Offensive Security Analyst

SPROCKET SECURITY, LLC
Madison, WI, United States
about 2 months ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Computer Programming Python (Programming Language) Open Web Application Security Generative AI Information Technology Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

  • Triage, validate, and QA findings surfaced by Sprocket’s automation. Reproduce, confirm true positives, and eliminate false positives before anything reaches a client.
  • Author and refine findings to client-ready quality in the Sprocket voice, and publish them through the platform.
  • Calibrate severity to real business impact against Sprocket’s standards, judging real-world impact over theoretical.
  • Handle roughly 90% of findings independently and make accurate handle-versus-escalate decisions using the platform workflow, escalating the hard 10% to an Adversarial Engineer with full context attached.
  • Feed pattern-level signal back to R&D and the Adversarial Engineering team to tune attack automations and cut false positives at the source. You’ll be one of the tightest feedback loops we have into R&D.
  • Log validation notes, flag false-positive patterns, and contribute to the knowledge base.
  • Script away repetitive validation steps wherever they appear.
  • Partner with your fellow R&D team members and the Service Delivery team on the automation feedback loop and client-experience improvements.
  • Seek to programmatically enhance automation pipeline with new or updated capabilities when triage is complete and capacity allows, pairing with an Adversarial Engineer as needed.
  • Attend daily standups, weekly 1:1s, monthly company calls, and all-hands.

Requirements

  • Demonstrated experience triaging or reproducing vulnerabilities surfaced by a security tool (vulnerability scanner, SAST/DAST/SCA/IAST, or similar automation) in a professional setting.
  • Some software programming experience, Python preferred.
  • Some exposure to utilizing Generative AI tools for day-to-day tasks, Claude preferred.
  • A strong Development, IT, or Infosec foundation, paired with genuine, self-directed security study.
  • Enough security depth to validate common vulnerability classes hands-on, including OWASP Top 10, network, and auth issues, not just name them.
  • Clear, detail-oriented written communication that holds up under volume.
  • The self-direction to manage a high-volume queue independently, without hourly guidance.

Preferred:

  • Security+, eJPT, CPTS, PNPT, or a similar foundational credential.
  • CTF achievements (HackTheBox, TryHackMe, PortSwigger Academy).
  • A degree in computer science, engineering, or IT.
  • Genuine interest in working toward OSCP or an equivalent hands-on certification over time.

Benefits & conditions

Pulled from the full job description

  • Paid training
  • 401(k)
  • Health insurance
  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Dental insurance, * Unlimited and mandatory PTO for healthy work/life balance.
  • Company matched 401k (immediate eligibility, no one should have to wait to start saving).
  • 75% company contribution for health insurance for employees and 50% for dependents.
  • 100% company contribution for dental and vision.
  • Flexible working hours.
  • Hardware and tools of your choice
  • Support for your career development with paid training, conferences, certifications, etc.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:37 min

Tracing the evolution from early AI to generative AI

Mike Mike · World Congress 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:31 min

Revolutionizing computer programming through natural language code generation

Demetris Cheatham Demetris Cheatham +1 · World Congress 2024

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

2:14 min

Introduction to generative AI and content warnings

Cheuk Ho · World Congress 2023

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all