Experience with offensive toolkits for both cloud and network penetration testing
Demonstrable knowledge in the following areas: Exploiting security misconfigurations for core cloud services such as Compute Storage Databases Networking Kubernetes and other PAAS services IAM security fundamentals and how to leverage excessive permissions for lateral movement and privilege escalation within the cloud Testing external cloud attack surfaces Testing internal cloud attack surfaces
Desirables
Programming experience in one or more of the following languages: Python PowerShell C# Go
Experience researching new cloud service offerings with the goal of identifying misconfigurations and vulnerabilities
Web Application pentesting experience
What the job involves
Execute cloud penetration tests against AWS environments
Develop innovative TTPs in support of Cloud testing
Create attack narratives and findings-based penetration test reports for clients
NetSPI is dedicated to providing proactive security solutions that identify and mitigate critical vulnerabilities, empowering businesses to secure their most valuable assets through innovative services like Penetration Testing as a Service, Attack Surface Management, and Breach and Attack Simulation.
Company benefits
World-class team of experts
Collaborative and innovative environment
Opportunity to contribute with tools presentations white papers and blogs