AppLocker / Santa), removable-media control, security monitoring with automated remediation, and audit-grade logging integrated with our identity provider, CI/CD and ITSM tooling on a self-hosted Kubernetes stack. You should have: - Solid Linux endpoint depth (systemd, udev, PAM/sudoers, LUKS); - Hands-on experience with Fleet, osquery, or a comparable endpoint management/telemetry platform; - Working knowledge of Windows (BitLocker, AppLocker/WDAC) and macOS (FileVault, MDM profiles) security; - API/webhook integration skills and comfort with backend automation and scripting (Go is a plus—parts of our tooling are written in it); - Sound judgement on key custody and secrets handling; and clear written English. Engagement: ~10-15 hours/week, remote, with some overlap with GMT+7 (Hanoi). When applying, please describe: (a) an endpoint-security or device-management project you've shipped, (b) your experience with osquery/Fleet or similar, (c) one hard lesson from Linux endpoint security. Client's questions:
Hourly rate:
30 - 40 USD
1 day ago
|
|||||
|
Program Manager - Cyber Security and IT Networks
Applied
|
$25 - $40
/ hr
|
1 day ago |
5
|
||
|
Program Manager – Cyber Security & Network Infrastructure
Employment Type: Full-Time Experience Required: 18+ Years Working Time Zone: IST Role: Senior Program Management – Network Infrastructure & Cyber Security About the Role We are looking for a highly experienced Program Manager – Cyber Security & Network Infrastructure to lead and manage complex enterprise Network Infrastructure and Cyber Security programs. The successful candidate will be responsible for managing multiple concurrent projects and technical workstreams, coordinating technical teams and vendors, managing senior stakeholders, and ensuring successful delivery against agreed scope, timelines, budgets and quality requirements. This is a full-time permanent position and requires strong experience in both Network Infrastructure and Cyber Security program delivery. Key Experience Required 18+ years of overall IT industry experience, with at least 7–8 years in Project/Program Management roles. Minimum 5+ years of experience managing Network Infrastructure and/or Cyber Security programs within large enterprise environments. Proven experience managing multiple concurrent projects and complex technical workstreams. Experience managing large technology programs, preferably with program values of AUD $2M–$5M+. Strong experience delivering programs involving: LAN/WAN Data Centre Networks Firewalls & Network Security SD-WAN Wireless Infrastructure Cloud & Hybrid Cloud Connectivity Cyber Security Demonstrated experience managing firewall refresh/migration programs. Experience with network transformation and modernisation initiatives. Experience managing data centre migration programs. Experience with EOL/EOS remediation and technology lifecycle programs. Experience delivering security uplift and infrastructure modernisation initiatives. Strong experience managing customers, senior stakeholders, architects, engineers, vendors and delivery partners. Excellent program governance, risk management, financial management, resource management and executive reporting capabilities. Exceptional English communication skills, with strong verbal, written, presentation and senior stakeholder engagement capabilities. Key Required Certifications Candidates must hold at least one recognised Project/Program Management certification: PMP – Project Management Professional PRINCE2 Practitioner MSP – Managing Successful Programmes Highly Desirable Certifications ITIL 4 Foundation or higher SAFe Agilist / Agile Project Management CISSP – Certified Information Systems Security Professional CISM – Certified Information Security Manager Working Hours The position will operate primarily in the IST time zone. Candidates should be comfortable working an early-start schedule, preferably from approximately 7:00 AM IST or earlier when required, to support customer and project requirements.
Hourly rate:
25 - 40 USD
1 day ago
|
|||||
|
DevOps, Infrastructure & Security Agency for Static AI
Applied
|
$1,450
|
1 day ago |
3
|
||
|
Static Enterprises LLC is seeking an established agency to lead Infrastructure, Reliability & Security for Static AI, our conversational AI and CRM platform serving collection agencies, sales teams, and other high-volume call operations.
We have an existing platform and are organizing development into five specialized departments. Your agency will take responsibility for the infrastructure, deployment systems, monitoring, recovery processes, and security controls that support reliable daily operations. This engagement includes initial assessment, prioritized improvements, ongoing infrastructure management, and incident response. Your agency’s responsibilities will include: Assessing the existing hosting environment, servers, networking, configurations, access controls, deployment processes, and infrastructure costs. Identifying reliability risks, security weaknesses, capacity constraints, and single points of failure, then developing a prioritized remediation roadmap. Maintaining separation between development, sandbox, and production environments. Building and maintaining repeatable infrastructure configurations, deployment pipelines, release controls, and rollback procedures. Implementing useful monitoring, centralized logging, health checks, and actionable alerts across critical services. Managing capacity, resource allocation, networking, and scaling in coordination with the backend and AI/telephony teams. Supporting the infrastructure requirements of real-time calling, including network stability, connectivity, and resource availability. Managing named accounts, multifactor authentication, least-privilege access, secrets, and credential rotation. Maintaining infrastructure patching, vulnerability management, secure configurations, and appropriate protection for sensitive customer data. Implementing backups, validating restores, and documenting disaster recovery procedures. Handling infrastructure incidents through documented triage, escalation, recovery, and root-cause analysis. Tracking operating costs and recommending measurable improvements to infrastructure efficiency. Maintaining architecture documentation, operating procedures, access inventories, and continuity plans. Your agency will supply and manage the technical leadership, infrastructure engineers, security expertise, and project coordination required to deliver the agreed scope. Proposals must identify the actual team available, committed capacity, support hours, on-call arrangements, and backup personnel. Incident coverage and response commitments must be clearly defined before engagement. We need demonstrated experience operating production SaaS infrastructure, introducing changes while clients remain active, and recovering services when failures occur. Experience supporting real-time communications or voice AI workloads is particularly relevant. You will work alongside our Backend, AI/Voice/Telephony, Frontend, and QA departments. Clear coordination is essential when application changes affect capacity, security, deployment requirements, or system availability. Changes must be developed and validated in our sandbox environment before entering the approved production release process. Routine production releases follow our scheduled windows on the 1st and 15th. Urgent incidents must be escalated through agreed response and approval procedures. Infrastructure accounts, repositories, deployment systems, monitoring tools, secrets management, and documentation must remain under company control. Access must be attributable to individual team members, with documented handoff and access-removal procedures. Performance will be measured through agreed service availability, incident detection and response, recovery times, deployment stability, vulnerability remediation, backup restoration results, and infrastructure costs. Specific targets will be established after assessing the existing environment and business requirements. Regular reporting must show completed improvements, unresolved risks, incidents, capacity trends, and operating costs. We are proposing a long-term revenue-participation partnership. The agency will be responsible for funding and managing its delivery team under the agreed arrangement. Revenue-share percentages, eligible revenue, payment calculations, contract duration, staffing commitments, service targets, and termination provisions will be defined in the final agreement. Actual compensation will depend on eligible revenue. Responsibility for hosting, software licenses, and other third-party operating costs will be defined separately. Please address these three points in your proposal: Describe a production SaaS environment your agency managed or inherited. Explain the reliability or security problems you resolved and provide measurable results where available. Identify the team you would assign, their relevant experience, committed availability, incident coverage, escalation process, and earliest start date. Confirm your interest in a revenue-participation partnership and explain how your agency would sustain staffing, operational coverage, documentation, and continuity throughout the engagement. We are looking for a team that identifies problems early, responds clearly when incidents occur, and takes responsibility for maintaining dependable, secure operations.
Fixed budget:
1,450 USD
1 day ago
|
|||||
|
Commercial Legal Counsel For a Croatian-based IT Company
Applied
|
$25 - $50
/ hr
|
1 day ago |
3
|
||
|
Svrha ovog oglasa je naci pravnog savjetnika sposobnog pruziti pravni savjet koji mi je potreban u svrhu obavljanja svoje obrtne djelatnosti.
Moja situacija je sljedeca. Trenutno sam vlasnik obrta koji obavlja djelatnost savjetnistva i razvoja softvera. Kroz sljedecih tjedan dana, cilj mi je poceti sluziti strana trzista ukljucujuci cijelu Europu, Sjedinjene Americke Drzave, i potencijalno trziste jugoistocne Azije. S druge strane, vizija mi je suradjivati sa podizvodjacima na vecim projektima. Stoga, potreban mi je pravni savjet, te pravna dokumentacija kojom cu moci ostvariti iznad opisane svrhe. Nakon kratkog istrazivanja koje sam svojerucno proveo, dosao sam do informacije da ce mi biti potrebni sljedeci dokumenti: - Master Services Agreement (MSA), - Statement of Work (SOW), te - Data Processing Agreement (DPA), sa obje, klijentske i podizvodjacke strane. Ukoliko imate iskustva u savjetodavanju i definiranju spomenutih dokumenata za nekoga u mojoj situaciji, prijavite se na natjecaj kako bi organizirali sastanak. Radujem se citanju Vase prijave!
Hourly rate:
25 - 50 USD
1 day ago
|
|||||
|
Trustpilot & Review Automation Expert
Applied
|
not specified | 1 day ago |
1
|
||
|
We need an expert to set up and manage a Trustpilot review automation system for our business. The work includes configuring the review flow, connecting it to our operations, and ensuring reviews are collected consistently. You will deal with negative reviews and promote positive ones. We are looking fro someone who can keep the system running smoothly and help strengthen our customer feedback process.
Budget:
not specified
1 day ago
|
|||||
|
Cybersecurity & Digital Organization Expert for Solo Healthcare Practice
Applied
|
$45 - $75
/ hr
|
1 day ago |
1
|
||
|
I am a licensed clinical social worker and owner of Bedrock Therapies, a solo psychotherapy practice in California. I am looking for an experienced, highly organized cybersecurity/IT professional to help me **secure, simplify, and organize my entire digital business environment**.
I am NOT looking for someone who simply runs an automated security scan and gives me a report. I need someone who can work directly with me by Zoom/screen share, identify vulnerabilities and organizational problems, **implement the fixes with me**, and leave me with a system that is secure, simple, and easy for me to maintain. ### What I Need Help With **Google Workspace & Email** * Review and secure my business Google account/email * MFA/2FA * Recovery methods and backup codes * Google Drive permissions/security * Review account access and connected applications * SPF, DKIM and DMARC for my business email/domain * Make sure losing my phone or computer would not lock me out of my business **Passwords & Account Security** * Review my current password-management system * Help organize and secure passwords * Identify reused/weak/old passwords * MFA/2FA on important accounts * Determine where hardware security keys make sense * Establish secure recovery procedures * Remove old/unnecessary access I do NOT want to hand someone a master spreadsheet containing all of my passwords. I want someone who understands secure ways of working together while I retain control of sensitive credentials. **WordPress Website / Domain / Hosting** * Security audit of my WordPress website * WordPress administrator accounts * Plugins/themes and updates * Login protection/MFA * Malware/vulnerability protection * Backups and recovery * SSL/HTTPS * Hosting account security * Domain registrar and DNS security * Review who has administrative access * Make sure I can recover the website/domain if something goes wrong **Computers, Phones & Network** * Mac security * iPhone/iPad security as applicable * Encryption, updates and device access * Wi-Fi/router security * Backup strategy * Lost/stolen device recovery * Review unnecessary software, extensions or access **Business & Financial Account Organization** I have accumulated too many online accounts and saved credit cards/payment methods over time, including Amazon and other services. I want help: * Inventorying important business accounts * Cleaning up unnecessary/duplicate accounts * Removing expired/unnecessary stored credit cards * Better separating business and personal payment methods * Reviewing subscriptions * Organizing recurring payments * Securing financial accounts while I personally retain control of banking/financial credentials **Healthcare / Privacy** Because I operate a psychotherapy practice, security and privacy are especially important. Experience with healthcare, HIPAA, mental-health practices, medical practices, or other highly confidential professional environments is strongly preferred. If your work would require access to systems containing PHI, we would need to determine appropriate access controls and BAA requirements before access is provided. ### What I Want at the End I don't just want to be told what is wrong. I want the problems **fixed and organized**. At the end of the project I want: 1. My highest-risk security issues identified and remediated. 2. Google Workspace/email properly secured. 3. WordPress website, domain, DNS and hosting secured. 4. Passwords, MFA and account recovery properly organized. 5. Macs/iPhones/network/backups appropriately secured. 6. Online business accounts and payment methods cleaned up and organized. 7. Old/unnecessary access removed. 8. A reliable emergency recovery process if my phone/computer/account is lost or compromised. 9. A simple **Bedrock Therapies Digital Security & Accounts Map** showing what my important systems are, where they live, who has access, how they are protected, and how they can be recovered. 10. A short checklist showing what I should review monthly, quarterly and annually. ### Simplicity Is Important I am a psychotherapist, not an IT professional. I want strong security, but I do NOT want someone to install a complicated enterprise-level system that becomes another job for me to manage. The best outcome is a system that is **highly secure, streamlined, organized, documented, and easy for me to use.** ### How I Prefer to Work I would like to work collaboratively by Zoom/screen share. For highly sensitive accounts, I can enter passwords and authentication codes myself rather than providing the credentials to the consultant. I value someone who is patient, communicates clearly in plain English, and can explain why we are making important changes without overwhelming me with technical terminology. ### Ideal Experience Strong experience in several of the following: * Cybersecurity / information security * Google Workspace administration and security * Identity and access management * MFA / security keys * Password management * WordPress security * Website hosting * Domain registrar / DNS security * SPF / DKIM / DMARC * Mac and iOS security * Network/Wi-Fi security * Backup/disaster recovery * Healthcare/HIPAA environments * Small-business IT organization Security certifications are welcome, but **demonstrated hands-on experience and good judgment are more important to me than certifications alone.** ### When Applying, Please Answer These Questions 1. Have you completed a similar security and digital-organization project for a solo healthcare, mental-health, medical, legal, financial, or other highly confidential professional practice? Please briefly describe it. 2. If you had your first 2–3 hours with me, what would you assess and secure first, and why? 3. Which parts of this project can you personally **implement**, rather than simply audit and recommend? 4. How would you work securely with me without requiring me to give you a master list of passwords? 5. What experience do you have with Google Workspace security, WordPress, domains/DNS, MFA, password managers, Macs/iPhones and backups? 6. What experience do you have with HIPAA or healthcare cybersecurity? Are you comfortable signing a BAA if your level of access requires one? 7. What is your hourly rate and approximately how many hours do you believe the initial security audit, cleanup, remediation, organization and documentation would require? 8. Are you comfortable working directly with me through Zoom/screen sharing and teaching me the system as we go? I am looking for **one excellent person who can take ownership of this project from beginning to end**, rather than hiring several different specialists. My priority is not a fancy report. My priority is to finish this project feeling confident that my business is secure, organized, recoverable, and substantially easier to manage. Client's questions:
Hourly rate:
45 - 75 USD
1 day ago
|
|||||
|
Penetration Testing for B2B SaaS Platform (OWASP-based, formal report required)
Applied
|
$1,500
|
2 days ago |
4
|
||
|
We are a B2B SaaS company serving clients in healthcare and the public sector. We're looking for an experienced penetration tester to perform a grey-box penetration test of our web platform.
Scope: Web application (multi-tenant SaaS, role-based access: admins, coaches, coachees/employees) REST API Authentication & session management (incl. password reset flows) Testing against OWASP Top 10: SQL injection, XSS, CSRF, IDOR/broken access control, authentication flaws, security misconfigurations Multi-tenancy isolation testing (can tenant A access tenant B's data?) ... Deliverables: A formal penetration test report (in English) including executive summary, methodology, findings classified by severity (CVSS), reproduction steps, and remediation advice A debrief call to walk through the findings Context: We are working toward ISO 27001 certification and our clients require evidence of regular security testing, so the report must be suitable to share (in redacted/summary form) with auditors and client procurement teams. Requirements: Proven experience with web application pentesting (please share sample/redacted reports) Certifications such as OSCP, OSWE, CEH, or eWPT are a strong plus Testing will be performed on a dedicated staging environment; an NDA and rules-of-engagement document must be signed before starting Willing to work within an agreed testing window and scope Please include in your proposal: your methodology, estimated hours, example report structure, and relevant certifications. Client's questions:
Fixed budget:
1,500 USD
2 days ago
|
|||||
|
US tech transactions attorney: vendor-side review and redline of enterprise software license and DPA
Applied
|
$3,000
|
2 days ago |
5
|
||
|
We are a US software company licensing a maintained, hardened distribution of an open-source application to enterprise customers on an annual subscription. An enterprise customer — a large US insurer — is sending us their end-user licence agreement and a data processing agreement. We need a fixed-fee review, redline, and negotiation position, not blank-page drafting.
Scope of the engagement: + Review the customer's EULA and DPA, plus any information security addendum or vendor code of conduct that attaches. + Deliver a tracked-changes redline with fallback positions where a first ask is likely to be refused. + Deliver a short issues memo, two pages maximum, ranking every issue as must-have, worth trading, or accept. We need to know what to spend our leverage on. + Review our one-page order form for a small fixed-fee assessment that will execute ahead of the licence. + One 30-minute call to walk through the memo. + Structure the redline so the positions are reusable as our standard form for future customers, not one-off to this deal. Our positions going in, which we will explain on the call: + No assignment of intellectual property. We license; we do not transfer. Watch specifically for deliverables or work-product clauses that would sweep in software changes. + An express right to contribute changes derived from customer-specific patches to the upstream open-source project under its own licence. This is commercially essential and non-negotiable for us. + Warranty carve-out for third-party open-source behavior we do not control. Liability cap at fees paid, with a supercap for the usual carve-outs. Expect the customer to open much higher. + We use engineering personnel outside the United States. Expect subcontractor and personnel-location restrictions and help us position controls rather than a blanket prohibition. + We process no personal data. We would prefer no DPA, or a narrow one recording that no personal data is transferred. + Confidential customer material we receive includes technical and security documentation, and we want handling obligations that are workable rather than absolute. Requirements: + Licensed and in good standing in a US state. Please state which. Familiarity with New York and Delaware governing law preferred. + Demonstrable experience representing software vendors against enterprise or Fortune 500 procurement and legal teams. Vendor side specifically, not customer side. + Working knowledge of open-source licensing, particularly permissive licences and downstream distribution. + Available to start this week. Redline and memo within five business days of receiving the documents. Please respond with: 1. Your state licence and bar number. 2. Two examples of enterprise software agreements you have negotiated on the vendor side, described without breaching confidentiality. 3. A fixed fee for the scope above, and a separate fixed fee per subsequent negotiation round. 4. Your view, in three or four sentences, on how a small vendor should approach a liability cap when the customer is a large insurer. 5. Confirmation that you have no conflict representing large US insurance carriers adverse to software vendors. We will share the specific counterparty name privately, under a confidentiality agreement, before any documents change hands. 6. How do you use AI tools in review and redlining, if at all? Confidential client documents in this engagement may not be entered into any AI tool that retains inputs, trains on them, or lacks a zero-retention/no-training guarantee. Tell us what you use and how you keep client material out of it. Please do not apply if you are not a licensed US attorney, if you work only from templates, or if you cannot quote a fixed fee.
Fixed budget:
3,000 USD
2 days ago
|
|||||
|
Ethical Hacker for Security Testing
Applied
|
not specified | 2 days ago |
1
|
||
|
We need an ethical hacker to perform security testing on our systems and identify vulnerabilities. The ideal freelancer should be able to assess risks, conduct penetration tests, and provide clear recommendations for improving security. Experience with network and application security is important, along with the ability to communicate findings effectively. This is a part-time project for someone who can work independently and deliver reliable results.
Budget:
not specified
2 days ago
|
|||||
|
Sophisticated Logo for Cyber Resilience Firm
Applied
|
~338 - 1,015 USD
|
2 days ago |
-
|
||
|
I need a Business Logo. I am starting a new Business - Cernis Advisory Limited. We provide business advisory services to organisations looking to strengthen their Cyber Security maturity and Resilience. We help organisations navigate security frameworks, manage third-party risk, and achieve audit-ready compliance without operational friction.
