
Closed
Posted
I need an experienced network-security professional to conduct an in-depth threat analysis of our cloud infrastructure. The environment spans several AWS accounts with VPC peering, Transit Gateway routing, and a mix of Kubernetes clusters and serverless workloads. Your job is to map likely attack vectors, evaluate existing controls, and clearly articulate the real-world risks we face. I will grant read-only access to relevant CloudTrail, GuardDuty, and VPC Flow Logs as well as diagrams of our current architecture. Feel free to weave in additional tooling such as Nmap, Nessus, Wireshark, Metasploit, or custom scripts—whatever produces the most accurate picture. Deliverables • Threat model highlighting assets, actors, and entry points • Evidence-backed risk ratings with CVSS or a similar scoring method • A mitigation roadmap ordered by impact and effort • Executive summary (non-technical) plus a detailed technical report Acceptance criteria: findings must be reproducible, each risk tied to a specific log, scan result, or configuration snapshot, and recommendations mapped to industry standards (NIST CSF or CIS Benchmarks). Timetable is flexible within reason, but I would like the first draft of the threat model within one week of project start so we can iterate quickly. Let me know your relevant certifications, past cloud-focused engagements, and which toolset you prefer so I can streamline access on day one.
Project ID: 40591424
45 proposals
Remote project
Active 1 min ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
45 freelancers are bidding on average $21 USD/hour for this job

As a network-security and cloud computing expert with over 10 years of experience, I bring a deep understanding of the complexity of your project and an array of skills that make me uniquely qualified for this task. Throughout my career, I have successfully worked with companies to effectively plan, design and implement secure network infrastructures. I actively work towards incorporating best practices in everything I do, which will be particularly valuable during your threat analysis project. My proficiency extends to key tools such as Nmap, Nessus, Wireshark, Metasploit, as well as custom scripts; tools I am more than ready to utilize to provide the most accurate and comprehensive security assessment. With my expertise in handling networks that are similar to your multi-cloud AWS environment with VPC peering and Transit Gateway routing, I can seamlessly navigate through your network infrastructure and strategically identify potential attack vectors. To ensure my findings are actionable and reproducible, your acceptance criteria align closely with my values as well. In a nutshell; my extensive technical know-how aligned precisely with the challenges posed by this project makes me an exceptional fit for this role. Let's equip your organization with a battle-tested defense posture that safeguards your assets and weathers any cyber storm that might come your way!
$20 USD in 40 days
7.3
7.3

With over a decade of solid experience, I specialize in exactly what you're looking for – Cloud Security. As the Founder of A2Z Research Consultants, our team's technical expertise spans across cloud infrastructure, cybersecurity, and research analysis – the perfect trifecta for your project. Regarding certifications, my team and I hold the highly-regarded Certified Information Systems Security Professional (CISSP) certification. Moreover, our implementation of industry-recognized frameworks such as NIST CSF and CIS Benchmarks in our previous engagements will ensure that my deliverables align with your requirements. In addition to well-established tools like Nmap and Nessus, we also have proficiency in developing custom scripts which could be instrumental in conducting an effective threat analysis on your unique environment. Being methodical has always been our approach -from documenting reproducible findings tied to specific logs or scan results to delivering detailed yet non-technical executive summaries. My preferred time frame for providing the first draft of threat model is one week following the project onset to keep things agile from day one.
$20 USD in 40 days
6.6
6.6

As a Linux system administration expert and software engineer it's vital to understand not only the cloud infrastructure you're moving to but also the risks that come with them. Over 8 years, I've been exposed to a variety of operating systems like Linux, Windows, Unix and more. This makes me equipped to understand your current AWS accounts with VPC peering, Transit Gateway routing, and a mix of Kubernetes clusters and serverless workloads.
$20 USD in 40 days
6.5
6.5

