Cloud Network Threat Analysis Specialist
Budget: $15 – $25 USD
I need an experienced network-security professional to conduct an in-depth threat analysis of our cloud infrastructure. The environment spans several AWS accounts with VPC peering, Transit Gateway routing, and a mix of Kubernetes clusters and serverless workloads.
Your job is to map likely attack vectors, evaluate existing controls, and clearly articulate the real-world risks we face. I will grant read-only access to relevant CloudTrail, GuardDuty, and VPC Flow Logs as well as diagrams of our current architecture. Feel free to weave in additional tooling such as Nmap, Nessus, Wireshark, Metasploit, or custom scripts—whatever produces the most accurate picture.
Deliverables
• Threat model highlighting assets, actors, and entry points
• Evidence-backed risk ratings with CVSS or a similar scoring method
• A mitigation roadmap ordered by impact and effort
• Executive summary (non-technical) plus a detailed technical report
Acceptance criteria: findings must be reproducible, each risk tied to a specific log, scan result, or configuration snapshot, and recommendations mapped to industry standards (NIST CSF or CIS Benchmarks).
Timetable is flexible within reason, but I would like the first draft of the threat model within one week of project start so we can iterate quickly. Let me know your relevant certifications, past cloud-focused engagements, and which toolset you prefer so I can streamline access on day one.
Your job is to map likely attack vectors, evaluate existing controls, and clearly articulate the real-world risks we face. I will grant read-only access to relevant CloudTrail, GuardDuty, and VPC Flow Logs as well as diagrams of our current architecture. Feel free to weave in additional tooling such as Nmap, Nessus, Wireshark, Metasploit, or custom scripts—whatever produces the most accurate picture.
Deliverables
• Threat model highlighting assets, actors, and entry points
• Evidence-backed risk ratings with CVSS or a similar scoring method
• A mitigation roadmap ordered by impact and effort
• Executive summary (non-technical) plus a detailed technical report
Acceptance criteria: findings must be reproducible, each risk tied to a specific log, scan result, or configuration snapshot, and recommendations mapped to industry standards (NIST CSF or CIS Benchmarks).
Timetable is flexible within reason, but I would like the first draft of the threat model within one week of project start so we can iterate quickly. Let me know your relevant certifications, past cloud-focused engagements, and which toolset you prefer so I can streamline access on day one.
Related categories:
Linux
Computer Security
Cloud Computing
Cisco
Network Administration
Kubernetes
Cloud Security
Network Security