1

Cloud Pentesting Jobs (NOW HIRING)

CLOUD SECURITY EXPERT

Rancho Cordova, CA · On-site

$69.75 - $92.75/hr

CLOUD SECURITY EXPERT MUST HAVE THE FOLLOWING SKILLS/EXPERIENCE: Healthcare industry experience ... Experience in Vulnerability Scanning and Pentesting Experience with Data Leakage Prevention ...

Responsibilities The Cloud Platform Engineer provisions and configures Government-approved cloud infrastructure to support autonomous pentesting execution and large-scale data ingestion. This role ...

Security Research Engineer

New York, NY · On-site

$120K - $175K/yr

Experience with cloud security (AWS, GCP, Azure) and containerized environments * Familiarity with compliance frameworks (SOC 2, ISO 27001, PCI DSS) as they relate to pentesting Benefits

... pentesting, red teaming, security engineering, solutions engineering, or technical security consulting * Strong hands-on understanding of modern vulnerability classes across web, cloud, APIs, and ...

Enable ELT pipelines from autonomous pentesting data sources * Ensure data integrity, performance ... TS/SCI CI Poly * 9+ years of experience with cloud data platforms, databases, or lakehouse ...

... cloud hardening delivered through Terraform and CI/CD rather than documentation. Run detection and response in our own environment, on our own telemetry. * Build agentic continuous pentesting with ...

... cloud infrastructure, software configuration, and data handling approaches developed during IOC ... Early cybersecurity involvement ensures autonomous pentesting capabilities are deployed responsibly ...

Systems Architect

Fort George G Meade, MD · On-site

$161K - $199K/yr

... for an autonomous pentesting and data collection capability supporting rapid cyber terrain ... TS/SCI CI Poly * 10 years of experience in systems, cyber, or cloud architecture * Strong ...

... cloud environments, enabling reliable ingestion of autonomous pentesting data at scale. This role focuses on boundary protections, segmentation strategies, and connectivity planning, including ...

Security Engineer

San Francisco, CA · On-site

$214K - $280K/yr

Direct experience with application security, cloud security, or product security. Ideally you've ... Pentesting tooling: Decide which agentic pentesting solution Apollo will use, and whether to build ...

next page

Showing results 1-20

Cloud Pentesting information

See salary details

$10

$64

$92

How much do cloud pentesting jobs pay per hour?

As of Sep 12, 2026, the average hourly pay for cloud pentesting in the United States is $64.53, according to ZipRecruiter salary data. Most workers in this role earn between $56.25 and $76.68 per hour, depending on experience, location, and employer.

What is cloud pentesting?

Cloud pentesting, or cloud penetration testing, is the process of simulating cyberattacks on cloud-based systems, applications, and infrastructure to identify security vulnerabilities. It involves testing for misconfigurations, insecure interfaces, and other weaknesses specific to cloud environments. The goal is to help organizations secure their cloud resources by uncovering and addressing potential threats before malicious actors can exploit them.

What are the key skills and qualifications needed to thrive as a cloud pentester?

To thrive as a Cloud Pentester, you need expertise in cloud security principles, penetration testing methodologies, and familiarity with platforms like AWS, Azure, or Google Cloud, often supported by certifications such as OSCP, CEH, or cloud provider-specific credentials. Proficiency with tools like Burp Suite, Metasploit, and cloud-native security services is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for identifying vulnerabilities and explaining findings to stakeholders. These skills and qualities are essential to ensure cloud environments remain secure and compliant with industry standards.

What are some common challenges faced by cloud pentesters when assessing cloud-based environments?

Cloud pentesters often face challenges such as navigating complex permission models, understanding diverse cloud service architectures, and dealing with multi-tenant environments that restrict certain testing activities. Unlike traditional networks, cloud environments frequently update, requiring pentesters to stay current with new features and security controls. Collaborating closely with cloud administrators and DevOps teams is essential to ensure testing is comprehensive and aligns with organizational policies, while also respecting provider-imposed limitations.

What is the difference between Cloud Pentesting vs Cloud Security Analyst?

AspectCloud PentestingCloud Security Analyst
CertificationsCEH, OSCP, CISSPCISSP, CCSP, Security+
Work EnvironmentConducts simulated attacks on cloud systemsMonitors, analyzes, and implements security measures
Employer & Industry UsageSecurity firms, cloud providers, consultingOrganizations with cloud infrastructure, IT departments
Search & Comparison IntentUnderstanding penetration testing roles in cloudUnderstanding security analysis roles in cloud

While both roles focus on cloud security, Cloud Pentesting involves actively testing cloud systems for vulnerabilities through simulated attacks. Cloud Security Analysts primarily monitor, analyze, and improve security measures. The roles complement each other but differ in approach: pentesters identify weaknesses, analysts maintain ongoing security posture.

Is cloud pentesting a good career?

Cloud pentesting is a specialized cybersecurity role focused on identifying vulnerabilities in cloud environments, requiring knowledge of cloud platforms, security tools, and scripting. It is a growing field with high demand for skilled professionals, often requiring certifications like OSCP or CEH and familiarity with cloud services such as AWS or Azure.

Is cloud pentesting in demand?

