Principal Penetration Tester (Cloud Infrastructure, Kubernetes and Containers)
Bengaluru
Saviynt
Embrace Zero Trust, secure sensitive & privileged access, and stay in continuous compliance with the world’s #1 cloud identity governance platform.
Saviynt is an identity authority platform built to power and protect the world at work. In a world of digital transformation, where organizations are faced with increasing cyber risk but cannot afford defensive measures to slow down progress, Saviynt’s Enterprise Identity Cloud gives customers unparalleled visibility, control and intelligence to better defend against threats while empowering users with right-time, right-level access to the digital technologies and tools they need to do their best work.
We are seeking a highly skilled and experienced Lead/Principal Penetration Tester to join our security team. This role has a string focus exclusively on advanced penetration testing of cloud infrastructure (AWS and Azure) and containerized environments, including Kubernetes (EKS and AKS). You will collaborate closely with Architecture, Cloud Platform Engineering, Cloud Operations and Security teams to identify vulnerabilities, assess risks, and recommend effective mitigation strategies.
Saviynt is an equal opportunity employer, and we welcome everyone to our team. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
We are seeking a highly skilled and experienced Lead/Principal Penetration Tester to join our security team. This role has a string focus exclusively on advanced penetration testing of cloud infrastructure (AWS and Azure) and containerized environments, including Kubernetes (EKS and AKS). You will collaborate closely with Architecture, Cloud Platform Engineering, Cloud Operations and Security teams to identify vulnerabilities, assess risks, and recommend effective mitigation strategies.
WHAT YOU WILL BE DOING
- Conduct in-depth penetration testing of cloud infrastructure, deployment models, and cloud-native services on AWS and Azure.
- Perform security assessments and penetration testing on Kubernetes clusters (EKS and AKS), including container images and associated components.
- Identify and exploit misconfigurations or vulnerabilities in Kubernetes clusters, workload security, and related cloud environments.
- Analyse and prioritize vulnerabilities across AWS, Azure, and containerized deployments based on risk, impact, and business context.
- Prepare comprehensive reports detailing findings, potential impacts, and actionable remediation steps. Communicate these reports effectively to both technical and non-technical stakeholders.
- Collaborate with Cloud Ops, DevOps, and Cloud Engineering teams to provide expert guidance and support for remediating vulnerabilities in cloud infrastructure and containerized environments.
- Leverage and customize industry-standard security tools (e.g., Trivy, kube-hunter, Aqua, Falco) and develop custom scripts or tools to enhance testing capabilities. Automate repetitive tasks to streamline penetration testing workflows.
- Participate in threat modelling exercises to identify risks specific to AWS, Azure, EKS, and AKS environments.
- Ensure all penetration testing activities adhere to industry standards and compliance frameworks, such as NIST, ISO 27001, CSA, and Kubernetes Security Best Practices.
- Develop and communicate targeted remediation strategies for cloud and container security risks, ensuring alignment with organizational goals and business priorities.
- Mentor and guide junior penetration testers, fostering continuous learning and professional growth in cloud and container security practices.
WHAT YOU BRING
- Bachelor’s degree in computer science, Information Security, or a related field.
- 10+ years of hands-on experience in penetration testing, with at least 3 years focused on AWS and Azure cloud infrastructures.
- Proven expertise in penetration testing of cloud services, deployments, Kubernetes clusters (EKS and AKS), and containerized applications.
- Hands-on experience with cloud infrastructure architecture reviews, threat modelling, cloud configuration assessments, and container/Kubernetes security.
- Proficiency in scripting and automation using Python, Go, Shell, or Bash for custom testing.
- Strong knowledge of security tools and techniques for cloud, Kubernetes, and containerized environments.
- Any of the relevant certification such as OSCP, Kubernetes Security Specialist, AWS Certified Security – Specialty, or Microsoft Azure Security Engineer.
Saviynt is an equal opportunity employer, and we welcome everyone to our team. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
1
0
0
Categories:
CloudSec Jobs
PenTesting Jobs
Tags: Automation AWS Azure Bash Cloud Compliance Computer Science DevOps Exploit ISO 27001 Kubernetes NIST OSCP Pentesting Python Scripting Security assessment Vulnerabilities
Perks/benefits: Career development Startup environment
Region:
Asia/Pacific
Country:
India
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Senior Cybersecurity Engineer jobsInformation Security Officer jobsSenior Cloud Security Engineer jobsInformation System Security Officer jobsInformation Security Manager jobsInformation Security Specialist jobsCyber Security Specialist jobsSecurity Consultant jobsIT Security Engineer jobsSenior Network Security Engineer jobsSenior Information Security Analyst jobsSystems Engineer jobsSecurity Specialist jobsSystems Administrator jobsIT Security Analyst jobsSenior Cyber Security Engineer jobsChief Information Security Officer jobsSenior Penetration Tester jobsInformation System Security Officer (ISSO) jobsStaff Security Engineer jobsCyber Security Architect jobsSenior Product Security Engineer jobsInformation Systems Security Engineer jobsThreat Intelligence Analyst jobsSecurity Operations Analyst jobs
APIs jobsEncryption jobsForensics jobsTop Secret jobsEDR jobsSaaS jobsGDPR jobsRMF jobsIDS jobsSplunk jobsSDLC jobsIPS jobsSQL jobsActive Directory jobsBash jobsDoDD 8570 jobsIntrusion detection jobsThreat detection jobsITIL jobsCompTIA jobsFinance jobsGIAC jobsOWASP jobsDocker jobsCRISC jobs
UNIX jobsSANS jobsClearance Required jobsIndustrial jobsTCP/IP jobsTerraform jobsOSCP jobsHIPAA jobsJavaScript jobsCCSP jobsIT infrastructure jobsBanking jobsData Analytics jobsDNS jobsVPN jobsSOC 2 jobsCISO jobsNIST 800-53 jobsSAP jobsPolygraph jobsSOX jobsGCIH jobsMITRE ATT&CK jobsAnsible jobsGSEC jobs