Azure Penetration Test Engineer

Posted 22 Days Ago
Be an Early Applicant
Hiring Remotely in Venezuela
Remote
Senior level
Cloud • Mobile • Professional Services • Software • Consulting
We are a leading Microsoft Azure Gold Partner & Azure Expert MSP
The Role
The Azure Penetration Test Engineer conducts security testing on Azure and Microsoft 365, identifying threats and validating security configurations while producing detailed reports and collaborating with security teams.
Summary Generated by Built In
Atmosera empowers businesses to redefine what's possible with modern technology and human expertise. Our exceptional experience across Applications, Data & AI, DevOps, Security, and the Microsoft Azure platform enables organizations to accelerate innovation, enhance security, and optimize operational agility. As a Microsoft Partner with seven specializations, GitHub AI Partner of the Year, a member of the GitHub Advisory Board, and a member of the prestigious Microsoft Intelligent Security Association (MISA), Atmosera expertly delivers cutting-edge, integrated solutions that deliver business value.

The Azure Penetration Test Engineer is responsible for conducting authorized security testing against Microsoft Azure and Microsoft 365 environments to identify, exploit, and document security weaknesses. This role focuses on cloud-native attack paths, identity compromise, misconfigurations, and exposure risks specific to Azure infrastructure-as-a-service, platform-as-a-service, and SaaS workloads.

The engineer operates as a trusted advisor to security, engineering, and leadership teams by producing actionable findings, validating remediation effectiveness, and aligning testing activities with industry frameworks such as NIST, MITRE ATT&CK, and Microsoft cloud security best practices. This role requires strong hands‑on technical depth, professional reporting skills, and the ability to work independently within defined rules of engagement. 

Key Responsibilities

    Penetration Testing and Offensive Security 

    Conduct penetration tests against Azure and M365 environments, including but not limited to: 

  • Azure AD and Entra ID identity and access configurations 
  • Privileged role assignments and conditional access policies 
  • Azure App Services, Function Apps, Storage Accounts, SQL, Key Vault, and API endpoints 
  • Virtual networks, NSGs, private endpoints, service endpoints, and hybrid network integrations 
  • Microsoft 365 services including Exchange Online, SharePoint Online, Teams, and OneDrive 
  • Simulate real‑world attacker techniques, including credential theft, token abuse, privilege escalation, lateral movement, and persistence within Azure and M365 environments. 

    Validate security controls implemented across Defender for Cloud, Defender for Identity, Defender for Endpoint, and Sentinel detection pipelines. 

    Identity and Access Attack Scenarios 

    Assess identity attack surfaces including: 

  • Service principals, managed identities, and application registrations 
  • OAuth consent abuse and Graph API permission misuse 
  • Legacy authentication exposure and password spraying susceptibility 
  • Privileged Identity Management configuration gaps 
  • Demonstrate practical attack paths that result in data access, privilege escalation, or persistent control. 

    Reporting and Documentation 

    Produce clear, professional penetration test reports that include: 

  • Executive summaries suitable for leadership review 
  • Reproducible technical findings with evidence and attack chains 
  • Risk ratings aligned to organizational risk models 
  • Remediation guidance mapped to Azure and Microsoft security best practices 
  • Present findings directly to security leadership and technical stakeholders as required. 

    Collaboration and Advisory Support 

    Work closely with: 

  • Security Operations teams to validate detection coverage 
  • Cloud engineering teams to confirm remediation feasibility 
  • GRC teams to align findings with compliance requirements such as SOC 2, ISO 27001, and NIST 800‑53 
  • Provide retesting and validation support following remediation efforts. 

    Continuous Improvement 

    Stay current on emerging Azure attack techniques, Microsoft security platform changes, and cloud exploitation research. 

    Contribute to internal penetration testing methodologies, tooling, and runbooks.

Required Qualifications

  • Minimum 5 years of professional penetration testing or offensive security experience 
  • Strong hands‑on experience testing Microsoft Azure and Microsoft 365 environments 
  • Deep understanding of Azure AD and Entra ID security models 
  • Proficiency with common penetration testing tools and techniques, including PowerShell, Azure CLI, Graph API, and cloud‑specific testing frameworks 
  • Strong knowledge of networking fundamentals, identity protocols, and authentication flows 
  • Demonstrated ability to write high‑quality technical and executive‑level reports 

Preferred Qualifications

  • Relevant certifications such as OSCP, AZ‑500, SC‑100, CRTO, or equivalent 
  • Experience in consulting, MSSP, or regulated enterprise environments 
  • Familiarity with Microsoft Sentinel and Defender XDR telemetry 
  • Experience aligning penetration testing findings to NIST AI RMF, NIST CSF, or MITRE ATT&CK Cloud Matrix 

Competencies and Attributes

  • High degree of professional judgment and ethical responsibility 
  • Strong written and verbal communication skills 
  • Ability to operate independently within defined rules of engagement 
  • Methodical and evidence‑driven testing approach 
  • Strong attention to detail and risk prioritization 

Working Conditions

    This role may require participation in authorized testing windows, coordination across time zones, and occasional after‑hours testing based on client or organizational requirements. 
     
    #LI-LV1

This is a contractor position in the United States with the ability to work from home but may require travel to a client site.
 
Atmosera is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. All employment is decided on the basis of qualifications, merit, and business need.

Skills Required

  • Minimum 5 years of professional penetration testing or offensive security experience
  • Strong hands-on experience testing Microsoft Azure and Microsoft 365 environments
  • Deep understanding of Azure AD and Entra ID security models
  • Proficiency with common penetration testing tools and techniques
  • Strong knowledge of networking fundamentals, identity protocols, and authentication flows
  • Demonstrated ability to write high-quality technical and executive-level reports

Atmosera Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Atmosera and has not been reviewed or approved by Atmosera.

  • Affordable Benefits Employee premiums for medical, dental, and vision are advertised as fully covered, reducing out‑of‑pocket costs. Employer‑paid life and disability coverage are also referenced as part of the package.
  • Retirement Support A 401(k) with a company match is consistently described as part of the offering. This provides a predictable savings component alongside cash compensation.
  • Leave & Time Off Breadth Time off is presented as including PTO, paid holidays, and paid parental leave, with some roles citing flexible time‑off policies. Community service leave is also highlighted in perk lists.

Atmosera Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Beaverton, OR
80 Employees
Year Founded: 1995

What We Do

Atmosera is full lifecycle cloud technology transformation firm, offering Application and Data Professional services, Security & Compliance Management, Azure operations, and Technology Training. Our expertise across Applications, Data, and the Microsoft Azure platform allows us to accelerate innovation speed, increase operational agility, and vastly improve the return on investment in modern technology and human expertise.

Gallery

Gallery

Similar Jobs

Luxury Presence Logo Luxury Presence

Design Engineer

Marketing Tech • Real Estate • Software • PropTech • SEO
Easy Apply
Remote or Hybrid
12 Locations
500 Employees

Teya Logo Teya

Sales Representative

Fintech • Payments • Financial Services
Remote or Hybrid
Valencia, Carabobo, VEN
1000 Employees
27K-45K Annually

Mondelēz International Logo Mondelēz International

Pasante de Comunicaciones Internas

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
Caracas, Municipio Libertador, Distrito Capital, VEN
90000 Employees

Luxury Presence Logo Luxury Presence

Staff Data Engineer

Marketing Tech • Real Estate • Software • PropTech • SEO
Easy Apply
Remote or Hybrid
12 Locations
500 Employees

Similar Companies Hiring

Fairly Even Thumbnail
Hardware • Other • Robotics • Sales • Software • Hospitality
New York, NY
30 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account