Offensive Security Analyst
Job Description
Sprocket Security is seeking an Offensive Security Analyst to act as the human judgment layer in an offensive automation pipeline for client-ready results.
Responsibilities
- Triage, validate, and QA findings surfaced by Sprocket’s automation workflow
- Reproduce and confirm true positives while eliminating false positives before results reach a client
- Author and refine findings to client-ready quality, maintaining the Sprocket voice, then publish through the platform
- Calibrate severity to real business impact using Sprocket standards, prioritizing practical impact over theoretical risk
- Handle roughly 90% of findings independently, making accurate handle-versus-escalate decisions using platform workflow
- Escalate the hard 10% to an Adversarial Engineer with full context attached
- Provide pattern-level feedback to R&D and the Adversarial Engineering team to tune attack automations and reduce false positives
- Log validation notes, flag false-positive patterns, and contribute to the knowledge base
- Script away repetitive validation tasks wherever they appear
- Collaborate with R&D and the Service Delivery team to improve the automation feedback loop and client experience
- After triage is complete and capacity allows, help programmatically enhance the automation pipeline with new or updated capabilities, pairing with an Adversarial Engineer as needed
- Attend daily standups, weekly 1:1s, monthly company calls, and all-hands
Requirements
- Demonstrated experience triaging or reproducing vulnerabilities surfaced by a security tool (vulnerability scanner, SAST/DAST/SCA/IAST, or similar automation) in a professional setting
- Some software programming experience, with Python preferred
- Exposure to using Generative AI tools for day-to-day tasks, with Claude preferred
- Strong Development, IT, or Infosec foundation plus genuine self-directed security study
- Hands-on validation depth across common vulnerability classes, including OWASP Top 10, network, and authentication issues
- Clear, detail-oriented written communication that remains effective under volume
- Self-direction to manage a high-volume queue independently without hourly guidance
Technologies
- Python
- Claude
- Generative AI
- SAST
- DAST
- SCA
- IAST
- OWASP Top 10
- Vulnerability scanner
Benefits
- Unlimited and mandatory PTO for healthy work/life balance
- Company matched 401k with immediate eligibility
- 75% company contribution for health insurance for employees and 50% for dependents
- 100% company contribution for dental and vision
- Flexible working hours
- Hardware and tools of your choice
- Paid training, conferences, and certifications to support career development
Mission and Product Context
- Company mission: help secure as many companies as possible by prioritizing penetration testing
- Emphasis: offensive security for enterprises, building robust defense strategies based on individual business risk
- Platform approach: an expert-driven Continuous Penetration Testing platform combining automated and manual testing
- Your role: the human judgment layer who decides what is real, calibrates severity, and ensures findings read in the Sprocket voice before client delivery
Preferred
- Security+, eJPT, CPTS, PNPT, or similar foundational credential
- CTF achievements (HackTheBox, TryHackMe, PortSwigger Academy)
- Degree in computer science, engineering, or IT
- Interest in working toward OSCP or an equivalent hands-on certification over time
Location: Madison, WI (onsite)