An AWS environment with multiple accounts, VPC peering, Transit Gateway routing, Kubernetes clusters, and serverless workloads requires more than a standard security scan. My approach is to build an evidence-based threat model that maps your assets, trust boundaries, attack paths, and existing security controls, then validate every finding against real data from CloudTrail, GuardDuty, VPC Flow Logs, and your infrastructure configuration. I'll supplement this with tools such as Nmap, Nessus, Wireshark, and custom scripts where appropriate to identify exposed services, misconfigurations, and potential attack vectors without disrupting production. Every risk will be tied to supporting evidence, scored using CVSS, and mapped to NIST CSF and CIS Benchmarks, with a prioritized mitigation roadmap based on impact and implementation effort. You'll receive both an executive summary for stakeholders and a detailed technical report with reproducible findings and clear remediation guidance. I work in review milestones, can deliver the initial threat model within one week, and I'm ready to begin as soon as read-only access is available.
$30 USD in 40 days
6.2
6.2

Hello, I have extensive experience in cloud and network security assessments and would be glad to assist with your AWS threat analysis. I hold a PhD in Cyber Security, a Bachelor's degree in Computer Science, and professional certifications including CCNA and CCNP, with hands-on experience assessing enterprise cloud environments. For your engagement, I will: • Develop a comprehensive threat model covering assets, trust boundaries, attack vectors, and threat actors • Analyze CloudTrail, GuardDuty, and VPC Flow Logs to identify evidence-backed risks • Review VPC peering, Transit Gateway routing, Kubernetes, and serverless configurations • Prioritize findings using CVSS and align recommendations with NIST CSF and CIS Benchmarks • Deliver both an executive summary and a detailed technical report with a mitigation roadmap My preferred toolset includes Wireshark, Nmap, Nessus, Metasploit, AWS-native security services, and custom analysis scripts where appropriate. Every finding will be traceable to supporting logs, configuration evidence, or scan results to ensure reproducibility. I can provide an initial threat model within one week and work collaboratively to refine the assessment as new information becomes available. I look forward to discussing your environment and getting started.
$20 USD in 40 days
5.8
5.8

As someone deeply experienced in AWS, DevOps, and Kubernetes orchestration, I offer the unique blend of skills your project demands. Over the last five years, I have not only built scalable cloud infrastructures but also developed an intimate understanding of the potential risks and vulnerabilities that come with complex environments like yours. My familiarity with tools such as Nmap, Nessus, Wireshark, and Metasploit - in addition to my ability to design CI/CD pipelines and implement Infrastructure as Code - ensures I can provide you with a comprehensive threat analysis. The evidentiary nature of my work will give every risk a clear origin that you can reproduce. Ultimately, my goal is to enable you to absolutely understand your unique threat landscape before providing a detailed mitigation roadmap. When it comes to mapping security standards, I am comfortable using NIST CSF or CIS Benchmarks - offering you a level of precision for risk scoring that's founded on industry standards. I bring an added layer of proficiency in securing infrastructure and achieving compliance with frameworks such as HIPAA, PCI-DSS, GDPR, and ISO standards – a testament to the detail-oriented way in which I approach network security. On top of everything else? My timetable is flexible within reason so we can attend to any iterations that may arise. Let’s safeguard your cloud infrastructure together.
$25 USD in 40 days
5.4
5.4

Hi, I recently completed a cloud security assessment where multiple AWS environments were reviewed using logs, network flows, and configuration analysis to identify real attack paths instead of generic security findings. I can deliver a structured threat model, evidence-backed risk ratings, prioritized mitigation roadmap, and reports for both technical and business teams. I prefer combining CloudTrail, GuardDuty, VPC Flow Logs, and targeted validation tools to keep every recommendation traceable. One question: are your Kubernetes clusters managed through EKS only, or do you also have self-managed clusters that should be included? Looking forward to helping strengthen your environment before attackers find the weak spots. Best regards, Dev S.
$50 USD in 40 days
5.2
5.2

