I will run an llm and ai application security test using the owasp llm top 10
Cloud Security Architect for Hybrid Cloud, IAM and Zero Trust
Vetted by Fiverr Pro
Marlon Costa was selected by the Fiverr Pro team for their expertise.
Vetted for
Cloud Computing
Cybersecurity
About this Gig
Vetted Pro
Shipping an LLM feature opens an attack surface your web app scanner cannot see. Prompt injection, cross-user data leakage, system prompt extraction, and agents tricked into unsafe actions are the most common findings in real AI applications.
I am a senior security architect. I test your AI application against the OWASP LLM Top 10 and MITRE ATLAS, using OWASP GenAI red teaming methodology, and map results to NIST AI RMF so the output serves both engineering and governance.
Most "AI security" gigs are automated prompt fuzzing with a cover report. I run two batteries:
- Baseline: a broad automated adversarial scan across the OWASP LLM Top 10
- Targeted: manual, architecture-aware testing of what automation misses, including indirect injection through RAG, tool and function-call abuse, and insecure output handling
You receive a findings report with severity, reproduction steps, business impact, and remediation, plus an executive summary.
Authorization required: I test only systems you own or are authorized to test, under a written scope agreed upfront. No denial-of-service and no third-party infrastructure testing.
Message me before ordering so I can scope to your app.
Expertise:
Data protection
•
Risk assessment
•
Threat intelligence
Technology:
Cloud - IaaS
•
Monitoring
•
Saas
•
Databases
•
Web application
Regulation:
GRC
My Portfolio
Other Cybersecurity Services I Offer
FAQ
Is this a real test or just an automated scan?
Both layers. A broad automated baseline for coverage, then manual targeted testing for the high-impact risks automation cannot find, such as indirect injection through RAG. You get reproduction steps and real findings, not just scanner output.
Do you need access to my system?
I test the application layer you authorize. A staging or test environment is preferred. Production testing is possible with your explicit written consent and agreed limits.
What do you need to start?
Your application or endpoint, a short architecture description (model, RAG, tools or plugins, data sources), and written authorization to test. We agree scope before any order.
Do you test the model provider, like OpenAI or Anthropic?
No. I test your application and its integration layer, where almost all real risk lives. I do not test third-party model infrastructure.
Is this legal?
Yes, when authorized. I require written confirmation that you own or control the target and permit testing within an agreed scope and window. This protects both sides.
Do you cover AI agents and RAG?
Yes. Agentic tool and function-call abuse and indirect injection through retrieval are core parts of the targeted battery.
How does this relate to your AI governance gig?
This is the technical security testing layer. If you need framework readiness across NIST AI RMF, ISO 42001, or the EU AI Act, that is my separate AI Governance assessment. They complement each other.

