This one is closed
Live roles like this one
-
C
4h ago
Werkstudent (m/w/d) Schwachstellenmanagement: Von der SBOM zur Entscheidung
Langlauf Security Automation GmbH Lippstadt
-
C
20h ago
Senior Security Engineer, Identity and Access Management
HackerOne Netherlands, UK, USA
- D 17h ago
- C 1d ago
See every "Cloud Penetration Tester" role →
Get new “Cloud Penetration Tester” roles by email
One email a day with what is new in "Cloud Penetration Tester". Nothing new, no email.
We confirm the address first, and every mail carries an unsubscribe link. Alerts are ours, not a third party's.
Why this grade This listing scored 76/100, which is a B. It lost the most ground on remote clarity. See the breakdown
- Pay transparency 25 / 25 A published salary range, worth more than any other single factor because it is what a candidate cannot find out without applying.
- Description depth 20 / 20 How much the posting actually says about the work, measured in characters of real text.
- Freshness 12 / 15 How recently it was posted. Older postings are likelier to be filled or abandoned.
- Remote clarity 8 / 15 Whether "remote" means anywhere, or is quietly restricted to one country.
- Role specificity 6 / 10 Whether the listing is tagged well enough to tell what the role actually is.
- Corroboration 5 / 10 Whether more than one source carries this listing.
Every figure above is arithmetic over the posting itself — its salary field, its text, its age, its tags and how many sources carry it. How the grades work →
Developer Mid level Senior Contractor
Invadel is a New York City penetration testing firm. Every engagement is fixed-scope and fixed-price, agreed in writing, with public prices at invadel.com/pricing and a free retest. This is a contract role, remote within the United States, paid per engagement; engagements run five to ten testing days plus a retest and are performed within each provider’s penetration testing policy.
What you will do: review IAM policies, roles and trust relationships, storage exposure, compute and container configuration, network controls, secrets handling and logging against the CIS foundations benchmark; attempt privilege escalation and data access from an assumed-breach position and document the attack path and blast radius; record whether the client’s detection would have caught each step; write the report with CVSS-scored findings, prioritized remediation and compliance mapping, then retest; leave nothing persistent behind.
What we need: four or more years of cloud security work with hands-on offensive testing on at least two of AWS, Azure and GCP; working fluency with infrastructure as code, containers and Kubernetes; based in the United States with authorization to work here; reports written for engineers and auditors, with a redacted sample report as part of the application; two professional references.
Nice to have: internal network and Active Directory testing; experience producing evidence for SOC 2, PCI DSS or HIPAA audits. An offensive security certification is welcome; it does not replace a verifiable engagement record.
Full description, pay range and application:
Originally posted on Himalayas
Apply for this role Opens himalayas.app — the link as listed; we have not yet verified it is the employer's own page
Quick question · anonymous · one tap
Would you apply to this job?
Answer to see what other job seekers said.
Your turn · no account needed
Help the next applicant
You may know something about this listing that we cannot see from here. One tap. No account needed. Signed-in reports earn points once the evidence agrees with you.
I know what it pays
Sign in with Google to earn points for reports — 100 confirmed points buy a week of Early Access.
Where this listing came from
- 15 Sep 2026 Himalayas first sighting
Seen on 1 board over 0 days.