Open role
Cloud Penetration Tester (AWS, Azure, GCP), Contract
Assess and attack client cloud environments on AWS, Azure and GCP: a CIS benchmark review of the account, then exploitation from a realistic starting point such as a compromised developer credential or an over-permissive role.
- Engagement
- Contract, paid per engagement
- Location
- Remote, United States
- Pay range
- $175,000 to $265,000 per year
- Posted
- September 14, 2026
The engagement
Contract, remote within the United States, paid per engagement. Engagements run five to ten testing days plus a retest and are performed within each provider’s penetration testing policy.
What you will do
- Review IAM policies, roles and trust relationships, storage exposure, compute and container configuration, network controls, secrets handling and logging against the CIS foundations benchmark for the provider.
- Attempt privilege escalation and data access from an assumed-breach position and document the attack path and blast radius.
- Record whether the client’s detection (CloudTrail, Activity Log, Cloud Audit Logs) would have caught each step.
- Write the report with CVSS-scored findings, remediation in priority order and the compliance mapping the client needs, then retest.
- Leave nothing persistent behind and log every action with timestamps for the client’s defenders.
What we need
- Four or more years of cloud security work with hands-on offensive testing on at least two of AWS, Azure and GCP.
- Working fluency with infrastructure as code, containers and Kubernetes, and the identity constructs of each provider.
- Based in the United States with authorization to work here; engagements run on US time and clients are US companies.
- Reports written for two readers at once: an engineer who has to fix the finding and an auditor who has to accept the evidence. A redacted sample report is part of the application.
- Comfortable working to a fixed, written scope and saying early when something in it is wrong.
- Two professional references from people who have seen your work on a live engagement.
Nice to have
- Internal network and Active Directory testing, for hybrid environments.
- Experience producing evidence for SOC 2, PCI DSS or HIPAA audits of cloud-hosted systems.
- An offensive security certification is welcome; it does not replace a verifiable engagement record.