> Markdown version of [/jobs/ext/1281165-offensive-security-analyst](https://www.wearedevelopers.com/jobs/ext/1281165-offensive-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Offensive Security Analyst - **Company:** SPROCKET SECURITY, LLC - **Location:** Madison, WI, United States - **Contract:** Permanent contract - **Skills:** Cyber Security, Computer Programming, Python (Programming Language), Open Web Application Security, Generative AI, Information Technology, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** July 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3bbee15be7945bf3 ## About the Role * Demonstrated experience triaging or reproducing vulnerabilities surfaced by a security tool (vulnerability scanner, SAST/DAST/SCA/IAST, or similar automation) in a professional setting. * Some software programming experience, Python preferred. * Some exposure to utilizing Generative AI tools for day-to-day tasks, Claude preferred. * A strong Development, IT, or Infosec foundation, paired with genuine, self-directed security study. * Enough security depth to validate common vulnerability classes hands-on, including OWASP Top 10, network, and auth issues, not just name them. * Clear, detail-oriented written communication that holds up under volume. * The self-direction to manage a high-volume queue independently, without hourly guidance. Preferred: * Security+, eJPT, CPTS, PNPT, or a similar foundational credential. * CTF achievements (HackTheBox, TryHackMe, PortSwigger Academy). * A degree in computer science, engineering, or IT. * Genuine interest in working toward OSCP or an equivalent hands-on certification over time. ## Description * Triage, validate, and QA findings surfaced by Sprocket's automation. Reproduce, confirm true positives, and eliminate false positives before anything reaches a client. * Author and refine findings to client-ready quality in the Sprocket voice, and publish them through the platform. * Calibrate severity to real business impact against Sprocket's standards, judging real-world impact over theoretical. * Handle roughly 90% of findings independently and make accurate handle-versus-escalate decisions using the platform workflow, escalating the hard 10% to an Adversarial Engineer with full context attached. * Feed pattern-level signal back to R&D and the Adversarial Engineering team to tune attack automations and cut false positives at the source. You'll be one of the tightest feedback loops we have into R&D. * Log validation notes, flag false-positive patterns, and contribute to the knowledge base. * Script away repetitive validation steps wherever they appear. * Partner with your fellow R&D team members and the Service Delivery team on the automation feedback loop and client-experience improvements. * Seek to programmatically enhance automation pipeline with new or updated capabilities when triage is complete and capacity allows, pairing with an Adversarial Engineer as needed. * Attend daily standups, weekly 1:1s, monthly company calls, and all-hands. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Your imaginations is (no longer) the limit: how Generative AI empowers people to be creative](https://www.wearedevelopers.com/videos/741-your-imaginations-is-no-longer-the-limit-how-generative-ai-empowers-people-to-be-creative) - [Photonic Computing: Programming a New Class of AI Accelerators (incl. Live Coding)](https://www.wearedevelopers.com/videos/100196-photonic-computing-programming-a-new-class-of-ai-accelerators-incl-live-coding) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [The shadows that follow the AI generative models](https://www.wearedevelopers.com/videos/624-the-shadows-that-follow-the-ai-generative-models) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)