Freelance Security Engineers in Los Angeles
Freelance Security Engineers in Los Angeles
Sign Up
Post a job
Sign Up
Log In
Filters
2
Projects
People
Results that are similar to your search
Similar results
Abubakar Chan
pro
Lahore, Pakistan
AI Automation Engineer | Full-Stack Apps & Integrations
66x
Hired
4.9
Rating
154
Followers
Expert
Expert
+2
Follow
Message
AI Automation Engineer | Full-Stack Apps & Integrations
1
Gut Health SaaS Platform Development
1
14
4
Provider Portal for Healthcare MSO
4
46
6
Magnai | UK Public Affairs
6
87
7
Humoni - secure housing in under 72 hours
7
144
Security Engineer
(2)
Follow
Message
Raymond Asogwa
pro
Cyprus
Ship your SaaS MVP in weeks - web, mobile, payments.
$25k+
Earned
14x
Hired
4.9
Rating
104
Followers
Expert
Mentor
+1
Follow
Message
Ship your SaaS MVP in weeks - web, mobile, payments.
0
Unexposed – The Document Vault That Can't See Your Documents
0
33
0
Bolt Template Development
0
6
0
Full-Stack Mobile App for Couples
0
3
0
Togethr – Turn Community Voice into Product Momentum
0
142
Security Engineer
(1)
Follow
Message
Himanshu Kumar
pro
Bengaluru, India
Helping founders turn Replit MVPs into secure, scalable SaaS
13x
Hired
5.0
Rating
45
Followers
Expert
Follow
Message
Helping founders turn Replit MVPs into secure, scalable SaaS
0
Secure Auth & Multi-Tenant System for Industrial SaaS
0
19
3
BuildWise Construction Project Management
3
4
0
Automated Real-time Booking System Development
0
7
2
Workflow Automation for Industrial Services
2
43
Security Engineer
(1)
Follow
Message
Jason Smyth
pro
Copthorne, UK
Cyber expert specialising in Azure Security Services.
$10k+
Earned
4x
Hired
5.0
Rating
22
Followers
Follow
Message
Cyber expert specialising in Azure Security Services.
0
Microsoft Sentinel & Splunk ES Engineer for up to 6 months
0
13
0
Extended Interview Process for CrowdStrike SIEM Specialist
0
13
1
Setting up and optimising Microsoft Sentinel
1
53
0
Configure SIEM Security Operation using Microsoft Sentinel
0
45
Security Engineer
(1)
Follow
Message
Stephen Kisong'e
Nairobi, Kenya
Cyber Security Analyst
Follow
Message
Cyber Security Analyst
0
Built a controlled Kiso Secure AI red teaming lab using Promptfoo to test a local RAG application for prompt injection, system prompt leakage, indirect prompt injection, and sensitive data exposure. The setup used AnythingLLM with a Kiso Secure knowledge base, automated adversarial testing, and a hardened workspace to compare security behavior before and after remediation.
2
0
68
2
This project focused on building and testing a practical AI security assessment lab for evaluating LLM defenses against prompt injection and jailbreak attacks. I integrated Spikee by Reversec with a locally hosted cybersecurity model running through LM Studio, then added NVIDIA NeMo Guardrails to compare model behavior under three conditions: no guardrails, input filtering, and combined input/output protection. The work included configuring the local model environment, building a custom FastAPI gateway, integrating NeMo Guardrails, troubleshooting model latency and timeout issues, creating a reusable Spikee target, and analyzing attack results using Spikee’s built-in reporting tools. The project also explored different adversarial testing approaches, including prompt injection datasets, obfuscation, encoded attacks, Best-of-N testing, synthetic canary leakage tests, and structured benchmark comparisons. The objective was to measure how much the guardrails reduced successful attacks while keeping the model, dataset, and testing conditions consistent. Tools used: Spikee, NVIDIA NeMo Guardrails, LM Studio, Python, FastAPI, PowerShell, Parrot OS, local LLMs, JSONL datasets, and custom security testing scripts. This project demonstrates a hands-on approach to LLM red teaming, AI safety testing, prompt-injection assessment, and guardrail validation for organizations deploying generative AI systems.
7
2
155
1
I conducted an authorized AI security assessment of Lily Cybersecurity 7B to evaluate how effectively a hardened system prompt could resist jailbreak and prompt injection attacks. Using Prompt Fuzzer, I ran 15 attack techniques against the model. The system prompt successfully blocked 8 attempts, including most roleplay and social engineering attacks. The successful bypasses mainly used translated or altered wording to disguise the intent of the request. This project demonstrates why system prompts should be supported by input validation, moderation, output filtering, and continuous AI red team testing.
1
209
0
Designed and documented a secure environment for running Robin, an AI-powered dark web OSINT tool, inside a compartmentalized Qubes OS and Qubes-Whonix setup. The environment was structured to separate research activity, Tor-routed traffic, sensitive credentials, untrusted content, and final reporting. Robin was deployed through Docker inside a dedicated research qube, with traffic routed through sys-whonix and sensitive notes stored separately in an offline vault qube. Disposable qubes were incorporated for opening potentially unsafe links and files. The setup was built around security by compartmentalization rather than relying on a single tool for protection. Particular attention was given to Docker mount restrictions, credential hygiene, network-boundary verification, lawful research scope, and keeping raw research data isolated from personal or client environments. The final result was a repeatable AI-assisted OSINT workflow that supports faster search refinement, result filtering, investigation summarization, and structured reporting while maintaining stronger operational security and clearer separation between collection, analysis, and final output.
0
198
Security Engineer
(8)
Follow
Message
Nitika Kumari
Bhopal, India
Web, API and Android Penetration Tester
New to Contra
Follow
Message
Web, API and Android Penetration Tester
0
Comprehensive validation testing, proof-of-concept verification, and structural remediation audits to ensure complete security patch efficacy. The Objective: A development organization required a rigorous follow-up assessment to validate that security patches introduced after an initial audit were correctly implemented, completely neutralized the identified threat vectors, and did not introduce new regression flaws into the environment. The Approach: I executed a dedicated verification cycle focused specifically on replicating the original attack patterns using the exact tools and exploits from the initial assessment. Every patch was manually tested using Burp Suite Professional, custom Python exploit scripts, and runtime debuggers to confirm the vulnerability's status and measure remediation success against standard CVSS 3.1 metrics. From a dedicated retesting scope targeting 20 original security findings, I delivered the following lifecycle results: Closed (Remediated): Successfully verified the resolution of 16 findings, including all critical business logic bypasses and sensitive data exposure pathways, confirming they are no longer exploitable. Bypassed (Incomplete Fixes): Identified 2 instances where a development team used client-side input validation instead of server-side sanitization, allowing the original exploit to still bypass the patch. New Regression: Discovered 2 minor configuration errors introduced by changes made to the access control framework during the patching process. Documentation Provided: Delivered updated Proof-of-Concept (PoC) logs and step-by-step documentation for the outstanding issues to guide the team to a permanent fix.
0
44
0
Comprehensive web application penetration test, API endpoint analysis, and vulnerability assessment for a production-facing infrastructure ecosystem. The Objective: An enterprise client required a full-scope security assessment to evaluate their external attack surface, verify strict alignment with the OWASP Application Security Verification Standard (ASVS Level 3), and uncover critical server-side and business logic flaws before deploying a major code release. The Approach: I executed a hybrid security assessment combining automated reconnaissance with deep manual exploitation across the application layer and its integrated APIs. Every vulnerability was manually validated using Burp Suite Professional, SQLmap, and Postman to eliminate false positives and scored using standard CVSS 3.1 metrics. From a single comprehensive audit, I uncovered 24 reproducible findings: 2 High Severity: Broken Object Level Authorization (BOLA/IDOR) on critical billing endpoints and a SQL injection flaw in the primary authentication pathway. 5 Medium Severity: Faulty session management allowing session fixation, missing Rate Limiting on public API routes, and Cross-Site Scripting (XSS) via un-sanitized comment inputs. 7 Low Severity: Lax CORS configuration rules, missing secure flag attributes on cookies, and verbose server error disclosures. 10 Informational: Exposure of outdated software banners and missing HTTP security headers (such as Content-Security-Policy).
