Cloud Penetration Tester (AWS, Azure, GCP), Contract

Invadelhimalayaspublished 09/15/2026
This job is no longer listed
The source has removed this listing — applying via the original link is no longer possible.
Must-have:AWSAzureGoogle CloudKubernetesCloudSecurity
Nice-to-have:Remote

Invadel is a New York City penetration testing firm. Every engagement is fixed-scope and fixed-price, agreed in writing, with public prices at invadel.com/pricing and a free retest. This is a contract role, remote within the United States, paid per engagement; engagements run five to ten testing days plus a retest and are performed within each provider’s penetration testing policy.

What you will do:

  • review IAM policies, roles and trust relationships, storage exposure, compute and container configuration, network controls, secrets handling and logging against the CIS foundations benchmark; attempt privilege escalation and data access from an assumed-breach position and document the attack path and blast radius; record whether the client’s detection would have caught each step; write the report with CVSS-scored findings, prioritized remediation and compliance mapping, then retest; leave nothing persistent behind.

What we need:

  • four or more years of cloud security work with hands-on offensive testing on at least two of AWS, Azure and GCP;
  • working fluency with infrastructure as code, containers and Kubernetes;
  • based in the United States with authorization to work here;
  • reports written for engineers and auditors, with a redacted sample report as part of the application;
  • two professional references.

Nice to have:

  • internal network and Active Directory testing;
  • experience producing evidence for SOC 2, PCI DSS or HIPAA audits.
  • An offensive security certification is welcome; it does not replace a verifiable engagement record.

Full description, pay range and application:

Originally posted on Himalayas