{"schemaVersion":"jobsearcher.job.v1","id":"c7a6340f6ee9abaafa398e32","url":"https://jobsearcher.com/jobs/c7a6340f6ee9abaafa398e32","canonicalUrl":"https://jobsearcher.com/jobs/c7a6340f6ee9abaafa398e32","title":"OSOC Security Analyst - Cloud Pentesting","description":"Evolve Security is looking for an OSOC Security Analyst to join our growing team. This position will assist with the overall successful delivery of various application vulnerability assessments, continuous internal / external penetration assessments, cloud security assessments, incident response and detection assessments, and other types of security strategy and architecture reviews.\n\nResponsibilities include:\n\nConduct hands-on cloud penetration testing across Azure, AWS, and GCP environments, identifying IAM misconfigurations, excessive permissions, privilege escalation paths, exposed storage buckets/blobs, and exploitable service misconfigurations\nPerform offensive enumeration and attack-path mapping against cloud environments using tools such as ScoutSuite, Prowler, Pacu, ROADtools/ADRecon, and GCP-focused tooling.\nReview eASM dashboard daily to monitor for any anomalies or security incidents.\nConduct testing and validation of vulnerabilities identified by the ASM system, providing evidence of validation to support remediation efforts.\nInvestigate eASM vulnerabilities thoroughly, analyzing potential impact and root causes.\nConduct various types of penetration testing, including scanning and password attacks, to identify potential weaknesses in the system.\nPerform cloud penetration testing and security configuration reviews across Azure and AWS environments, identifying misconfigurations, excessive permissions, and exploitable weaknesses.\nPerform technical vulnerability scans and validate remediation efforts to ensure effective security posture.\nEscalate identified vulnerabilities and security incidents to appropriate client or internal team members for resolution.\nEngage with clients during project kick-off meetings to understand their specific security requirements and objectives.\nAssist in maturing eASM Evolve Security processes, procedures, templates, and methodologies to enhance overall effectiveness.\nTake on other duties as assigned to support the growth and expansion of enterprise and academy initiatives, contributing to the overall success of the security program.\n\nRequirements\n\nPassionate about cybersecurity with a curiosity to learn\nFoundational understanding of cloud security concepts and offensive testing methodology for Azure, AWS, and/or GCP (e.g., IAM abuse, privilege escalation, storage misconfigurations, metadata service exploitation).\nHands-on exposure (via labs, coursework, CTFs, or professional experience) to cloud-native offensive tools such as ScoutSuite, Prowler, Pacu, ROADtools, ADRecon, or GCP enumeration/exploitation tooling.\nSecurity+ required; cloud security or offensive certifications a strong plus (AZ-500, AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer, or equivalent cloud pentesting coursework/labs).\n0-1 years of information technology experience, ideally with a focus on information security\n0- 1 years penetration testing, application and vulnerability management experience through education or security/consulting firm\nExposure to cloud security concepts and penetration testing methodologies for Azure and/or AWS environments (e.g., IAM misconfigurations, storage bucket/blob exposure, privilege escalation paths), gained through education, labs, or professional experience\nKnowledge of multiple operating systems and associated command-line administration tools (Bash / PowerShell)\nKnowledge of the application stack including web\nFamiliarity with cloud-native and cloud pentesting tools (e.g., ScoutSuite, Prowler, Pacu, ROADtools, ADRecon) is a plus\nScripting experience in one or more of: Ruby, Python, Perl, Bash\nESCP, Security+ certifications; cloud security certifications (e.g., AZ-500, AWS Certified Security – Specialty) a plus\nA desire to tinker and understand how things work\nAbility to interface with clients, utilizing consulting and negotiating skills\nStrongly self-motivated and able to work independently towards team objectives\nStrong communication skills (oral and written) and ability to work as part of a team\n\nBenefits\n\nWho is Evolve Security?\n\nEvolve Security is a cybersecurity services firm headquartered in Chicago, IL. We are dedicated to improving our client’s security posture by providing continuous penetration testing, training services, and talent solutions.\n\nIn addition to our professional cybersecurity service offerings, Evolve Security offers a cybersecurity bootcamp, “Evolve Academy”, currently ranked the #1 cybersecurity bootcamp in the world. The Cybersecurity Bootcamp in Chicago provides immersive training, giving students the concrete and practical skills, needed on the job. Students gain real work experience through live security assessment work that they perform on not-for-profit companies.\n\nWe are passionate about directly improving our customers’ security posture, and we proudly train others to help meet the need for qualified cybersecurity talent.\n\nBenefits Include\n\nHealthcare Benefits\n401(k) Match\nParental Leave\nFlexible Paid Time Off\nAnnual vacation reimbursement\n\nSalary: $50,000/year","company":"Evolvesecurity","rawCompany":"evolvesecurity","city":"Denver","state":"CO","isRemote":false,"isActive":false,"createdAt":"2026-09-04T09:19:49.407Z","occupations":[{"code":"15-1299.04","title":"Penetration Testers","slug":"penetration-testers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"},{"code":"541513","title":"Computer Facilities Management Services","slug":"computer-facilities-management-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"OSOC Security Analyst - Cloud Pentesting","description":"Evolve Security is looking for an OSOC Security Analyst to join our growing team. This position will assist with the overall successful delivery of various application vulnerability assessments, continuous internal / external penetration assessments, cloud security assessments, incident response and detection assessments, and other types of security strategy and architecture reviews.\n\nResponsibilities include:\n\nConduct hands-on cloud penetration testing across Azure, AWS, and GCP environments, identifying IAM misconfigurations, excessive permissions, privilege escalation paths, exposed storage buckets/blobs, and exploitable service misconfigurations\nPerform offensive enumeration and attack-path mapping against cloud environments using tools such as ScoutSuite, Prowler, Pacu, ROADtools/ADRecon, and GCP-focused tooling.\nReview eASM dashboard daily to monitor for any anomalies or security incidents.\nConduct testing and validation of vulnerabilities identified by the ASM system, providing evidence of validation to support remediation efforts.\nInvestigate eASM vulnerabilities thoroughly, analyzing potential impact and root causes.\nConduct various types of penetration testing, including scanning and password attacks, to identify potential weaknesses in the system.\nPerform cloud penetration testing and security configuration reviews across Azure and AWS environments, identifying misconfigurations, excessive permissions, and exploitable weaknesses.\nPerform technical vulnerability scans and validate remediation efforts to ensure effective security posture.\nEscalate identified vulnerabilities and security incidents to appropriate client or internal team members for resolution.\nEngage with clients during project kick-off meetings to understand their specific security requirements and objectives.\nAssist in maturing eASM Evolve Security processes, procedures, templates, and methodologies to enhance overall effectiveness.\nTake on other duties as assigned to support the growth and expansion of enterprise and academy initiatives, contributing to the overall success of the security program.\n\nRequirements\n\nPassionate about cybersecurity with a curiosity to learn\nFoundational understanding of cloud security concepts and offensive testing methodology for Azure, AWS, and/or GCP (e.g., IAM abuse, privilege escalation, storage misconfigurations, metadata service exploitation).\nHands-on exposure (via labs, coursework, CTFs, or professional experience) to cloud-native offensive tools such as ScoutSuite, Prowler, Pacu, ROADtools, ADRecon, or GCP enumeration/exploitation tooling.\nSecurity+ required; cloud security or offensive certifications a strong plus (AZ-500, AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer, or equivalent cloud pentesting coursework/labs).\n0-1 years of information technology experience, ideally with a focus on information security\n0- 1 years penetration testing, application and vulnerability management experience through education or security/consulting firm\nExposure to cloud security concepts and penetration testing methodologies for Azure and/or AWS environments (e.g., IAM misconfigurations, storage bucket/blob exposure, privilege escalation paths), gained through education, labs, or professional experience\nKnowledge of multiple operating systems and associated command-line administration tools (Bash / PowerShell)\nKnowledge of the application stack including web\nFamiliarity with cloud-native and cloud pentesting tools (e.g., ScoutSuite, Prowler, Pacu, ROADtools, ADRecon) is a plus\nScripting experience in one or more of: Ruby, Python, Perl, Bash\nESCP, Security+ certifications; cloud security certifications (e.g., AZ-500, AWS Certified Security – Specialty) a plus\nA desire to tinker and understand how things work\nAbility to interface with clients, utilizing consulting and negotiating skills\nStrongly self-motivated and able to work independently towards team objectives\nStrong communication skills (oral and written) and ability to work as part of a team\n\nBenefits\n\nWho is Evolve Security?\n\nEvolve Security is a cybersecurity services firm headquartered in Chicago, IL. We are dedicated to improving our client’s security posture by providing continuous penetration testing, training services, and talent solutions.\n\nIn addition to our professional cybersecurity service offerings, Evolve Security offers a cybersecurity bootcamp, “Evolve Academy”, currently ranked the #1 cybersecurity bootcamp in the world. The Cybersecurity Bootcamp in Chicago provides immersive training, giving students the concrete and practical skills, needed on the job. Students gain real work experience through live security assessment work that they perform on not-for-profit companies.\n\nWe are passionate about directly improving our customers’ security posture, and we proudly train others to help meet the need for qualified cybersecurity talent.\n\nBenefits Include\n\nHealthcare Benefits\n401(k) Match\nParental Leave\nFlexible Paid Time Off\nAnnual vacation reimbursement\n\nSalary: $50,000/year","datePosted":"2026-09-04T09:19:49.407Z","dateModified":"2026-09-04T09:19:49.407Z","hiringOrganization":{"@type":"Organization","name":"Evolvesecurity","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Denver","addressRegion":"CO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"c7a6340f6ee9abaafa398e32"},"url":"https://jobsearcher.com/jobs/c7a6340f6ee9abaafa398e32"}}