Hiring a Freelance AML & Cybersecurity Consultant: What to Look For

Hiring a freelance or independent consultant for cybersecurity, GRC or financial-crime work can move faster and cost less than a full-time hire — if you pick the right person. The market ranges from genuine senior practitioners to slide-deck merchants, and the difference only shows up after you’ve paid. Here’s how to tell them apart before you sign.

Start with the outcome

Be clear on the problem: passing an audit, hardening an app, building an ISMS, training a team, or getting a compliance programme unstuck. A good consultant scopes to a measurable result — “ISO 27001 Stage 2 ready by Q3”, “critical findings closed and re-tested” — not to billable hours. If you can’t state the outcome in one sentence yet, that’s fine: the first thing a strong consultant will do is help you write that sentence, often in a free scoping call.

What to check

  • Credentials that match the work — security certifications (e.g. CompTIA Security+, cloud security certs) for technical work; recognised compliance training for GRC and AML-adjacent engagements.
  • Hands-on evidence, not just theory — ask what they personally configured, tuned or built with the actual tools (SIEM, cloud platforms, monitoring systems), and listen for specifics.
  • Domain blend where it matters — someone who understands both security and the regulated-business context (banking, fintech, data protection) speaks to engineers, compliance and regulators at once, and translates between them.
  • References and artefacts — a redacted report, a sample register or policy. The quality of their documents is the quality of your deliverable.

Questions that expose the pretenders

  • “Walk me through the last one you did.” Real practitioners tell stories with friction in them — what went wrong, what they changed. Pretenders recite methodology.
  • “What will you leave behind?” The right answer includes documentation, working configuration and people who’ve been shown how — not a dependency on the consultant.
  • “How will we measure success?” If there’s no metric — findings closed, click-rate trend, audit result — you’re buying activity, not outcomes.
  • “What’s out of scope?” Honest consultants say no to work outside their lane and tell you who to use instead.

Engagement models and pricing

Decide between a fixed-scope project (best for audits, tests and builds with a clear end state) and a retainer (best for ongoing advisory or fractional security leadership). Confirm they can work the way you need — remote, onsite or hybrid — and insist any quote separates the deliverable, the timeline and what happens if scope changes. Day rates vary widely by market and seniority; what matters is the cost of the outcome, not the day. A senior freelancer who finishes in two weeks beats a cheap one who circles for three months.

Red flags

  • Vague scope that never becomes a written statement of work.
  • Slideware with no implementation — strategy decks that leave your controls exactly where they were.
  • No metrics for success, no baseline, no re-test.
  • Guaranteed outcomes nobody can guarantee — certification “in 30 days”, rankings “at #1”, audits “passed, promise”.
  • Dependency by design — no documentation, no handover, everything in their head or their tooling.

Good consultants leave you with documentation, working controls and measurable improvement — the same standard I set for hiring a freelance web developer, because it’s the same discipline. If your need is cybersecurity, GRC, data protection or security training — with the financial-crime domain context that regulated businesses appreciate — that’s exactly what I offer — grounded in 6+ years across security, GRC and financial-crime technology: see my services or get in touch, remote, onsite or hybrid.

Bader Alkandery

Freelance cybersecurity, GRC & data-protection consultant in Kuwait — MSc Cyber Security & Networks (Best Paper), CompTIA Security+.

Keep reading

More insights