Boost Your Security Analysis Freelancing
Discover projects tailored to your expertise in security analysis on platforms like Upwork. Vollna enhances your search with advanced filters, real-time notifications, and comprehensive analytics, enabling you to bid smarter and win more.
Signup for free
to get access to all filter attributes and instant notifications when new jobs are posted.
Setup filter
Get access to over 30+ filter attributes, setup instant notifications, integrate with your CRM and marketing tools, and more.
Start free trial
139 projects
published for past 72 hours.
| Job Title | Budget | Published | |||
|---|---|---|---|---|---|
|
Ethical Hacker for Security Testing
Applied
|
not specified | 9 hours ago |
1
|
||
|
We need an ethical hacker to perform security testing on our systems and identify vulnerabilities. The ideal freelancer should be able to assess risks, conduct penetration tests, and provide clear recommendations for improving security. Experience with network and application security is important, along with the ability to communicate findings effectively. This is a part-time project for someone who can work independently and deliver reliable results.
Budget:
not specified
9 hours ago
|
|||||
|
Ethical Hacking for Phone Security
Applied
|
$20 - $50
/ hr
|
9 hours ago |
1
|
||
|
I need help securing my phone and removing potential remote spyware or tracking threats. I have already changed my number, phone, and used a cloud Yubi Key, but I still feel vulnerable. I’m looking for someone experienced to investigate possible remote Trojan or spyware access, secure my device, and perform backward forensics if possible to identify who might be tracking me. I also want penetration testing to test how secure my phone is and confirm that it cannot be hacked remotely.
Hourly rate:
20 - 50 USD
9 hours ago
|
|||||
|
Analyst
Applied
|
not specified | 10 hours ago |
1
|
||
|
Research & Analytical Writer — Military, Geopolitical & Security Topics
We are looking for an experienced research and analytical writer to support a project involving detailed written reports on military, geopolitical, security, and international affairs topics. The ideal candidate will be comfortable researching complex subjects, evaluating information from reliable publicly accessible sources, identifying key developments and trends, and presenting findings in a clear, structured, and analytical format. Responsibilities Conduct thorough research using reliable, legally accessible sources Analyze military, geopolitical, security, and international affairs topics Produce well-structured research reports and analytical briefs Distinguish facts, assessments, and source-supported conclusions Synthesize information from multiple sources into clear written analysis Maintain strong standards of accuracy, objectivity, and attribution Revise reports based on feedback and project requirements Ideal Background We are particularly interested in candidates with experience in one or more of the following: Military journalism or military-related writing Intelligence or security analysis Geopolitical or international affairs research OSINT-based research using publicly available information Government, defense, military, or national-security research Investigative or long-form analytical journalism Strong professional writing and research skills are essential. What We Are Looking For Excellent English writing and editing skills Strong analytical and research abilities Ability to understand complex subjects and explain them clearly Ability to work independently and meet deadlines Strong attention to factual accuracy and source quality Experience producing substantive reports, briefs, articles, or analytical content Important: All research must be conducted using lawful, appropriate, and publicly accessible sources. The project does not require or authorize access to classified, restricted, confidential, or proprietary information. When applying, please briefly describe your relevant research/writing experience and provide examples of comparable work where possible.
Budget:
not specified
10 hours ago
|
|||||
|
Long-Term Full-Stack & Technical Specialist Needed | Finance Domain
Applied
|
$800
|
1 day ago |
3
|
||
|
We are an established finance company with more than 12 years of experience, building secure and scalable applications for individuals and businesses.
We are looking for a versatile technical professional to join our team on a long-term basis. This is a hands-on role covering software development, cloud infrastructure, servers, security, monitoring, and technical operations. You will work alongside our System Administrator and support our Technical Manager and management team on various technical matters. We need someone who can take ownership, make decisions, troubleshoot independently, and work across different areas of technology. 🔧 Key Responsibilities Develop and maintain applications using NestJS, TypeScript, Angular, MySQL and Redis. Build and maintain APIs and integrations. Troubleshoot application, server, and production issues. Work with Microsoft Azure and OVH Cloud environments. Manage and troubleshoot Linux/Windows servers and cloud infrastructure. Monitor systems, logs, performance, and availability. Support deployments, backups, and disaster recovery. Work with the System Administrator on infrastructure and technical issues. Support the Technical Manager with technical analysis and implementation. Identify security risks and recommend improvements. Manage and review access, permissions, MFA, and authentication mechanisms. Understand public/private keys, SSH keys, certificates and secure credential management. Support security of Microsoft Outlook, OneDrive and Microsoft 365. Understand and apply principles related to ISO 27001 and GDPR. Assist with vulnerability assessments and penetration testing. Investigate incidents and perform root-cause analysis. 🛡️ Security Knowledge Security is an important part of this role. You should have practical knowledge of: ISO 27001 GDPR IAM and least privilege Microsoft Entra ID / Azure AD MFA and Conditional Access Server hardening Vulnerability management Penetration testing Security monitoring Data protection Private/public key mechanisms 🤖 AI Tools You should be highly comfortable using modern AI tools such as Claude and Antigravity for development, troubleshooting, code review, documentation, security analysis, and technical research. You must also be able to verify AI-generated solutions rather than blindly relying on them. 🎯 Ideal Candidate 5+ years of relevant technical experience. Strong NestJS, TypeScript, Angular, MySQL and Redis experience. Good understanding of backend and frontend development. Practical experience with Azure and OVH Cloud. Good server, networking, and infrastructure knowledge. Good understanding of cybersecurity and data protection. Comfortable working independently across multiple technical areas. Strong problem-solving and decision-making skills. Able to explain technical issues clearly and without unnecessary complexity. Comfortable working with developers, system administrators, and management. Willing to take ownership rather than waiting for step-by-step instructions. 📋 Please Include in Your Application Short summary of your relevant experience. Your experience with NestJS, Angular, TypeScript, MySQL and Redis. Your Azure and OVH Cloud experience. Your experience with security, ISO 27001 and GDPR. Examples of technical/security problems you have solved. Your experience with Claude, Antigravity, or similar AI tools. GitHub/portfolio/LinkedIn links if available. Availability per week and hourly rate. Attention to Detail Please begin your proposal with the word: Credebt Proposals that do not follow this instruction may not be considered. We are looking for someone interested in a long-term relationship who can contribute across development, infrastructure, cloud, security, and technical operations.
