I will pentest and secure your cloud and kubernetes
Offensive Security Engineer
Vetted by Fiverr Pro
Eric L was selected by the Fiverr Pro team for their expertise.
Vetted for
Cybersecurity
About this Gig
Vetted Pro
Cloud & Kubernetes Penetration Testing AWS, Azure, GCP
6+ years in offensive security. Cloud and Kubernetes security assessment aligned to CIS Benchmarks, OWASP Kubernetes Top 10, and NIST SP 800-115, suitable for SOC 2, ISO 27001, HIPAA, and PCI-DSS.
Platforms: AWS, Azure, GCP, EKS, AKS, GKE, self-managed Kubernetes
Scope:
- IAM users, roles, policies, privilege escalation paths
- Storage S3, Blob, GCS buckets, public exposure, encryption
- Network security groups, VPC, exposed services
- Compute EC2, VMs, metadata service, secrets in user data
- Serverless & containers Lambda, Functions, ECR/ACR images
- Logging & monitoring CloudTrail, GuardDuty, alerting gaps
- Kubernetes RBAC, pod security, network policies, secrets
- Cluster attacks container escape, API server, etcd, kubelet
- CI/CD pipeline secrets, image supply chain, admission controls
Deliverables:
- Executive summary for leadership and auditors
- Technical report with CVSSv4, PoC, reproduction steps
- CIS Benchmark compliance matrix
- Attack path diagrams
- Prioritized remediation roadmap with IaC fixes
- Retest (depends on the ordered package)
Industries: fintech, healthcare, SaaS, crypto/Web3, enterprise.
My Portfolio
Other Cybersecurity Services I Offer
FAQ
Which cloud providers do you test?
AWS, Azure, and GCP, including managed Kubernetes (EKS, AKS, GKE) and self-hosted clusters. Multi-cloud environments are welcome.
What do you need from me to get started?
A read-only (SecurityAudit) IAM role or service account, a kubeconfig with view access, and a brief overview of your architecture and critical assets. For black-box testing, only your account IDs and public endpoints.
Is this a configuration audit or a real penetration test?
Both. I audit configurations against CIS Benchmarks, then actively exploit findings to demonstrate real attack paths such as privilege escalation, lateral movement, and container escape.
Will testing disrupt my production environment?
No. Testing is non-destructive and read-only by default. Any exploitation is done within agreed scope and time windows, and I never delete, modify, or exfiltrate customer data.
Can you test only Kubernetes or only cloud?
Yes. Either can be scoped separately or combined for a full assessment.
What does the final report look like?
An executive summary for leadership and auditors, a technical report with CVSSv4 scores, PoC, and reproduction steps, a CIS compliance matrix, attack path diagrams, and remediation guidance with Terraform and YAML fixes.
Is my environment and data kept confidential?
Yes. I sign an NDA on request, use temporary credentials that you revoke after the engagement, and permanently delete all evidence and artifacts after delivery.
