1

Cloud Penetration Tester Jobs (NOW HIRING)

WV · On-site

Automated Testing, AWS Cloud Computing, Infrastructure Penetration Testing, Security Controls, Security Testing Certifications: None Experience: 8 + years of related experience US Citizenship ...

Experience performing IoT, mobile, and cloud penetration testing * Experience supporting High Value Asset (HVA) assessments * Experience applying MITRE ATT&CK, OSSTMM, OWASP, NIST, PTES, and ISSAF ...

Experience performing IoT, mobile, and cloud penetration testing * Experience supporting High Value Asset (HVA) assessments * Experience applying MITRE ATT&CK, OSSTMM, OWASP, NIST, PTES, and ISSAF ...

Experience with cloud penetration testing (AWS, Azure). * Familiarity with aircraft systems, avionics, or aviation communication protocols. * Prior red team experience in a government or military ...

Penetration Tester

Herndon, VA · On-site

$86K - $198K/yr

... GIAC Cloud Penetration Tester Certification Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified ...

Penetration Tester

Herndon, VA · On-site +1

$86K - $198K/yr

... GIAC Cloud Penetration Tester Certification Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified ...

Penetration Tester

Herndon, VA · On-site

$86K - $198K/yr

... GIAC Cloud Penetration Tester Certification Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified ...

next page

Showing results 1-20

Cloud Penetration Tester information

See salary details

$22.5K

$119.9K

$168.5K

How much do cloud penetration tester jobs pay per year?

As of Aug 10, 2026, the average yearly pay for cloud penetration tester in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

Is cloud penetration testing in demand?

Cloud penetration testers are in high demand due to the increasing adoption of cloud services and the need to identify security vulnerabilities in cloud environments. Employers seek professionals with skills in cloud platforms, security tools, and certifications like OSCP or CISSP to ensure cloud infrastructure security.

What is a cloud penetration tester?

A Cloud Penetration Tester is a cybersecurity professional who assesses cloud environments for vulnerabilities by simulating real-world attacks. They identify security weaknesses in cloud infrastructure, applications, and services to help organizations strengthen their defenses. This role requires expertise in cloud platforms like AWS, Azure, and GCP, as well as penetration testing tools and methodologies. Cloud Penetration Testers also provide detailed reports with remediation recommendations to mitigate risks effectively.

How much do cloud penetration testers make?

Cloud penetration testers typically earn between $80,000 and $150,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in cloud security tools may earn higher salaries, often exceeding $150,000.

What are the key skills and qualifications needed to thrive as a cloud penetration tester?

To thrive as a Cloud Penetration Tester, you need in-depth knowledge of cloud platforms (such as AWS, Azure, and Google Cloud), vulnerability assessment, security best practices, and strong programming or scripting skills, often backed by a degree in computer science or information security. Familiarity with tools like Kali Linux, Burp Suite, Metasploit, and certifications such as OSCP or AWS Certified Security are highly valued. Strong analytical thinking, attention to detail, clear communication, and a collaborative attitude help set you apart in this role. These skills ensure you can identify and address cloud security vulnerabilities effectively while working across technical and business teams.

How do you become a cloud penetration tester?

To become a cloud penetration tester, you should gain a strong understanding of cloud platforms like AWS, Azure, or Google Cloud, and develop skills in cybersecurity, networking, and scripting. Earning relevant certifications such as Certified Cloud Security Professional (CCSP) or Offensive Security Certified Professional (OSCP) can also improve your qualifications. Practical experience with penetration testing tools and methodologies is essential for this role.

What are some common challenges faced by cloud penetration testers on the job?

Cloud Penetration Testers often encounter challenges like staying current with constantly evolving cloud security threats, navigating complex or hybrid cloud environments, and understanding the unique configurations and security controls of various cloud service providers. They may also face the task of coordinating with multiple internal teams and ensuring that testing activities do not disrupt ongoing cloud services. This role often requires balancing technical security testing with clear, accessible communication of findings to both technical and non-technical stakeholders. Overcoming these challenges helps testers provide valuable insights that strengthen an organization's cloud security posture.

More about Cloud Penetration Tester jobs
What cities are hiring for Cloud Penetration Tester jobs? Cities with the most Cloud Penetration Tester job openings:
What are the most commonly searched types of Cloud Penetration Tester jobs? The most popular types of Cloud Penetration Tester jobs are:
What states have the most Cloud Penetration Tester jobs? States with the most job openings for Cloud Penetration Tester jobs include:
Infographic showing various Cloud Penetration Tester job openings in the United States as of August 2026, with employment types broken down into 57% Full Time, and 43% Contract. Highlights an 71% In-person, and 29% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

Penetration Tester

GDIT

WV • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted yesterday


General Dynamics Information Technology rating

7.8

Company rating: 7.8 out of 10

Based on 63 frontline employees who took The Breakroom Quiz

88th of 223 rated it services


Job description

Type of Requisition:

Regular

Clearance Level Must Currently Possess:

None

Clearance Level Must Be Able to Obtain:

None

Public Trust/Other Required:

Other

Job Family:

Cyber and IT Risk Management

Job Qualifications:

Skills:

Automated Testing, AWS Cloud Computing, Infrastructure Penetration Testing, Security Controls, Security Testing

Certifications:

None

Experience:

8 + years of related experience

US Citizenship Required:

No

Job Description:

The Penetration Tester supports the Case Management Modernization (CMM) Program for the Administrative Office of the U.S. Courts (AO) by conducting security, penetration, and vulnerability assessments required prior to Application ATO (Authority to Operate). This role ensures that CMM applications-built using React, NodeJS, AWS cloud services, and microservices-meet federal security standards and demonstrate resilience against realworld cyber threats.

Working within Agile DevSecOps teams, the Penetration Tester performs handson exploitation, validates security controls, identifies weaknesses, and collaborates with engineering teams to remediate findings. This role is critical to ensure that CMM systems comply with NIST 80053, RMF, and AO security requirements before production authorization.

Key Responsibilities:

  • Perform application, API, and cloud penetration tests on CMM systems prior to ATO submission.
  • Conduct web, mobile, API, and microservices security testing using industrystandard tools and manual exploitation techniques.
  • Execute AWS cloud penetration testing within approved boundaries (IAM, S3, Lambda, API Gateway, ECS/EKS, networking).
  • Perform static and dynamic analysis, including code review for security vulnerabilities.
  • Conduct credentialed and uncredentialed scans, privilege escalation testing, and lateral movement analysis.
  • Validate implementation of NIST 80053 controls, including AC, AU, IA, SC, SI, and CM families.
  • Support RMF Step 3 (Security Assessment) activities and provide evidence for ATO packages.
  • Identify vulnerabilities across application layers, cloud infrastructure, and CI/CD pipelines.
  • Work with developers, cloud engineers, and DevSecOps teams to validate fixes and retest vulnerabilities.
  • Provide detailed remediation guidance aligned with secure coding and cloud security best practices.
  • Track findings in Jira or equivalent tools and ensure closure prior to ATO milestones.
  • Prepare Security Assessment Reports (SAR), penetration test summaries, and risk findings for AO stakeholders.
  • Document exploitation steps, proofofconcepts, and risk severity aligned with federal scoring methodologies.
  • Contribute to System Security Plans (SSP), POA&Ms, and ATO evidence packages.
  • Support preATO readiness reviews, including control validation and security walkthroughs.
  • Participate in tabletop exercises, threat modeling sessions, and architecture reviews.
  • Validate system resilience through stress, failover, and adversarial resilience testing.
  • Ensure compliance with federal security standards, including NIST, FISMA, and AO-specific guidelines.
  • Work closely with development teams to integrate security testing into Agile sprints.
  • Provide security insights during sprint planning, backlog refinement, and release readiness reviews.
  • Support secure CI/CD pipeline enhancements, including automated security scanning.