Derived from the classical Latin verb cernere, Cernis translates directly to "you perceive," "you see clearly," or "you distinguish." It forms the core philosophy of our advisory practice: Distinguishing Signal from Noise: We filter out technical jargon, IT reports, and operational hype to reveal the true underlying risk posture of your business. Uncovering Hidden Blind Spots: As an independent partner, we bring a fresh perspective to highlight critical cyber, data, and compliance exposures that internal teams or MSPs might overlook. Empowering Board Clarity: We equip Directors, FDs, and Trustees with the clear, plain-English insight required to fulfil their fiduciary duties and make confident strategic decisions. Industry: B2B Information Security, Cyber Resilience, and GRC Advisory Brand Voice: Authoritative, pragmatic, structured, senior-led, trusted. Primary Color Palette: Deep Slate Navy (#0B192C), Forest Emerald (#059669), and Slate Gray (#334155). Skills: Graphic Design, Logo Design, Photoshop, Illustrator, Branding, Corporate Identity, Business Card Design, Marketing Strategy, Business Consulting, Visual Design
Fixed budget:
250 - 750 GBP
2 days ago
|
|||||
|
Linux System Administrator (Onsite Opportunity in Killeen, Texas)
Applied
|
$35 - $55
/ hr
|
2 days ago |
5
|
||
|
Linux Systems Administrator
Job Type: Full-Time Location: Killeen, Texas Department: Systems Support Job Summary We are looking for an experienced Linux Systems Administrator to administer, monitor, secure, and maintain enterprise Linux environments. The ideal candidate will have strong hands-on experience with RHEL, Ubuntu, and CentOS, along with familiarity with Windows Server, VMware, and containerized environments such as OpenShift and Kubernetes. This role will provide Tier 2/3 technical support, troubleshoot complex infrastructure issues, support enterprise applications, and collaborate closely with development, DevOps, and security teams. Key Responsibilities Administer, monitor, maintain, and troubleshoot Linux systems, including RHEL, Ubuntu, and CentOS. Install, configure, secure, and optimize Linux services such as systemd, SSH, Apache/Nginx, cron, and related services. Perform Linux system upgrades, patching, configuration, and security hardening. Provide Tier 2/3 support for escalated server and infrastructure issues. Identify, research, and implement Linux and OpenShift solutions and applications. Support and troubleshoot enterprise applications and their underlying server environments. Manage Linux security administration in collaboration with information security teams. Monitor system health, performance, availability, and capacity, and proactively address potential issues. Collaborate with development, DevOps, infrastructure, and security teams to support application and infrastructure requirements. Provide technical guidance and support to IT teams on Linux configuration and administration. Maintain awareness of Linux and OpenShift updates, changes, and new releases, and communicate relevant changes to stakeholders. Work with vendors and internal teams to resolve technical issues and support applications and infrastructure. Create and maintain accurate technical documentation, processes, and standard operating procedures. Participate in a weekly on-call rotation to respond to after-hours infrastructure issues. Travel to other data centers or company locations as required. Perform other duties and assignments as needed. Windows Server & Virtualization Provide administration and support for Windows Server environments and related services. Working knowledge of Active Directory, Group Policy, DNS, DHCP, and PowerShell. Administer VMware vSphere/ESXi environments, including: Virtual machine deployment Resource management VM administration Snapshots Basic troubleshooting OpenShift & Containerization Support and administer OpenShift/Kubernetes environments. Install, configure, maintain, upgrade, monitor, and troubleshoot OpenShift/Kubernetes clusters. Support containerized applications using OpenShift, Kubernetes, or Docker. Stay current with developments, updates, and best practices in container orchestration technologies. Security & Compliance Ensure compliance with security standards, patching schedules, and organizational policies. Apply security hardening practices to Linux and server environments. Understand common web application and infrastructure vulnerabilities, risks, and appropriate countermeasures. Work closely with security teams to identify and remediate security issues. Maintain confidentiality of sensitive customer, business, and internal information. Required Qualifications & Skills Bachelor's degree in Computer Science, Computer Engineering, Information Technology, or a related field preferred. Equivalent relevant experience may be considered. Strong hands-on experience administering Linux servers, preferably RHEL, Ubuntu, and/or CentOS. Strong troubleshooting and analytical skills with the ability to independently