Developer, Consultant or Firm: Who Should Secure Your SaaS?
In-house security engineer, freelance consultant or specialized firm to protect your SaaS, fintech or app? A comparison of pros, cons and costs.
Security researcher and founder of No Vuln

You've decided your platform needs better security. Good news. Now comes the hard part: who do you hire? The market offers at least four different routes — a dedicated in-house security engineer, a freelancer, an independent consultant or a specialized firm — and each one makes sense in a different situation.
This is an honest guide to help you, a business owner who isn't in IT, decide which route fits where your company is right now. No jargon, no vague “it depends.”
The 4 possible paths
Costs below are Brazilian market ranges, in Brazilian reais (R$).
| Who | Approximate cost | Best for |
|---|---|---|
| In-house engineer focused on security | R$ 15k–30k / month | Companies with 30+ devs, a critical platform and a fast pace of change |
| Freelancer / one-off consultant | R$ 100–500 / hour | A specific task, a short deadline, no ongoing need |
| Independent consultant on retainer | R$ 8k–20k / month | Mid-size companies with no in-house security engineer and a medium-term project |
| Firm specializing in pentesting and security audits | R$ 3k–60k per project Recurring: varies / month, depending on scope | One-off audits, compliance, security validation |
Path 1: Hire an in-house security engineer (full-time)
When it makes sense
You have more than 30 developers, run a critical platform (financial, healthcare, sensitive data at volume) and your business depends on constant code changes. Think Brazilian companies like Stone, Nubank, iFood or CloudWalk.
What this person does day to day
- Reviews code before it ships
- Teaches developers secure coding practices
- Sets up continuous detection tooling
- Investigates small incidents before they become big ones
- Makes architecture decisions alongside the technical leads
Why smaller companies should be careful with this route
Good security people are expensive: in Brazil, 2026 salaries run between R$ 15,000 and R$ 30,000 a month (full-time employment under the CLT, Brazil's standard labor regime, including payroll charges). For a company with 5–15 developers, that one hire costs as much as 2 or 3 additional developers. And, to be blunt: one in-house person can't cover everything. Even at Big Tech companies, security is a team effort — not a solo hero act.
Warning sign
If you're thinking about hiring “a security dev” just to pass an audit, think again. You'd be paying an ongoing salary to solve a one-time, project-sized problem. A specialized firm does that for a fraction of the cost.
Path 2: Hire a freelancer or one-off consultant
When it makes sense
A specific task, a short deadline, a well-defined scope. For example:
- “Set up our Cloudflare WAF”
- “Add 2FA to our admin area”
- “Review our AWS configuration before launch”
- “Audit this specific piece of code”
Typical costs
Security freelancers in Brazil charge between R$ 100 and R$ 500 an hour, depending on seniority. Consultants who specialize in a niche (pentesting, AppSec, cloud security) can go higher.
Risks of this route
- Inconsistent coverage. The freelancer does the task you asked for. If you asked for the wrong thing, the problem stays — a freelancer isn't responsible for finding problems you didn't list.
- No ongoing accountability. Something breaks 60 days later? Not their responsibility. They go dark? You're on your own.
- Quality is hard to judge. Good freelancers have a portfolio (published CVEs, bug bounty findings, conference talks). Someone with no public portfolio probably isn't at the same level as someone who has one.
How to hire well on this route
Always ask for:
- A public portfolio (bug bounty findings, CVEs, talks)
- References from 2–3 previous clients
- A proposal with a crystal-clear scope (what's in, what's out)
- An NDA before the technical call
- A written final deliverable
Path 3: An independent consultant on retainer
When it makes sense
Your company has no in-house security engineer, but you need someone continuously involved — weighing in on architecture decisions, reviewing code periodically, being your “security person” without being on payroll.
How it works
It's usually a contract for 10 to 30 hours a month with a senior consultant. In Brazil, that costs between R$ 8,000 and R$ 20,000 a month, depending on seniority and the number of hours.
Advantages vs. a full-time hire
- Costs half as much or less
- No payroll taxes or employment obligations
- Access to someone far more experienced than you could hire full-time for that money
- Flexibility — scale up or down as needed
Disadvantages vs. a full-time hire
- The person isn't “inside” the company's day-to-day
- Their time may be split across other clients
- It doesn't replace a SOC or an incident response team
When NOT to hire a consultant on retainer
If what you need is a one-off audit with a formal report (e.g., to pass SOC 2, to meet an enterprise customer's requirement, to comply with a data protection law such as Brazil's LGPD), a retainer consultant isn't the right tool. For that, go with a specialized firm (path 4).
Path 4: A firm specializing in offensive security
When it makes sense
- You need a formal security audit or pentest
- An enterprise customer asked for evidence of security testing
- You're preparing for SOC 2, ISO 27001, PCI DSS or the LGPD
- You want to validate security before a critical launch
- You've had an incident and want to know what else is vulnerable
- You need continuous attack surface monitoring
What's different from the other options
A specialized firm has a methodology: a documented process, its own tooling and a team with complementary specialties. You hire a project and get:
- A formal report, formatted for audits
- A reproducible proof of concept (PoC) for every finding
- Calibrated severity (not just a technical score)
- A retest after you fix the issues
- A live walkthrough session with your team
Typical costs (Brazilian market)
- One-off pentest of a small application: R$ 3,000 to R$ 6,000
- Pentest of a SaaS in production: R$ 6,000 to R$ 12,000
- Full-stack enterprise pentest (regulated sector): R$ 18,000 to R$ 60,000+
- Monthly recurring (monitoring + focused pentests): varies — monthly or quarterly hour bank, depending on scope
How to choose a specialized firm (red flags)
These are signs you're about to pay for bad work:
- “100% automated pentest” — no such thing. Automation covers 30–40% of the work; the rest is manual.
- A report full of scanner screenshots (Nessus, Acunetix) with no manual PoC — that's a scanner with a fancy name.
- Retests billed separately — they charge you again to confirm you fixed the issue? Outdated model. Walk away.
- No NDA before the first technical call — a sign of disorganization or bad faith.
- No answer to “who, specifically, will work on my project?” — good professionals have names and portfolios. If a firm hides that, be suspicious.
- An “ethical hackers” tagline — dated terminology (circa 2010). The modern term is “security researcher.”
The decision, simplified
| Your situation | Recommended path |
|---|---|
| Launching an MVP, no customers yet | Specialized firm — one-off pentest before launch |
| SaaS in production, no in-house security engineer | Specialized firm (annual pentest) + a light consultant retainer |
| An enterprise customer asked for pentest evidence | Specialized firm — one-off pentest with an audit-ready report |
| You've had an incident and want to understand the damage | Specialized firm — emergency pentest + investigation |
| Company with 30+ devs and nobody on security | One senior full-time hire + a specialized firm for quarterly audits |
| One-off task: set up a WAF, turn on 2FA, review AWS | Freelancer or one-off consultant |
| You want someone involved day to day, weighing in on decisions | Independent consultant on retainer |
Conclusion
For most companies with 5 to 100 employees and an online platform in production, the combination that makes the most sense is:
A specialized firm for an annual one-off pentest + a light monthly recurring service for continuous attack surface monitoring (public leaks, new endpoints, CVEs in dependencies). In the Brazilian market, the total investment usually runs between R$ 18,000 and R$ 60,000 a year. For a company with R$ 1 million or more in annual revenue, that's a small share of revenue — protecting a reputation worth tens of millions.
If you want to figure out which scenario fits your company, just talk to No Vuln. The first scoping call comes with no strings attached, and we sign an NDA before any technical conversation.
Next step
Want to apply this to your system?
No Vuln runs in-depth penetration tests with the same methodology described in this article. Request a proposal: mutual NDA within 24h, scope defined on a technical call.