openqareer

Cloud Penetration Tester (AWS, Azure, GCP), Contract

Invadel · Удалённо · United States · 175 000 — 265 000 USD

# Cloud Penetration Tester (AWS, Azure, GCP), Contract **Invadel** · United States · `Remote` · `Contractor` 💼 **Уровень роли:** `Mid-level` 💰 **Компенсация:** `$175,000 – $265,000` 🕒 **Статус:** *Опубликовано: сегодня* · *Источник: Himalayas (JSON API)* --- ### Top Skills & Match 🎯 **Ключевой стек роли:** `[Cloud-Penetration-Tester]` `[Freelance-Penetration-Tester]` `[Penetration-Testing-Jobs]` `[Staff-Penetration-Tester]` `[Senior-Penetration-Tester]` `[Penetration-Tester]` --- ### About the Role Invadel is a New York City penetration testing firm. Every engagement is fixed-scope and fixed-price, agreed in writing, with public prices at invadel.com/pricing and a free retest. This is a contract role, remote within the United States, paid per engagement; engagements run five to ten testing days plus a retest and are performed within each provider’s penetration testing policy. What you will do: review IAM policies, roles and trust relationships, storage exposure, compute and container configuration, network controls, secrets handling and logging against the CIS foundations benchmark; attempt privilege escalation and data access from an assumed-breach position and document the attack path and blast radius; record whether the client’s detection would have caught each step; write the report with CVSS-scored findings, prioritized remediation and compliance mapping, then retest; leave nothing persistent behind. What we need: four or more years of cloud security work with hands-on offensive testing on at least two of AWS, Azure and GCP; working fluency with infrastructure as code, containers and Kubernetes; based in the United States with authorization to work here; reports written for engineers and auditors, with a redacted sample report as part of the application; two professional references. Nice to have: internal network and Active Directory testing; experience producing evidence for SOC 2, PCI DSS or HIPAA audits. An offensive security certification is welcome; it does not replace a verifiable engagement record. Full description, pay range and application: Originally posted on Himalayas

Наблюдалась 2026-09-15, впервые 2026-09-15, источник — Himalayas (JSON API).

Открыть у работодателя