SC Cleared CTL Pen Tester - Fully Remote - Outside IR35
Role Overview
We are looking for a SC Cleared CTL Penetration Tester to join on a contract basis, delivering expert-level penetration testing across cloud environments, containerised infrastructure, and CI/CD pipelines. The role requires deep hands-on offensive security experience across AWS and Azure platforms, Kubernetes environments, and modern DevSecOps pipelines - operating within a regulated, security-cleared environment.
Key Responsibilities
- Plan and execute penetration tests across AWS and Azure cloud environments, identifying vulnerabilities in cloud-native services, configurations, IAM policies, and network architecture
- Conduct penetration testing and security assessments across Kubernetes clusters and containerised workloads, identifying misconfigurations, privilege escalation paths, and container escape risks
- Assess CI/CD pipeline security, identifying weaknesses in build and deployment processes, secrets management, and pipeline configurations that could be exploited by threat actors
- Produce clear, detailed penetration test reports with risk-rated findings, proof-of-concept evidence, and actionable remediation guidance tailored to both technical and non-technical audiences
- Collaborate with engineering and security teams to validate remediation of identified vulnerabilities, providing re-testing and security assurance across cloud and DevSecOps environments
Top 5 Skills
- Hands-on penetration testing experience across AWS and Azure cloud environments, including IAM abuse, misconfiguration exploitation, and cloud-native service vulnerabilities
- Proven experience testing Kubernetes and containerised environments - including pod escape, RBAC misconfigurations, and lateral movement within cluster infrastructure
- Experience assessing CI/CD pipeline security across tools such as GitHub Actions, Jenkins, or Azure DevOps, including secrets exposure, dependency confusion, and supply chain attack vectors
- Strong offensive security methodology with proficiency across tooling such as Burp Suite, Metasploit, Nmap, and cloud-specific exploitation frameworks
- Relevant penetration testing certifications such as CHECK Team Leader (CTL), OSCP, Crest CRT, or equivalent - Active SC clearance required
Contract Details
- Initial 6 Month Contract
- Day Rate: £550 per day Outside IR35
- Fully Remote