REQUIREMENTS:

  • 8+ years of experience in penetration testing, application security, or ethical hacking security roles.
  • Experience documenting test plans, test procedures, and detailed security findings.
  • Experience supporting federal security assessments or enterprise-scale security testing.
  • Hands-on experience performing penetration tests on web applications, APIs, microservices, and cloud environments.
  • Strong proficiency with tools such as Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, Nikto, K6 Security, or custom scripts.
  • Experience testing applications built with NodeJS, ReactJS, REST APIs, and microservices.
  • Strong understanding of AWS security, including IAM, VPC, S3, Lambda, API Gateway, ECS/EKS, CloudTrail, and CloudWatch.
  • Experience with NIST 80053, RMF, FedRAMP, or federal ATO processes.
  • Ability to interpret logs, metrics, and security telemetry to identify attack paths.
  • Familiarity with SIEM and monitoring tools such as Datadog, ELK, CloudWatch, Grafana.
  • Experience with container security (Docker, Kubernetes, OpenShift).
  • Understanding of network security, distributed tracing, and adversarial testing techniques.
  • Strong analytical, communication, and documentation skills.

QUALIFICATIONS:

  • 8+ years of general experience in information systems with BS/BA Degree, or 6+ years with MA/MS Degree
  • 6+ years experience with in integration, regression, and system testing using automated testing tools in web-based applications
  • Experience in writing test cases, test plans, executing test scripts, reporting defects and preparing test results reports
  • Experience in the entire QA Life Cycle, to include designing, developing and execution on the entire QA process and documentation of test plans, test cases, test procedures and test scripts
  • Experience may be considered in lieu of degree

CERTIFICATIONS:

  • OSCP, OSWE, GWAPT, GPEN, or similar offensive security certifications.
  • AWS Security Specialty
  • SAFe, DevSecOps, or Agile certifications beneficial.

TOOLS & TECHNOLOGIES:

  • Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, Nikto
  • K6 Security, custom Python/JavaScript tools
  • AWS CloudWatch, CloudTrail, GuardDuty
  • Datadog, ELK Stack, Prometheus, Grafana
  • Jenkins, GitLab CI/CD, GitHub Actions
  • SAST/DAST tools (SonarQube, Checkmarx, Fortify)
  • Jira, Confluence, SharePoint, MS Teams
  • Power BI, Grafana dashboards

COMMUNICATION & ORGANIZATIONAL

  • Excellent presentation and communication (oral and written) skills.
  • Consultant mindset with the ability to work with high level customer stakeholders and build excellent customer relationship.
  • Experience identifying and applying industry tools, solutions, methods best practices, and emerging technologies.
  • Strong analytical skills and problem-solving skills with the ability to formulate and communicate recommendations for improvement.
  • Demonstrated ability to work effectively, independently, and as part of a team.
The likely salary range for this position is $123,250 - $166,750. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:

40

Travel Required:

None

Telecommuting Options:

Remote

Work Location:

Any Location / Remote

Additional Work Locations:

Total Rewards at GDIT:

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. GDIT typically provides new employees with 15 days of paid leave per calendar year to be used for vacations, personal business, and illness and an additional 10 paid holidays per year. Paid leave and paid holidays are prorated based on the employee's date of hire. The GDIT Paid Family Leave program provides a total of up to 160 hours of paid leave in a rolling 12 month period for eligible employees. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

Our Identity Verification Process:

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About Our Work:

We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.Join our Talent Community to stay up to date on our career opportunities and events at

gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

What General Dynamics Information Technology employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


General Dynamics Information Technology logo

About General Dynamics Information Technology

Sourced by ZipRecruiter

GDIT is a global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense, and intelligence community. Its 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. The company operates across 50+ countries worldwide, offering leading capabilities in digital modernization, AI/ML, cloud, cyber, and application development.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Falls Church, VA, US