Azure Penetration Test Engineer

1 month, 1 week ago
Contract
Senior
Cybersecurity
Atmosera

Atmosera

Atmosera is a trusted global cloud partner offering Azure managed cloud services with a focus on security and compliance for critical business applications worldwide.

IT Services
51-250
Founded 1995

Description

  • Conduct penetration tests against Azure and Microsoft 365 environments to identify and exploit security weaknesses.
  • Assess Azure AD and Entra ID identity and access configurations, including privileged roles and conditional access policies.
  • Test cloud services and infrastructure such as App Services, Function Apps, Storage Accounts, SQL, Key Vault, API endpoints, virtual networks, and hybrid integrations.
  • Simulate real-world attacker techniques including credential theft, token abuse, privilege escalation, lateral movement, and persistence.
  • Evaluate identity attack surfaces such as service principals, managed identities, application registrations, OAuth consent abuse, and legacy authentication exposure.
  • Validate security controls across Defender for Cloud, Defender for Identity, Defender for Endpoint, and Sentinel detection pipelines.
  • Produce professional penetration test reports with executive summaries, reproducible findings, attack chains, risk ratings, and remediation guidance.
  • Present findings to security leadership and technical stakeholders and support retesting after remediation.
  • Collaborate with security operations, cloud engineering, and GRC teams to validate detections, confirm fixes, and align with compliance requirements.
  • Stay current on emerging Azure attack techniques and contribute to internal testing methodologies, tooling, and runbooks.

Requirements

  • Minimum 5 years of professional penetration testing or offensive security experience.
  • Strong hands-on experience testing Microsoft Azure and Microsoft 365 environments.
  • Deep understanding of Azure AD and Entra ID security models.
  • Proficiency with PowerShell, Azure CLI, Graph API, and cloud-specific testing frameworks.
  • Strong knowledge of networking fundamentals, identity protocols, and authentication flows.
  • Demonstrated ability to write high-quality technical and executive-level reports.
  • Relevant certifications such as OSCP, AZ-500, SC-100, CRTO, or equivalent are preferred.
  • Experience in consulting, MSSP, or regulated enterprise environments is preferred.
  • Familiarity with Microsoft Sentinel and Defender XDR telemetry is preferred.
  • Experience aligning penetration testing findings to NIST AI RMF, NIST CSF, or MITRE ATT&CK Cloud Matrix is preferred.

Benefits

  • Remote work from home.
  • Contractor position.
  • May require travel to a client site.
  • Participation in authorized testing windows with occasional after-hours testing based on client or organizational needs.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Oracle Security & Controls consultant 6 Months Contract

Belmont Lavan 11-50 Professional Services

Belmont Lavan Ltd is hiring an Oracle Security & Controls Consultant for a 6-month contract to assess, design, and implement security controls across Oracle environments that support data integrity, confidentiality, and regulatory compliance.

Oracle
5 hours, 29 minutes ago

Senior Information Security GRC Specialist

BHG Financial 1K-5K Diversified Financial Services

BHG Financial is hiring a Senior Information Security GRC Specialist to lead enterprise business continuity and disaster recovery efforts while supporting risk and compliance initiatives for its financial services operations.

5 hours, 29 minutes ago

Senior Penetration Tester

Bridewell 251-1K Internet Software & Services

Bridewell is hiring a Senior Penetration Tester to deliver client-facing offensive security assessments across web applications, APIs, and infrastructure while supporting reporting, pre-sales, and service development.

AWS Azure Bash Cybersecurity GCP LLM Penetration Testing PowerShell Python
5 hours, 44 minutes ago

Pentester, Offensive Forward Deployment Engineer

Mistral AI 201-500 Artificial Intelligence

Mistral AI is hiring a hands-on Pentester for its Offensive Security team to run real client engagements, uncover vulnerabilities in Mistral’s systems and external targets, and help shape AI-assisted offensive security capabilities.

Active Directory AWS Azure CI/CD GCP Penetration Testing
5 hours, 59 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers