
Offensive Security Analyst
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Triage, validate, and perform quality assurance on findings identified by Sprocket's automation. Reproduce and confirm genuine positives while eliminating false positives before they reach the client.
• Write and enhance findings to meet client-ready standards in the Sprocket voice, and publish them through the platform.
• Assess severity based on actual business impact according to Sprocket's standards, prioritizing real-world implications over theoretical assessments.
• Independently manage approximately 90% of findings and make precise handle-versus-escalate decisions utilizing the platform workflow, escalating the challenging 10% to an Adversarial Engineer with complete context attached.
• Provide pattern-level signals back to the R&D and Adversarial Engineering teams to refine attack automations and reduce false positives at their origin. You will serve as one of the most critical feedback channels into R&D.
• Document validation notes, identify false-positive patterns, and contribute to the knowledge base.
• Automate repetitive validation steps wherever they occur.
• Collaborate with fellow R&D team members and the Service Delivery team on the automation feedback loop and enhancements to the client experience.
• Aim to programmatically improve the automation pipeline with new or updated capabilities once triage is finished and capacity allows, partnering with an Adversarial Engineer as necessary.
• Participate in daily standups, weekly one-on-ones, monthly company meetings, and all-hands gatherings.
• Proven experience in triaging or reproducing vulnerabilities identified by a security tool (such as vulnerability scanners, SAST/DAST/SCA/IAST, or similar automation) in a professional environment.
• Some programming experience, preferably in Python.
• Familiarity with using Generative AI tools in daily tasks, with a preference for Claude.
• A solid foundation in Development, IT, or Information Security, accompanied by a genuine, self-motivated pursuit of security knowledge.
• Sufficient depth in security to validate common vulnerability categories hands-on, including OWASP Top 10, network, and authentication issues, rather than merely naming them.
• Strong written communication skills that are clear and detail-oriented, capable of maintaining quality under volume.
• The ability to independently manage a high-volume queue without the need for hourly oversight.
• Security+, eJPT, CPTS, PNPT, or a similar foundational certification (preferred).
• Achievements in Capture The Flag (CTF) competitions (such as HackTheBox, TryHackMe, PortSwigger Academy) (preferred).
• A degree in computer science, engineering, or IT (preferred).
• A genuine interest in pursuing OSCP or an equivalent hands-on certification over time (preferred).
• Unlimited and mandatory paid time off (PTO) to ensure a healthy work/life balance.
• Company-matched 401(k) with immediate eligibility, allowing you to start saving right away.
• 75% company contribution towards health insurance for employees and 50% for dependents.
• 100% company coverage for dental and vision insurance.
• Flexible working hours.
• Choice of hardware and tools.
• Support for your career advancement through paid training, conferences, certifications, and more.
Cresol Cooperativa
LTS
Equity Resources, Inc
IronArch Technology
Get handpicked remote jobs straight to your inbox weekly.