Azure Penetration Test Engineer

2 weeks, 6 days ago
Contract
Senior
Cybersecurity
Atmosera

Atmosera

Atmosera is a trusted global cloud partner offering Azure managed cloud services with a focus on security and compliance for critical business applications worldwide.

IT Services
51-250
Founded 1995

Description

  • Conduct penetration tests against Azure and Microsoft 365 environments to identify and exploit security weaknesses.
  • Assess Azure AD and Entra ID identity and access configurations, including privileged roles and conditional access policies.
  • Test cloud services and infrastructure such as App Services, Function Apps, Storage Accounts, SQL, Key Vault, API endpoints, virtual networks, and hybrid integrations.
  • Simulate real-world attacker techniques including credential theft, token abuse, privilege escalation, lateral movement, and persistence.
  • Evaluate identity attack surfaces such as service principals, managed identities, application registrations, OAuth consent abuse, and legacy authentication exposure.
  • Validate security controls across Defender for Cloud, Defender for Identity, Defender for Endpoint, and Sentinel detection pipelines.
  • Produce professional penetration test reports with executive summaries, reproducible findings, attack chains, risk ratings, and remediation guidance.
  • Present findings to security leadership and technical stakeholders and support retesting after remediation.
  • Collaborate with security operations, cloud engineering, and GRC teams to validate detections, confirm fixes, and align with compliance requirements.
  • Stay current on emerging Azure attack techniques and contribute to internal testing methodologies, tooling, and runbooks.

Requirements

  • Minimum 5 years of professional penetration testing or offensive security experience.
  • Strong hands-on experience testing Microsoft Azure and Microsoft 365 environments.
  • Deep understanding of Azure AD and Entra ID security models.
  • Proficiency with PowerShell, Azure CLI, Graph API, and cloud-specific testing frameworks.
  • Strong knowledge of networking fundamentals, identity protocols, and authentication flows.
  • Demonstrated ability to write high-quality technical and executive-level reports.
  • Relevant certifications such as OSCP, AZ-500, SC-100, CRTO, or equivalent are preferred.
  • Experience in consulting, MSSP, or regulated enterprise environments is preferred.
  • Familiarity with Microsoft Sentinel and Defender XDR telemetry is preferred.
  • Experience aligning penetration testing findings to NIST AI RMF, NIST CSF, or MITRE ATT&CK Cloud Matrix is preferred.

Benefits

  • Remote work from home.
  • Contractor position.
  • May require travel to a client site.
  • Participation in authorized testing windows with occasional after-hours testing based on client or organizational needs.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security Business Partner, Frontier Systems

Anduril Industries 1K-5K Aerospace & Defense

Anduril Industries is seeking a Security Business Partner to embed strategic security support within its Frontier Systems Division, enabling classified defense programs and business growth across Department of War and Intelligence Community customers.

SAP
3 hours, 3 minutes ago

Principal DFIR Consultant - Remote (Anywhere in the U.S.)

GuidePoint Security 251-1K Internet Software & Services

GuidePoint Security is seeking a Principal DFIR Consultant to lead its most complex incident response and forensic engagements while shaping practice methodology, mentoring staff, and supporting client and business growth.

AWS Azure Bash Go PowerShell Python SIEM
4 hours, 36 minutes ago

Senior Technical Consultant - Network Security

AHEAD 1K-5K IT Services

AHEAD is hiring a Senior Technical Consultant to lead client-facing network security engagements spanning firewall, network access control, and SASE/Zero Trust design, implementation, and delivery for enterprise environments.

Ansible AWS Azure Fortinet HIPAA Juniper Kubernetes SIEM Splunk Terraform
9 hours, 48 minutes ago

Manager, Governance, Risk and Compliance

Path Robotics 51-250 Automotive

Path Robotics is hiring a Cybersecurity GRC Manager to build and lead its enterprise governance, risk, and compliance program as the company scales into regulated markets.

AWS Azure Cybersecurity GCP
21 hours, 57 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers