About the job
Appspace is looking for a Cloud Security and Penetration Testing Engineer to join the team remotely from Dallas, Texas. This role centers on securing cloud environments and performing manual penetration testing for clients across a range of industries. The focus is on Google Cloud Platform, but work also extends to Microsoft Azure and Amazon Web Services.
Role overview
This engineer partners directly with clients to design secure cloud configurations, test web applications, and protect complex cloud deployments. The position calls for hands-on experience in SaaS security, network security, and compliance. Both strategic guidance and practical support are part of the day-to-day work, helping clients keep their cloud infrastructures secure and compliant.
What you will do
- Conduct manual penetration testing on web and mobile applications using black-box, gray-box, and white-box methods, as well as DAST and SAST tools. Red teaming experience is important.
- Analyze application architecture, understand business goals, and review code at a high level. Contribute to establishing secure coding practices.
- Serve as the subject matter expert for web application security, with a strong focus on the OWASP Top 10 and Application Security Verification Standard (ASVS). Present findings and recommend solutions.
- Design, implement, and refine cloud security architectures. Monitor and respond to security alerts from SIEM and related systems. The role requires availability Monday through Friday, 8 AM to 5 PM EDT, plus on-call shifts during evenings and weekends.
- Apply network and cloud security knowledge to address customer questions and concerns.
Requirements
- Hands-on experience in SaaS security, network security, and compliance.
- Strong background in cloud platforms, especially GCP, with exposure to Azure and AWS.
- Experience with manual penetration testing and red teaming.
- Familiarity with secure coding practices and application security standards.
- Ability to communicate technical findings clearly to clients and recommend practical solutions.
- Willingness to work standard hours (Monday–Friday, 8 AM to 5 PM EDT) and participate in on-call shifts.