Fixed budget:
800 USD
1 day ago
|
|||||
|
Cyber Security Talent Recruiter
Applied
|
$500
|
1 day ago |
1
|
||
|
I'm looking for an outstanding technology recruiter with a proven track record in cyber security. The mindset is simple: quality over quantity. Exceptional standards in candidate selection and meticulous attention to detail are essential. Less is more. Provided it is done properly. Reliability, clear communication and a strong service ethos are paramount. Success means achieving results together, rather than simply rushing through tasks and ticking boxes.
cyberunity.io | cyber security expertHUB Client's questions:
Fixed budget:
500 USD
1 day ago
|
|||||
|
Wifi problem
Applied
|
not specified | 1 day ago |
1
|
||
|
Hi, I’m having an intermittent Wi-Fi problem with my PC.
The Wi-Fi works normally on my other devices, but on this PC the connection becomes extremely slow, has very high/inconsistent latency, and sometimes disconnects. I tested by pinging my router and I was getting very unstable results, including around 118 ms, over 1000 ms, and 392 ms. Interestingly, my phone’s hotspot works normally on the same PC, so the problem seems to occur specifically when the PC connects to my home Wi-Fi. I updated the PC’s Wi-Fi/network drivers, and that temporarily fixed the problem. However, the exact same issue has now returned. Could you please check whether this could be a problem with the Wi-Fi adapter, its driver, Windows network settings, or compatibility with my router? I’d like to find the underlying cause because the driver update only fixed it temporarily.
Budget:
not specified
1 day ago
|
|||||
|
Network Security Analysis
Applied
|
not specified | 1 day ago |
3
|
||
|
Network Security Assessment
We are looking to develop an automated solution that scans network-connected machines, identifies security vulnerabilities and configuration risks, analyzes the findings, and generates a clear security report with recommended actions. The goal is to proactively identify risks across servers, workstations, and network devices before they become security incidents.
Budget:
not specified
1 day ago
|
|||||
|
Senior Cyber Security Consultant
Applied
|
$50 - $70
/ hr
|
1 day ago |
3
|
||
|
Project Description and Responsibilities:
To provide senior cyber security consultancy, advisory and delivery support to CSS Assure and its UK and international clients across information security, governance, risk, compliance and cyber resilience engagements, ensuring successful delivery and the continual improvement of CSS Assure's security services. Priority requirement: Proven experience delivering Cyber Assessment Framework (CAF) engagements, including scoping, assessment against CAF objectives and contributing outcomes, gap analysis and remediation planning for organisations in scope of NIS Regulations or CAF-aligned assurance regimes. The role may include: Leading and delivering cyber security, governance, risk, compliance and assurance engagements for CSS Assure clients. Performing assessments, audits, risk assessments, vulnerability reviews and compliance evaluations against recognised standards and frameworks, including CAF, ISO 27001 and Cyber Essentials. Conducting Cyber Essentials assessments and supporting certification body activities in line with scheme and accreditation standards. Acting as subject matter expert for Darktrace, Qualys and other security technologies used by CSS Assure and its clients. Developing and improving information security frameworks, policies, procedures and controls. Producing reports, findings, recommendations and remediation roadmaps, and supporting clients in remediating identified risks and gaps. Providing technical oversight, quality assurance and peer review of engagements and deliverables. Advising clients on risks, threats, emerging trends, good practice and regulatory requirements. Supporting incident response, breach management, disaster recovery and business continuity activities for CSS Assure and its clients. Developing and delivering security awareness, governance and specialist training. Mentoring and coaching CSS Assure consultants to build capability and service quality. Contributing to service, methodology and product development, and to business development activities including proposals, statements of work and solution design. Supporting CSS Assure's internal security and compliance activities, including ISO 27001, Cyber Essentials and continual improvement. Reporting significant delivery, operational or security risks identified during consultancy activities. Client's questions:
Hourly rate:
50 - 70 USD
1 day ago
|
|||||
|
Long-Term Full-Stack & Technical Specialist Needed | Finance Domain
Applied
|
$800
|
1 day ago |
3
|
||
|
We are an established finance company with more than 12 years of experience, building secure and scalable applications for individuals and businesses.
We are looking for a versatile technical professional to join our team on a long-term basis. This is a hands-on role covering software development, cloud infrastructure, servers, security, monitoring, and technical operations. You will work alongside our System Administrator and support our Technical Manager and management team on various technical matters. We need someone who can take ownership, make decisions, troubleshoot independently, and work across different areas of technology. 🔧 Key Responsibilities Develop and maintain applications using NestJS, TypeScript, Angular, MySQL and Redis. Build and maintain APIs and integrations. Troubleshoot application, server, and production issues. Work with Microsoft Azure and OVH Cloud environments. Manage and troubleshoot Linux/Windows servers and cloud infrastructure. Monitor systems, logs, performance, and availability. Support deployments, backups, and disaster recovery. Work with the System Administrator on infrastructure and technical issues. Support the Technical Manager with technical analysis and implementation. Identify security risks and recommend improvements. Manage and review access, permissions, MFA, and authentication mechanisms. Understand public/private keys, SSH keys, certificates and secure credential management. Support security of Microsoft Outlook, OneDrive and Microsoft 365. Understand and apply principles related to ISO 27001 and GDPR. Assist with vulnerability assessments and penetration testing. Investigate incidents and perform root-cause analysis. 🛡️ Security Knowledge Security is an important part of this role. You should have practical knowledge of: ISO 27001 GDPR IAM and least privilege Microsoft Entra ID / Azure AD MFA and Conditional Access Server hardening Vulnerability management Penetration testing Security monitoring Data protection Private/public key mechanisms 🤖 AI Tools You should be highly comfortable using modern AI tools such as Claude and Antigravity for development, troubleshooting, code review, documentation, security analysis, and technical research. You must also be able to verify AI-generated solutions rather than blindly relying on them. 🎯 Ideal Candidate 5+ years of relevant technical experience. Strong NestJS, TypeScript, Angular, MySQL and Redis experience. Good understanding of backend and frontend development. Practical experience with Azure and OVH Cloud. Good server, networking, and infrastructure knowledge. Good understanding of cybersecurity and data protection. Comfortable working independently across multiple technical areas. Strong problem-solving and decision-making skills. Able to explain technical issues clearly and without unnecessary complexity. Comfortable working with developers, system administrators, and management. Willing to take ownership rather than waiting for step-by-step instructions. 📋 Please Include in Your Application Short summary of your relevant experience. Your experience with NestJS, Angular, TypeScript, MySQL and Redis. Your Azure and OVH Cloud experience. Your experience with security, ISO 27001 and GDPR. Examples of technical/security problems you have solved. Your experience with Claude, Antigravity, or similar AI tools. GitHub/portfolio/LinkedIn links if available. Availability per week and hourly rate. Attention to Detail Please begin your proposal with the word: Credebt Proposals that do not follow this instruction may not be considered. We are looking for someone interested in a long-term relationship who can contribute across development, infrastructure, cloud, security, and technical operations.
Fixed budget:
800 USD
1 day ago
|
|||||
|
Cybersecurity and Pentester Expert
Applied
|
$20 - $50
/ hr
|
1 day ago |
1
|
||
|
We need an expert to assess our website and network security, identify vulnerabilities, and provide clear recommendations for improvement. The work includes reviewing current security measures, testing for weaknesses, and delivering a detailed report with actionable next steps. This is a short-term project for someone who can work independently and communicate findings clearly.
Hourly rate:
20 - 50 USD
1 day ago
|
|||||
|
Long-Term Full-Stack & Technical Specialist Needed | Finance Domain
Applied
|
$800
|
1 day ago |
3
|
||
|
We are an established finance company with more than 12 years of experience, building secure and scalable applications for individuals and businesses.
We are looking for a versatile technical professional to join our team on a long-term basis. This is a hands-on role covering software development, cloud infrastructure, servers, security, monitoring, and technical operations. You will work alongside our System Administrator and support our Technical Manager and management team on various technical matters. We need someone who can take ownership, make decisions, troubleshoot independently, and work across different areas of technology. 🔧 Key Responsibilities Develop and maintain applications using NestJS, TypeScript, Angular, MySQL and Redis. Build and maintain APIs and integrations. Troubleshoot application, server, and production issues. Work with Microsoft Azure and OVH Cloud environments. Manage and troubleshoot Linux/Windows servers and cloud infrastructure. Monitor systems, logs, performance, and availability. Support deployments, backups, and disaster recovery. Work with the System Administrator on infrastructure and technical issues. Support the Technical Manager with technical analysis and implementation. Identify security risks and recommend improvements. Manage and review access, permissions, MFA, and authentication mechanisms. Understand public/private keys, SSH keys, certificates and secure credential management. Support security of Microsoft Outlook, OneDrive and Microsoft 365. Understand and apply principles related to ISO 27001 and GDPR. Assist with vulnerability assessments and penetration testing. Investigate incidents and perform root-cause analysis. 🛡️ Security Knowledge Security is an important part of this role. You should have practical knowledge of: ISO 27001 GDPR IAM and least privilege Microsoft Entra ID / Azure AD MFA and Conditional Access Server hardening Vulnerability management Penetration testing Security monitoring Data protection Private/public key mechanisms 🤖 AI Tools You should be highly comfortable using modern AI tools such as Claude and Antigravity for development, troubleshooting, code review, documentation, security analysis, and technical research. You must also be able to verify AI-generated solutions rather than blindly relying on them. 🎯 Ideal Candidate 5+ years of relevant technical experience. Strong NestJS, TypeScript, Angular, MySQL and Redis experience. Good understanding of backend and frontend development. Practical experience with Azure and OVH Cloud. Good server, networking, and infrastructure knowledge. Good understanding of cybersecurity and data protection. Comfortable working independently across multiple technical areas. Strong problem-solving and decision-making skills. Able to explain technical issues clearly and without unnecessary complexity. Comfortable working with developers, system administrators, and management. Willing to take ownership rather than waiting for step-by-step instructions. 📋 Please Include in Your Application Short summary of your relevant experience. Your experience with NestJS, Angular, TypeScript, MySQL and Redis. Your Azure and OVH Cloud experience. Your experience with security, ISO 27001 and GDPR. Examples of technical/security problems you have solved. Your experience with Claude, Antigravity, or similar AI tools. GitHub/portfolio/LinkedIn links if available. Availability per week and hourly rate. Attention to Detail Please begin your proposal with the word: Credebt Proposals that do not follow this instruction may not be considered. We are looking for someone interested in a long-term relationship who can contribute across development, infrastructure, cloud, security, and technical operations.
Fixed budget:
800 USD
1 day ago
|
|||||
|
Malware Removal from Hostinger Server
Applied
|
$20 - $50
/ hr
|
2 days ago |
4
|
||
|
Need a freelancer to remove malware from a Hostinger server and ensure the site is secure. The work includes identifying and cleaning infected files, removing malicious code, and verifying that the site is functioning properly after cleanup. Please have experience handling server security issues and be able to provide clear steps taken during the process.
Hourly rate:
20 - 50 USD
2 days ago
|
|||||
|
Google CASA AL1 Security Documentation & Compliance Specialist
Applied
|
$30
|
2 days ago |
5
|
||
|
We are looking for an experienced security/compliance consultant to help prepare the documentation and evidence package required for a Google CASA AL1 (Application Defense Alliance – CASA) security assessment for our SaaS application.
About the Project We have a production SaaS application called Esigen, built with: ASP.NET Core / .NET backend Angular frontend Electron desktop application SQLite databases with tenant isolation Google Workspace API integration AWS S3 backups Nginx / Ubuntu production server GitHub private repository We are preparing for a Google CASA AL1 security assessment and have already completed much of the technical security work internally. What We Need We need someone who can review our existing security implementation and prepare professional, assessor-ready documentation and evidence. The work is primarily documentation, compliance mapping, and evidence organization, not building the application. Expected documentation includes: Security Policies Incident Response Procedure Security Incident / Breach Notification Procedure Access Review Procedure Credential Rotation Procedure Security Awareness / Training Procedure Architecture Documentation Application Architecture Diagram Google Workspace Data-Flow Diagram Security boundaries and trust boundaries Authentication/authorization flows Tenant isolation architecture Data Protection Documentation Data Inventory Asset Inventory Data retention/deletion documentation Privacy Policy review/recommendations Google Workspace data handling documentation Access & Infrastructure Evidence Production access documentation SSH/access-control evidence TLS configuration evidence Security headers evidence Backup/security configuration evidence Security Testing Evidence SAST results/documentation DAST results/documentation Dependency vulnerability scan documentation Remediation tracking CASA Evidence Index Map each CASA requirement/control to the appropriate document or technical evidence Identify missing evidence Organize the final assessor package in a clear structure Important We do not want generic templates copied from the internet. The documentation must be based on our actual application architecture, infrastructure, security controls, and implementation. We can provide: Source-code information Architecture information Server configuration/output Security scan results Backup configuration Google Workspace integration details Existing Privacy Policy and Terms of Service Existing security procedures/evidence Sensitive credentials and private keys will never be shared. Deliverables The final result should include a professional folder such as: CASA-Assessment/ ├── Security-Policies/ ├── Architecture/ ├── Data-Protection/ ├── Access-Control/ ├── Backup-Recovery/ ├── Security-Testing/ ├── Infrastructure/ └── CASA-Evidence-Index.xlsx Documents should be suitable for submission to a professional security assessor. Ideal Freelancer You should have experience with one or more of: Google CASA / CASA AL1 Google API security / OAuth SaaS security compliance SOC 2 / ISO 27001 documentation Application security Security assessment preparation Security policies and procedures Evidence collection and control mapping Direct CASA experience is strongly preferred. What I Expect From You Please don't just create documents from templates. I want you to: Understand our actual architecture. Review the evidence we provide. Identify documentation gaps. Prepare the required documents. Map the documents/evidence to CASA requirements. Clearly identify anything that still needs to be fixed technically. Deliver a clean, professional final evidence package. This is a documentation and compliance preparation project, not a request to perform unauthorized penetration testing or access sensitive credentials. To Apply Please provide: Your experience with Google CASA / CASA AL1 Examples of similar security/compliance documentation you've prepared Whether you have worked with Google Workspace API applications Your estimated fixed price or hourly rate Estimated timeline Bonus: If you have previously prepared a CASA assessment package that was successfully accepted by a Google-approved assessor, please mention it in your proposal.
Fixed budget:
30 USD
2 days ago
|
|||||
|
Ubiquiti Setup Specialist Needed
Applied
|
~14 - 20 USD
/ hr
|
4 days ago |
-
|
||
|
I need an experienced Ubiquiti engineer to set up and configure Unifi Access Points on the ceiling.
Key tasks include: - Initial setup and configuration of Unifi Access Points - Designing optimal placement and connectivity - Access control Ideal skills and experience: - Expertise in Ubiquiti products, especially Unifi - Strong networking knowledge - Experience with ceiling-mounted installations Looking for someone who can ensure a robust and reliable network setup. Please provide relevant experience in your bids. Skills: System Admin, Linux, Wireless, Cisco, Network Administration, Network Security, Network Engineering, Wireless Site Survey, Wireless Network Security Analysis, Ubiquiti
Hourly rate:
10 - 15 GBP
4 days ago
|
|||||
|
Senior Odoo Backend Developer Needed for Odoo 13 to 18 Migration & Custom Development
Applied
|
$5 - $10
/ hr
|
4 days ago |
1
|
||
|
We are looking for an experienced Senior Odoo Backend Developer to work with us on a 3-month project.
Our current system is running on Odoo 13, hosted on DigitalOcean, and we are planning to upgrade and migrate it to Odoo 18. The developer will be responsible for: Reviewing our current Odoo 13 environment and database. Migrating existing modules, data, configurations, and custom developments to Odoo 18. Updating or rebuilding custom modules when required. Fixing compatibility issues during the migration. Improving backend performance and database structure. Testing the migrated system and resolving errors. Assisting with deployment on our DigitalOcean server. Providing clean and documented code. We are looking for someone with strong experience in: Odoo 13–18 Python PostgreSQL Odoo ORM Custom module development Odoo migrations Linux / Ubuntu servers Git DigitalOcean or similar cloud platforms This is not a basic Odoo configuration project. We need a strong backend developer who understands Odoo architecture and can handle migration, custom modules, database issues, and technical troubleshooting. I will personally manage and follow the project from the IT side, so good communication and clear technical reporting are important. Please include examples of previous Odoo migration projects, especially migrations between major Odoo versions.
Hourly rate:
5 - 10 USD
4 days ago
|
|||||
|
MSP Support Technician
Applied
|
not specified | 5 days ago |
3
|
||
|
We are an MSP that requires assistance with onboarding customers for remote management, M365 implementations including Intune, Defender, MDM, automated patching, scripting, and ongoing monitoring of customer platforms.
Budget:
not specified
5 days ago
|
|||||
|
Basic Cyber Security Website
Applied
|
$600
|
5 days ago |
1
|
||
|
I need a simple website for a Cyber Security service, focused on a clean landing page where visitors can leave contact details. The site should be easy to navigate and include a privacy policy to cover the collection of contact information. I’m looking for someone who can create a straightforward, professional online presence that clearly communicates the service and encourages inquiries.
