OSOC Security Analyst – Cloud Pentesting

Job not on LinkedIn

🕒 May 7

🇺🇸 United States – Remote

💵 $50k / year

⏰ Full Time

🟢 Junior

🔐 Security Analyst

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 26%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Evolve Security

Evolve Security

51 - 200 employees

🔒 Cybersecurity

Cybersecurity

Evolve Security is a cybersecurity company offering a range of services designed to protect and secure technology infrastructures. Their comprehensive offerings include penetration testing, vulnerability scanning, cloud security assessment, and social engineering assessments. The company utilizes its Darwin Attack® platform to provide continuous and proactive security services, helping organizations improve security posture and compliance while reducing risks. Evolve Security is committed to helping clients manage their external attack surface, offering strategic advisory services to enhance security programs.

📋 Description

• Conduct hands-on cloud penetration testing across Azure, AWS, and GCP environments • Identify IAM misconfigurations, excessive permissions, privilege escalation paths, exposed storage buckets/blobs, and exploitable service misconfigurations • Perform offensive enumeration and attack-path mapping using ScoutSuite, Prowler, Pacu, ROADtools/ADRecon, and GCP-focused tooling • Review the eASM dashboard daily to monitor for anomalies or security incidents • Test and validate vulnerabilities identified by the ASM system and provide evidence supporting remediation • Investigate eASM vulnerabilities, analyzing potential impact and root causes • Conduct penetration testing, including scanning and password attacks • Perform cloud security configuration reviews across Azure and AWS • Perform technical vulnerability scans and validate remediation efforts • Escalate vulnerabilities and security incidents to appropriate client or internal team members • Engage with clients during project kick-off meetings to understand security requirements and objectives • Assist in maturing Evolve Security eASM processes, procedures, templates, and methodologies • Support enterprise and academy initiatives and other assigned duties

🎯 Requirements

• Passionate about cybersecurity with a curiosity to learn • Foundational understanding of cloud security concepts and offensive testing methodology for Azure, AWS, and/or GCP • Hands-on exposure via labs, coursework, CTFs, or professional experience to cloud-native offensive tools such as ScoutSuite, Prowler, Pacu, ROADtools, ADRecon, or GCP enumeration/exploitation tooling • Security+ required • 0-1 years of information technology experience, ideally with a focus on information security • 0-1 years penetration testing, application and vulnerability management experience through education or security/consulting firm • Exposure to cloud security concepts and penetration testing methodologies for Azure and/or AWS environments • Knowledge of multiple operating systems and associated command-line administration tools, including Bash and PowerShell • Knowledge of the application stack including web • Familiarity with cloud-native and cloud pentesting tools such as ScoutSuite, Prowler, Pacu, ROADtools, and ADRecon is a plus • Scripting experience in Ruby, Python, Perl, or Bash • ESCP and Security+ certifications; cloud security certifications such as AZ-500 or AWS Certified Security – Specialty are a plus • Ability to interface with clients, utilizing consulting and negotiating skills • Strongly self-motivated and able to work independently towards team objectives • Strong communication skills, oral and written, and ability to work as part of a team

🏖️ Benefits

• Healthcare Benefits • 401(k) Match • Parental Leave • Flexible Paid Time Off • Annual vacation reimbursement

Apply Now