Hello, I'm Usman, a Cloud Solutions Architect and DevOps Engineer with 7+ years of experience designing, securing, and automating AWS cloud infrastructure. My expertise includes AWS networking, VPCs, Transit Gateway, EKS/Kubernetes, IAM, CloudTrail, GuardDuty, Terraform, and Infrastructure as Code. I'm AWS Certified Solutions Architect – Associate and have worked with production cloud environments focusing on security, scalability, and compliance. For this assessment, I'll start by reviewing your AWS architecture, CloudTrail, GuardDuty, VPC Flow Logs, IAM policies, network configurations, and Kubernetes security posture to build a comprehensive threat model. I'll identify attack vectors, validate findings using AWS-native tools along with Nmap, Nessus, Wireshark, and custom analysis scripts where appropriate, and provide evidence-backed risk ratings using CVSS. Every recommendation will be mapped to NIST CSF and CIS Benchmarks, with a prioritized remediation roadmap based on impact and effort. You'll receive an executive summary, a detailed technical report, and the initial threat model within the first week so we can review and iterate together. I look forward to discussing your environment and helping improve its security posture.
$15 USD in 40 days
4.7
4.7

Dear sir, I have hands-on working experience in AWS VPC, VPC peering, Transit Gateway routing, EKS, ECS, CloudTrail, GuardDuty, and VPC Flow Logs, etc. I can conduct an in-depth threat analysis of your cloud infrastructure, identify risks, threats, and produce the necessary reports with remedies. Please conact me to discuss more abour your project. Best regards, Swamy.
$15 USD in 40 days
4.6
4.6

As a seasoned network-security professional with a versatile skill set, I believe I'm a great fit for your Cloud Network Threat Analysis project. With over six years of experience in the field, I've handled numerous cloud-focused engagements much like yours across multiple platforms. My understanding of network administration goes hand in hand with my expertise in network security, enabling me to conduct in-depth analyses while offering strategic solutions. Your project has some critical expectations which resonate deeply with my approach to work. From delivering findings tied to specific logs and configurations to mapping recommendations to industry standards like NIST CSF and CIS benchmarks, I take pride in producing thoroughly documented, reproducible and actionable results. Moreover, I am familiar with many tools usually employed in threat analysis such as Nmap, Nessus, Wireshark, Metasploit - and can write custom scripts if necessary. Enhancing cloud infrastructure security requires astute attention to detail - and that is my specialty. I will leverage my comprehensive knowledge of AWS and Kubernetes structures as well as my ability to quickly analyze large volumes of data from CloudTrail, GuardDuty, and VPC Flow Logs to provide you with a most accurate picture of your vulnerabilities and means to mitigate them. I promise an expedient first draft giving us more time for iterative feedbacks. Allow me the opportunity to fortify your cloud infrastructure!
$20 USD in 40 days
4.2
4.2

Hi, I am a full-stack AI developer with 8 years of rich experience in software development, with a background in cloud security, network security, AWS, Kubernetes, Linux, and computer security. I am familiar with AWS, CloudTrail, GuardDuty, VPC Flow Logs, Kubernetes, Transit Gateway, VPC networking, Nmap, Nessus, Wireshark, Metasploit, NIST CSF, CIS Benchmarks, and risk assessment. I can perform a comprehensive threat analysis of your cloud infrastructure by reviewing AWS logs and network architecture, identifying attack paths, validating risks with evidence, and delivering a prioritized mitigation roadmap with both executive and technical reports aligned with industry security standards. I'm an individual freelancer and can work on any time zone you want. Please contact me with the best time for you to have a quick chat. Looking forward to discussing more details. Thanks. Emile.
$20 USD in 40 days
4.0
4.0

Hi, I reviewed your project: Cloud Network Threat Analysis Specialist. I can help with server setup, deployment, SSL, Nginx/Apache configuration, Docker, Linux troubleshooting, optimization, backups, monitoring, and secure production deployment. I work with Laravel, Node.js, React, databases, APIs, and VPS/cloud environments. Please message me with your server details and application stack so I can prepare a clean deployment plan. Portfolio: https://www.freelancer.com/u/irfanui Regards, Mohammad 4th Dimension Partners
$25 USD in 42 days
2.6
2.6

In-depth cloud security threat analysis is crucial for safeguarding your multi-AWS environment with varied workloads. This proposal offers a comprehensive approach: mapping attack vectors, evaluating controls, and articulating real risks through proven methodologies. Leveraging CloudTrail, GuardDuty, and VPC Flow Logs, along with optional tools like Nmap and Nessus, I will produce a detailed threat model, risk assessment, and mitigation roadmap aligned with industry standards. Our collaborative process ensures findings are reproducible, backed by specific logs or scans, and tailored to your architecture. I will prioritize delivering a clear, actionable executive summary alongside detailed technical insights. Expect a thorough first draft within one week, enabling quick iteration and refinement.
$20 USD in 40 days
1.3
1.3

The bid amount and timeline above are rough placeholders - the real numbers depend on how many accounts we're covering and how deep the Kubernetes side goes. You're running a multi-account AWS environment with VPC peering, Transit Gateway routing, and a mix of Kubernetes and serverless workloads, which means the attack surface is spread across a lot of trust boundaries. CloudTrail, GuardDuty, and Flow Logs give us solid evidence to work from. The goal isn't a generic checklist report - it's a threat model your team can actually act on, with every finding tied back to a specific log entry or config snapshot, scored with CVSS, and mapped to NIST CSF or CIS Benchmarks so the mitigation roadmap has clear priorities. Here's how we'd approach this: - Asset and architecture mapping: Review your account structure, VPC peering topology, Transit Gateway routes, and Kubernetes cluster configs to build a full asset inventory and define trust boundaries before anything else. - Log analysis and detection: Parse CloudTrail events, GuardDuty findings, and VPC Flow Logs for anomalies, lateral movement signals, and misconfiguration patterns - correlating across peered accounts where shared risk exists. - Active scanning: Run Nmap and Nessus against exposed surfaces to validate what's actually reachable from outside and from within peered segments, plus Wireshark where traffic capture is in scope. - Kubernetes and serverless review: Check RBAC configs, pod security policies, IAM role bindings, and Lambda execution contexts for privilege escalation paths. - Risk scoring and roadmap: Assign CVSS scores to each finding, then order mitigations by impact-to-effort so your team knows exactly where to start. After a short call to confirm access scope and account count, we'll put together a written proposal covering deliverables, timeline, and firm pricing. Want to jump on a quick call this week so we can nail down access on day one? Best, 96 Studio
$25 USD in 14 days
1.1
1.1

I can make the infrastructure behind Cloud Network Threat Analysis Specialist stable, secure, and deployment-ready. My work includes Linux/VPS setup, Nginx or Apache, SSL, Docker, databases, Redis, backups, monitoring, performance tuning, and troubleshooting for Laravel, Node.js, React, and API systems. Please share the server details, application stack, current issue, and expected traffic. I will prepare a focused setup or recovery plan. Portfolio: https://www.freelancer.in/u/heenafullstacken Regards, Heena | A Plus IT House
$25 USD in 41 days
0.0
0.0

We’ll produce an evidence-backed threat analysis tailored to a multi-account AWS environment with VPC peering, Transit Gateway routing, and mixed Kubernetes + serverless workloads. The work will map assets, plausible actors, and concrete entry points, then connect each risk directly to an observed signal, CloudTrail events, GuardDuty findings, VPC Flow Logs patterns, and configuration snapshots, so every conclusion is reproducible. Deliverables: • Threat model covering assets, actors, entry points, and trust boundaries across the peering/TGW topology. • Evidence-backed risk ratings using a CVSS-style approach, aligned to what’s actually present in logs/scans. • Mitigation roadmap prioritized by impact vs. effort, mapped to NIST CSF and CIS Benchmarks. • Executive summary (non-technical) plus a detailed technical report suitable for engineers and security leadership. Early deliverable: a first draft threat model within one week so you can iterate quickly on scope and assumptions. The assessment can incorporate targeted validation techniques (e.g., Nessus/Nmap-style checks, packet analysis) where appropriate to strengthen the accuracy of the threat picture without breaking reproducibility.
$20 USD in 40 days
0.0
0.0

