Personal · Fast Clean $
Freelance security.
Invited, paid, no dups.
Bounties were a dup-graveyard. Cold outreach carries risk. Freelance is the opposite: a client hires you, scope is signed, the work is authorized, and you get paid for the hours. This is the fastest clean first dollar.
Why this, why now: it's permission-based (zero accusation risk), it uses skills you already have receipts for, clients pay in USD/CAD, and it's fully remote from Canada. A gig can land in one to two weeks.
1Your unfair advantage on a freelance marketplace
Most freelance "security" sellers are generalists with no proof. You walk in with 6 published CVEs (soon 9) on software used by millions, a running security firm, Immunefi clearance, and a multi-year pentest history. On Upwork that is a top-1% profile. You are not competing on price, you are competing on proof nobody else has.
2What you sell (packaged, not vague)
- Web app / API security audit — a fixed-scope review with a clear report. Your bread and butter.
- External / posture review — exactly what the research engine does, but authorized for one client who hired you.
- Code / dependency security review — the incomplete-fix eye that found your CVEs.
- ⭐ AI / LLM / MCP security review — the niche almost no freelancer offers, where your CVEs are the proof. Premium, low competition.
- Smart-contract review — Immunefi-cleared, for the web3 gigs.
3The setup (a focused evening)
1
Reactivate + rebuild the Upwork profile, receipts-first. Title: "Security Researcher · AppSec + AI/Agent Security · Published CVEs". Lead the overview with the CVEs + the firm. I draft the whole profile for you.
2
Post 3-4 fixed-scope "service" offerings (Upwork Project Catalog) so clients can buy directly: a Starter audit, a Full audit, an AI-security review, a smart-contract review. I write the listings + pricing.
3
Set rate. Your profile justifies a premium. Start at a rate that wins the first 1-2 reviews, then climb fast. I give you the number + the climb plan.
4
Proposal template. A short, receipts-led template you tweak per job (lead with a relevant CVE, one specific observation, a clear deliverable). I write it.
4The rhythm (lands the first gig)
Apply to 5-10 well-matched jobs a day with the tweaked template. Security + AI-security demand is high and the receipts-led proposal cuts through. First review is the hardest; price to win it, over-deliver, then the rate and inbound climb. Consider also Fiverr Pro (buyers come to you) + direct subcontracting to security firms (they bring the authorized client, you do the work) as parallel channels.
5How it feeds the bigger machine
Every freelance audit is a Securva case study, a testimonial, and sometimes a recurring client. The freelance lane is the fast cash that funds the runway while Securva + the brand ramp. And the AI-security gigs are literally Securva's flagship service, sold one client at a time. Fast money now, firm later, same skill.