research and resolve complex technical issues. Experience with Linux system administration, configuration, patching, and security. Knowledge of Windows Server administration and core services. Familiarity with VMware vSphere/ESXi. Knowledge of web/application server technologies such as Apache and Nginx. Understanding of server and web application security principles. Ability to manage multiple priorities and meet project deadlines. Strong written and verbal communication skills. Ability to collaborate effectively with technical and non-technical stakeholders. Ability to work independently as well as part of a broader IT team. Willingness to participate in an on-call rotation. Preferred Qualifications Experience with OpenShift, Kubernetes, and/or Docker. Experience installing, configuring, upgrading, monitoring, and troubleshooting OpenShift/Kubernetes clusters. Familiarity with CI/CD pipelines, Git, and DevOps practices. Experience with Infrastructure as Code (IaC) tools such as Terraform and Ansible. Experience with monitoring and logging platforms such as Prometheus, Grafana, ELK, or Splunk. Familiarity with Linux security hardening and patch management. Certifications such as RHCSA, RHCE, CKA, CKAD, or OpenShift certifications are a plus. What We're Looking For We are looking for someone who is technically strong, security-conscious, and comfortable working across Linux infrastructure, virtualization, and modern containerized environments. The ideal candidate should be proactive, capable of handling complex production issues, and able to collaborate effectively across IT, DevOps, development, and security teams.
Hourly rate:
35 - 55 USD
2 days ago
|
|||||
|
Dogstar systems
Applied
|
not specified | 2 days ago |
1
|
||
|
Hi Connor,
I want to stop expanding DogStar Life and define the smallest credible private beta we can build, launch to approximately 25–50 users, and learn from. The beta should test whether users can complete the core workflow, return to the product, perceive enough value to consider paying, and provide actionable feedback. I do not want to build the full DogStar vision yet. Please provide a direct proposal covering: 1. The specific user problem and core workflow the beta should support. 2. What you can confidently build yourself and what would require outside expertise. 3. The minimum features and functionality required. 4. What should be explicitly excluded or postponed, including unnecessary features, integrations, automations, and design work. 5. A detailed scope distinguishing included, excluded, and future-consideration items. 6. Whether you recommend the current stack: • Lovable frontend • Supabase Auth + Database • Supabase Edge Functions • Server-side AI/model abstraction • Stripe If you recommend changes, explain the reason, cost, and timeline impact. 7. All assumptions about existing code, designs, content, accounts, integrations, and requirements. 8. Dependencies, potential blockers, and decisions or materials required from me or third parties. 9. Recommended milestones, deliverables, acceptance criteria, and how we will determine that each milestone and the completed beta are finished and working. 10. Estimated cost for each milestone and the total cost for the complete private beta. 11. Expected timeline, including assumed client-review and approval time. 12. Files, accounts, repository access, documents, content, credentials, product decisions, and other materials needed before work begins. 13. Required privacy, security, accessibility, QA, analytics, legal, and other work, including anything requiring a separate specialist. 14. Recommended testing, instrumentation, feedback collection, and success measures for the first 25–50 users. 15. What must be completed for the beta to be production-capable rather than a demo. 16. What you believe I am overbuilding, underestimating, or spending money on too early. 17. Expected ongoing monthly costs for hosting, database, authentication, AI/API usage, email, payments, monitoring, analytics, and other required services. Please structure the proposal under these headings: • In scope for the smallest credible beta • Explicitly out of scope • Assumptions • Dependencies and client responsibilities • Milestones and deliverables • Acceptance criteria • Estimated costs • Timeline • Ongoing operating costs • Risks and open questions The central constraint is to build only what is necessary to test the core hypothesis with real users. Please protect me from overbuilding: if a feature is not required to evaluate usage, retention, feedback, or willingness to pay, recommend excluding it. Ultimately, I need to know exactly what the smallest credible private beta would include and exclude, what assumptions and dependencies it requires, how acceptance will be defined, what it will cost, how long it will take, and what I will have when it is complete. Thanks, Brandt Evans Founder DogStar Systems LLC
Budget:
not specified
2 days ago
|
|||||
Related freelance jobs queries: