Infrastructure Penetration tester
Experience: 8+ years
Location :Sanjose CA (Onsite from Day 1) Level: Senior Security Engineer / Senior Penetration Tester Function: Cybersecurity / Offensive Security
W2
About the Role
We are seeking an experienced Senior Infrastructure Penetration Tester to join our Offensive Security organization. The ideal candidate will have approximately 6+ years of hands-on penetration testing experience in large-scale technology environments and a strong understanding of enterprise infrastructure, cloud platforms, identity systems, networks, and modern attack techniques.
In this role, you will conduct sophisticated security assessments across corporate infrastructure, cloud environments, data centers, production services, identity platforms, and internet-facing assets. You will work closely with infrastructure, cloud, engineering, security operations, and incident response teams to identify exploitable weaknesses and drive measurable risk reduction.
The successful candidate should be comfortable operating independently, developing attack paths, chaining vulnerabilities, and communicating technical findings to both engineers and senior leadership.
Key Responsibilities
Infrastructure Penetration Testing
- Plan and execute internal and external infrastructure penetration tests across large enterprise environments.
- Assess Windows, Linux, Unix, network, virtualization, container, and hybrid infrastructure.
- Conduct network, host, service, and application-layer security testing.
- Identify vulnerabilities and demonstrate realistic attack paths and business impact.
- Perform authenticated and unauthenticated penetration testing.
- Conduct lateral movement, privilege escalation, credential-access, and persistence assessments within authorized environments.
- Evaluate segmentation and security controls between corporate, production, R&D, cloud, and restricted environments.
- Assess security of common enterprise services including DNS, DHCP, VPN, SSH, HTTP/S, LDAP, Kerberos, SMB, RDP, databases, proxies, and authentication infrastructure.
Active Directory & Identity Security
- Perform penetration testing of Active Directory and enterprise identity environments.
- Assess Kerberos, NTLM, LDAP, Group Policy, trusts, privileged accounts, service accounts, and delegation configurations.
- Identify paths to domain administrator and other high-value privileges.
- Evaluate identity federation, SSO, MFA, privileged access management, and service identities.
- Assess identity attack paths across hybrid environments such as on-premises Active Directory and cloud identity providers.
Cloud & Modern Infrastructure
- Conduct penetration testing across AWS, Azure, and/or Google Cloud Platform environments.
- Assess cloud IAM, roles, policies, storage, compute, networking, APIs, secrets, and management interfaces.
- Test cloud-to-corporate and cloud-to-production attack paths.
- Assess Kubernetes, containers, Docker, service meshes, and cloud-native infrastructure.
- Identify privilege-escalation and lateral-movement opportunities across cloud environments.
- Evaluate infrastructure-as-code and configuration risks where applicable.
External Attack Surface
- Perform continuous and point-in-time assessments of internet-facing infrastructure.
- Identify exposed services, misconfigurations, vulnerabilities, weak authentication, and attack paths.
- Conduct reconnaissance and attack-surface analysis using both commercial and open-source technologies.
- Validate findings from vulnerability scanners through manual exploitation and controlled testing.
- Assess perimeter security, WAFs, firewalls, VPNs, reverse proxies, CDN infrastructure, and other defensive controls.
Adversary Simulation
- Develop realistic attack scenarios based on current threat actor techniques.
- Chain multiple weaknesses to demonstrate realistic compromise scenarios.
- Collaborate with Red Team, Purple Team, Detection Engineering, and Security Operations teams.
- Develop proof-of-concept exploits and attack automation where appropriate.
- Validate preventive and detective security controls.
- Translate offensive findings into actionable defensive improvements.
Automation & Tool Development
- Develop scripts and tooling to improve penetration-testing efficiency and scalability.
- Automate reconnaissance, vulnerability validation, attack-path discovery, evidence collection, and reporting.
- Integrate offensive-security tooling into enterprise security workflows.
- Leverage Python, PowerShell, Bash, and other scripting/programming languages.
- Evaluate and responsibly use AI-assisted security testing tools while maintaining human validation and authorization controls.
Reporting & Risk Management
- Produce high-quality penetration-testing reports that clearly communicate:
- Vulnerability
- Attack path
- Exploitability
- Business impact
- Affected assets
- Evidence
- Remediation recommendations
- Present findings to engineering teams, security leadership, and executive stakeholders.
- Work with infrastructure owners to validate remediation and perform retesting.
- Track recurring weaknesses and identify systemic security issues.
- Help establish security metrics such as remediation rates, exploitability, attack-path reduction, and risk exposure.
Required Qualifications
- 6+ years of professional experience in penetration testing, offensive security, infrastructure security, or closely related cybersecurity disciplines.
- Strong hands-on experience conducting enterprise infrastructure penetration tests.
- Deep understanding of TCP/IP networking and common enterprise protocols.
- Strong Windows and Linux security knowledge.
- Demonstrated experience with Active Directory and enterprise identity systems.
- Experience with cloud security and at least one major cloud platform: AWS, Azure, or Google Cloud Platform.
- Experience identifying and exploiting common infrastructure vulnerabilities.
- Strong understanding of authentication, authorization, privilege escalation, lateral movement, and defense evasion concepts.
- Experience with vulnerability scanners and manual validation.
- Strong scripting skills in Python, PowerShell, Bash, or similar languages.
- Ability to independently scope, execute, document, and communicate penetration-testing engagements.
- Strong written and verbal communication skills.
- Ability to work effectively with infrastructure and engineering teams in a large technology organization.
- Demonstrated ability to operate within strict rules of engagement and responsible-disclosure requirements.
Preferred Qualifications
- Experience working in a large-scale Big Tech or hyperscale technology environment.
- Experience with Kubernetes, Docker, containers, service meshes, and cloud-native architectures.
- Experience testing CI/CD infrastructure, DevOps platforms, and infrastructure-as-code.
- Experience with security testing of APIs and microservices.
- Experience with red teaming or adversary simulation.
- Experience developing custom offensive-security tooling.
- Experience with attack-path analysis and identity-centric security assessments.
- Experience assessing zero-trust architectures.
- Experience with security testing of SaaS and internally developed enterprise platforms.
- Understanding of software supply-chain security and CI/CD attack paths.
- Experience working with bug bounty or vulnerability disclosure programs.
- Experience integrating penetration testing into enterprise security programs.
Technical Skills
Operating Systems
- Windows / Windows Server
- Linux / Unix
- macOS
Networking
- TCP/IP
- DNS
- HTTP/S
- SSH
- VPN
- SMB
- RDP
- LDAP
- Kerberos
- TLS
- Firewalls / WAF / Proxies
Identity
- Active Directory
- Entra ID / Azure AD
- LDAP
- Kerberos
- SAML
- OAuth/OIDC
- MFA
- PAM
Cloud
- AWS
- Azure
- Google Cloud Platform
- IAM
- VPC/VNet
- Cloud storage
- Containers
- Kubernetes
Security Tools
Candidates should be able to understand and adapt tools rather than simply execute automated scanners.
Core Competencies
- Offensive Security Mindset
- Enterprise Infrastructure Expertise
- Identity & Active Directory Security
- Cloud Security
- Attack-Path Analysis
- Adversary Simulation
- Automation & Tool Development
- Risk-Based Thinking
- Strong Technical Communication
- Engineering Partnership
Role Profile
This is a hands-on senior individual contributor role. The ideal candidate is not simply a vulnerability scanner or compliance tester they are an experienced security engineer who can think like an attacker, understand complex enterprise infrastructure, demonstrate realistic compromise paths, and work with engineering teams to eliminate systemic weaknesses.