Freelance Security Engineers in Los AngelesFreelance Security Engineers in Los Angeles

Results that are similar to your search

Similar results

AI Automation Engineer | Full-Stack Apps & Integrations
66x
Hired
4.9
Rating
154
Followers
AI Automation Engineer | Full-Stack Apps & Integrations
Ship your SaaS MVP in weeks - web, mobile, payments.
$25k+
Earned
14x
Hired
4.9
Rating
104
Followers
Ship your SaaS MVP in weeks - web, mobile, payments.
Helping founders turn Replit MVPs into secure, scalable SaaS
13x
Hired
5.0
Rating
45
Followers
Helping founders turn Replit MVPs into secure, scalable SaaS
Cyber expert specialising in Azure Security Services.
$10k+
Earned
4x
Hired
5.0
Rating
22
Followers
Cyber expert specialising in Azure Security Services.
Cyber Security Analyst
Cyber Security Analyst
Web, API and Android Penetration Tester
New to Contra
Web, API and Android Penetration Tester
Cover image for Comprehensive validation testing, proof-of-concept verification,
Comprehensive validation testing, proof-of-concept verification, and structural remediation audits to ensure complete security patch efficacy. The Objective: A development organization required a rigorous follow-up assessment to validate that security patches introduced after an initial audit were correctly implemented, completely neutralized the identified threat vectors, and did not introduce new regression flaws into the environment. The Approach: I executed a dedicated verification cycle focused specifically on replicating the original attack patterns using the exact tools and exploits from the initial assessment. Every patch was manually tested using Burp Suite Professional, custom Python exploit scripts, and runtime debuggers to confirm the vulnerability's status and measure remediation success against standard CVSS 3.1 metrics. From a dedicated retesting scope targeting 20 original security findings, I delivered the following lifecycle results: Closed (Remediated): Successfully verified the resolution of 16 findings, including all critical business logic bypasses and sensitive data exposure pathways, confirming they are no longer exploitable. Bypassed (Incomplete Fixes): Identified 2 instances where a development team used client-side input validation instead of server-side sanitization, allowing the original exploit to still bypass the patch. New Regression: Discovered 2 minor configuration errors introduced by changes made to the access control framework during the patching process. Documentation Provided: Delivered updated Proof-of-Concept (PoC) logs and step-by-step documentation for the outstanding issues to guide the team to a permanent fix.
0
44
Cover image for Comprehensive external/internal network penetration test,
Comprehensive external/internal network penetration test, cloud infrastructure review, and vulnerability assessment for a production hosting ecosystem. The Objective: A production hosting provider required a full-scope security audit to evaluate their perimeter defense, verify compliance with the CIS Benchmarks and OWASP Top 10 for Cloud, and uncover critical misconfigurations before public deployment. The Approach: I executed a hybrid security assessment combining automated infrastructure reconnaissance with deep manual configuration checks. Every vulnerability was manually validated using tools like Nmap, Wireshark, and CloudBrute to eliminate false positives and scored using standard CVSS 3.1 metrics. From a single comprehensive audit, I uncovered 31 reproducible findings: 3 High Severity: Exposed database backups publicly accessible via misconfigured AWS S3 buckets, and unauthenticated remote code execution (RCE) vectors on perimeter network appliances. 6 Medium Severity: Overly permissive IAM policies granting excessive root privileges, missing multi-factor authentication (MFA) enforcement on management panels, and outdated SSH protocol versions in use. 10 Low Severity: Unrestricted directory listings on internal staging servers, insecure network daemon configurations, and loose firewall rules permitting unnecessary inbound traffic. 12 Informational: Internal IP address disclosures in HTTP response headers, missing asset tagging, and verbose system version banners.
0
48
Smart Contract Audit for Secure Results
Smart Contract Audit for Secure Results