Evolve Security logo
Evolve Security
Posted 12 days agoVerified live 1d ago

OSOC Security Analyst - Cloud Pentesting

Brief overview

Remote
UndergradOr in progress
$50k/yrStated minimum
Cloud Penetration TestingAzure Cloud SecurityAWS Cloud SecurityGCP Cloud SecuritySecurity+ScoutSuiteProwlerPacuROADtoolsADReconPythonBashConsulting and Negotiation

About the company

Evolve Security logo
Evolve Securityevolvesecurity.com

Evolve Security is a technical cybersecurity services firm dedicated to improving your security posture where you are most vulnerable.

Job description

Summary

Evolve Security is a cybersecurity services firm providing continuous penetration testing, training services, and talent solutions. The OSOC Security Analyst will conduct cloud penetration testing, vulnerability assessments, attack-path mapping, security configuration reviews, and incident investigations across Azure, AWS, and GCP environments while supporting clients and improving security processes.

Responsibilities

  • Conduct hands-on cloud penetration testing across Azure, AWS, and GCP environments, identifying IAM misconfigurations, excessive permissions, privilege escalation paths, exposed storage buckets/blobs, and exploitable service misconfigurations
  • Perform offensive enumeration and attack-path mapping against cloud environments using tools such as ScoutSuite, Prowler, Pacu, ROADtools/ADRecon, and GCP-focused tooling
  • Review eASM dashboard daily to monitor for any anomalies or security incidents
  • Conduct testing and validation of vulnerabilities identified by the ASM system, providing evidence of validation to support remediation efforts
  • Investigate eASM vulnerabilities thoroughly, analyzing potential impact and root causes
  • Conduct various types of penetration testing, including scanning and password attacks, to identify potential weaknesses in the system
  • Perform cloud penetration testing and security configuration reviews across Azure and AWS environments, identifying misconfigurations, excessive permissions, and exploitable weaknesses
  • Perform technical vulnerability scans and validate remediation efforts to ensure effective security posture
  • Escalate identified vulnerabilities and security incidents to appropriate client or internal team members for resolution
  • Engage with clients during project kick-off meetings to understand their specific security requirements and objectives
  • Assist in maturing eASM Evolve Security processes, procedures, templates, and methodologies to enhance overall effectiveness
  • Take on other duties as assigned to support the growth and expansion of enterprise and academy initiatives, contributing to the overall success of the security program

Skills

  • Passionate about cybersecurity with a curiosity to learn
  • Foundational understanding of cloud security concepts and offensive testing methodology for Azure, AWS, and/or GCP (e.g., IAM abuse, privilege escalation, storage misconfigurations, metadata service exploitation)
  • Hands-on exposure (via labs, coursework, CTFs, or professional experience) to cloud-native offensive tools such as ScoutSuite, Prowler, Pacu, ROADtools, ADRecon, or GCP enumeration/exploitation tooling
  • Security+ required
  • 0-1 years of information technology experience, ideally with a focus on information security
  • 0- 1 years penetration testing, application and vulnerability management experience through education or security/consulting firm
  • Exposure to cloud security concepts and penetration testing methodologies for Azure and/or AWS environments (e.g., IAM misconfigurations, storage bucket/blob exposure, privilege escalation paths), gained through education, labs, or professional experience
  • Knowledge of multiple operating systems and associated command-line administration tools (Bash / PowerShell)
  • Knowledge of the application stack including web
  • Scripting experience in one or more of: Ruby, Python, Perl, Bash
  • ESCP, Security+ certifications
  • A desire to tinker and understand how things work
  • Ability to interface with clients, utilizing consulting and negotiating skills
  • Strongly self-motivated and able to work independently towards team objectives
  • Strong communication skills (oral and written) and ability to work as part of a team
  • Cloud security or offensive certifications a strong plus (AZ-500, AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer, or equivalent cloud pentesting coursework/labs)
  • Familiarity with cloud-native and cloud pentesting tools (e.g., ScoutSuite, Prowler, Pacu, ROADtools, ADRecon) is a plus
  • Cloud security certifications (e.g., AZ-500, AWS Certified Security – Specialty) a plus

Qualifications

Must Haves

  • Passionate about cybersecurity with a curiosity to learn
  • Foundational understanding of cloud security concepts and offensive testing methodology for Azure, AWS, and/or GCP (e.g., IAM abuse, privilege escalation, storage misconfigurations, metadata service exploitation)
  • Hands-on exposure (via labs, coursework, CTFs, or professional experience) to cloud-native offensive tools such as ScoutSuite, Prowler, Pacu, ROADtools, ADRecon, or GCP enumeration/exploitation tooling
  • Security+ required
  • 0-1 years of information technology experience, ideally with a focus on information security
  • 0- 1 years penetration testing, application and vulnerability management experience through education or security/consulting firm
  • Exposure to cloud security concepts and penetration testing methodologies for Azure and/or AWS environments (e.g., IAM misconfigurations, storage bucket/blob exposure, privilege escalation paths), gained through education, labs, or professional experience
  • Knowledge of multiple operating systems and associated command-line administration tools (Bash / PowerShell)
  • Knowledge of the application stack including web
  • Scripting experience in one or more of: Ruby, Python, Perl, Bash
  • ESCP, Security+ certifications
  • A desire to tinker and understand how things work
  • Ability to interface with clients, utilizing consulting and negotiating skills
  • Strongly self-motivated and able to work independently towards team objectives
  • Strong communication skills (oral and written) and ability to work as part of a team

Nice to Haves

  • cloud security or offensive certifications a strong plus (AZ-500, AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer, or equivalent cloud pentesting coursework/labs)
  • Familiarity with cloud-native and cloud pentesting tools (e.g., ScoutSuite, Prowler, Pacu, ROADtools, ADRecon) is a plus
  • cloud security certifications (e.g., AZ-500, AWS Certified Security – Specialty) a plus

Benefits

  • Healthcare Benefits
  • 401(k) Match
  • Parental Leave
  • Flexible Paid Time Off
  • Annual vacation reimbursement

More jobs like this