SC Cleared CTL Pen Tester - Fully Remote - Outside IR35

SC Cleared CTL Pen Tester - Fully Remote - Outside IR35

Role Overview

We are looking for a SC Cleared CTL Penetration Tester to join on a contract basis, delivering expert-level penetration testing across cloud environments, containerised infrastructure, and CI/CD pipelines. The role requires deep hands-on offensive security experience across AWS and Azure platforms, Kubernetes environments, and modern DevSecOps pipelines - operating within a regulated, security-cleared environment.

Key Responsibilities

  • Plan and execute penetration tests across AWS and Azure cloud environments, identifying vulnerabilities in cloud-native services, configurations, IAM policies, and network architecture
  • Conduct penetration testing and security assessments across Kubernetes clusters and containerised workloads, identifying misconfigurations, privilege escalation paths, and container escape risks
  • Assess CI/CD pipeline security, identifying weaknesses in build and deployment processes, secrets management, and pipeline configurations that could be exploited by threat actors
  • Produce clear, detailed penetration test reports with risk-rated findings, proof-of-concept evidence, and actionable remediation guidance tailored to both technical and non-technical audiences
  • Collaborate with engineering and security teams to validate remediation of identified vulnerabilities, providing re-testing and security assurance across cloud and DevSecOps environments

Top 5 Skills

  • Hands-on penetration testing experience across AWS and Azure cloud environments, including IAM abuse, misconfiguration exploitation, and cloud-native service vulnerabilities
  • Proven experience testing Kubernetes and containerised environments - including pod escape, RBAC misconfigurations, and lateral movement within cluster infrastructure
  • Experience assessing CI/CD pipeline security across tools such as GitHub Actions, Jenkins, or Azure DevOps, including secrets exposure, dependency confusion, and supply chain attack vectors
  • Strong offensive security methodology with proficiency across tooling such as Burp Suite, Metasploit, Nmap, and cloud-specific exploitation frameworks
  • Relevant penetration testing certifications such as CHECK Team Leader (CTL), OSCP, Crest CRT, or equivalent - Active SC clearance required

Contract Details

  • Initial 6 Month Contract
  • Day Rate: £550 per day Outside IR35
  • Fully Remote

Job Details

Company
Hamilton Barnes
Location
United Kingdom
Hybrid / Remote Options
Employment Type
Contract
Salary
GBP Daily
Posted