Cloud pentesting is in high demand as organizations increasingly adopt cloud services and need to identify security vulnerabilities. Professionals with skills in cloud environments, penetration testing tools, and relevant certifications like OSCP or CISSP are sought after to help secure cloud infrastructure and applications.

What other helpful pages are available for Cloud Pentesting?

Other pages related to Cloud Pentesting:

Infographic showing various Cloud Pentesting job openings in the United States as of September 2026, with employment types broken down into 100% Full Time. Highlights an 57% In-person, 11% Hybrid, and 32% Remote job distribution, with an average salary of $134,230 per year, or $64.5 per hour.

OSOC Security Analyst - Cloud Pentesting

Remote

Evolve Security
Network Security • 11 - 50 employees

Full-time

Medical, Retirement, PTO

Re-posted 9 days ago


Job description

Evolve Security is looking for an OSOC Security Analyst to join our growing team. This position will assist with the overall successful delivery of various application vulnerability assessments, continuous internal / external penetration assessments, cloud security assessments, incident response and detection assessments, and other types of security strategy and architecture reviews.
Responsibilities include:
  • Conduct hands-on cloud penetration testing across Azure, AWS, and GCP environments, identifying IAM misconfigurations, excessive permissions, privilege escalation paths, exposed storage buckets/blobs, and exploitable service misconfigurations
  • Perform offensive enumeration and attack-path mapping against cloud environments using tools such as ScoutSuite, Prowler, Pacu, ROADtools/ADRecon, and GCP-focused tooling.
  • Review eASM dashboard daily to monitor for any anomalies or security incidents.
  • Conduct testing and validation of vulnerabilities identified by the ASM system, providing evidence of validation to support remediation efforts.
  • Investigate eASM vulnerabilities thoroughly, analyzing potential impact and root causes.
  • Conduct various types of penetration testing, including scanning and password attacks, to identify potential weaknesses in the system.
  • Perform cloud penetration testing and security configuration reviews across Azure and AWS environments, identifying misconfigurations, excessive permissions, and exploitable weaknesses.
  • Perform technical vulnerability scans and validate remediation efforts to ensure effective security posture.
  • Escalate identified vulnerabilities and security incidents to appropriate client or internal team members for resolution.
  • Engage with clients during project kick-off meetings to understand their specific security requirements and objectives.
  • Assist in maturing eASM Evolve Security processes, procedures, templates, and methodologies to enhance overall effectiveness.
  • Take on other duties as assigned to support the growth and expansion of enterprise and academy initiatives, contributing to the overall success of the security program.

Requirements
  • Passionate about cybersecurity with a curiosity to learn
  • Foundational understanding of cloud security concepts and offensive testing methodology for Azure, AWS, and/or GCP (e.g., IAM abuse, privilege escalation, storage misconfigurations, metadata service exploitation).
  • Hands-on exposure (via labs, coursework, CTFs, or professional experience) to cloud-native offensive tools such as ScoutSuite, Prowler, Pacu, ROADtools, ADRecon, or GCP enumeration/exploitation tooling.
  • Security+ required; cloud security or offensive certifications a strong plus (AZ-500, AWS Certified Security - Specialty, GCP Professional Cloud Security Engineer, or equivalent cloud pentesting coursework/labs).
  • 0-1 years of information technology experience, ideally with a focus on information security
  • 0- 1 years penetration testing, application and vulnerability management experience through education or security/consulting firm
  • Exposure to cloud security concepts and penetration testing methodologies for Azure and/or AWS environments (e.g., IAM misconfigurations, storage bucket/blob exposure, privilege escalation paths), gained through education, labs, or professional experience
  • Knowledge of multiple operating systems and associated command-line administration tools (Bash / PowerShell)
  • Knowledge of the application stack including web
  • Familiarity with cloud-native and cloud pentesting tools (e.g., ScoutSuite, Prowler, Pacu, ROADtools, ADRecon) is a plus
  • Scripting experience in one or more of: Ruby, Python, Perl, Bash
  • ESCP, Security+ certifications; cloud security certifications (e.g., AZ-500, AWS Certified Security - Specialty) a plus
  • A desire to tinker and understand how things work
  • Ability to interface with clients, utilizing consulting and negotiating skills
  • Strongly self-motivated and able to work independently towards team objectives
  • Strong communication skills (oral and written) and ability to work as part of a team

Benefits
Who is Evolve Security?
Evolve Security is a cybersecurity services firm headquartered in Chicago, IL. We are dedicated to improving our client's security posture by providing continuous penetration testing, training services, and talent solutions.
In addition to our professional cybersecurity service offerings, Evolve Security offers a cybersecurity bootcamp, "Evolve Academy", currently ranked the #1 cybersecurity bootcamp in the world. The Cybersecurity Bootcamp in Chicago provides immersive training, giving students the concrete and practical skills, needed on the job. Students gain real work experience through live security assessment work that they perform on not-for-profit companies.
We are passionate about directly improving our customers' security posture, and we proudly train others to help meet the need for qualified cybersecurity talent.
Benefits Include
  • Healthcare Benefits
  • 401(k) Match
  • Parental Leave
  • Flexible Paid Time Off
  • Annual vacation reimbursement

Salary: $50,000/year