Senior Cybersecurity Specialist For Full-Stack Hardening

Job ID: 39276820

Budget: €250 – €750 EUR

Freelance Cybersecurity Engineer Wanted – Full-Stack Infra & App Security Hey! I'm looking for a freelance cybersecurity specialist (or a senior-level engineer with strong security instincts) to help harden and monitor a full-stack cloud-based environment. This isn’t just about network traffic — I need someone who can take a security-first look at everything from infrastructure to backend services, frontend endpoints, CI/CD, and runtime environments. The system is containerized and running in Azure, and we're looking to seriously level up our security posture across the board. Scope / What Needs Doing: - Network Layer: Monitor, log, and analyze traffic (internal + external), set up NSG rules, flow logs, threat detection on Azure - Host-Level: Secure VM/Container instances (harden images, disable unnecessary services, intrusion detection, etc.) - Backend Services (mostly Golang): Code review for common security pitfalls, auth/authz checks, API abuse prevention - Frontend (minor): Audit exposed endpoints, CORS configs, XSS/CSRF protections - Cloud: Identity & access control (Azure AD), storage security, key vault usage, role assignments, resource policies -Container Security: Docker image hardening, scanning, runtime protections (Falco, AppArmor, etc.) - IaC (Terraform): Review and improve security around IaC templates — least privilege, secrets handling, proper tagging & resource policies - CI/CD Pipelines:Secrets management, artifact integrity, enforce security gates during build/deploy - Logging & Monitoring:Centralized logging, alerting for suspicious behavior, possible SIEM integrations (e.g., Azure Sentinel, ELK) - Threat Modeling: Help identify key risks in the current setup, document findings and mitigation recommendations Tech Stack You’ll Be Working With: - Golang (backend services) - Docker (everything containerized) - Terraform - Preferably Azure Cloud (VMs, Functions, Key Vault, NSGs, etc.) - GitHub Actions for CI/CD - Some use of PostgreSQL, Redis, and NGINX - Might pull in: Suricata, OSQuery, Zeek, Falco, Grafana, Prometheus, or Sentinel depending on your preferences/experience What I'm Looking For: - Someone with a broad and deep understanding of security across the stack - Real-world experience securing modern cloud-native applications - Strong familiarity with both offensive and defensive techniques - Can explain things clearly and document what you implement - Bonus if you've done any compliance-related work (ISO 27001, SOC2, etc.) Timeline & Budget: Looking to get started soon. We can start with a time-boxed audit & recommendations phase, then move into implementation. Open to hourly or fixed project rate depending on scope and experience. If you’ve got examples of past work, CVEs, writeups, GitHub links — even better. Let me know what you bring to the table and what availability looks like for you. Looking forward to locking this down with someone who gets it.