I will perform a vulnerability assessment and identify security weaknesses
Cyber Security Engineer
About this Gig
Know exactly where your business is exposed before an attacker, or an auditor, finds out first.
I'm a cybersecurity engineer with hands-on experience running vulnerability assessments at an MSP across Microsoft 365, Entra ID, and network environments. This isn't a raw scanner dump: every scan is manually reviewed, false positives are removed, and findings are prioritized by real business risk not just a CVSS number.
What you get:
- External and Internal vulnerability scanning using industry-standard tools
- CVSS and EPSS prioritized findings list
- Clear remediation guidance for every issue
- A report built for stake holders and the executive team, not just engineers
This is ideal if you are:
- Renewing cyber insurance and need a current risk picture
- Preparing for a compliance audit (SOC 2, HIPAA, PCI)
- A small business that has never had a real security assessment
Every engagement starts with a quick scope conversation so you know exactly what is being tested before work begins. Message me with any questions happy to help you pick the right package.
Device:
Desktop
•
Laptop
•
Server
•
Printer
•
Other
Operating system:
Windows
•
Other
My Portfolio
FAQ
What information do you need from me before starting?
It depends on scope. For external scanning, I'll need your domain(s) and/or IP range(s). For internal scanning, I'll need the device count, operating systems, and either an agent or read-only credentialed access. I'll also need confirmation that you own or are authorized to test these systems.
Will this cause any downtime or disruption to my systems?
No. Vulnerability scanning is passive and non-disruptive by design — it identifies weaknesses without exploiting them. Your systems stay fully operational throughout the assessment.
Is Vulnerability assessment the same as a penetration test?
No — a vulnerability assessment identifies potential weaknesses, while a penetration test actively exploits them to prove real-world risk. If you need exploitation validation, check out my Penetration Testing gig instead.
Do I need to provide system access, or is this done externally?
No access is needed for the external scan. For the internal scan, a lightweight scanning agent is needed to install on the endpoints.
I don't know exactly how many assets I have — is that a problem?
Not at all. Send me what you know (a domain name is often enough to start), and I'll help identify the actual scope during our initial scope conversation before testing begins.
Can I see a sample report before ordering?
Yes, message me and I'll share a redacted sample so you know exactly what the deliverable looks like before you commit.
Do you sign an NDA?
Yes. I'm happy to sign your NDA, or I can provide a standard confidentiality and authorization agreement covering the engagement.