Hi, this is Joshua from Davis. I have strong experience in cloud security and network analysis. I understand you need a deep threat analysis of a complex AWS environment. You want clear attack paths, proven risks, and practical fixes. I can map the architecture, validate controls, and deliver a report you can act on. I would review CloudTrail, GuardDuty, VPC Flow Logs, and your diagrams. I would trace exposed entry points, lateral movement paths, and weak trust boundaries. I would tie each finding to evidence, score it with CVSS, and map it to NIST CSF or CIS. I can communicate in real time in your time zone and can provide a simple demo or part of the project within 12 hours of starting. Q1: Which AWS accounts and regions are in scope? Q2: Do you want the first draft focused more on executive risk or technical depth? Q3: Which tools or scan methods do you prefer me to prioritize? Best regards, Joshua
$20 USD in 25 days
0.0
0.0

Hello, We will deliver a full threat model across your AWS accounts, covering VPC peering, Transit Gateway, EKS clusters, and serverless entry points. Our approach: correlate GuardDuty findings with VPC Flow Logs first to surface active risks before running scans. Each finding will map to NIST CSF controls with CVSS scoring. A couple of quick things to confirm: 1) Are your Kubernetes clusters running EKS or self-managed? 2) Do you have existing Security Hub aggregation enabled across accounts? The number quoted here is a starting estimate. The exact cost and timeline will be confirmed after we go through the full scope together. Looking forward to your response. Best regards, Faizan
$19 USD in 40 days
0.0
0.0

Hey , I am a US based Freelancer, I just finished reading the job description and I see you are looking for someone experienced in Kubernetes, Cloud Security, Network Security. This is something I can do. I will map attack paths across your AWS accounts, VPC peering, Transit Gateway routes, Kubernetes clusters, and serverless workloads using CloudTrail, GuardDuty, VPC Flow Logs, plus targeted tools like Nmap, Nessus, Wireshark, Metasploit, and custom scripts where needed. I’ll tie every finding to reproducible evidence, score risks with CVSS, and organize the report so your executive summary is clear while the technical section gives you exact logs, scans, and configuration snapshots behind each issue. I’ll also align mitigation steps to NIST CSF or CIS Benchmarks and deliver a first threat-model draft within one week. To start, I need read-only access details, the current architecture diagrams, and the list of AWS accounts, Kubernetes clusters, and security controls in scope. Drop me a message before placing an order price can be discussed after discussion.- Hey , Write a line like, I am a US based Freelancer, I just finished reading the job description and I see you are looking for someone experienced in Kubernetes, Cloud Security, Network Security. This is something I can do. Read the job description carefully and tell how you will solve their problem and do you need from him to start Drop me a message before placing an order.
$20 USD in 36 days
0.0
0.0

Hi, I can help with your cloud infrastructure threat analysis and security assessment. I have experience with Odoo-based systems and Python, along with a strong understanding of secure application environments, access controls, monitoring, and vulnerability assessment concepts. For your AWS environment, I can assist with reviewing architecture, identifying attack surfaces, analyzing security controls, and preparing a structured threat model with actionable recommendations. My approach includes: • Review of AWS architecture, VPC design, IAM, networking, and workload exposure • Analysis of CloudTrail, GuardDuty, and VPC Flow Logs • Identification of possible attack paths and security gaps • Risk prioritization using industry standards such as CVSS, NIST CSF, and CIS Benchmarks • Clear executive summary and technical documentation • Mitigation roadmap focused on impact and effort I can work with your read-only access model and provide evidence-based findings with reproducible details. I would be happy to discuss your AWS setup, required tools, timeline, and deliverables.
$15 USD in 40 days
0.0
0.0

PALM COAST, United States
Payment method verified
Member since Feb 22, 2022
$2-8 USD / hour
$15-25 USD / hour
$250-750 USD
$10-30 USD
$250-750 USD
₹600-1500 INR
$25-50 USD / hour
$30-250 USD
$30-250 USD
$30-250 USD
$30-250 USD
₹1500-12500 INR
$250-750 USD
$8-15 CAD / hour
$30-250 USD
₹12500-37500 INR
$15-25 USD / hour
₹1500-12500 INR
$750-1500 USD
$50-60 AUD / hour
₹750-1250 INR / hour
$10-30 USD
₹12500-37500 INR
$10000-20000 CAD
$750-1500 USD