Cloud Penetration Tester

🕒 May 8

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Bishop Fox

Bishop Fox

201 - 500 employees

Founded 2007

💼 Consulting

📦 Logistics

📣 Marketing

💰 $46M Series B on 2022-11

Consulting • Logistics • Marketing

Bishop Fox is a leader in offensive security, offering a range of continuous security solutions to protect dynamic attack surfaces. Their services include attack surface management, application penetration testing, cloud security assessments, network security, and more. They focus on proactive defense strategies, subjecting clients' networks to real-world attack scenarios to bolster security resilience. Bishop Fox collaborates with major partners like Google, Facebook, and Amazon, ensuring robust security solutions for complex ecosystems. Their commitment to advancing security is rooted in innovative research and collaboration with the broader cybersecurity community.

📋 Description

• Perform hands-on security testing • Analyze application behavior • Review source code • Identify realistic exploitation scenarios • Validate security controls across modern architectures • Work closely with clients and internal teams to deliver high-quality technical assessments and actionable remediation guidance

🎯 Requirements

• 4+ years of experience in application security assessments, penetration testing, or offensive security engagements • Strong understanding of application security fundamentals, modern attack techniques, and common vulnerabilities affecting web applications, APIs, mobile applications, and cloud-native environments • Hands-on experience testing REST APIs, including authentication/authorization flaws, IDORs, injection vulnerabilities, session management issues, and business logic flaws • Strength with AWS services and cloud security concepts, including IAM, STS, S3, Lambda, API Gateway, CloudTrail, CloudWatch, and secure communication patterns such as SigV4 • Solid understanding of networking and web fundamentals, including HTTP/HTTPS, TCP/IP, DNS, API communication flows, cookies, headers, and related concepts • Experience reviewing source code for security issues in Java, C#, and Python applications • Knowledge of secure coding principles and common risks such as SSRF, insecure deserialization, injection vulnerabilities, sensitive data exposure, and insecure cloud integrations • Understanding of SDLC, CI/CD pipelines, and secure development practices • Experience using security assessment and code review tools such as Burp Suite, Semgrep, Git, AWS CLI, and API testing/debugging tools • Comfortable working across Linux, Windows, and macOS environments • Experience or strong interest in AI/LLM security, including prompt injection, RAG risks, insecure integrations, excessive permissions, and the OWASP Top 10 for LLM Applications • Strong written and verbal communication skills, with the ability to deliver clear, actionable findings and communicate technical risks to both technical and executive stakeholders • Experience following structured testing methodologies, documentation standards, and validation/retesting workflows • Strong collaboration and interpersonal skills when working with security, engineering, and client teams • Ability to manage multiple concurrent engagements while maintaining high-quality deliverables and attention to detail • Curious, adaptable, and professional mindset with a passion for continuous learning and emerging security trends

🏖️ Benefits

• Generous Time Off and Company-Wide Holidays • Team Events and International Travel Opportunities • Work From Home Support • Training Budget • Saving Fund • Food Coupons • Health and Wellbeing programs

Apply Now

Similar Jobs

🕒 May 7

Wilson

1001 - 5000

💼 Consulting

📣 Marketing

🎯 Recruiter

Talent Attraction Specialist working with clients and recruiters to find top-notch talent for various roles. Engage in innovative sourcing strategies and maintain strong candidate relationships focusing on quality assurance and regulatory.

🕒 April 30

Capgemini

10,000+ employees

💼 Consulting

🏥 Healthcare

📦 Logistics

UAT Tester conducting user acceptance testing collaborating with cross-functional teams to ensure systems meet requirements. Key role in identifying defects and ensuring software quality.

🗣️🇪🇸 Spanish Required

🕒 April 24

VALCE Talent Solutions

11 - 50

🤝 B2B

🎯 Recruiter

💼 Consulting

SAP Tester Manager responsible for managing tests across SAP modules at Techmahindra. Leading collaboration with multiple teams to ensure quality and functionality.

🗣️🇪🇸 Spanish Required

🕒 April 14

Workana

51 - 200

👥 HR Tech

🏪 Marketplace

🎯 Recruiter

Partner Support & QA Specialist providing support for LATAM partners at Nuweb Group. Ensure high-quality assistance, on-boarding, and contribute to product quality through testing.

🗣️🇪🇸 Spanish Required

🕒 April 1

Alten México

10,000+ employees

🚘 Automotive

💼 Consulting

Manual Functional Tester responsible for high-quality manual testing in varied technology projects at ALTEN México. Collaborating with development and stakeholders to ensure deliverables meet business requirements.

🗣️🇪🇸 Spanish Required

SDLC