SC Cleared CTL Pen Tester - Fully Remote - Outside IR35
Hamilton Barnes
Charing Cross, United Kingdom
2 days ago
Role details
Contract type
Contract Employment type
Full-time (> 32 hours) Working hours
Regular working hours Languages
English Compensation
£ 143KJob location
Remote
Charing Cross, United Kingdom
Tech stack
Amazon Web Services (AWS)
Software System Penetration Testing
Azure
Burp Suite
Cloud Computing
Cloud Engineering
Continuous Integration
Github
Identity and Access Management
Network Architecture
NMap
Role-Based Access Control
SC Clearance
Kubernetes
Metasploit
Devsecops
Serverless Computing
Jenkins
Vulnerability Analysis
Job description
SC Cleared CTL Pen Tester - Fully Remote - Outside IR35
Role Overview
We are looking for a SC Cleared CTL Penetration Tester to join on a contract basis, delivering expert-level penetration testing across cloud environments, containerised infrastructure, and CI/CD pipelines. The role requires deep hands-on offensive security experience across AWS and Azure platforms, Kubernetes environments, and modern DevSecOps pipelines - operating within a regulated, security-cleared environment.
Key Responsibilities
- Plan and execute penetration tests across AWS and Azure cloud environments, identifying vulnerabilities in cloud-native services, configurations, IAM policies, and network architecture
- Conduct penetration testing and security assessments across Kubernetes clusters and containerised workloads, identifying misconfigurations, privilege escalation paths, and container escape risks
- Assess CI/CD pipeline security, identifying weaknesses in build and deployment processes, secrets management, and pipeline configurations that could be exploited by threat actors
- Produce clear, detailed penetration test reports with risk-rated findings, proof-of-concept evidence, and actionable remediation guidance tailored to both technical and non-technical audiences
- Collaborate with engineering and security teams to validate remediation of identified vulnerabilities, providing re-testing and security assurance across cloud and DevSecOps environments
Top 5 Skills
- Hands-on penetration testing experience across AWS and Azure cloud environments, including IAM abuse, misconfiguration exploitation, and cloud-native service vulnerabilities
- Proven experience testing Kubernetes and containerised environments - including pod escape, RBAC misconfigurations, and lateral movement within cluster infrastructure
- Experience assessing CI/CD pipeline security across tools such as GitHub Actions, Jenkins, or Azure DevOps, including secrets exposure, dependency confusion, and supply chain attack vectors
- Strong offensive security methodology with proficiency across tooling such as Burp Suite, Metasploit, Nmap, and cloud-specific exploitation frameworks
- Relevant penetration testing certifications such as CHECK Team Leader (CTL), OSCP, Crest CRT, or equivalent - Active SC clearance required
Contract Details
- Initial 6 Month Contract
- Day Rate: £550 per day Outside IR35
- Fully Remote
Requirements
- Hands-on penetration testing experience across AWS and Azure cloud environments, including IAM abuse, misconfiguration exploitation, and cloud-native service vulnerabilities
- Proven experience testing Kubernetes and containerised environments - including pod escape, RBAC misconfigurations, and lateral movement within cluster infrastructure
- Experience assessing CI/CD pipeline security across tools such as GitHub Actions, Jenkins, or Azure DevOps, including secrets exposure, dependency confusion, and supply chain attack vectors
- Strong offensive security methodology with proficiency across tooling such as Burp Suite, Metasploit, Nmap, and cloud-specific exploitation frameworks
- Relevant penetration testing certifications such as CHECK Team Leader (CTL), OSCP, Crest CRT, or equivalent - Active SC clearance required
Benefits & conditions
- Initial 6 Month Contract
- Day Rate: £550 per day Outside IR35
- Fully Remote