Full-Time

OSOC Security Analyst

Cloud Pentesting

Evolve Security

Evolve Security

51-200 employees

Continuous penetration testing with ASM

Compensation Overview

$50k/yr

Remote in USA

Remote

Category
Cybersecurity (1)
Required Skills
PowerShell
Bash
Microsoft Azure
Python
Incident Response
Ruby
Vulnerability Analysis
AWS
Perl
Penetration Testing
Google Cloud Platform

Get referred to Evolve Security

See people who can refer or advise you

Requirements
  • Foundational understanding of cloud security concepts and offensive testing methodology for Azure, Amazon Web Services, and/or Google Cloud Platform, including identity and access management abuse, privilege escalation, storage misconfigurations, and metadata service exploitation.
  • Hands-on exposure through labs, coursework, capture-the-flag exercises, or professional experience to cloud-native offensive tools such as ScoutSuite, Prowler, Pacu, ROADtools, ADRecon, or Google Cloud Platform enumeration and exploitation tooling.
  • Security+ certification is required.
  • Zero to one year of information technology experience, ideally focused on information security.
  • Zero to one year of penetration testing, application security, and vulnerability management experience gained through education or a security or consulting firm.
  • Exposure to cloud security concepts and penetration testing methodologies for Azure and/or Amazon Web Services environments, including identity and access management misconfigurations, storage bucket or blob exposure, and privilege escalation paths, gained through education, labs, or professional experience.
  • Knowledge of multiple operating systems and associated command-line administration tools, including Bash and PowerShell.
  • Knowledge of the web application stack.
  • Scripting experience in one or more of Ruby, Python, Perl, or Bash.
  • Ability to interface with clients using consulting and negotiating skills.
  • Ability to work independently toward team objectives and as part of a team.
Responsibilities
  • Assist with the successful delivery of application vulnerability assessments, continuous internal and external penetration assessments, cloud security assessments, incident response and detection assessments, and security strategy and architecture reviews.
  • Conduct hands-on cloud penetration testing across Azure, Amazon Web Services, and Google Cloud Platform environments, identifying identity and access management misconfigurations, excessive permissions, privilege escalation paths, exposed storage buckets or blobs, and exploitable service misconfigurations.
  • Perform offensive enumeration and attack-path mapping against cloud environments using ScoutSuite, Prowler, Pacu, ROADtools, ADRecon, and Google Cloud Platform-focused tooling.
  • Review the external attack surface management dashboard daily to monitor for anomalies or security incidents.
  • Test and validate vulnerabilities identified by the attack surface management system, providing evidence to support remediation efforts.
  • Investigate external attack surface management vulnerabilities, analyzing potential impact and root causes.
  • Conduct penetration testing, including scanning and password attacks, to identify potential system weaknesses.
  • Perform cloud penetration testing and security configuration reviews across Azure and Amazon Web Services environments, identifying misconfigurations, excessive permissions, and exploitable weaknesses.
  • Perform technical vulnerability scans and validate remediation efforts.
  • Escalate identified vulnerabilities and security incidents to appropriate client or internal team members for resolution.
  • Engage with clients during project kick-off meetings to understand their security requirements and objectives.
  • Assist in improving external attack surface management processes, procedures, templates, and methodologies.
  • Take on other assigned duties supporting enterprise and academy initiatives.
Desired Qualifications
  • Cloud security or offensive certifications such as AZ-500, AWS Certified Security – Specialty, or Google Cloud Professional Cloud Security Engineer, or equivalent cloud penetration testing coursework or labs.
  • Familiarity with cloud-native and cloud penetration testing tools such as ScoutSuite, Prowler, Pacu, ROADtools, and ADRecon.
  • Curiosity and a desire to understand how systems work.

Evolve Security focuses on offensive cybersecurity with continuous testing. It provides Attack Surface Management (ASM) and Continuous Penetration Testing (CPT) through the Darwin Attack Platform, combining AI automation with human expert involvement and cyber advisory services. The approach works by continuously scanning and probing an organization’s exposed systems and applications, using automated tools to identify weaknesses and manual testing to validate findings, then offering guidance to fix gaps. Differentiation comes from the blend of automated AI-driven testing and expert human review, the ongoing nature of CPT and ASM (not one-off scans), and the brand’s cyber advisory and training arm, including an Academy ranked #1 cybersecurity bootcamp for six straight years. The goal is to improve clients’ cyber resiliency by maintaining persistent visibility into attack surfaces and regularly uncovering and addressing weaknesses before real attackers can exploit them.

Company Size

51-200

Company Stage

N/A

Total Funding

N/A

Headquarters

Chicago, Illinois

Founded

2016

Get referred to Evolve Security

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • June 22, 2026 Momentum Cyber recognition improves enterprise credibility and buyer trust.
  • August 12, 2026 OSOC reporting showed five actively exploited vulnerabilities, proving operational relevance.
  • The 2026 platform added Asset Intelligence, expanding cross-sell into larger customer attack-surface programs.

What critics are saying

  • Tracxn shows only $13.5M total funding, limiting sales and R&D firepower.
  • Crowded CTEM and pentest rivals can undercut Evolve Security's services pricing quickly.
  • If CPT adoption stalls, 2024-2026 investor momentum turns into a thin-services death spiral.

What makes Evolve Security unique

  • Evolve Security's 2026 CPT blends automation and human validation across AI, cloud, and network.
  • Its OSOC delivers continuous penetration testing, not annual point-in-time assessments.
  • Momentum Cyber named Evolve Security a 2026 cybersecurity services market-report firm.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

401(k) Company Match

Parental Leave

Paid Vacation

Company News

CyberTech - Cyber Technology Insights
Mar 17th, 2025
Evolve Security Transforms Pen Testing, Expands Leadership

Evolve Security, a leader in proactive offensive cybersecurity, announces three executive hires - Mark Carney as Chief Executive Officer; Ray Ruemmele as Chief Revenue Officer; and Jason Rowland as Chief Delivery Officer.

Simplilearn
Aug 7th, 2023
Program Overview: A Sneak Peek into Caltech's Cyber Security Bootcamp

Uncover the fundamentals of cybersecurity with the Cybersecurity Bootcamp in collaboration with Caltech CTME.

Evolve Security
Jul 12th, 2022
Evolve Security hires Rob Kraus as Senior Director of Security Services

Evolve Security is very pleased to announce that Rob Kraus has joined Evolve Security as its Senior Director of Security Services, focusing on development, growth, and successful delivery of cybersecurity services to its clients.