I used to be where you were - I wanted to be an independent consultant, I wanted to find clients and I wanted to grow my business. Now I operate as a high-end consultant for application security. I can tell you what I did, and hopefully it will help you as well.
I offer web and mobile penetration tests, source code analysis and best practices workshops for companies between the seed and Series A stage (I have also worked with recognizable enterprises you'd know of). Through September I'm fully booked at 100% capacity, mostly with Y Combinator companies. I charge a static rate of $10,000/week, though I discount this for certain circumstances (good referral, long term contract, etc).
So, that's me. How did I get to this place? How can you get to this place?
1. I network a lot. I don't go to meetups. I don't have a blog. I don't hand out business cards. I network with people in 1x1 ways that show my value. My best referrals have come from people who I helped pro bono for something seemingly insignificant who turned out to be very well connected. I don't network in a way characteristic of a salesman, I do so in a way that starts by genuinely listening to someone talk about a problem. If I can help, I frame myself as a person who can solve a business problem that happens to be related to security, not as a fly-by-night freelancer. I talk to people because I genuinely like talking to people - I will often just welcome people to email me to chat - not for a consultation, literally just to chat. It opens doors. The best way to start this is to literally reach out to people who are in influential groups - not influential people themselves - and help them in an honest manner. They will naturally refer you to people who have both problems and excess money, who are your qualified leads.
2. I have a strong value proposition. My work involves a lot of technical proficiency - I'm not just using a vulnerability scanner - and I deliver very solid results every time. I don't give canned reports and I can communicate effectively with both developers and managers. I am consistently well referred to others and over time this has led me to a place where I have excellent clients more often than not and I have to say no more than I can say yes.
3. I have read probably every comment by patio11 (Patrick McKenzie) and tptacek (Thomas Ptacek) on consulting. I have probably read all of them several times, in fact. They are both very good people (talk to them sometime) and they both have excellent advice. Those comments give you literally everything you need to know to run a consultancy on your own. They will give you all the non-technical savvy you need to run a technical business.
4. I am confident in my rates and don't back down from them. I will change on scope, but not my rates. I charge weekly and if I am not a good financial fit for someone I make a good faith effort to redirect them somewhere else.
5. I'm honest. I used to work at a security firm, one of the largest in fact. A lot of firms do things I don't agree with, like writing "has autocomplete enabled" on a security report. This doesn't mean that they are bad people, but it is tonedeaf to what your client really wants most of the time. I don't exaggerate findings and I do present my work in a very honest light. I also strive to be honest in business dealings as well. There is a lot of snake oil in this industry and I don't rip off my clients - I will not work with someone if something feels "off" or I don't feel I'm legitimately contributing value.
You can do it. It took me a long time, but you can do it. I would advise you start out by subcontracting another firm that needs work. Dirty secret - many security firms will subcontract to you, and you can build a client base that way.
Let me know if I can help you in any way, my email is in my profile. I agree with what others have said here that you should focus on either security or usability. Do one thing, and one thing well (or at least one domain well). I also don't think you should be putting so much effort into marketing. A blog is helpful for long term leads, but it won't help you in < 6 months usually. Ads are impersonal and probably won't get you what you're looking for either. Find influential groups and mingle with them in an honest way.
Also, if you're going to work in security, I advise you to work at a security firm before striking out on your own. If nothing else, it will show you the entire process the "real players" use.
I think you need to figure yourself out a bit more, because you're not achieving what you want to yet. Sit down, and write answers to the following:
1. Who are you? What is your value proposition? Why should I hire you?
2. Look at your answer above. If you're dispassionate about it, does it really solve a business need? Ask a few uninvested friends in the field.
3. Do you have a network? If not, why do you have a blog or Twitter? That's not how you build a network. That's how you maintain a network and grow a network. It isn't a seed, it's water.
4. Who can you immediately identify who needs your services? How can you put yourself in front of them in a way that is more organic than forced?
Good luck.