0
55
0
Comprehensive Android application penetration test, reverse engineering analysis, and vulnerability assessment for a production-ready mobile application. The Objective: A mobile application provider required a full-scope security audit to evaluate their client-side attack surface, verify compliance with the OWASP Mobile Application Security Verification Standard (MASVS Level 2), and uncover critical runtime flaws before public deployment. The Approach: I executed a hybrid security assessment combining static application security testing (SAST), dynamic instrumentation (DAST), and automated reconnaissance. Every vulnerability was manually validated using tools like Frida, Objection, Jadx-GUI, and Burp Suite to eliminate false positives and scored using standard CVSS 3.1 metrics. From a single comprehensive audit, I uncovered 19 reproducible findings: 1 High Severity: Insecure local data storage exposing unencrypted user credentials and private API keys in the shared preferences file. 4 Medium Severity: Broken cryptography implementations, insufficient SSL pinning mechanisms permitting Man-in-the-Middle (MitM) attacks, and unprotected exported Activities allowing unauthorized internal intents. 6 Low Severity: Lack of root detection, weak code obfuscation rules, and excessive logging of sensitive debug information via Logcat. 8 Informational: Outdated third-party SDK dependencies and missing compiler exploit mitigation configurations.
0
57
0
Comprehensive external/internal network penetration test, cloud infrastructure review, and vulnerability assessment for a production hosting ecosystem. The Objective: A production hosting provider required a full-scope security audit to evaluate their perimeter defense, verify compliance with the CIS Benchmarks and OWASP Top 10 for Cloud, and uncover critical misconfigurations before public deployment. The Approach: I executed a hybrid security assessment combining automated infrastructure reconnaissance with deep manual configuration checks. Every vulnerability was manually validated using tools like Nmap, Wireshark, and CloudBrute to eliminate false positives and scored using standard CVSS 3.1 metrics. From a single comprehensive audit, I uncovered 31 reproducible findings: 3 High Severity: Exposed database backups publicly accessible via misconfigured AWS S3 buckets, and unauthenticated remote code execution (RCE) vectors on perimeter network appliances. 6 Medium Severity: Overly permissive IAM policies granting excessive root privileges, missing multi-factor authentication (MFA) enforcement on management panels, and outdated SSH protocol versions in use. 10 Low Severity: Unrestricted directory listings on internal staging servers, insecure network daemon configurations, and loose firewall rules permitting unnecessary inbound traffic. 12 Informational: Internal IP address disclosures in HTTP response headers, missing asset tagging, and verbose system version banners.
0
48
Security Engineer
(3)
Follow
Message
Dragos Moruz
Timișoara, Romania
Seasoned cybersecurity leader.
5.0
Rating
4
Followers
Follow
Message
Seasoned cybersecurity leader.
2
Firewall Configuration & Rule Review
2
25
1
Security Testing for iOS and Android Mobile Applications
1
19
1
Automated Vulnerability Scanning and Security Assessment
1
14
1
Free Vulnerability Scanning Demo - Instant Security Insight
1
32
Security Engineer
(3)
Follow
Message
Saif Sghaier
Tunis, Tunisia
Smart Contract Audit for Secure Results
Follow
Message
Smart Contract Audit for Secure Results
0
Audit Report: BEING Project
0
19
0
Audit Report: BlindDoge Project
0
10
0
Audit Report: Viku Project
0
10
View more →
Security Engineer
(3)
Follow
Message
Explore people