For Employers

Evolve Security

OSOC Security Analyst - Cloud Pentesting

Posted 2 hours ago
Apply Now

Please mention DailyRemote when applying

?/100
Resume Match Score

Match your resume skills with our AI powered skill match!

Get professional review

Questions interviewers often ask for this role, with sample answers.

Create a cover letter for this job

Upload your resume and we draft a letter for this exact role, tailored to what it asks for.

  • Tailored to this role
  • Based on your resume
  • Fully editable

Evolve Security is looking for an OSOC Security Analyst to join our growing team. This position will assist with the overall successful delivery of various application vulnerability assessments, continuous internal / external penetration assessments, cloud security assessments, incident response and detection assessments, and other types of security strategy and architecture reviews.

Responsibilities include:

  • Conduct hands-on cloud penetration testing across Azure, AWS, and GCP environments, identifying IAM misconfigurations, excessive permissions, privilege escalation paths, exposed storage buckets/blobs, and exploitable service misconfigurations
  • Perform offensive enumeration and attack-path mapping against cloud environments using tools such as ScoutSuite, Prowler, Pacu, ROADtools/ADRecon, and GCP-focused tooling.
  • Review eASM dashboard daily to monitor for any anomalies or security incidents.
  • Conduct testing and validation of vulnerabilities identified by the ASM system, providing evidence of validation to support remediation efforts.
  • Investigate eASM vulnerabilities thoroughly, analyzing potential impact and root causes.
  • Conduct various types of penetration testing, including scanning and password attacks, to identify potential weaknesses in the system.
  • Perform cloud penetration testing and security configuration reviews across Azure and AWS environments, identifying misconfigurations, excessive permissions, and exploitable weaknesses.
  • Perform technical vulnerability scans and validate remediation efforts to ensure effective security posture.
  • Escalate identified vulnerabilities and security incidents to appropriate client or internal team members for resolution.
  • Engage with clients during project kick-off meetings to understand their specific security requirements and objectives.
  • Assist in maturing eASM Evolve Security processes, procedures, templates, and methodologies to enhance overall effectiveness.
  • Take on other duties as assigned to support the growth and expansion of enterprise and academy initiatives, contributing to the overall success of the security program.

Requirements

  • Passionate about cybersecurity with a curiosity to learn 
  • Foundational understanding of cloud security concepts and offensive testing methodology for Azure, AWS, and/or GCP (e.g., IAM abuse, privilege escalation, storage misconfigurations, metadata service exploitation).
  • Hands-on exposure (via labs, coursework, CTFs, or professional experience) to cloud-native offensive tools such as ScoutSuite, Prowler, Pacu, ROADtools, ADRecon, or GCP enumeration/exploitation tooling.
  • Security+ required; cloud security or offensive certifications a strong plus (AZ-500, AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer, or equivalent cloud pentesting coursework/labs).
  • 0-1 years of information technology experience, ideally with a focus on information security  
  • 0- 1 years penetration testing, application and vulnerability management experience through education or security/consulting firm 
  • Exposure to cloud security concepts and penetration testing methodologies for Azure and/or AWS environments (e.g., IAM misconfigurations, storage bucket/blob exposure, privilege escalation paths), gained through education, labs, or professional experience
  • Knowledge of multiple operating systems and associated command-line administration tools (Bash / PowerShell) 
  • Knowledge of the application stack including web 
  • Familiarity with cloud-native and cloud pentesting tools (e.g., ScoutSuite, Prowler, Pacu, ROADtools, ADRecon) is a plus
  • Scripting experience in one or more of: Ruby, Python, Perl, Bash
  • ESCP, Security+ certifications; cloud security certifications (e.g., AZ-500, AWS Certified Security – Specialty) a plus
  • A desire to tinker and understand how things work 
  • Ability to interface with clients, utilizing consulting and negotiating skills 
  • Strongly self-motivated and able to work independently towards team objectives 
  • Strong communication skills (oral and written) and ability to work as part of a team 

Benefits

Who is Evolve Security?  

Evolve Security is a cybersecurity services firm headquartered in Chicago, IL. We are dedicated to improving our client’s security posture by providing continuous penetration testing, training services, and talent solutions.    

In addition to our professional cybersecurity service offerings, Evolve Security offers a cybersecurity bootcamp, “Evolve Academy”, currently ranked the #1 cybersecurity bootcamp in the world. The Cybersecurity Bootcamp in Chicago provides immersive training, giving students the concrete and practical skills, needed on the job. Students gain real work experience through live security assessment work that they perform on not-for-profit companies.  

We are passionate about directly improving our customers’ security posture, and we proudly train others to help meet the need for qualified cybersecurity talent.  

Benefits Include 

  • Healthcare Benefits 
  • 401(k) Match 
  • Parental Leave 
  • Flexible Paid Time Off 
  • Annual vacation reimbursement 

Salary: $50,000/year

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Others jobs →

AI Response Evaluator

Freelance France, Japan, Mexico +3 more $10K – $20K Others

Operations Manager, Travel & Meetings Services

Full Time United States $75000 - $110K per year Others

bnsf tech Trainee 2027 (Remote - US)

Full Time United States $105K per year Others

Partner Business Manager

Full Time United States $175K - $411K per year Others

Partner Business Manager

Full Time United States $175K - $411K per year Others

Client Manager, Commercial Risk - Innovation Practice

Full Time United States Others
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Featuring 219,844+ Jobs in Security Analyst

Answer easy questions

Answer easy questions

219,844+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified