561,906open jobs
22,097companies
76,904added this week
Browse all
Salary
$50k per year
Location
Remote (United States)
Employment
Full-Time
Overview
Company
Impact
Profile match

Evolve Security is looking for an OSOC Security Analyst to join our growing team. This position will assist with the overall successful delivery of various application vulnerability assessments, continuous internal / external penetration assessments, cloud security assessments, incident response and detection assessments, and other types of security strategy and architecture reviews.

Responsibilities include:

  • Conduct hands-on cloud penetration testing across Azure, AWS, and GCP environments, identifying IAM misconfigurations, excessive permissions, privilege escalation paths, exposed storage buckets/blobs, and exploitable service misconfigurations
  • Perform offensive enumeration and attack-path mapping against cloud environments using tools such as ScoutSuite, Prowler, Pacu, ROADtools/ADRecon, and GCP-focused tooling.
  • Review eASM dashboard daily to monitor for any anomalies or security incidents.
  • Conduct testing and validation of vulnerabilities identified by the ASM system, providing evidence of validation to support remediation efforts.
  • Investigate eASM vulnerabilities thoroughly, analyzing potential impact and root causes.
  • Conduct various types of penetration testing, including scanning and password attacks, to identify potential weaknesses in the system.
  • Perform cloud penetration testing and security configuration reviews across Azure and AWS environments, identifying misconfigurations, excessive permissions, and exploitable weaknesses.
  • Perform technical vulnerability scans and validate remediation efforts to ensure effective security posture.
  • Escalate identified vulnerabilities and security incidents to appropriate client or internal team members for resolution.
  • Engage with clients during project kick-off meetings to understand their specific security requirements and objectives.
  • Assist in maturing eASM Evolve Security processes, procedures, templates, and methodologies to enhance overall effectiveness.
  • Take on other duties as assigned to support the growth and expansion of enterprise and academy initiatives, contributing to the overall success of the security program.

Requirements

  • Passionate about cybersecurity with a curiosity to learn
  • Foundational understanding of cloud security concepts and offensive testing methodology for Azure, AWS, and/or GCP (e.g., IAM abuse, privilege escalation, storage misconfigurations, metadata service exploitation).
  • Hands-on exposure (via labs, coursework, CTFs, or professional experience) to cloud-native offensive tools such as ScoutSuite, Prowler, Pacu, ROADtools, ADRecon, or GCP enumeration/exploitation tooling.
  • Security+ required; cloud security or offensive certifications a strong plus (AZ-500, AWS Certified Security - Specialty, GCP Professional Cloud Security Engineer, or equivalent cloud pentesting coursework/labs).
  • 0-1 years of information technology experience, ideally with a focus on information security
  • 0- 1 years penetration testing, application and vulnerability management experience through education or security/consulting firm
  • Exposure to cloud security concepts and penetration testing methodologies for Azure and/or AWS environments (e.g., IAM misconfigurations, storage bucket/blob exposure, privilege escalation paths), gained through education, labs, or professional experience
  • Knowledge of multiple operating systems and associated command-line administration tools (Bash / PowerShell)
  • Knowledge of the application stack including web
  • Familiarity with cloud-native and cloud pentesting tools (e.g., ScoutSuite, Prowler, Pacu, ROADtools, ADRecon) is a plus
  • Scripting experience in one or more of: Ruby, Python, Perl, Bash
  • ESCP, Security+ certifications; cloud security certifications (e.g., AZ-500, AWS Certified Security - Specialty) a plus
  • A desire to tinker and understand how things work
  • Ability to interface with clients, utilizing consulting and negotiating skills
  • Strongly self-motivated and able to work independently towards team objectives
  • Strong communication skills (oral and written) and ability to work as part of a team

Benefits

Who is Evolve Security?

Evolve Security is a cybersecurity services firm headquartered in Chicago, IL. We are dedicated to improving our client’s security posture by providing continuous penetration testing, training services, and talent solutions.

In addition to our professional cybersecurity service offerings, Evolve Security offers a cybersecurity bootcamp, “Evolve Academy”, currently ranked the #1 cybersecurity bootcamp in the world. The Cybersecurity Bootcamp in Chicago provides immersive training, giving students the concrete and practical skills, needed on the job. Students gain real work experience through live security assessment work that they perform on not-for-profit companies.

We are passionate about directly improving our customers’ security posture, and we proudly train others to help meet the need for qualified cybersecurity talent.

Benefits Include

  • Healthcare Benefits
  • 401(k) Match
  • Parental Leave
  • Flexible Paid Time Off
  • Annual vacation reimbursement

Salary: $50,000/year

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
561,906 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
DevOps Engineer 8 hours ago
$16k – $45k per year (Estimated) • In office • 3+ years exp • Bengaluru
Python
Bash
DevOps
Terraform
GCP
Helm
Azure DevOps
Azure
CI/CD
GitOps
AWS
Docker
Kubernetes
SRE
Platform Engineering
IAM
Cybersecurity
ISO 27001
SOC 2
Apply
Remote/Hybrid • 6+ years exp • Bachelor's Degree
C#
C#
.NET
DevOps
GCP
Azure
CI/CD
AWS
Kubernetes
Apply
$116k – $194k per year • Remote • 8+ years exp
Python
SQL
Databases
Snowflake
AI/ML
LangGraph
LangChain
LlamaIndex
dbt
Embeddings
Prompt Engineering
Function Calling
AI Agents
LLM
RAG
LLM Guardrails
Agentic Workflows
Tool Use
DevOps
GCP
Prometheus
Azure
CI/CD
AWS
Docker
Kubernetes
Vector
Cortex
Apply
Remote/Hybrid • 5+ years exp
Python
JavaScript
Java
C#
C++
Java
Maven
C#
.NET
Databases
Oracle
MS SQL
Apache Kafka
Frontend
React.js
DevOps
GCP
Azure
CI/CD
Git
AWS
Docker
Kubernetes
Apply
Sr. AI Engineer 9 hours ago
Remote/Hybrid • 10+ years exp
Python
C#
C#
.NET
Databases
Weaviate
Milvus
Pinecone
FAISS
AI/ML
LangGraph
LangChain
LlamaIndex
LoRA
Vertex AI
Fine-tuning
Embeddings
RLHF
Reinforcement Learning
Prompt Engineering
Function Calling
AI Agents
PEFT
QLoRA
RAG
OpenAI
Anthropic
Amazon SageMaker
DPO
SFT
PPO
GRPO
LLM Guardrails
Multi-Agent Systems
Tool Use
DevOps
GCP
Azure
AWS
Kubernetes
Vector
Apply
See all jobs
This is one of many
561,906 more open roles from verified company boards, updated every day.