Fixed budget:
600 USD
5 days ago
|
|||||
|
US-Based Security Expert for VAR/MSSP
Applied
|
not specified | 5 days ago |
3
|
||
|
Seeking a US-based security expert to partner and help run a VAR/MSSP business. You will lead security operations, be technical solutions as I find and manage clients. The ideal candidate has experience building and scaling security services, working with partners, and delivering reliable protection for clients. This is a long-term opportunity for someone who can help grow the business and maintain strong security for customers.
Budget:
not specified
5 days ago
|
|||||
|
Product Security Engineer — Digital Health AWS & SOC 2/ISO
Applied
|
not specified | 5 days ago |
3
|
||
|
Security Engineer — Digital Health / SaaS Platform
Contract / Project-based | Remote | Approx. 40 hours initial scope We are a digital mental health and neurodiversity platform being built around Therapy, ADHD Assessment, Autism Assessment and clinician-led support services. The platform uses a modern cloud architecture including Next.js, Supabase/PostgreSQL, GitHub and AWS, with sensitive health and personal data, multiple user roles, clinician workflows and AI-enabled functionality. We are approaching production readiness and are looking for an experienced Security Engineer to help complete the security, privacy and compliance controls required for launch. The Role You will take ownership of the remaining technical security work across the platform, working closely with our Founder. The role is highly practical. We are looking for someone who can review the existing architecture and codebase, identify genuine security gaps, implement or guide remediation, produce evidence and help take the platform through security testing and production launch. You should be comfortable reviewing application code, PostgreSQL/Supabase permissions, authentication, APIs, cloud configuration and CI/CD controls. Key Responsibilities Application & API Security Review and harden: * authentication and session security; * role-based access control; * server-side authorization; * IDOR/BOLA protections; * cross-user and cross-role isolation; * API/server-action security; * admin privilege boundaries; * clinician/member access separation; * secure error handling; * rate limiting and abuse protections where appropriate. Platform uses several distinct roles, including: * Member; * Therapist/Clinician; * ADHD/Autism Assessor; * Content Creator; * Admin/Clinical Operations roles. You will help ensure that access fails closed and that users cannot access data belonging to another Member, clinician, provider or role. Supabase / PostgreSQL Security Review and complete: * Row Level Security policies; * PostgreSQL grants; * views; * RPCs / SECURITY DEFINER functions; * storage permissions; * service-role boundaries; * direct database/API access tests; * cross-member isolation; * cross-clinician isolation; * secure document/report access. Experience with Supabase RLS would be particularly valuable. Authentication & Identity Review: * Supabase Auth configuration; * password/authentication controls; * email verification; * MFA; * OAuth; * session management; * disabled/suspended account handling; * privileged/admin access; * account lifecycle controls. Secure Files & Sensitive Health Data Help secure: * clinical documents; * assessment reports; * clinician application documents; * uploaded evidence; * signed/private URLs; * storage buckets; * document metadata; * file access and deletion; * malware/file validation controls where appropriate. Particular attention is required because Mellowly processes sensitive personal and health information. Cloud & Production Security Work alongside DevOps to review: * AWS security configuration; * IAM; * production secrets; * environment separation; * Supabase/AWS boundaries; * logging; * monitoring; * security alerts; * backups; * disaster recovery; * production access; * branch/release controls; * infrastructure exposure. Secure Development Lifecycle Help formalise and evidence: * security review within pull requests; * dependency scanning; * secret scanning; * SAST where appropriate; * vulnerability management; * severity classification; * remediation SLAs; * secure change management; * migration safety; * release security gates. Threat Modelling & Risk Management Create/update: * platform threat model; * security risk register; * attack-surface assessment; * abuse cases; * architecture security risks; * risk treatments; * residual-risk decisions. Coverage should include: * Therapy; * Find a Therapist; * ADHD Assessment; * Autism Assessment; * Clinician Dashboard; * Member Portal; * Admin Portal; * Content Creator Portal; * AI functionality. Clinician AI / AI Security Clinician AI Copilot You will work with the AI Engineer to ensure appropriate controls around: * prompt injection; * unauthorized retrieval; * cross-member AI leakage; * cross-clinician leakage; * source grounding; * AI audit logging; * sensitive-data minimisation; * model/provider access; * prompt/model versioning; * AI kill switches; * provider data-retention/training policies; * human review gates. The AI must not be able to bypass the underlying application authorization model. Experience securing LLM/RAG applications would therefore be highly valuable. Penetration Testing & Launch Security You will help prepare Mellowly for an independent third-party penetration test Responsibilities include: * define testing scope; * prepare Rules of Engagement; * confirm test environment and accounts; * coordinate with the independent tester; * triage findings; * remediate or coordinate remediation; * verify fixes; * coordinate external retesting; * retain remediation evidence. The independent penetration test itself will be conducted by a separate qualified external provider. Launch requirement: * zero unresolved Critical findings; * zero unresolved High findings; * Medium issues remediated or formally risk-assessed and accepted. SOC 2 / ISO Readiness You will help implement the technical and governance controls supporting platform's planned: SOC 2 Type II ISO/IEC 27001 ISO/IEC 27701 ISO/IEC 42001 ISO 9001 Cyber Essentials Plus You are not expected to act as the external auditor or certification body. Your role is to help make the platform audit-ready and ensure technical controls are properly implemented and evidenced. This includes: * information asset inventory; * data classification; * security risk register; * ISO 27001 Statement of Applicability support; * access-control procedures; * privileged-access controls; * access reviews; * supplier security reviews; * vulnerability management; * security logging; * incident response; * business continuity; * backup/restore controls; * secure configuration; * compliance evidence. A control is not considered complete simply because code exists. We would expect: Policy + Owner + Implementation + Test + Evidence Privacy & Digital Health Governance Work with the wider team to support: * UK GDPR; * DPIAs; * ROPA/data-flow mapping; * special-category health data controls; * retention/deletion; * supplier/subprocessor security; * DTAC security requirements; * DCB0129 clinical safety processes; * DCB0160 deployment considerations. Direct prior NHS experience is helpful but not essential if you have strong healthcare/SaaS security experience. Required Experience We are looking for someone with strong practical experience in several of the following: * application security; * SaaS security; * cloud security; * API security; * PostgreSQL security; * Supabase security/RLS; * AWS; * IAM; * OAuth/authentication; * RBAC; * OWASP Top 10; * OWASP API Security Top 10; * IDOR/BOLA testing; * secure SDLC; * threat modelling; * vulnerability management; * GitHub/GitHub Actions; * security logging and monitoring; * penetration-test remediation. You should be comfortable inspecting code and configuration rather than only producing compliance documents. Technology Environment Experience with the following would be useful: * TypeScript * Next.js * React * Node.js * PostgreSQL * Supabase * AWS * GitHub Actions * Playwright * REST/API security You do not need to be the primary application developer, but you should be capable of understanding and reviewing the codebase and proposing precise remediation. Desirable Experience Particularly valuable: * healthcare / digital health; * mental health platforms; * NHS DTAC; * DCB0129 / DCB0160; * ISO 27001; * ISO 27701; * ISO 42001; * SOC 2; * clinical data security; * LLM/RAG security; * AI governance; * penetration testing; * CREST/OSCP/CISSP/CCSP/CISM or equivalent practical experience. Initial Deliverables The first engagement will include launch-security work. Key outputs include: 1. security architecture/codebase review; 2. permissions/RLS closeout; 3. remaining authentication/access hardening; 4. storage/document security review; 5. threat model and security risk register; 6. secrets/logging/configuration review; 7. API/IDOR isolation testing; 8. vulnerability-management process; 9. production security review; 10. SOC 2 / ISO technical control evidence; 11. penetration-test preparation; 12. penetration-test remediation support; 13. external retest support; 14. final production security sign-off recommendation. Definition of Done The Security Engineer should be able to leave us with: No known Critical or High security issues, independently tested access boundaries, evidence-backed security controls, an auditor-ready security baseline, and a clearly documented residual-risk register. Who We're Looking For This role would suit someone who is: * methodical; * pragmatic; * comfortable challenging insecure design decisions; * able to distinguish genuine vulnerabilities from theoretical concerns; * able to explain issues clearly to developers and non-technical stakeholders; * evidence-driven; * experienced working independently; * comfortable taking ownership of a security workstream through to closure. Application Please include: * examples of SaaS/cloud platforms you have secured; * experience with Supabase/PostgreSQL RLS, if any; * AWS security experience; * examples of IDOR/API authorization testing; * experience preparing for SOC 2 or ISO 27001; * healthcare/digital-health experience, if applicable; * AI/LLM security experience, if applicable; * penetration-test remediation experience; * your availability over the next 2–4 weeks.
Budget:
not specified
5 days ago
|
|||||
|
Recover Hacked Crypto Shares
Applied
|
not specified | 5 days ago |
4
|
||
|
I need help recovering crypto shares that were hacked. The issue involves unauthorized access to my account, and I need a freelancer to investigate what happened, identify vulnerabilities, and help secure the account. I’m looking for someone who can assess the situation, provide a clear recovery plan, and guide me through the next steps to protect my assets. Experience with cryptocurrency security and account recovery is important.
Budget:
not specified
5 days ago
|
|||||
|
Independent security and infrastructure review of a Next.js / Supabase community app
Applied
|
$1,200
|
5 days ago |
1
|
||
|
Women in Tri UK is a UK registered charity (1203093) with a community of over 900 women. In 2026 we launched our own members-only community app: Next.js (App Router) on Vercel, Supabase (Postgres, Storage, Auth) with row-level security, Capacitor shells for iOS and Android, push via APNs, FCM and web push, pg_cron jobs, GitHub Actions.
The app was built by directing AI coding tools under a documented brief-and-review process. It has had internal audits but never an independent human engineer's review. We are looking for one. What you will do - A read-only review of the repository, focused on: - Security and data access: RLS policies, API route authorisation, session handling, the members-only gate, any exposed secrets or keys. - Data protection: what member data is stored and whether account deletion removes it. - Silent failure: push delivery, scheduled jobs, swallowed errors. - Would we know if these broke? - Infrastructure configuration as visible from the repo: environment variable usage, CI, deployment settings. The top five code-health risks. Five, not fifty. You will not change any code. You will not receive production credentials or dashboard access. Where a check needs a live query, you write it, we run it, and share the output. Deliverables 1. A written report in plain English, findings ranked by severity, each naming the file or setting, the risk, and the fix. Technical detail in an appendix. 2. A prioritised fix list we can turn into our own work items. One 45-minute video call to walk through findings. You should have - Real production experience with Next.js and Supabase, including writing and reviewing RLS policies. - Experience reviewing code you did not write, with a security lens. - Clear written English aimed at a non-technical readers. - Familiarity with Capacitor is a plus. You will sign a short NDA before receiving repository access. Read-only GitHub access is granted on signing and revoked on completion.
Fixed budget:
1,200 USD
5 days ago
|
|||||
|
Web3 Security and Smart Contract Expert
Applied
|
$25 - $47
/ hr
|
5 days ago |
3
|
||
|
Seeking an expert to audit protocols, optimize DeFi architectures, and secure cryptographic systems against advanced vulnerabilities. You will review smart contract code, identify risks, and recommend improvements to strengthen system integrity and resilience. Ideal candidates have deep experience in blockchain security, DeFi infrastructure, and hands-on auditing of complex decentralized systems. This is a remote, high-tier role for someone who can deliver clear, actionable security insights and help protect critical Web3 projects.
Hourly rate:
25 - 47 USD
5 days ago
|
|||||
|
Ethical Hacker Needed for Website Penetration and XSS Testing
Applied
|
not specified | 5 days ago |
5
|
||
|
I am looking for an experienced ethical hacker/web application penetration tester to perform an authorized security assessment of my website and its customer lead forms.
The primary goal is to determine whether an outside attacker could exploit the website to inject malicious JavaScript, intercept information entered into lead forms, or compromise customer data without having administrative access. Testing should include: • Web application penetration testing • Vulnerability assessment based on the OWASP Top 10 • Stored, reflected, and DOM-based XSS testing • SQL injection, CSRF, authentication, session, API, and access-control testing • Review of forms, third-party scripts, cookies, headers, Content Security Policy, and data exposure • A controlled keystroke-capture simulation to demonstrate whether malicious injected code could capture information typed into a test lead form • Verification of whether captured test data could be transmitted outside the application • Clear recommendations and assistance fixing confirmed vulnerabilities • Retesting after the fixes are implemented All work must be conducted only on systems and domains that I own and explicitly authorize. The keystroke-capture simulation must be performed in a controlled staging environment using fake test information only. No real customer information may be accessed, collected, retained, or transmitted. No destructive testing, denial-of-service testing, persistence, or testing of third-party/dealership systems is permitted. Deliverables: 1. A written vulnerability report with severity ratings and evidence 2. A safe proof of concept for each confirmed issue 3. A clear explanation of how each vulnerability could affect customer lead information 4. Step-by-step remediation recommendations 5. Assistance implementing or verifying the fixes 6. A final retest report confirming which vulnerabilities were resolved Please include examples of similar authorized web application penetration tests you have completed, the tools and methodology you use, your relevant certifications or experience, your estimated completion time, and your fixed-price quote.
Budget:
not specified
5 days ago
|
|||||
|
Security Researcher: Benchmark Automated DAST Engine vs. Manual Exploit Validation
Applied
|
$20
|
6 days ago |
3
|
||
|
We are seeking an active Web Application Penetration Tester or Bug Bounty Hunter to benchmark our black-box AppSec scanning engine (SecRecon) against an authorized public target.
Our engine is engineered for Proof-Verified Findings (OAST callbacks, deterministic cURL proofs, zero false positives). We want you to run the scanner on a live, in-scope target of your choice from Bugcrowd or HackerOne, compare the automated findings against your manual triage, and evaluate real-world detection accuracy. Scope of Work: Target Selection: Choose any authorized, in-scope public target you actively hunt on via Bugcrowd or HackerOne. Scanner Execution: Launch a target scan using your SecRecon account. Precision & PoC Verification: Review the flagged findings and test the generated reproduction steps (cURL commands/HTTP requests). Confirm whether the flaws are true positives or false alarms. Manual Delta Comparison: Compare the output with your manual testing on that target: Did SecRecon identify any valid vulnerabilities you verified? Did the scanner flag any false positives? What obvious endpoints or logic flaws did the scanner miss that you found manually? Deliverable Required for Milestone Release: A brief Markdown or text comparison scorecard: Target Program Name: (Bugcrowd / HackerOne program link). Precision Breakdown: Total scanner findings vs. confirmed true positives. PoC Reliability: Did the generated cURLs reproduce the issues? Manual Delta: Any valid bugs found manually that the scanner missed. Contract Details: Budget: $20 Fixed-Price (Funded in escrow, released immediately upon receipt of the benchmark breakdown). Client's questions:
Fixed budget:
20 USD
6 days ago
|
|||||
|
Automated Web Security & Server Hardening
Applied
|
not specified | 6 days ago |
1
|
||
|
SLF Guardian | AI-Powered Web Security Scanning & Reporting
SLF Guardian is an automated web security tool running from our dedicated data center infrastructure. We monitor target websites, perform AI-powered analysis, and deliver clear, plain-language security reports. How It Works: Send Us Your Address: Simply provide your website address. No FTP passwords, root credentials, or system access required. - Data Center & AI-Powered Checks: Checks run at regular intervals directly from our data center with AI-powered analysis, following our own internal procedures. - Findings & Reports Delivered: At the end of the scan/cycle, we share the relevant findings from our checks and deliver a report written in plain, easy-to-understand language. What You Receive: Non-Intrusive External Scanning: Only requires your website URL and permission to proceed. Plain-Language Reporting: Technical details translated into clear, actionable summaries. Regular Monitoring Output: Scheduled scan logs and findings based on our standard evaluation metrics.
Budget:
not specified
6 days ago
|
|||||
|
WordPress Infrastructure & Security Consultant
Applied
|
$30 - $50
/ hr
|
6 days ago |
5
|
||
|
Title: WordPress Security & Infrastructure Consultant — consolidate ~80 client sites onto managed hosting (Kinsta), remove personal data, harden against future breaches
We're a digital agency looking for an experienced WordPress infrastructure and security consultant to lead a portfolio-wide clean-up and migration following a recent security incident. We maintain ~80 client websites under a "SiteCare" retainer — roughly 71 WordPress, plus a handful of Next.js, Astro and Shopify sites. They're currently scattered across Laravel Forge, Cloudways, Kinsta, Vercel and a few other/unknown hosts, with inconsistent update, backup and PHP-version status. We need this consolidated, secured and put on a repeatable maintenance footing. What we need you to do: Audit every site's current setup (hosting, WP/PHP versions, plugins, backups, DNS, access) working alongside our internal team, and fill the gaps in our tracker. Design and stand up a consolidated hosting infrastructure — most likely on Kinsta (already in use for some sites) — where all sites can live, with a clear standard for staging, backups, updates and security. Migrate the sites onto that infrastructure with minimal downtime. Remove all personal data stored insecurely on the sites (e.g. form submissions retained in the WordPress backend / Gravity Forms), and advise on GDPR-compliant handling going forward. Harden every site and the platform against reintrusion (updates, WAF, access control, monitoring). Build a repeatable ongoing maintenance process our internal team can run, and help us communicate the changes to clients. You'll work closely with our internal developers and ops team — we want knowledge transferred in, not locked to you. Please share relevant experience with agency-scale WordPress fleets, managed hosting migrations (Kinsta a plus), and post-incident remediation. Tell us how you'd approach the first two weeks.
