远程工作雷达

云渗透测试员(AWS、Azure、GCP),合同制

Cloud Penetration Tester (AWS, Azure, GCP), Contract

开发工程限定地区(需当地身份)
公司Invadel
薪资$175,000 - $265,000/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Contractor
发布时间昨天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

Invadel 是一家位于纽约市的渗透测试公司。每次服务都是固定范围和固定价格,以书面形式达成一致,公开价格见 invadel.com/pricing,并提供免费的重新测试。这是一个合同职位,远程工作,仅限美国境内,按项目支付;每个项目需要五到十天的测试时间,加上一次重新测试,并按照每位提供者的渗透测试政策执行。

你将负责:根据 CIS 基础标准审查 IAM 策略、角色和信任关系、存储暴露、计算和容器配置、网络控制、秘密处理和日志记录;从假设入侵的位置尝试权限提升和数据访问,并记录攻击路径和影响范围;记录客户检测系统是否能捕捉每一步;编写带有 CVSS 评分结果的报告,优先级修复建议和合规性映射,然后进行重新测试;不留下任何持久化痕迹。

我们需要:至少四年云安全工作经验,且在 AWS、Azure 和 GCP 中至少两个平台上有实际进攻性测试经验;熟练使用基础设施即代码、容器和 Kubernetes;位于美国并拥有在此工作的授权;能够为工程师和审计师撰写报告,并在申请时提供一份经过脱敏的报告样本;两名专业推荐人。

加分项:内部网络和 Active Directory 测试经验;有为 SOC 2、PCI DSS 或 HIPAA 审计生成证据的经验。拥有进攻性安全认证是欢迎的,但不会替代可验证的项目记录。

完整描述、薪资范围和申请方式:
最初发布于 Himalayas

查看英文原文

Invadel is a New York City penetration testing firm. Every engagement is fixed-scope and fixed-price, agreed in writing, with public prices at invadel.com/pricing and a free retest. This is a contract role, remote within the United States, paid per engagement; engagements run five to ten testing days plus a retest and are performed within each provider’s penetration testing policy.
What you will do: review IAM policies, roles and trust relationships, storage exposure, compute and container configuration, network controls, secrets handling and logging against the CIS foundations benchmark; attempt privilege escalation and data access from an assumed-breach position and document the attack path and blast radius; record whether the client’s detection would have caught each step; write the report with CVSS-scored findings, prioritized remediation and compliance mapping, then retest; leave nothing persistent behind.
What we need: four or more years of cloud security work with hands-on offensive testing on at least two of AWS, Azure and GCP; working fluency with infrastructure as code, containers and Kubernetes; based in the United States with authorization to work here; reports written for engineers and auditors, with a redacted sample report as part of the application; two professional references.
Nice to have: internal network and Active Directory testing; experience producing evidence for SOC 2, PCI DSS or HIPAA audits. An offensive security certification is welcome; it does not replace a verifiable engagement record.
Full description, pay range and application:
Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位