OSOC Security Analyst - Cloud Pentesting
Evolve Security · Remote · United States · Remote
Posted Sep 23, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Evolve Security is looking for an OSOC Security Analyst to join our growing team. This position will assist with the overall successful delivery of various application vulnerability assessments, continuous internal / external penetration assessments, cloud security assessments, incident response and detection assessments, and other types of security strategy and architecture reviews.
Responsibilities include:
Conduct hands-on cloud penetration testing across Azure, AWS, and GCP environments, identifying IAM misconfigurations, excessive permissions, privilege escalation paths, exposed storage buckets/blobs, and exploitable service misconfigurations
Perform offensive enumeration and attack-path mapping against cloud environments using tools such as ScoutSuite, Prowler, Pacu, ROADtools/ADRecon, and GCP-focused tooling.
Review eASM dashboard daily to monitor for any anomalies or security incidents.
Conduct testing and validation of vulnerabilities identified by the ASM system, providing evidence of validation to support remediation efforts.
Investigate eASM vulnerabilities thoroughly, analyzing potential impact and root causes.
Conduct various types of penetration testing, including scanning and password attacks, to identify potential weaknesses in the system.
Perform cloud penetration testing and security configuration reviews across Azure and AWS environments, identifying misconfigurations, excessive permissions, and exploitable weaknesses.
Perform technical vulnerability scans and validate remediation efforts to ensure effective security posture.
Escalate identified vulnerabilities and security incidents to appropriate client or internal team members for resolution.
Engage with clients during project kick-off meetings to understand their specific security requirements and objectives.
Assist in maturing eASM Evolve Security processes, procedures, templates, and methodologies to enhance overall effectiveness.
Take on other duties as assigned to support the growth and expansion of enterprise and academy initiatives, contributing to the overall success of the security program.
Requirements
Passionate about cybersecurity with a curiosity to learn
Foundational understanding of cloud security concepts and offensive testing methodology for Azure, AWS, and/or GCP (e.g., IAM abuse, privilege escalation, storage misconfigurations, metadata service exploitation).
Hands-on exposure (via labs, coursework, CTFs, or professional experience) to cloud-native offensive tools such as ScoutSuite, Prowler, Pacu, ROADtools, ADRecon, or GCP enumeration/exploitation tooling.
Security+ required; cloud security or offensive certifications a strong plus (AZ-500, AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer, or equivalent cloud pentesting coursework/labs).
0-1 years of information technology experience, ideally with a focus on information security
0- 1 years penetration testing, application and vulnerability…