WPR-50538
Cybersecurity & Cloud
Published project
Project Budget
USD 42,000 – 58,000
Cybersecurity & Cloud: Secure Our Hybrid Environment and Standardize Cloud Operations
We have expanded our cloud use faster than our security practices have matured. Identity controls, monitoring, backups, network rules, and administrative access now need a thorough review. We are looking for a senior cloud-security specialist who can identify the real risks, correct the most important gaps, and leave our team with a secure environment that is practical to operate.
Industry Sector
General Industry
Work Arrangement
remote (San Antonio)
Project Sourcing
WPR-50538 (Project reference)
Published Date
8/24/2026
Detailed Scope of Work & Deliverables
Milestone 1: Identify Current Exposure | Weeks 1–2
Review cloud accounts, selected on-premise systems, applications, networks, user access, integrations, and third-party connections.
Examine privileged accounts, inactive users, public endpoints, firewall rules, encryption, backups, logs, and existing security alerts.
Deliver a prioritized risk register separating urgent vulnerabilities from longer-term improvements.
Provide a 30-day action list for any issue requiring immediate containment.
Milestone 2: Design the Secure Cloud Standard | Weeks 3–4
Create a target architecture covering account structure, network segmentation, identity, encryption, key management, logging, backup, and disaster recovery.
Define minimum security requirements for new cloud resources and deployments.
Map the recommended controls against NIST Cybersecurity Framework 2.0 and applicable organizational requirements.
Agree on the workloads and systems included in the implementation phase.
Milestone 3: Correct Priority Security Gaps | Weeks 5–8
Strengthen multifactor authentication, single sign-on, role-based access, privileged administration, and service-account controls.
Secure internet-facing services, storage, databases, APIs, secrets, and encryption keys.
Centralize important logs and configure meaningful alerts for suspicious access, configuration changes, and abnormal activity.
Establish vulnerability management, patching priorities, and configuration-review procedures.
Milestone 4: Modernize Selected Cloud Workloads | Weeks 9–13
Securely migrate or reconfigure up to three agreed workloads.
Use infrastructure-as-code for repeatable deployment wherever appropriate.
Introduce security checks within the deployment pipeline.
Test application availability, access permissions, backup restoration, failover, and rollback procedures.
Record cost, performance, and security improvements against the starting position.
Milestone 5: Validate and Hand Over | Weeks 14–16
Conduct a controlled security validation and an incident-response tabletop exercise.
Resolve agreed critical and high-priority findings.
Deliver architecture diagrams, access matrices, configuration records, response procedures, backup instructions, and operating checklists.
Train the internal technology team and provide a prioritized 90-day improvement plan.
REQUIRED SKILLS & COMPETENCIES
At least eight years of experience in cloud infrastructure, cybersecurity, network security, or DevSecOps
Strong production experience with AWS, Microsoft Azure, or Google Cloud
Hands-on expertise in IAM, zero-trust access, network segmentation, encryption, key management, secrets management, and cloud logging
Experience with Terraform or another infrastructure-as-code platform
Working knowledge of SIEM, CSPM/CNAPP, endpoint protection, vulnerability management, and incident response
Familiarity with NIST Cybersecurity Framework 2.0, CIS controls, SOC 2 readiness, and cloud shared-responsibility principles
Ability to secure cloud migrations without causing unnecessary operational disruption
CISSP or CCSP certification preferred
Relevant AWS, Azure, or Google Cloud security certification preferred
Clear documentation, stakeholder communication, and technical training skills
Availability during U.S. business hours
Ability to attend up to two on-site workshops in San Antonio, if required
Required Competencies & Skills
CybersecurityCloud ArchitecturePenetration Testing
Verified Proposal Workflow
Workfry protects professional engagements through structured proposal submissions, milestone estimations, and verified identity tiers. Project Chat unlocks exclusively when a proposal is formally accepted and confirmed by the Expert.
