Skip to content

Open role

Cloud Penetration Tester (AWS, Azure, GCP), Contract

Assess and attack client cloud environments on AWS, Azure and GCP: a CIS benchmark review of the account, then exploitation from a realistic starting point such as a compromised developer credential or an over-permissive role.

Engagement
Contract, paid per engagement
Location
Remote, United States
Pay range
$175,000 to $265,000 per year
Posted
September 14, 2026

The engagement

Contract, remote within the United States, paid per engagement. Engagements run five to ten testing days plus a retest and are performed within each provider’s penetration testing policy.

What you will do

  • Review IAM policies, roles and trust relationships, storage exposure, compute and container configuration, network controls, secrets handling and logging against the CIS foundations benchmark for the provider.
  • Attempt privilege escalation and data access from an assumed-breach position and document the attack path and blast radius.
  • Record whether the client’s detection (CloudTrail, Activity Log, Cloud Audit Logs) would have caught each step.
  • Write the report with CVSS-scored findings, remediation in priority order and the compliance mapping the client needs, then retest.
  • Leave nothing persistent behind and log every action with timestamps for the client’s defenders.

What we need

  • Four or more years of cloud security work with hands-on offensive testing on at least two of AWS, Azure and GCP.
  • Working fluency with infrastructure as code, containers and Kubernetes, and the identity constructs of each provider.
  • Based in the United States with authorization to work here; engagements run on US time and clients are US companies.
  • Reports written for two readers at once: an engineer who has to fix the finding and an auditor who has to accept the evidence. A redacted sample report is part of the application.
  • Comfortable working to a fixed, written scope and saying early when something in it is wrong.
  • Two professional references from people who have seen your work on a live engagement.

Nice to have

  • Internal network and Active Directory testing, for hybrid environments.
  • Experience producing evidence for SOC 2, PCI DSS or HIPAA audits of cloud-hosted systems.
  • An offensive security certification is welcome; it does not replace a verifiable engagement record.