Familiarity with cloud-native and cloud pentesting tools (e.g., ScoutSuite, Prowler, Pacu, ROADtools, ADRecon) is a plus * Scripting experience in one or more of: Ruby, Python, Perl, Bash * ESCP ...
Familiarity with cloud-native and cloud pentesting tools (e.g., ScoutSuite, Prowler, Pacu, ROADtools, ADRecon) is a plus * Scripting experience in one or more of: Ruby, Python, Perl, Bash * ESCP ...
Senior Product Marketing Manager, Internal & Cloud Pentesting
$123K - $162K/yr
What You'll Do We are looking for a Senior Product Marketing Manager to own the go-to-market engine for NodeZero's Internal and Cloud Pentesting portfolio. This role will shape how Horizon3 explains ...
Senior Product Marketing Manager, Internal & Cloud Pentesting
$123K - $162K/yr
What You'll Do We are looking for a Senior Product Marketing Manager to own the go-to-market engine for NodeZero's Internal and Cloud Pentesting portfolio. This role will shape how Horizon3 explains ...
CLOUD SECURITY EXPERT
Rancho Cordova, CA · On-site
$69.75 - $92.75/hr
CLOUD SECURITY EXPERT MUST HAVE THE FOLLOWING SKILLS/EXPERIENCE: Healthcare industry experience ... Experience in Vulnerability Scanning and Pentesting Experience with Data Leakage Prevention ...
CLOUD SECURITY EXPERT
Rancho Cordova, CA · On-site
$69.75 - $92.75/hr
CLOUD SECURITY EXPERT MUST HAVE THE FOLLOWING SKILLS/EXPERIENCE: Healthcare industry experience ... Experience in Vulnerability Scanning and Pentesting Experience with Data Leakage Prevention ...
Cloud Platform Engineer
Fort George G Meade, MD · On-site
$197K - $217K/yr
Responsibilities The Cloud Platform Engineer provisions and configures Government-approved cloud infrastructure to support autonomous pentesting execution and large-scale data ingestion. This role ...
Cloud Platform Engineer
Fort George G Meade, MD · On-site
$197K - $217K/yr
Responsibilities The Cloud Platform Engineer provisions and configures Government-approved cloud infrastructure to support autonomous pentesting execution and large-scale data ingestion. This role ...
... cloud environments, and emerging AI/ML systems, including Large Language Models (LLMs) and GenAI platforms. The ideal candidate combines deep technical pentesting expertise with hands-on experience ...
... cloud environments, and emerging AI/ML systems, including Large Language Models (LLMs) and GenAI platforms. The ideal candidate combines deep technical pentesting expertise with hands-on experience ...
Security Research Engineer
New York, NY · On-site
$120K - $175K/yr
Experience with cloud security (AWS, GCP, Azure) and containerized environments * Familiarity with compliance frameworks (SOC 2, ISO 27001, PCI DSS) as they relate to pentesting Benefits
Security Research Engineer
New York, NY · On-site
$120K - $175K/yr
Experience with cloud security (AWS, GCP, Azure) and containerized environments * Familiarity with compliance frameworks (SOC 2, ISO 27001, PCI DSS) as they relate to pentesting Benefits
... pentesting, red teaming, security engineering, solutions engineering, or technical security consulting * Strong hands-on understanding of modern vulnerability classes across web, cloud, APIs, and ...
Quick apply
... pentesting, red teaming, security engineering, solutions engineering, or technical security consulting * Strong hands-on understanding of modern vulnerability classes across web, cloud, APIs, and ...
... pentesting, red teaming, security engineering, solutions engineering, or technical security consulting * Strong hands-on understanding of modern vulnerability classes across web, cloud, APIs, and ...
... pentesting, red teaming, security engineering, solutions engineering, or technical security consulting * Strong hands-on understanding of modern vulnerability classes across web, cloud, APIs, and ...
... pentesting, red teaming, security engineering, solutions engineering, or technical security consulting * Strong hands-on understanding of modern vulnerability classes across web, cloud, APIs, and ...
... pentesting, red teaming, security engineering, solutions engineering, or technical security consulting * Strong hands-on understanding of modern vulnerability classes across web, cloud, APIs, and ...
... pentesting, red teaming, security engineering, solutions engineering, or technical security consulting * Strong hands-on understanding of modern vulnerability classes across web, cloud, APIs, and ...
... pentesting, red teaming, security engineering, solutions engineering, or technical security consulting * Strong hands-on understanding of modern vulnerability classes across web, cloud, APIs, and ...
Infrastructure Security Engineer
Burbank, CA · On-site
$153K/yr
... pentesting to validate weaknesses and demonstrate real-world risk. This role requires at least a ... AWS & GCP VPC, load balancing, routing & cloud firewalls. * Acts as the L3 escalation point for ...
Infrastructure Security Engineer
Burbank, CA · On-site
$153K/yr
... pentesting to validate weaknesses and demonstrate real-world risk. This role requires at least a ... AWS & GCP VPC, load balancing, routing & cloud firewalls. * Acts as the L3 escalation point for ...
Database Administrator
Fort George G Meade, MD · On-site
$126K - $146K/yr
Enable ELT pipelines from autonomous pentesting data sources * Ensure data integrity, performance ... TS/SCI CI Poly * 9+ years of experience with cloud data platforms, databases, or lakehouse ...
Database Administrator
Fort George G Meade, MD · On-site
$126K - $146K/yr
Enable ELT pipelines from autonomous pentesting data sources * Ensure data integrity, performance ... TS/SCI CI Poly * 9+ years of experience with cloud data platforms, databases, or lakehouse ...
Infrastructure Security Engineer
Burbank, CA · On-site
$153K/yr
... pentesting to validate weaknesses and demonstrate real-world risk. This role requires at least a ... Secure hybrid and multi cloud environments, applying security controls for cloud networking ...
Infrastructure Security Engineer
Burbank, CA · On-site
$153K/yr
... pentesting to validate weaknesses and demonstrate real-world risk. This role requires at least a ... Secure hybrid and multi cloud environments, applying security controls for cloud networking ...
... cloud hardening delivered through Terraform and CI/CD rather than documentation. Run detection and response in our own environment, on our own telemetry. * Build agentic continuous pentesting with ...
... cloud hardening delivered through Terraform and CI/CD rather than documentation. Run detection and response in our own environment, on our own telemetry. * Build agentic continuous pentesting with ...
The ideal candidate has a deep offensive security mindset, excels at dissecting complex cloud ... Orchestrate Breach and Attack Simulation (BAS) and Autonomous Pentesting exercises, safely ...
New
The ideal candidate has a deep offensive security mindset, excels at dissecting complex cloud ... Orchestrate Breach and Attack Simulation (BAS) and Autonomous Pentesting exercises, safely ...
New
Cybersecurity Engineer
Fort George G Meade, MD · On-site
$193K - $213K/yr
... cloud infrastructure, software configuration, and data handling approaches developed during IOC ... Early cybersecurity involvement ensures autonomous pentesting capabilities are deployed responsibly ...
Cybersecurity Engineer
Fort George G Meade, MD · On-site
$193K - $213K/yr
... cloud infrastructure, software configuration, and data handling approaches developed during IOC ... Early cybersecurity involvement ensures autonomous pentesting capabilities are deployed responsibly ...
Systems Architect
Fort George G Meade, MD · On-site
$161K - $199K/yr
... for an autonomous pentesting and data collection capability supporting rapid cyber terrain ... TS/SCI CI Poly * 10 years of experience in systems, cyber, or cloud architecture * Strong ...
Systems Architect
Fort George G Meade, MD · On-site
$161K - $199K/yr
... for an autonomous pentesting and data collection capability supporting rapid cyber terrain ... TS/SCI CI Poly * 10 years of experience in systems, cyber, or cloud architecture * Strong ...
Network Engineer SME
Fort George G Meade, MD · On-site
$176K - $196K/yr
... cloud environments, enabling reliable ingestion of autonomous pentesting data at scale. This role focuses on boundary protections, segmentation strategies, and connectivity planning, including ...
Network Engineer SME
Fort George G Meade, MD · On-site
$176K - $196K/yr
... cloud environments, enabling reliable ingestion of autonomous pentesting data at scale. This role focuses on boundary protections, segmentation strategies, and connectivity planning, including ...
Application Security Engineer
Post Falls, ID · On-site +1
$175K/yr
Pentesting experience in mobile apps, APIs, and/or cloud environments a bonus * 4+ years of professional experience in Ruby on Rails or equivalent and Vue or a Frontend equivalent framework
Application Security Engineer
Post Falls, ID · On-site +1
$175K/yr
Pentesting experience in mobile apps, APIs, and/or cloud environments a bonus * 4+ years of professional experience in Ruby on Rails or equivalent and Vue or a Frontend equivalent framework
Security Engineer
San Francisco, CA · On-site
$214K - $280K/yr
Direct experience with application security, cloud security, or product security. Ideally you've ... Pentesting tooling: Decide which agentic pentesting solution Apollo will use, and whether to build ...
Security Engineer
San Francisco, CA · On-site
$214K - $280K/yr
Direct experience with application security, cloud security, or product security. Ideally you've ... Pentesting tooling: Decide which agentic pentesting solution Apollo will use, and whether to build ...
Cloud Pentesting information
See salary details
$10.10 - $17.59
5% of jobs
$17.59 - $25.09
0% of jobs
$25.09 - $32.58
0% of jobs
$32.58 - $40.08
1% of jobs
$40.08 - $47.57
5% of jobs
$47.57 - $55.07
11% of jobs
$56.10 is the 25th percentile. Wages below this are outliers.
$55.07 - $62.57
21% of jobs
The median wage is $65 / hr.
$62.57 - $70.06
21% of jobs
$74.33 is the 75th percentile. Wages above this are outliers.
$70.06 - $77.56
19% of jobs
$77.56 - $85.05
11% of jobs
$85.05 - $92.55
6% of jobs
$10
$64
$92
How much do cloud pentesting jobs pay per hour?
What is cloud pentesting?
What are the key skills and qualifications needed to thrive as a cloud pentester?
What are some common challenges faced by cloud pentesters when assessing cloud-based environments?
What is the difference between Cloud Pentesting vs Cloud Security Analyst?
| Aspect | Cloud Pentesting | Cloud Security Analyst |
|---|---|---|
| Certifications | CEH, OSCP, CISSP | CISSP, CCSP, Security+ |
| Work Environment | Conducts simulated attacks on cloud systems | Monitors, analyzes, and implements security measures |
| Employer & Industry Usage | Security firms, cloud providers, consulting | Organizations with cloud infrastructure, IT departments |
| Search & Comparison Intent | Understanding penetration testing roles in cloud | Understanding security analysis roles in cloud |
While both roles focus on cloud security, Cloud Pentesting involves actively testing cloud systems for vulnerabilities through simulated attacks. Cloud Security Analysts primarily monitor, analyze, and improve security measures. The roles complement each other but differ in approach: pentesters identify weaknesses, analysts maintain ongoing security posture.
Is cloud pentesting a good career?
Is cloud pentesting in demand?
What other helpful pages are available for Cloud Pentesting?
Other pages related to Cloud Pentesting:

OSOC Security Analyst - Cloud Pentesting
Remote
Full-time
Medical, Retirement, PTO
Re-posted 9 days ago
Job description
Responsibilities include:
- Conduct hands-on cloud penetration testing across Azure, AWS, and GCP environments, identifying IAM misconfigurations, excessive permissions, privilege escalation paths, exposed storage buckets/blobs, and exploitable service misconfigurations
- Perform offensive enumeration and attack-path mapping against cloud environments using tools such as ScoutSuite, Prowler, Pacu, ROADtools/ADRecon, and GCP-focused tooling.
