Description review
Cloud Penetration Tester (AWS, Azure, GCP), Contract
Invadel · United States · back to the listing
HR standards
75/100
solid
Title ↔ description
86/100
strong
Reads as
Security Engineer
98% confident
What this role officially is
ICT security administrator — ESCO, the EU occupation classification
ICT security administrators plan and carry out security measures to protect information and data from unauthorised access, deliberate attack, theft and corruption.
Also known as: network security administrator, system security administrator, ICT security administrators, IT security administrator
How others title the same work
Large employers
- Security Risk Management Specialist Canonical Ltd.
- Security Software Engineer Canonical Ltd.
- Senior Security Operations Engineer Canonical Ltd.
- Staff Security Operations Engineer Canonical Ltd.
- Ubuntu Security Engineer Canonical Ltd.
Startups
- Security Engineer (Bangalore, India) AiPrise
- Security & Trust Engineer Alex
- Elucid | Senior Security Engineer | Boston, MA | ONSITE (hybrid) | $130k–$170k Elucid
- Factory | Security Engineer | ONSITE, San Francisco, CA | Full-Time Factory
- Factory | Security Engineer | Onsite in San Francisco | Full-time Factory
The listing, marked up
Nothing in the wording of this listing tripped a check. The scores above still judge how complete and coherent it is.
Invadel is a New York City penetration testing firm. Every engagement is fixed-scope and fixed-price, agreed in writing, with public prices at invadel.com/pricing and a free retest. This is a contract role, remote within the United States, paid per engagement; engagements run five to ten testing days plus a retest and are performed within each provider’s penetration testing policy.
What you will do: review IAM policies, roles and trust relationships, storage exposure, compute and container configuration, network controls, secrets handling and logging against the CIS foundations benchmark; attempt privilege escalation and data access from an assumed-breach position and document the attack path and blast radius; record whether the client’s detection would have caught each step; write the report with CVSS-scored findings, prioritized remediation and compliance mapping, then retest; leave nothing persistent behind.
What we need: four or more years of cloud security work with hands-on offensive testing on at least two of AWS, Azure and GCP; working fluency with infrastructure as code, containers and Kubernetes; based in the United States with authorization to work here; reports written for engineers and auditors, with a redacted sample report as part of the application; two professional references.
Nice to have: internal network and Active Directory testing; experience producing evidence for SOC 2, PCI DSS or HIPAA audits. An offensive security certification is welcome; it does not replace a verifiable engagement record.
Full description, pay range and application:
Originally posted on Himalayas
What you will do: review IAM policies, roles and trust relationships, storage exposure, compute and container configuration, network controls, secrets handling and logging against the CIS foundations benchmark; attempt privilege escalation and data access from an assumed-breach position and document the attack path and blast radius; record whether the client’s detection would have caught each step; write the report with CVSS-scored findings, prioritized remediation and compliance mapping, then retest; leave nothing persistent behind.
What we need: four or more years of cloud security work with hands-on offensive testing on at least two of AWS, Azure and GCP; working fluency with infrastructure as code, containers and Kubernetes; based in the United States with authorization to work here; reports written for engineers and auditors, with a redacted sample report as part of the application; two professional references.
Nice to have: internal network and Active Directory testing; experience producing evidence for SOC 2, PCI DSS or HIPAA audits. An offensive security certification is welcome; it does not replace a verifiable engagement record.
Full description, pay range and application:
Originally posted on Himalayas