Azure Penetration Test Engineer
AI Summary
The Azure Penetration Test Engineer conducts authorized security testing of Microsoft Azure and Microsoft 365 environments, identifying weaknesses, validating remediations, and delivering actionable findings to security and leadership teams.
About this role
The Azure Penetration Test Engineer is responsible for conducting authorized security testing against Microsoft Azure and Microsoft 365 environments to identify, exploit, and document security weaknesses. This role focuses on cloud-native attack paths, identity compromise, misconfigurations, and exposure risks specific to Azure infrastructure-as-a-service, platform-as-a-service, and SaaS workloads.
The engineer operates as a trusted advisor to security, engineering, and leadership teams by producing actionable findings, validating remediation effectiveness, and aligning testing activities with industry frameworks such as NIST, MITRE ATT&CK, and Microsoft cloud security best practices. This role requires strong hands‑on technical depth, professional reporting skills, and the ability to work independently within defined rules of engagement.
Key Responsibilities
Penetration Testing and Offensive Security
Conduct penetration tests against Azure and M365 environments, including but not limited to:
Simulate real‑world attacker techniques, including credential theft, token abuse, privilege escalation, lateral movement, and persistence within Azure and M365 environments.
Validate security controls implemented across Defender for Cloud, Defender for Identity, Defender for Endpoint, and Sentinel detection pipelines.
Identity and Access Attack Scenarios
Assess identity attack surfaces including:
Demonstrate practical attack paths that result in data access, privilege escalation, or persistent control.
Reporting and Documentation
Produce clear, professional penetration test reports that include:
Present findings directly to security leadership and technical stakeholders as required.
Collaboration and Advisory Support
Work closely with:
Provide retesting and validation support following remediation efforts.
Continuous Improvement
Stay current on emerging Azure attack techniques, Microsoft security platform changes, and cloud exploitation research.
Contribute to internal penetration testing methodologies, tooling, and runbooks.
Required Qualifications
Preferred Qualifications
Competencies and Attributes
Working Conditions
Skills
Explore related jobs
More jobs at Atmosera
Project Manager (Remote - LATAM)Remote - LATAM
Cloud Infrastructure Engineer (Remote - LATAM)Remote - LATAM
Senior Consultant - Data & AI (Microsoft Fabric) (Remote - LATAM)Remote - LATAM
GRC Analyst (Remote - LATAM)Remote - LATAM - MEX
Client Executive (Remote - Costa Rica)San Jose, Costa Rica
Senior Client Executive (Remote - Costa Rica)San Jose, Costa Rica