Summary
Evolve Security is a cybersecurity services firm providing continuous penetration testing, training services, and talent solutions. The OSOC Security Analyst will conduct cloud penetration testing, vulnerability assessments, attack-path mapping, security configuration reviews, and incident investigations across Azure, AWS, and GCP environments while supporting clients and improving security processes.
Responsibilities
- Conduct hands-on cloud penetration testing across Azure, AWS, and GCP environments, identifying IAM misconfigurations, excessive permissions, privilege escalation paths, exposed storage buckets/blobs, and exploitable service misconfigurations
- Perform offensive enumeration and attack-path mapping against cloud environments using tools such as ScoutSuite, Prowler, Pacu, ROADtools/ADRecon, and GCP-focused tooling
- Review eASM dashboard daily to monitor for any anomalies or security incidents
- Conduct testing and validation of vulnerabilities identified by the ASM system, providing evidence of validation to support remediation efforts
- Investigate eASM vulnerabilities thoroughly, analyzing potential impact and root causes
- Conduct various types of penetration testing, including scanning and password attacks, to identify potential weaknesses in the system
- Perform cloud penetration testing and security configuration reviews across Azure and AWS environments, identifying misconfigurations, excessive permissions, and exploitable weaknesses
- Perform technical vulnerability scans and validate remediation efforts to ensure effective security posture
- Escalate identified vulnerabilities and security incidents to appropriate client or internal team members for resolution
- Engage with clients during project kick-off meetings to understand their specific security requirements and objectives
- Assist in maturing eASM Evolve Security processes, procedures, templates, and methodologies to enhance overall effectiveness
- Take on other duties as assigned to support the growth and expansion of enterprise and academy initiatives, contributing to the overall success of the security program
Skills
- Passionate about cybersecurity with a curiosity to learn
- Foundational understanding of cloud security concepts and offensive testing methodology for Azure, AWS, and/or GCP (e.g., IAM abuse, privilege escalation, storage misconfigurations, metadata service exploitation)
- Hands-on exposure (via labs, coursework, CTFs, or professional experience) to cloud-native offensive tools such as ScoutSuite, Prowler, Pacu, ROADtools, ADRecon, or GCP enumeration/exploitation tooling
- Security+ required
- 0-1 years of information technology experience, ideally with a focus on information security
- 0- 1 years penetration testing, application and vulnerability management experience through education or security/consulting firm
- Exposure to cloud security concepts and penetration testing methodologies for Azure and/or AWS environments (e.g., IAM misconfigurations, storage bucket/blob exposure, privilege escalation paths), gained through education, labs, or professional experience
- Knowledge of multiple operating systems and associated command-line administration tools (Bash / PowerShell)
- Knowledge of the application stack including web
- Scripting experience in one or more of: Ruby, Python, Perl, Bash
- ESCP, Security+ certifications
- A desire to tinker and understand how things work
- Ability to interface with clients, utilizing consulting and negotiating skills
- Strongly self-motivated and able to work independently towards team objectives
- Strong communication skills (oral and written) and ability to work as part of a team
- Cloud security or offensive certifications a strong plus (AZ-500, AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer, or equivalent cloud pentesting coursework/labs)
- Familiarity with cloud-native and cloud pentesting tools (e.g., ScoutSuite, Prowler, Pacu, ROADtools, ADRecon) is a plus
- Cloud security certifications (e.g., AZ-500, AWS Certified Security – Specialty) a plus
Qualifications
Must Haves
- Passionate about cybersecurity with a curiosity to learn
- Foundational understanding of cloud security concepts and offensive testing methodology for Azure, AWS, and/or GCP (e.g., IAM abuse, privilege escalation, storage misconfigurations, metadata service exploitation)
- Hands-on exposure (via labs, coursework, CTFs, or professional experience) to cloud-native offensive tools such as ScoutSuite, Prowler, Pacu, ROADtools, ADRecon, or GCP enumeration/exploitation tooling
- Security+ required
- 0-1 years of information technology experience, ideally with a focus on information security
- 0- 1 years penetration testing, application and vulnerability management experience through education or security/consulting firm
- Exposure to cloud security concepts and penetration testing methodologies for Azure and/or AWS environments (e.g., IAM misconfigurations, storage bucket/blob exposure, privilege escalation paths), gained through education, labs, or professional experience
- Knowledge of multiple operating systems and associated command-line administration tools (Bash / PowerShell)
- Knowledge of the application stack including web
- Scripting experience in one or more of: Ruby, Python, Perl, Bash
- ESCP, Security+ certifications
- A desire to tinker and understand how things work
- Ability to interface with clients, utilizing consulting and negotiating skills
- Strongly self-motivated and able to work independently towards team objectives
- Strong communication skills (oral and written) and ability to work as part of a team
Nice to Haves
- cloud security or offensive certifications a strong plus (AZ-500, AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer, or equivalent cloud pentesting coursework/labs)
- Familiarity with cloud-native and cloud pentesting tools (e.g., ScoutSuite, Prowler, Pacu, ROADtools, ADRecon) is a plus
- cloud security certifications (e.g., AZ-500, AWS Certified Security – Specialty) a plus
Benefits
- Healthcare Benefits
- 401(k) Match
- Parental Leave
- Flexible Paid Time Off
- Annual vacation reimbursement