Hourly rate:
30 - 50 USD
6 days ago
|
|||||
|
Cyber Security Expert Needed
Applied
|
$50
|
6 days ago |
3
|
||
|
We are seeking a cyber security expert to help protect our systems and data. The ideal candidate will have experience in security analysis, network security and information security. The candidate will be responsible for identifying vulnerabilities, implementing security measures and ensuring our systems remain secure. This a part time work with flexible schedule and we are looking for someone who can work independently and communicate clearly.
Fixed budget:
50 USD
6 days ago
|
|||||
|
Certified Adult Trainer WSQ Advanced Certificate Learning And Performance (ACLP) 3 mth 15hr
Applied
|
$300
|
6 days ago |
3
|
||
|
Act as Singapore based Pedagogy expert for a Singapore adult learning project. 15hr work over 3 month period based in Singapore. Require Certified Adult Trainer with WSQ- Advanced Certificate In Learning And Performance (ACLP).
Own the pedagogical validity of the study design, approve methods before fieldwork begins, and author or approve every field instrument. Lead or co-lead practitioner engagement, including recruiting participants and running sessions. Interpret findings, sign off claims, and reject unsupported claims. Review the final deliverable before publication. Attend governance or worker-protection reviews and contribute the pedagogical view. Contribute to the public share-back session at the end of the project. Weekly checkpoint of thirty to forty-five minutes with the Team Lead. Client's questions:
Fixed budget:
300 USD
6 days ago
|
|||||
|
Application Security and CI/CD Automation
Applied
|
$15 - $25
/ hr
|
6 days ago |
5
|
||
|
We need a freelancer with application security experience to review our codebase and deployment environment, identify security issues, and implement automated security checks in our CI/CD pipeline. The work includes scanning for vulnerabilities, recommending fixes, and helping patch code when needed. You should be comfortable working with existing infrastructure and improving security processes to reduce risk over time.
Client's questions:
Hourly rate:
15 - 25 USD
6 days ago
|
|||||
|
Security Camera Footage Review
Applied
|
not specified | 7 days ago |
5
|
||
|
We need a freelancer to review NVR IP camera footage and identify relevant events or incidents. The work involves watching recorded video, noting timestamps, and summarizing key findings.
Client's questions:
Budget:
not specified
7 days ago
|
|||||
|
Independent Penetration Test – Microsoft Access / SQL Desktop Application
Applied
|
not specified | 7 days ago |
1
|
||
|
We are looking for an experienced cybersecurity specialist to perform a comprehensive independent penetration test of a business-critical desktop application.
The application architecture consists of: Microsoft Access / ACCDE frontend Microsoft Azure Virtual Desktop (AVD) Microsoft Azure SQL / SQL Server backend Azure-based file storage Microsoft authentication for access to the virtual desktop Multiple users with different roles and permissions Multiple projects/customers with confidential data The application is only intended to be accessible through the controlled virtual desktop environment. The desktop application communicates directly with the SQL database and file-storage backend. We specifically need a specialist with experience in Windows thick-client/desktop application penetration testing, preferably including Microsoft Access/ACCDE and SQL Server. Required scope The assessment should be a comprehensive grey-box/white-box penetration test, with significant manual testing rather than primarily automated vulnerability scanning. The test should include: Access/ACCDE frontend security Authentication and authorization Role-based access control User identity and session handling Privilege escalation Customer/project data segregation Attempts to bypass frontend security controls Direct database access outside the intended application controls SQL Server/Azure SQL permissions and authentication Database connection security Identification of embedded or recoverable credentials, connection strings, keys or other secrets Static/dynamic analysis of the ACCDE application where appropriate Process/memory analysis where appropriate Windows environment manipulation Local file and folder permissions Security of application installation files and scripts Azure file-storage permissions and access controls Attempts to bypass application-level file permissions through direct backend access Data exfiltration possibilities AVD configuration relevant to application security Local privilege escalation within the AVD File transfer and clipboard/redirection controls Network isolation and reachable services from the AVD Possibility of executing unauthorized applications/software Security implications of a compromised legitimate user account External attack surface relevant to the application Microsoft identity/access configuration relevant to access to the environment The assessment should consider both an external attacker perspective and an authenticated/compromised-user perspective. The existing architecture uses the AVD as an important outer security perimeter, while the Access application, SQL backend and file-storage environment provide additional security layers. We specifically want to determine whether compromising one layer allows an attacker to bypass controls implemented at another layer. Objective This is not simply a vulnerability scan or a retest of known vulnerabilities. We want a fresh, independent assessment of the complete current solution to identify vulnerabilities or attack paths that may not previously have been identified. A previous security assessment has been performed and remediation work has subsequently been completed. Details of that assessment can be provided to the selected tester after appropriate confidentiality arrangements are in place. The objective is to achieve a high level of confidence in the security of the current environment before a separate third party performs its own final verification. Deliverables We require a professional penetration-test report containing: Executive/management summary Scope and tested architecture Testing methodology Standards/frameworks used Technical tests performed Findings and severity classification Technical evidence Reproducible steps where appropriate Security/business impact Remediation recommendations Overall security assessment/conclusion Clear identification of any limitations or areas not tested After remediation of any findings, we would also like the tester to perform a retest and provide a closure/update report. The resulting documentation should be of sufficient professional quality to be used as supporting evidence within an ISO 27001 information-security management and certification process. Required experience Please respond with your experience in: Windows thick-client/desktop application penetration testing. Microsoft Access/ACCDE security testing. Microsoft SQL Server/Azure SQL security. Azure Virtual Desktop security. Static/dynamic analysis or reverse engineering of desktop applications. Authentication, authorization and privilege-escalation testing. Professional penetration-test reporting. Please also provide your proposed methodology, estimated effort, earliest availability and, if possible, a redacted example penetration-test report.
Budget:
not specified
7 days ago
|
|||||
Related freelance jobs queries: