Back to the blog
Guide11 min readUpdated

Developer, Consultant or Firm: Who Should Secure Your SaaS?

In-house security engineer, freelance consultant or specialized firm to protect your SaaS, fintech or app? A comparison of pros, cons and costs.

Diego Melo, author
Diego Melo

Security researcher and founder of No Vuln

Developer, Consultant or Firm: Who Should Secure Your SaaS?

You've decided your platform needs better security. Good news. Now comes the hard part: who do you hire? The market offers at least four different routes — a dedicated in-house security engineer, a freelancer, an independent consultant or a specialized firm — and each one makes sense in a different situation.

This is an honest guide to help you, a business owner who isn't in IT, decide which route fits where your company is right now. No jargon, no vague “it depends.”

The 4 possible paths

Costs below are Brazilian market ranges, in Brazilian reais (R$).

WhoApproximate costBest for
In-house engineer focused on securityR$ 15k–30k / monthCompanies with 30+ devs, a critical platform and a fast pace of change
Freelancer / one-off consultantR$ 100–500 / hourA specific task, a short deadline, no ongoing need
Independent consultant on retainerR$ 8k–20k / monthMid-size companies with no in-house security engineer and a medium-term project
Firm specializing in pentesting and security auditsR$ 3k–60k per project
Recurring: varies / month, depending on scope
One-off audits, compliance, security validation

Path 1: Hire an in-house security engineer (full-time)

When it makes sense

You have more than 30 developers, run a critical platform (financial, healthcare, sensitive data at volume) and your business depends on constant code changes. Think Brazilian companies like Stone, Nubank, iFood or CloudWalk.

What this person does day to day

  • Reviews code before it ships
  • Teaches developers secure coding practices
  • Sets up continuous detection tooling
  • Investigates small incidents before they become big ones
  • Makes architecture decisions alongside the technical leads

Why smaller companies should be careful with this route

Good security people are expensive: in Brazil, 2026 salaries run between R$ 15,000 and R$ 30,000 a month (full-time employment under the CLT, Brazil's standard labor regime, including payroll charges). For a company with 5–15 developers, that one hire costs as much as 2 or 3 additional developers. And, to be blunt: one in-house person can't cover everything. Even at Big Tech companies, security is a team effort — not a solo hero act.

Warning sign

If you're thinking about hiring “a security dev” just to pass an audit, think again. You'd be paying an ongoing salary to solve a one-time, project-sized problem. A specialized firm does that for a fraction of the cost.

Path 2: Hire a freelancer or one-off consultant

When it makes sense

A specific task, a short deadline, a well-defined scope. For example:

  • “Set up our Cloudflare WAF”
  • “Add 2FA to our admin area”
  • “Review our AWS configuration before launch”
  • “Audit this specific piece of code”

Typical costs

Security freelancers in Brazil charge between R$ 100 and R$ 500 an hour, depending on seniority. Consultants who specialize in a niche (pentesting, AppSec, cloud security) can go higher.

Risks of this route

  • Inconsistent coverage. The freelancer does the task you asked for. If you asked for the wrong thing, the problem stays — a freelancer isn't responsible for finding problems you didn't list.
  • No ongoing accountability. Something breaks 60 days later? Not their responsibility. They go dark? You're on your own.
  • Quality is hard to judge. Good freelancers have a portfolio (published CVEs, bug bounty findings, conference talks). Someone with no public portfolio probably isn't at the same level as someone who has one.

How to hire well on this route

Always ask for:

  • A public portfolio (bug bounty findings, CVEs, talks)
  • References from 2–3 previous clients
  • A proposal with a crystal-clear scope (what's in, what's out)
  • An NDA before the technical call
  • A written final deliverable

Path 3: An independent consultant on retainer

When it makes sense

Your company has no in-house security engineer, but you need someone continuously involved — weighing in on architecture decisions, reviewing code periodically, being your “security person” without being on payroll.

How it works

It's usually a contract for 10 to 30 hours a month with a senior consultant. In Brazil, that costs between R$ 8,000 and R$ 20,000 a month, depending on seniority and the number of hours.

Advantages vs. a full-time hire

  • Costs half as much or less
  • No payroll taxes or employment obligations
  • Access to someone far more experienced than you could hire full-time for that money
  • Flexibility — scale up or down as needed

Disadvantages vs. a full-time hire

  • The person isn't “inside” the company's day-to-day
  • Their time may be split across other clients
  • It doesn't replace a SOC or an incident response team

When NOT to hire a consultant on retainer

If what you need is a one-off audit with a formal report (e.g., to pass SOC 2, to meet an enterprise customer's requirement, to comply with a data protection law such as Brazil's LGPD), a retainer consultant isn't the right tool. For that, go with a specialized firm (path 4).

Path 4: A firm specializing in offensive security

When it makes sense

  • You need a formal security audit or pentest
  • An enterprise customer asked for evidence of security testing
  • You're preparing for SOC 2, ISO 27001, PCI DSS or the LGPD
  • You want to validate security before a critical launch
  • You've had an incident and want to know what else is vulnerable
  • You need continuous attack surface monitoring

What's different from the other options

A specialized firm has a methodology: a documented process, its own tooling and a team with complementary specialties. You hire a project and get:

  • A formal report, formatted for audits
  • A reproducible proof of concept (PoC) for every finding
  • Calibrated severity (not just a technical score)
  • A retest after you fix the issues
  • A live walkthrough session with your team

Typical costs (Brazilian market)

  • One-off pentest of a small application: R$ 3,000 to R$ 6,000
  • Pentest of a SaaS in production: R$ 6,000 to R$ 12,000
  • Full-stack enterprise pentest (regulated sector): R$ 18,000 to R$ 60,000+
  • Monthly recurring (monitoring + focused pentests): varies — monthly or quarterly hour bank, depending on scope

How to choose a specialized firm (red flags)

These are signs you're about to pay for bad work:

  • “100% automated pentest” — no such thing. Automation covers 30–40% of the work; the rest is manual.
  • A report full of scanner screenshots (Nessus, Acunetix) with no manual PoC — that's a scanner with a fancy name.
  • Retests billed separately — they charge you again to confirm you fixed the issue? Outdated model. Walk away.
  • No NDA before the first technical call — a sign of disorganization or bad faith.
  • No answer to “who, specifically, will work on my project?” — good professionals have names and portfolios. If a firm hides that, be suspicious.
  • An “ethical hackers” tagline — dated terminology (circa 2010). The modern term is “security researcher.”

The decision, simplified

Your situationRecommended path
Launching an MVP, no customers yetSpecialized firm — one-off pentest before launch
SaaS in production, no in-house security engineerSpecialized firm (annual pentest) + a light consultant retainer
An enterprise customer asked for pentest evidenceSpecialized firm — one-off pentest with an audit-ready report
You've had an incident and want to understand the damageSpecialized firm — emergency pentest + investigation
Company with 30+ devs and nobody on securityOne senior full-time hire + a specialized firm for quarterly audits
One-off task: set up a WAF, turn on 2FA, review AWSFreelancer or one-off consultant
You want someone involved day to day, weighing in on decisionsIndependent consultant on retainer

Conclusion

For most companies with 5 to 100 employees and an online platform in production, the combination that makes the most sense is:

A specialized firm for an annual one-off pentest + a light monthly recurring service for continuous attack surface monitoring (public leaks, new endpoints, CVEs in dependencies). In the Brazilian market, the total investment usually runs between R$ 18,000 and R$ 60,000 a year. For a company with R$ 1 million or more in annual revenue, that's a small share of revenue — protecting a reputation worth tens of millions.

If you want to figure out which scenario fits your company, just talk to No Vuln. The first scoping call comes with no strings attached, and we sign an NDA before any technical conversation.

Share

WhatsAppLinkedInX

Next step

Want to apply this to your system?

No Vuln runs in-depth penetration tests with the same methodology described in this article. Request a proposal: mutual NDA within 24h, scope defined on a technical call.