Evolve Security
USA
OSOC Security Analyst - Cloud Pentesting
We tailor your resume to this role and apply for you in seconds.
Apply to OSOC Security Analyst - Cloud Pentesting at Evolve SecurityJob details
- Location
- USA
- Work type
- Onsite
- Posted
- 3 days ago
- Apply on
- apply.workable.com
About this role
Evolve Security is looking for an OSOC Security Analyst to join its growing team. This position will assist with the overall successful delivery of various application vulnerability assessments, continuous internal / external penetration assessments, cloud security assessments, incident response and detection assessments, and other types of security strategy and architecture reviews.
## Responsibilities
- Conduct hands-on cloud penetration testing across Azure, AWS, and GCP environments, identifying IAM misconfigurations, excessive permissions, privilege escalation paths, exposed storage buckets/blobs, and exploitable service misconfigurations.
- Perform offensive enumeration and attack-path mapping against cloud environments using tools such as ScoutSuite, Prowler, Pacu, ROADtools/ADRecon, and GCP-focused tooling.
- Review the eASM dashboard daily to monitor for anomalies or security incidents.
- Conduct testing and validation of vulnerabilities identified by the ASM system, providing evidence of validation to support remediation efforts.
- Investigate eASM vulnerabilities thoroughly, analyzing potential impact and root causes.
- Conduct various types of penetration testing, including scanning and password attacks, to identify potential weaknesses in the system.
- Perform cloud penetration testing and security configuration reviews across Azure and AWS environments, identifying misconfigurations, excessive permissions, and exploitable weaknesses.
- Perform technical vulnerability scans and validate remediation efforts to ensure an effective security posture.
- Escalate identified vulnerabilities and security incidents to appropriate client or internal team members for resolution.
- Engage with clients during project kick-off meetings to understand their specific security requirements and objectives.
- Assist in maturing Evolve Security eASM processes, procedures, templates, and methodologies to enhance overall effectiveness.
- Take on other duties as assigned to support the growth and expansion of enterprise and academy initiatives, contributing to the overall success of the security program.
## Requirements
- Passion for cybersecurity and curiosity to learn.
- Foundational understanding of cloud security concepts and offensive testing methodology for Azure, AWS, and/or GCP, such as IAM abuse, privilege escalation, storage misconfigurations, and metadata service exploitation.
- Hands-on exposure through labs, coursework, CTFs, or professional experience to cloud-native offensive tools such as ScoutSuite, Prowler, Pacu, ROADtools, ADRecon, or GCP enumeration/exploitation tooling.
- Security+ required; cloud security or offensive certifications are a strong plus, including AZ-500, AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer, or equivalent cloud pentesting coursework/labs.
- 0–1 years of information technology experience, ideally with a focus on information security.
- 0–1 years of penetration testing, application, and vulnerability management experience through education or work at a security/consulting firm.
- Exposure to cloud security concepts and penetration testing methodologies for Azure and/or AWS environments, gained through education, labs, or professional experience.
- Knowledge of multiple operating systems and associated command-line administration tools (Bash / PowerShell).
- Knowledge of the application stack, including web.
- Familiarity with cloud-native and cloud pentesting tools such as ScoutSuite, Prowler, Pacu, ROADtools, and ADRecon is a plus.
- Scripting experience in one or more of Ruby, Python, Perl, or Bash.
- ESCP and Security+ certifications; cloud security certifications such as AZ-500 or AWS Certified Security – Specialty are a plus.
- Desire to tinker and understand how things work.
- Ability to interface with clients, utilizing consulting and negotiating skills.
- Strong self-motivation and ability to work independently toward team objectives.
- Strong oral and written communication skills and ability to work as part of a team.
Ready to apply to Evolve Security?
ApplyBolt finds matching jobs, tailors your resume, and submits applications for you.