Freelance Security Engineers
Freelance Security Engineers
Sign Up
Post a job
Sign Up
Log In
Filters
1
Projects
People
Abubakar Chan
pro
Lahore, Pakistan
AI Automation Engineer | Full-Stack Apps & Integrations
$100k+
Earned
66x
Hired
4.9
Rating
147
Followers
Expert
Expert
+2
Follow
Message
AI Automation Engineer | Full-Stack Apps & Integrations
0
Gut Health SaaS Platform Development
0
6
3
Provider Portal for Healthcare MSO
3
43
6
Magnai | UK Public Affairs
6
81
6
Humoni - secure housing in under 72 hours
6
139
Security Engineer
(2)
Follow
Message
Raymond Asogwa
pro
Cyprus
Ship your SaaS MVP in weeks - web, mobile, payments.
$25k+
Earned
14x
Hired
4.9
Rating
103
Followers
Expert
Mentor
+1
Follow
Message
Ship your SaaS MVP in weeks - web, mobile, payments.
0
Unexposed – The Document Vault That Can't See Your Documents
0
33
0
Bolt Template Development
0
3
0
Full-Stack Mobile App for Couples
0
2
0
Togethr – Turn Community Voice into Product Momentum
0
141
Security Engineer
(1)
Follow
Message
Himanshu Kumar
pro
Bengaluru, India
Helping founders turn Replit MVPs into secure, scalable SaaS
13x
Hired
5.0
Rating
46
Followers
Expert
Follow
Message
Helping founders turn Replit MVPs into secure, scalable SaaS
0
Secure Auth & Multi-Tenant System for Industrial SaaS
0
19
3
BuildWise Construction Project Management
3
4
0
Automated Real-time Booking System Development
0
5
2
Workflow Automation for Industrial Services
2
43
Security Engineer
(1)
Follow
Message
Jason Smyth
pro
Copthorne, UK
Cyber expert specialising in Azure Security Services.
$10k+
Earned
4x
Hired
5.0
Rating
22
Followers
Follow
Message
Cyber expert specialising in Azure Security Services.
0
Microsoft Sentinel & Splunk ES Engineer for up to 6 months
0
13
0
Extended Interview Process for CrowdStrike SIEM Specialist
0
12
1
Setting up and optimising Microsoft Sentinel
1
51
0
Configure SIEM Security Operation using Microsoft Sentinel
0
41
Security Engineer
(1)
Follow
Message
Safa Souli
Tunis, Tunisia
UI/UX Designer & Developer
5.0
Rating
16
Followers
Follow
Message
UI/UX Designer & Developer
1
Curatech – Website Design & Development
1
6
0
SecureIVAI
0
4
1
Genesis Robotics: Transforming Productivity
1
7
1
Qatar University - Redesgin
1
268
Security Engineer
(3)
Follow
Message
Dragos Moruz
Timișoara, Romania
Seasoned cybersecurity leader.
5.0
Rating
4
Followers
Follow
Message
Seasoned cybersecurity leader.
2
Firewall Configuration & Rule Review
2
24
1
Security Testing for iOS and Android Mobile Applications
1
17
1
Automated Vulnerability Scanning and Security Assessment
1
14
1
Free Vulnerability Scanning Demo - Instant Security Insight
1
32
Security Engineer
(3)
Follow
Message
Stephen Kisong'e
Nairobi, Kenya
Cyber Security Analyst
Follow
Message
Cyber Security Analyst
1
I conducted an authorized AI security assessment of Lily Cybersecurity 7B to evaluate how effectively a hardened system prompt could resist jailbreak and prompt injection attacks. Using Prompt Fuzzer, I ran 15 attack techniques against the model. The system prompt successfully blocked 8 attempts, including most roleplay and social engineering attacks. The successful bypasses mainly used translated or altered wording to disguise the intent of the request. This project demonstrates why system prompts should be supported by input validation, moderation, output filtering, and continuous AI red team testing.
1
151
0
Designed and documented a secure environment for running Robin, an AI-powered dark web OSINT tool, inside a compartmentalized Qubes OS and Qubes-Whonix setup. The environment was structured to separate research activity, Tor-routed traffic, sensitive credentials, untrusted content, and final reporting. Robin was deployed through Docker inside a dedicated research qube, with traffic routed through sys-whonix and sensitive notes stored separately in an offline vault qube. Disposable qubes were incorporated for opening potentially unsafe links and files. The setup was built around security by compartmentalization rather than relying on a single tool for protection. Particular attention was given to Docker mount restrictions, credential hygiene, network-boundary verification, lawful research scope, and keeping raw research data isolated from personal or client environments. The final result was a repeatable AI-assisted OSINT workflow that supports faster search refinement, result filtering, investigation summarization, and structured reporting while maintaining stronger operational security and clearer separation between collection, analysis, and final output.
0
145
1
A hands-on overview of CAI, an AI-assisted cybersecurity agent framework configured and explored in a Linux terminal environment. The demonstration focuses on how AI agents can be organized and used to support different areas of cybersecurity testing, analysis, and research. The walkthrough covers command-line navigation, available help options, agent selection, model configuration, and the use of specialized security agents. It includes a closer look at DFIR-focused agents for digital forensics and incident response, along with other agent categories designed for bug bounty research, red team activities, network security, reverse engineering, Wi-Fi security, and reporting. The setup also highlights parallel agent configuration, showing how multiple AI-driven security agents can be prepared for structured analysis and task separation. This makes the environment useful for handling different cybersecurity activities in a more organized and scalable way. Overall, the work reflects practical experience with AI-powered security tooling, terminal-based security environments, agent configuration, cybersecurity automation, and ethical AI-assisted security research.
1
187
0
Performed a manual, black-box security assessment of a locally-hosted large language model served through LM Studio, using Burp Suite as the primary testing tool. The engagement began with no prior knowledge beyond a single IP address, mirroring how an external attacker would approach an exposed AI server discovered on a network. Worked through a full discovery-first methodology: confirming the target was live, enumerating the server's exposed endpoints by probing and reading response codes, extracting the loaded model name directly from the API, and proving the expected request format through the server's own error responses rather than assuming it. This reconnaissance phase converted an unknown target into a complete map of its attack surface. With the attack surface established, executed a series of manual techniques through Burp's Repeater and Intruder tools, including prompt injection, system prompt extraction, role and system-message injection, parameter manipulation, error-message disclosure, and authentication testing. Demonstrated additional Burp capabilities relevant to AI systems, including response comparison to prove behavioral changes under attack, randomness testing of server-generated identifiers, and live request tampering to illustrate a man-in-the-middle scenario against AI traffic. Organized all findings into a structured vulnerability map aligned to OWASP LLM risk categories, recording each technique's result, severity, and supporting evidence. Delivered the work as a complete, reproducible, beginner-accessible walkthrough covering environment setup, discovery, exploitation, and reporting.
0
125
Security Engineer
(6)
Follow
Message
Guillaume Strohecker
London, UK
AI Agent Security Auditor | Fast, evidence-based reviews
New to Contra
Follow
Message
AI Agent Security Auditor | Fast, evidence-based reviews
0
I recently completed a security hardening pass on an AI-enabled mobile product. The most important issues weren’t exotic vulnerabilities. They were practical deployment risks: password reset race conditions missing abuse controls weak retention guarantees mobile backup exposure logging and CI gaps Each confirmed finding was fixed and backed by regression tests before the security baseline was marked PASS. One lesson stood out: security reviews are most useful when they produce evidence and actionable fixes, not just scanner output. I’m now offering focused 24-hour AI Agent Security Mini-Audits for founders and small teams. https://contra.com/s/2Z7YgYXU-ai-agent-security-mini-audit?r=guillaume_strohecker_6m06cchc
0
36
0
Mobile Security & Privacy Hardening Security hardening focused on mobile platform protections and privacy-preserving behavior. Android application backup was disabled to reduce risk around locally stored session material, and release builds were hardened to block cleartext traffic while keeping local development support isolated to debug/profile builds. The review also verified that BLE remains anonymous, one-sided interest stays private, precise coordinates are not exposed publicly, and Social Heat remains aggregate and threshold-gated.
0
19
0
API Rate Limiting & Abuse Protection Security hardening focused on API abuse resistance. Rate limits were added to registration, login, password-reset request and confirmation, Click Intent creation, and public Heat reads. The limiter was designed with bounded state, explicit email normalization, case-sensitive reset-token fingerprints, expiry sweeping, and fail-closed behavior under saturation. Regression tests verified throttling behavior and recovery.
0
26
0
Authentication & Password Reset Hardening Security hardening focused on authentication and account recovery. The work included stronger scrypt password hashing, legacy-hash migration, login timing protections, atomic password-reset token consumption, and session revocation after reset. PostgreSQL concurrency and regression tests verified that a reset token can only be successfully consumed once and that authentication behavior remains safe under failure conditions.
0
31
Security Engineer
(5)
Follow
Message
Explore people