Skip to content

Open nowPosted 11 days ago

OSOC Security Analyst - Cloud Pentesting

Workable (global search)108,016 open roles

Where
United States
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowOSOC Security Analyst - Cloud PentestingWorkable (global search) · United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 11 days ago

Workable (global search) median: 7 days open

The posting

Evolve Security is looking for an OSOC Security Analyst to join our growing team. This position will assist with the overall successful delivery of various application vulnerability assessments, continuous internal / external penetration assessments, cloud security assessments, incident response and detection assessments, and other types of security strategy and architecture reviews.

Responsibilities include:

  • Conduct hands-on cloud penetration testing across Azure, AWS, and GCP environments, identifying IAM misconfigurations, excessive permissions, privilege escalation paths, exposed storage buckets/blobs, and exploitable service misconfigurations
  • Perform offensive enumeration and attack-path mapping against cloud environments using tools such as ScoutSuite, Prowler, Pacu, ROADtools/ADRecon, and GCP-focused tooling.
  • Review eASM dashboard daily to monitor for any anomalies or security incidents.
  • Conduct testing and validation of vulnerabilities identified by the ASM system, providing evidence of validation to support remediation efforts.
  • Investigate eASM vulnerabilities thoroughly, analyzing potential impact and root causes.
  • Conduct various types of penetration testing, including scanning and password attacks, to identify potential weaknesses in the system.
  • Perform cloud penetration testing and security configuration reviews across Azure and AWS environments, identifying misconfigurations, excessive permissions, and exploitable weaknesses.
  • Perform technical vulnerability scans and validate remediation efforts to ensure effective security posture.
  • Escalate identified vulnerabilities and security incidents to appropriate client or internal team members for resolution.
  • Engage with clients during project kick-off meetings to understand their specific security requirements and objectives.
  • Assist in maturing eASM Evolve Security processes, procedures, templates, and methodologies to enhance overall effectiveness.
  • Take on other duties as assigned to support the growth and expansion of enterprise and academy initiatives, contributing to the overall success of the security program.

Requirements

  • Passionate about cybersecurity with a curiosity to learn
  • Foundational understanding of cloud security concepts and offensive testing methodology for Azure, AWS, and/or GCP (e.g., IAM abuse, privilege escalation, storage misconfigurations, metadata service exploitation).
  • Hands-on exposure (via labs, coursework, CTFs, or professional experience) to cloud-native offensive tools such as ScoutSuite, Prowler, Pacu, ROADtools, ADRecon, or GCP enumeration/exploitation tooling.
  • Security+ required; cloud security or offensive certifications a strong plus (AZ-500, AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer, or equivalent cloud pentesting coursework/labs).
  • 0-1 years of information technology experience, ideally with a focus on information security
  • 0- 1 years penetration testing, application and vulnerability management experience through education or security/consulting firm
  • Exposure to cloud security concepts and penetration testing methodologies for Azure and/or AWS environments (e.g., IAM misconfigurations, storage bucket/blob exposure, privilege escalation paths), gained through education, labs, or professional experience
  • Knowledge of multiple operating systems and associated command-line administration tools (Bash / PowerShell)
  • Knowledge of the application stack including web
  • Familiarity with cloud-native and cloud pentesting tools (e.g., ScoutSuite, Prowler, Pacu, ROADtools, ADRecon) is a plus
  • Scripting experience in one or more of: Ruby, Python, Perl, Bash
  • ESCP, Security+ certifications; cloud security certifications (e.g., AZ-500, AWS Certified Security – Specialty) a plus
  • A desire to tinker and understand how things work
  • Ability to interface with clients, utilizing consulting and negotiating skills
  • Strongly self-motivated and able to work independently towards team objectives
  • Strong communication skills (oral and written) and ability to work as part of a team

Benefits

Who is Evolve Security?

Evolve Security is a cybersecurity services firm headquartered in Chicago, IL. We are dedicated to improving our client’s security posture by providing continuous penetration testing, training services, and talent solutions.

In addition to our professional cybersecurity service offerings, Evolve Security offers a cybersecurity bootcamp, “Evolve Academy”, currently ranked the #1 cybersecurity bootcamp in the world. The Cybersecurity Bootcamp in Chicago provides immersive training, giving students the concrete and practical skills, needed on the job. Students gain real work experience through live security assessment work that they perform on not-for-profit companies.

We are passionate about directly improving our customers’ security posture, and we proudly train others to help meet the need for qualified cybersecurity talent.

Benefits Include

  • Healthcare Benefits
  • 401(k) Match
  • Parental Leave
  • Flexible Paid Time Off
  • Annual vacation reimbursement

Salary: $50,000/year

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.