This position is no longer accepting applications
Closed on September 3, 2026.
This role is filled — get an email when new Information Security roles open on CybersecurityJobs.io:
Offensive Security Analyst
Application Security
Cybersecurity Tools
Dynamic Application Security Testing
Information Security
InfoSec
Investigative Skills
Owasp Top Ten
Programming
Security Automation
Security Testing
Software Security
Static Application Security Testing
Vulnerability Scanners
Vulnerability Triage
View similar jobs
Get alerted when similar jobs are posted — set up a New Information Security jobs on CybersecurityJobs.io alert.
See other roles at Sprocket Security.
Job Description
Sprocket Security is seeking an Offensive Security Analyst to act as the human judgment layer in an offensive automation pipeline for client-ready results.
Responsibilities
- Triage, validate, and QA findings surfaced by Sprocket’s automation workflow
- Reproduce and confirm true positives while eliminating false positives before results reach a client
- Author and refine findings to client-ready quality, maintaining the Sprocket voice, then publish through the platform
- Calibrate severity to real business impact using Sprocket standards, prioritizing practical impact over theoretical risk
- Handle roughly 90% of findings independently, making accurate handle-versus-escalate decisions using platform workflow
- Escalate the hard 10% to an Adversarial Engineer with full context attached
- Provide pattern-level feedback to R&D and the Adversarial Engineering team to tune attack automations and reduce false positives
- Log validation notes, flag false-positive patterns, and contribute to the knowledge base
- Script away repetitive validation tasks wherever they appear
- Collaborate with R&D and the Service Delivery team to improve the automation feedback loop and client experience
- After triage is complete and capacity allows, help programmatically enhance the automation pipeline with new or updated capabilities, pairing with an Adversarial Engineer as needed
- Attend daily standups, weekly 1:1s, monthly company calls, and all-hands
Requirements
- Demonstrated experience triaging or reproducing vulnerabilities surfaced by a security tool (vulnerability scanner, SAST/DAST/SCA/IAST, or similar automation) in a professional setting
- Some software programming experience, with Python preferred
- Exposure to using Generative AI tools for day-to-day tasks, with Claude preferred
- Strong Development, IT, or Infosec foundation plus genuine self-directed security study
- Hands-on validation depth across common vulnerability classes, including OWASP Top 10, network, and authentication issues
- Clear, detail-oriented written communication that remains effective under volume
- Self-direction to manage a high-volume queue independently without hourly guidance
Technologies
- Python
- Claude
- Generative AI
- SAST
- DAST
- SCA
- IAST
- OWASP Top 10
- Vulnerability scanner
Benefits
- Unlimited and mandatory PTO for healthy work/life balance
- Company matched 401k with immediate eligibility
- 75% company contribution for health insurance for employees and 50% for dependents
- 100% company contribution for dental and vision
- Flexible working hours
- Hardware and tools of your choice
- Paid training, conferences, and certifications to support career development
Mission and Product Context
- Company mission: help secure as many companies as possible by prioritizing penetration testing
- Emphasis: offensive security for enterprises, building robust defense strategies based on individual business risk
- Platform approach: an expert-driven Continuous Penetration Testing platform combining automated and manual testing
- Your role: the human judgment layer who decides what is real, calibrates severity, and ensures findings read in the Sprocket voice before client delivery
Preferred
- Security+, eJPT, CPTS, PNPT, or similar foundational credential
- CTF achievements (HackTheBox, TryHackMe, PortSwigger Academy)
- Degree in computer science, engineering, or IT
- Interest in working toward OSCP or an equivalent hands-on certification over time
Location: Madison, WI (onsite)