1

Cloud Penetration Tester Jobs (NOW HIRING)

Penetration Tester

Herndon, VA · On-site

$86.80 - $198/hr

... GIAC Cloud Penetration Tester Certification Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified ...

Experience performing IoT, mobile, and cloud penetration testing * Experience supporting High Value Asset (HVA) assessments * Experience applying MITRE ATT&CK, OSSTMM, OWASP, NIST, PTES, and ISSAF ...

NJ · On-site

$125 - $170/hr

Proficiency in web application, network/infrastructure, API, mobile, thick client, AI, and cloud ... penetration testing. * In‑depth understanding of security mechanisms for applications, operating ...

Experience performing IoT, mobile, and cloud penetration testing * Experience supporting High Value Asset (HVA) assessments * Experience applying MITRE ATT&CK, OSSTMM, OWASP, NIST, PTES, and ISSAF ...

Penetration Tester

Washington, DC · On-site

$120 - $180/hr

Experience with cloud penetration testing (AWS, Azure). * Familiarity with aircraft systems, avionics, or aviation communication protocols. * Prior red team experience in a government or military ...

Experience with cloud penetration testing (AWS, Azure). * Familiarity with aircraft systems, avionics, or aviation communication protocols. * Prior red team experience in a government or military ...

Penetration Tester

Leesburg, VA · On-site

$125 - $155/hr

Fortreum is a trusted leader in cloud and cybersecurity services, ranked among the Top 5 FedRAMP ... We're seeking a seasoned Penetration Tester to join our team. Your expertise in cloud penetration ...

next page

Showing results 1-20

Cloud Penetration Tester information

See salary details

$22.5K

$119.9K

$168.5K

How much do cloud penetration tester jobs pay per year?

As of Aug 30, 2026, the average yearly pay for cloud penetration tester in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What is a cloud penetration tester?

A Cloud Penetration Tester is a cybersecurity professional who assesses cloud environments for vulnerabilities by simulating real-world attacks. They identify security weaknesses in cloud infrastructure, applications, and services to help organizations strengthen their defenses. This role requires expertise in cloud platforms like AWS, Azure, and GCP, as well as penetration testing tools and methodologies. Cloud Penetration Testers also provide detailed reports with remediation recommendations to mitigate risks effectively.

What are the key skills and qualifications needed to thrive as a cloud penetration tester?

To thrive as a Cloud Penetration Tester, you need in-depth knowledge of cloud platforms (such as AWS, Azure, and Google Cloud), vulnerability assessment, security best practices, and strong programming or scripting skills, often backed by a degree in computer science or information security. Familiarity with tools like Kali Linux, Burp Suite, Metasploit, and certifications such as OSCP or AWS Certified Security are highly valued. Strong analytical thinking, attention to detail, clear communication, and a collaborative attitude help set you apart in this role. These skills ensure you can identify and address cloud security vulnerabilities effectively while working across technical and business teams.

What are some common challenges faced by cloud penetration testers on the job?

Cloud Penetration Testers often encounter challenges like staying current with constantly evolving cloud security threats, navigating complex or hybrid cloud environments, and understanding the unique configurations and security controls of various cloud service providers. They may also face the task of coordinating with multiple internal teams and ensuring that testing activities do not disrupt ongoing cloud services. This role often requires balancing technical security testing with clear, accessible communication of findings to both technical and non-technical stakeholders. Overcoming these challenges helps testers provide valuable insights that strengthen an organization's cloud security posture.

More about Cloud Penetration Tester jobs

What cities are hiring for Cloud Penetration Tester jobs?

Cities with the most Cloud Penetration Tester job openings:

What are the most commonly searched types of Cloud Penetration Tester jobs?

The most popular types of Cloud Penetration Tester jobs are:

What states have the most Cloud Penetration Tester jobs?

States with the most job openings for Cloud Penetration Tester jobs include:

Infographic showing various Cloud Penetration Tester job openings in the United States as of August 2026, with employment types broken down into 82% Full Time, and 18% Contract. Highlights an 64% In-person, and 36% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

Red Team Operator/ Cloud Penetration Tester

Cyber Defense Technologies

Chantilly, VA • On-site

Full-time

Re-posted 15 days ago


Job description

Job Summary:
Cyber Defense Technologies is seeking a Red Team Operator/ Cloud Penetration Tester to support a government customer onsite in Chantilly, VA. The role involves performing cloud penetration testing and red teaming activities to enhance cyber defense and secure sensitive data for clients.
Responsibilities:
• Perform threat-driven cloud penetration testing, red teaming, remediation activities, and effective enhancement of cyber defense
• Support joint-team operations with internal and external partners to evaluate new cloud services
• Assist full project lifecycle scoping, planning, execution, monitoring, and closing activities to include: scoping engagements, preparing documentation, building/enhancing operational infrastructure, testing and validating capabilities, leading assessments from kick-off through remediation, and completing after-action reports/lessons learned
• Adhering to established policies and rules of engagement (ROE), safely utilize offensive tools, tactics, and procedures in mission critical environments
• Develop scripts, tools, and/or methodologies to enhance assessment processes
• Communicate complex, technical challenges and findings to client stakeholders, management, and executive leaders
• Develop comprehensive, actionable, and accurate reports & accompanying presentations for both executive leaders and technical audiences
Qualifications:
Required:
• Two plus (2+) years’ experience working in cloud environments (e.g., penetration testing, red team, assessment, engineering, & administration) with a strong understanding of cloud architecture and design
• Five plus (5+) years’ experience and possesses strong knowledge of Offensive Cyber Security and Penetration Testing methodologies
• Proven experience using and testing automation tools (Terraform, Docker, Ansible, shell scripting, etc.)
• Thorough understanding of network protocols, data transmission, and covert channels
• Strong knowledge of Unix/Linux/Mac/Windows operating systems, inclusive of command-line interface (CLI) usage through Bash and PowerShell
• Experience working as a member of a multi-disciplinary team, promoting a collaborative culture to achieve success
• Ability to interface with customer stakeholders to clearly and concisely communicate the purpose and benefits of an assessment
• Ability to effectively document and communicate technical details to executive leaders and principal stakeholders regarding kill chains, stages, dependencies, and impacts
• Excellent verbal and written communication skills to effectively convey complex technical information to non-technical customers and stakeholders
• Major cloud platforms, including AWS, Azure, Google, IBM, and/or Oracle Cloud
• Container orchestration tools, particularly Kubernetes, for managing and deploying containerized applications in cloud environments
• Strong knowledge of cloud architecture, including IAM, VPC, Storage Containers, and Databases
• Cloud Services, including functions, logging, APIs, and native services
• Bachelor’s Degree (Engineering, Computer Science, Cyber Security, or related field) +8 years; or relevant education/experience (High School +12 years; Associates +10 years; Masters/PhD +4 years)
• DoD 8140/8570 Professional Certification (required certification must be completed within six (6) months of start in the position)
Preferred:
• Cloud relevant certifications (Preferred)
• Incident Response, Incident Remediation, and Security Architecture experience
• Knowledge of cloud-based CI/CD products, such as AWS Code Pipeline, Azure DevOps, and GCP Cloud Build
• Knowledge of tools such as Terraform integrated with cloud-based CI/CD products
• Strong understanding of Offense Security principles and methodologies, with a focus on proactively identifying, testing, and addressing vulnerabilities in cloud environments to strengthen overall security posture
Company:
CDT is a Service Disabled Veteran Owned Small Business (SDVOSB) and cyber security firm that provides consulting and security services. Founded in 2010, the company is headquartered in Reston, USA, with a team of 11-50 employees. The company is currently Early Stage.