Offensive Security Analyst
SPROCKET SECURITY, LLC
Madison, WI, United States
about 2 months ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.indeed.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source
Tech stack
Cyber Security
Computer Programming
Python (Programming Language)
Open Web Application Security
Generative AI
Information Technology
Static Application Security Testing
Vulnerability Analysis
Dynamic Application Security Testing
Job description
- Triage, validate, and QA findings surfaced by Sprocket’s automation. Reproduce, confirm true positives, and eliminate false positives before anything reaches a client.
- Author and refine findings to client-ready quality in the Sprocket voice, and publish them through the platform.
- Calibrate severity to real business impact against Sprocket’s standards, judging real-world impact over theoretical.
- Handle roughly 90% of findings independently and make accurate handle-versus-escalate decisions using the platform workflow, escalating the hard 10% to an Adversarial Engineer with full context attached.
- Feed pattern-level signal back to R&D and the Adversarial Engineering team to tune attack automations and cut false positives at the source. You’ll be one of the tightest feedback loops we have into R&D.
- Log validation notes, flag false-positive patterns, and contribute to the knowledge base.
- Script away repetitive validation steps wherever they appear.
- Partner with your fellow R&D team members and the Service Delivery team on the automation feedback loop and client-experience improvements.
- Seek to programmatically enhance automation pipeline with new or updated capabilities when triage is complete and capacity allows, pairing with an Adversarial Engineer as needed.
- Attend daily standups, weekly 1:1s, monthly company calls, and all-hands.
Requirements
- Demonstrated experience triaging or reproducing vulnerabilities surfaced by a security tool (vulnerability scanner, SAST/DAST/SCA/IAST, or similar automation) in a professional setting.
- Some software programming experience, Python preferred.
- Some exposure to utilizing Generative AI tools for day-to-day tasks, Claude preferred.
- A strong Development, IT, or Infosec foundation, paired with genuine, self-directed security study.
- Enough security depth to validate common vulnerability classes hands-on, including OWASP Top 10, network, and auth issues, not just name them.
- Clear, detail-oriented written communication that holds up under volume.
- The self-direction to manage a high-volume queue independently, without hourly guidance.
Preferred:
- Security+, eJPT, CPTS, PNPT, or a similar foundational credential.
- CTF achievements (HackTheBox, TryHackMe, PortSwigger Academy).
- A degree in computer science, engineering, or IT.
- Genuine interest in working toward OSCP or an equivalent hands-on certification over time.
Benefits & conditions
Pulled from the full job description
- Paid training
- 401(k)
- Health insurance
- 401(k) matching
- Paid time off
- Vision insurance
- Dental insurance, * Unlimited and mandatory PTO for healthy work/life balance.
- Company matched 401k (immediate eligibility, no one should have to wait to start saving).
- 75% company contribution for health insurance for employees and 50% for dependents.
- 100% company contribution for dental and vision.
- Flexible working hours.
- Hardware and tools of your choice
- Support for your career development with paid training, conferences, certifications, etc.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
over 2 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
7 months ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
CH
Chris Heilmann
Dev Digest 138 - Are you secure about this?
almost 2 years ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago