Freelance cybersecurity consultant working from a home office at night
    Careers

    How to Start a Freelance Cybersecurity Career: A Practical Guide

    A step-by-step guide to going freelance in cybersecurity: when you are ready to make the move, how to set day rates that reflect your value, how to land your first clients, and the admin nobody warns you about.

    July 18, 20266 min read·The Cyberr Team
    All articles

    Freelance cybersecurity work has stopped being a fringe career choice. Organisations that cannot hire a full-time penetration tester, cloud security architect, or compliance lead still need the work done, and increasingly they buy it by the day rather than by the headcount. If you have solid skills and a few years of delivery behind you, freelancing is a realistic route to more control over your work and, usually, more money.

    It is also a business. This guide covers the parts that decide whether it works: knowing when you are ready, pricing properly, finding clients, and handling the unglamorous admin.

    Are you ready to go freelance?

    There is no certification that makes you a freelancer. What clients buy is the confidence that you can walk into an unfamiliar environment and deliver without supervision. In practice that means:

    • Two to five years of hands-on delivery in a specialism you can name in one sentence. "Cybersecurity generalist" is a hard sell. "Web application penetration testing for fintech" is not.
    • Evidence you can point at. Certifications (OSCP, CISSP, CCSP, ISO 27001 Lead Implementer), redacted report samples, CVEs, CTF placements, public write-ups, or references from people willing to take a call.
    • The ability to scope your own work. Clients will describe a vague problem. You need to turn it into a statement of work with deliverables, dates, and a price.
    • A financial runway. Three to six months of expenses covered. Your first invoice may not be paid for 60 days after your last salary lands.

    If you are missing one of these, you are not blocked — you are early. Contract inside an existing consultancy first, or take on weekend work alongside a permanent role where your contract allows it.

    Pick a specialism clients already budget for

    The freelance market pays best where demand is spiky and in-house cover is thin. Consistently strong areas:

    • Offensive security: penetration testing, red teaming, web and mobile application testing, and increasingly AI/LLM security testing.
    • Cloud security: AWS, Azure, and GCP hardening, IAM reviews, Kubernetes security, infrastructure-as-code review.
    • GRC and compliance: ISO 27001, SOC 2, NIS2, DORA, and GDPR programmes. Regulatory deadlines create work that has to happen on a date.
    • Incident response and DFIR: retainer work and surge capacity.
    • Fractional leadership: virtual CISO engagements for companies too small for a full-time security executive.

    Pick one to lead with. You can broaden later; you cannot market yourself before anyone can remember what you do.

    How to set your freelance rate

    Most new freelancers underprice, then discover they have built a job with worse benefits. Start from what you need to earn, not from what feels polite to ask.

    Step 1: work out your billable days. There are roughly 260 working days in a year. Subtract holiday, sick days, admin, sales, and training and you land at 180 to 200 billable days in a good year. In your first year, assume 120 to 150.

    Step 2: work out your target revenue. Take the salary you want, add employer costs you now carry yourself — pension, insurance, equipment, software, accountancy, training, downtime — and add a buffer. A common rule of thumb: target 1.5x to 2x your equivalent permanent salary to end up materially better off.

    Step 3: divide. Target revenue ÷ billable days = your day rate floor.

    Example: you want the equivalent of a €80,000 salary. Target revenue of €140,000 across 160 billable days gives a floor of roughly €875 per day.

    Step 4: sanity-check against the market. Day rates vary widely by region, specialism, and client type, and end clients pay more than agencies who take a margin. Ask peers directly — freelancers talk about rates far more openly than employees do, and inside communities like Cyberr you can compare notes with people doing your exact work in your market.

    A few pricing rules worth adopting from the start:

    • Quote in day rates, not hourly, for project work. Hourly invites micro-management.
    • Price fixed-scope deliverables as fixed fees once you know how long they take you. A penetration test you can deliver in four days does not have to be sold as four days.
    • Charge for retainers up front. Reserved capacity is worth paying for.
    • Never discount silently. If a client needs a lower price, reduce the scope with it.
    • Raise your rate on new clients first. It is easier than renegotiating with existing ones.

    Finding your first clients

    Freelance cybersecurity work is bought on trust, and trust travels through networks rather than job adverts. In rough order of return on effort:

    1. Your existing network. Former colleagues, managers, and vendors already know how you work. Tell them clearly what you are now available for and what a good referral looks like.
    2. Professional communities and networks. Being visible where security work gets discussed matters more than a polished website. On Cyberr you can publish a verified freelance profile, connect certifications, and be matched to freelance briefs by skill — including anonymously, if you are still employed.
    3. Consultancies and boutique firms who subcontract overflow work. Lower rates, but steady volume while you build.
    4. Public proof of work. Conference talks, write-ups, open-source tooling, and useful posts do more sales work than cold outreach ever will.
    5. Marketplaces and freelance job boards, used selectively. Good for a first engagement, less good as a long-term channel.

    Two habits separate freelancers who stay busy from those who cycle between famine and burnout: always keep one conversation warm while you are delivering, and ask every satisfied client for a referral and a testimonial before the engagement closes.

    The admin nobody warns you about

    • Register properly as a sole trader, limited company, or the local equivalent, and take 30 minutes of an accountant's time to pick the right one.
    • Get professional indemnity and cyber liability insurance. Many clients will not sign without it, and offensive work makes it non-negotiable.
    • Use a written contract for every engagement, covering scope, rates, payment terms, liability caps, IP ownership, and — for testing work — explicit written authorisation to test the in-scope systems.
    • Invoice on a schedule and chase late payment early. Net 30 with a stated late-payment charge is reasonable; do not let an invoice reach 60 days in silence.
    • Set money aside for tax from every payment, not at year end.
    • Book training and holiday into the calendar as unavailable days. Skills decay and burnout are the two most expensive risks in a one-person business.

    A realistic first-year timeline

    | Phase | Focus | | --- | --- | | Months −3 to 0 | Build runway, define your specialism, set your rate, line up one or two first engagements, sort registration and insurance. | | Months 1 to 3 | Deliver the first engagement well. Collect a testimonial. Publish something useful. Keep two conversations warm. | | Months 4 to 9 | Repeat business and referrals start arriving. Raise your rate for new clients. Turn down badly-scoped work. | | Months 10 to 12 | Convert your steadiest client to a retainer. Review your rate, utilisation, and specialism against what actually sold. |

    Where Cyberr fits

    Cyberr is a professional network built for cybersecurity people rather than a generic job board. Freelancers use it to publish a verified profile, connect and validate certifications from Credly, Hack The Box, and TryHackMe, be matched to freelance briefs by skill, and stay visible to hiring teams without broadcasting a job search to their current employer.

    Create your free Cyberr profile and start being found for the work you actually want.

    Related reading: [The future of cybersecurity freelancing](/blog/the-future-of-cybersecurity-freelancing) and [Cybersecurity careers: a path to a rewarding and in-demand profession](/blog/cybersecurity-careers-a-path-to-a-rewarding-and-in-demand-profession).

    Frequently asked questions

    Join the cybersecurity community

    Create your free Cyberr account today.