Azure Penetration Test Engineer

4 hours, 26 minutes ago
Contract
Senior
Cybersecurity
Atmosera

Atmosera

Atmosera is a trusted global cloud partner offering Azure managed cloud services with a focus on security and compliance for critical business applications worldwide.

IT Services
51-250
Founded 1995

Description

  • Conduct penetration tests against Azure and Microsoft 365 environments to identify and exploit security weaknesses.
  • Assess Azure AD and Entra ID identity and access configurations, including privileged roles and conditional access policies.
  • Test cloud services and infrastructure such as App Services, Function Apps, Storage Accounts, SQL, Key Vault, API endpoints, virtual networks, and hybrid integrations.
  • Simulate real-world attacker techniques including credential theft, token abuse, privilege escalation, lateral movement, and persistence.
  • Evaluate identity attack surfaces such as service principals, managed identities, application registrations, OAuth consent abuse, and legacy authentication exposure.
  • Validate security controls across Defender for Cloud, Defender for Identity, Defender for Endpoint, and Sentinel detection pipelines.
  • Produce professional penetration test reports with executive summaries, reproducible findings, attack chains, risk ratings, and remediation guidance.
  • Present findings to security leadership and technical stakeholders and support retesting after remediation.
  • Collaborate with security operations, cloud engineering, and GRC teams to validate detections, confirm fixes, and align with compliance requirements.
  • Stay current on emerging Azure attack techniques and contribute to internal testing methodologies, tooling, and runbooks.

Requirements

  • Minimum 5 years of professional penetration testing or offensive security experience.
  • Strong hands-on experience testing Microsoft Azure and Microsoft 365 environments.
  • Deep understanding of Azure AD and Entra ID security models.
  • Proficiency with PowerShell, Azure CLI, Graph API, and cloud-specific testing frameworks.
  • Strong knowledge of networking fundamentals, identity protocols, and authentication flows.
  • Demonstrated ability to write high-quality technical and executive-level reports.
  • Relevant certifications such as OSCP, AZ-500, SC-100, CRTO, or equivalent are preferred.
  • Experience in consulting, MSSP, or regulated enterprise environments is preferred.
  • Familiarity with Microsoft Sentinel and Defender XDR telemetry is preferred.
  • Experience aligning penetration testing findings to NIST AI RMF, NIST CSF, or MITRE ATT&CK Cloud Matrix is preferred.

Benefits

  • Remote work from home.
  • Contractor position.
  • May require travel to a client site.
  • Participation in authorized testing windows with occasional after-hours testing based on client or organizational needs.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Trainee IT Consultant IT-Security (m/w/d)

mindsquare 251-1K Internet Software & Services

mindsquare sucht einen Trainee für IT-Consulting, der sich im Bereich IT-Security innerhalb der ersten Jahre zum Senior IT Consultant entwickelt.

Salesforce SAP SAP ABAP
54 minutes ago

Director of Security/GRC

Censys 51-250 IT Services

Censys is hiring a Director of Security & GRC to lead corporate security, risk, and compliance programs for a remote U.S. team supporting internet intelligence operations.

AWS Azure Cybersecurity GCP SIEM
3 hours, 26 minutes ago

Senior Security Architect - AD/Entra (Remote in the US)

GuidePoint Security 251-1K Internet Software & Services

GuidePoint Security is hiring a Senior Security Architect for its IAM team to implement and enhance AD/Entra ID solutions in a fully remote role supporting client identity and access management needs.

Active Directory OAuth OpenID Connect Oracle PowerShell SAML
3 hours, 41 minutes ago

Associate, SOC Assessment

Coalfire 251-1K Internet Software & Services

Coalfire is hiring a remote Associate for SOC assessment work in the United Kingdom to evaluate client security and compliance controls against regulatory and industry frameworks and support client reporting.

Cybersecurity
4 hours, 26 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers