Part Time
$8/hour
20
Sep 17, 2026
Please read the subject line formatting rules carefully before submitting your application:
• If you have experience in ALL listed roles, use this exact subject format:
'All - CYBERSECURITY Freelance Network — Technical Role'
• If only SPECIFIC roles apply to you, list the corresponding item numbers in your subject format (e.g., if roles 1 and 3 fit your background):
'1, 3 - CYBERSECURITY Freelance Network — Technical Role'
Note: Each number corresponds directly to the numbered role in the job list.
Engagement Model
Deliverables reviewed by WWGRC lead before release to the client
NDA and background check required prior to first engagement
Rate negotiated per engagement based on scope, certifications, and geography
Priority Experience
We are particularly interested in cybersecurity professionals with hands-on experience in endpoint security and security logging/monitoring. Relevant experience may include EDR/XDR administration and tuning, endpoint threat detection and response, SIEM platforms, log collection and analysis, detection engineering, alert triage, and investigation of security events. Experience with tools such as Microsoft Defender, CrowdStrike, SentinelOne, Splunk, Microsoft Sentinel, Elastic, or similar platforms is highly valued.
1. Offensive Security & Vulnerability Management
Domain coverage: Vulnerability scanning, penetration testing, red teaming, secure configuration review
Responsibilities
Run internal/external vulnerability scans (Nessus, Qualys, Rapid7, OpenVAS) and triage results
Perform network, web-app, API, and wireless penetration tests with formal reports
Conduct segmentation testing (PCI 11.4.5) and validate remediation
Review firewall, router, and system hardening against CIS Benchmarks / DISA STIGs
Qualifications
OSCP, OSWE, GPEN, GWAPT, CEH, or equivalent hands-on experience
Proficient with Burp Suite, Metasploit, Nmap, BloodHound, and manual exploitation techniques
Ability to produce executive-ready reports with CVSS scoring and reproducible PoCs
2. Cloud & Infrastructure Security
Domain coverage: AWS / Azure / GCP configuration review, IaC scanning, Kubernetes/container security, network segmentation
Responsibilities
Review IAM, KMS, VPC/VNet, logging, and encryption posture across AWS/Azure/GCP
Assess Kubernetes/EKS/AKS/GKE clusters, container images, and admission controls
Audit Terraform / CloudFormation / Bicep against CIS and framework baselines
Validate network segmentation, ingress/egress controls, and zero-trust patterns
Qualifications
AWS Security Specialty, Azure AZ-500, GCP Professional Cloud Security Engineer, or CCSP
Experience with Prowler, ScoutSuite, Wiz/Prisma/Defender, kube-bench, Checkov, tfsec
Strong grasp of shared-responsibility model and multi-account/landing-zone design
3. Application Security & DevSecOps
Domain coverage: SAST/DAST/SCA, secure SDLC, threat modeling, API security, CI/CD pipeline hardening
Responsibilities
Perform code review and threat modeling (STRIDE / PASTA) for client applications
Configure and tune SAST/DAST/SCA/secrets-scanning tools in CI/CD pipelines
Assess API security (OWASP API Top 10), authentication, and authorization patterns
Review software supply-chain controls (SBOM, signing, provenance, SLSA)
Qualifications
CSSLP, GWEB, GWAPT, or 3+ years of hands-on AppSec engineering
Fluency in at least two of: Java, Python, JavaScript/TypeScript, C#, Go
Experience with Semgrep, Snyk, SonarQube, GitHub Advanced Security, ZAP, Burp
4. Endpoint, Identity & Data Protection
Domain coverage: EDR/XDR, MDM, IAM/PAM, MFA, DLP, encryption, key management
Responsibilities
Evaluate EDR/XDR (CrowdStrike, SentinelOne, Defender) coverage, policies, and alerting
Review Okta/Entra ID/Ping configurations: SSO, MFA, conditional access, lifecycle
Assess PAM tooling (CyberArk, BeyondTrust, Delinea) and privileged workflows
Audit DLP, data classification, disk/DB encryption, and KMS/HSM key lifecycle
Qualifications
Vendor certifications in Okta, Entra, CrowdStrike, or CISSP/CCSP with IAM focus
Hands-on endpoint security experience, including EDR/XDR deployment, policy configuration, alert investigation, endpoint threat detection, and remediation
Experience with SCIM, SAML, OIDC, FIDO2/WebAuthn, and just-in-time access patterns
Working knowledge of FIPS 140-3, PCI PIN, and cryptographic key management
5. Network Security & Zero Trust
Domain coverage: Firewalls, IDS/IPS, WAF, SASE/SSE, VPN, network segmentation, DNS security
Responsibilities
Review Palo Alto / Fortinet / Cisco / Check Point rulesets and change processes
Assess SASE/SSE deployments (Zscaler, Netskope, Cloudflare, Cato)
Validate WAF and DDoS protection posture (Cloudflare, Akamai, AWS WAF/Shield)
Design and audit micro-segmentation and zero-trust network architectures
Qualifications
CCNP Security, PCNSE, NSE 7, or equivalent hands-on network-security experience
Deep understanding of TLS, TCP/IP, BGP, DNS, and modern zero-trust reference architectures
6. Detection, SOC & I
Domain coverage: SIEM/SOAR engineering, threat hunting, DFIR, log pipelines, use-case development
Responsibilities
Design and tune SIEM (Splunk, Sentinel, Chronicle, Elastic) detections mapped to MITRE ATT&CK
Build SOAR playbooks and integrate with EDR/ITSM/ticketing
Lead or advise on i
Perform DFIR: memory/disk forensics, log timeline reconstruction, malware triage
Qualifications
GCIH, GCFA, GCIA, GNFA, or equivalent SOC/DFIR field experience
Hands-on log security and monitoring experience, including SIEM administration, log ingestion and normalization, detection tuning, event correlation, alert triage, and security-event investigation
Fluent in KQL, SPL, or equivalent query languages; scripting in Python/PowerShell
Familiarity with MITRE ATT&CK, D3FEND, and Sigma rule authoring
7. Privacy Engineering & Data Governance
Domain coverage: Data mapping, ROPA, DSAR automation, privacy-by-design, cross-border transfers, AI/data governance
Responsibilities
Build and maintain data inventories, ROPA, and cross-border transfer analyses
Design DSAR / consent workflows and integrate with OneTrust / Transcend / Ketch
Advise on PIAs, DPIAs, and AI-model risk assessments (NIST AI RMF / ISO 42001)
Review data-retention, minimization, pseudonymization, and de-identification controls
Qualifications
CIPP/E, CIPP/US, CIPT, CIPM, or FIP
Hands-on experience with OneTrust, BigID, Collibra, or equivalent
Working knowledge of AI/ML data-governance frameworks and emerging AI regulation
8. Auditor / Assessor (Framework-Certified)
Domain coverage: Independent framework assessment support: SOC 2, ISO 27001, PCI DSS, HITRUST, FedRAMP, CMMC
Responsibilities
Perform readiness assessments and mock audits against target frameworks
Validate control design and operating effectiveness with sampling and walkthroughs
Draft evidence-request lists, control narratives, and management-response memos
Coordinate with external auditors and QSAs to accelerate certification cycles
Qualifications
CISA, CISSP, ISO 27001 Lead Auditor, PCI QSA/ISA, HITRUST CCSFP, or CCA (CMMC)
3+ years performing audits or assessments for mid-market or enterprise clients
9. OT / ICS / IoT Security (On-Demand)
Domain coverage: Operational technology, industrial control systems, and connected-device security assessments
Responsibilities
Assess OT/ICS network segmentation, Purdue-model alignment, and safe scanning practices
Review IoT device provisioning, firmware update, and certificate lifecycle controls
Advise clients in manufacturing, energy, healthcare-device, and smart-building sectors
Qualifications
GICSP, GRID, ISA/IEC 62443 certification, or demonstrable OT project experience
Familiarity with Claroty, Nozomi, Dragos, or Armis