- Review eASM dashboard daily to monitor for any anomalies or security incidents.
- Conduct testing and validation of vulnerabilities identified by the ASM system, providing evidence of validation to support remediation efforts.
- Investigate eASM vulnerabilities thoroughly, analyzing potential impact and root causes.
- Conduct various types of penetration testing, including scanning and password attacks, to identify potential weaknesses in the system.
- Perform cloud penetration testing and security configuration reviews across Azure and AWS environments, identifying misconfigurations, excessive permissions, and exploitable weaknesses.
- Perform technical vulnerability scans and validate remediation efforts to ensure effective security posture.
- Escalate identified vulnerabilities and security incidents to appropriate client or internal team members for resolution.
- Engage with clients during project kick-off meetings to understand their specific security requirements and objectives.
- Assist in maturing eASM Evolve Security processes, procedures, templates, and methodologies to enhance overall effectiveness.
- Take on other duties as assigned to support the growth and expansion of enterprise and academy initiatives, contributing to the overall success of the security program.
Requirements
- Passionate about cybersecurity with a curiosity to learn
- Foundational understanding of cloud security concepts and offensive testing methodology for Azure, AWS, and/or GCP (e.g., IAM abuse, privilege escalation, storage misconfigurations, metadata service exploitation).
- Hands-on exposure (via labs, coursework, CTFs, or professional experience) to cloud-native offensive tools such as ScoutSuite, Prowler, Pacu, ROADtools, ADRecon, or GCP enumeration/exploitation tooling.
- Security+ required; cloud security or offensive certifications a strong plus (AZ-500, AWS Certified Security - Specialty, GCP Professional Cloud Security Engineer, or equivalent cloud pentesting coursework/labs).
- 0-1 years of information technology experience, ideally with a focus on information security
- 0- 1 years penetration testing, application and vulnerability management experience through education or security/consulting firm
- Exposure to cloud security concepts and penetration testing methodologies for Azure and/or AWS environments (e.g., IAM misconfigurations, storage bucket/blob exposure, privilege escalation paths), gained through education, labs, or professional experience
- Knowledge of multiple operating systems and associated command-line administration tools (Bash / PowerShell)
- Knowledge of the application stack including web
- Familiarity with cloud-native and cloud pentesting tools (e.g., ScoutSuite, Prowler, Pacu, ROADtools, ADRecon) is a plus
- Scripting experience in one or more of: Ruby, Python, Perl, Bash
- ESCP, Security+ certifications; cloud security certifications (e.g., AZ-500, AWS Certified Security - Specialty) a plus
- A desire to tinker and understand how things work
- Ability to interface with clients, utilizing consulting and negotiating skills
- Strongly self-motivated and able to work independently towards team objectives
- Strong communication skills (oral and written) and ability to work as part of a team
Benefits
Who is Evolve Security?
Evolve Security is a cybersecurity services firm headquartered in Chicago, IL. We are dedicated to improving our client's security posture by providing continuous penetration testing, training services, and talent solutions.
In addition to our professional cybersecurity service offerings, Evolve Security offers a cybersecurity bootcamp, "Evolve Academy", currently ranked the #1 cybersecurity bootcamp in the world. The Cybersecurity Bootcamp in Chicago provides immersive training, giving students the concrete and practical skills, needed on the job. Students gain real work experience through live security assessment work that they perform on not-for-profit companies.
We are passionate about directly improving our customers' security posture, and we proudly train others to help meet the need for qualified cybersecurity talent.
Benefits Include
- Healthcare Benefits
- 401(k) Match
- Parental Leave
- Flexible Paid Time Off
- Annual vacation reimbursement
Salary: $50,000/year
About Evolve Security
Sourced by ZipRecruiter
Industry
Network security
Company size
11 - 50 Employees
Headquarters location
Chicago, IL, US
Year founded
2016