CybersecurityJobs.io
← Back to all jobs

Job Description

Sprocket Security is seeking an Offensive Security Analyst to act as the human judgment layer in an offensive automation pipeline for client-ready results.

Responsibilities

  • Triage, validate, and QA findings surfaced by Sprocket’s automation workflow
  • Reproduce and confirm true positives while eliminating false positives before results reach a client
  • Author and refine findings to client-ready quality, maintaining the Sprocket voice, then publish through the platform
  • Calibrate severity to real business impact using Sprocket standards, prioritizing practical impact over theoretical risk
  • Handle roughly 90% of findings independently, making accurate handle-versus-escalate decisions using platform workflow
  • Escalate the hard 10% to an Adversarial Engineer with full context attached
  • Provide pattern-level feedback to R&D and the Adversarial Engineering team to tune attack automations and reduce false positives
  • Log validation notes, flag false-positive patterns, and contribute to the knowledge base
  • Script away repetitive validation tasks wherever they appear
  • Collaborate with R&D and the Service Delivery team to improve the automation feedback loop and client experience
  • After triage is complete and capacity allows, help programmatically enhance the automation pipeline with new or updated capabilities, pairing with an Adversarial Engineer as needed
  • Attend daily standups, weekly 1:1s, monthly company calls, and all-hands

Requirements

  • Demonstrated experience triaging or reproducing vulnerabilities surfaced by a security tool (vulnerability scanner, SAST/DAST/SCA/IAST, or similar automation) in a professional setting
  • Some software programming experience, with Python preferred
  • Exposure to using Generative AI tools for day-to-day tasks, with Claude preferred
  • Strong Development, IT, or Infosec foundation plus genuine self-directed security study
  • Hands-on validation depth across common vulnerability classes, including OWASP Top 10, network, and authentication issues
  • Clear, detail-oriented written communication that remains effective under volume
  • Self-direction to manage a high-volume queue independently without hourly guidance

Technologies

  • Python
  • Claude
  • Generative AI
  • SAST
  • DAST
  • SCA
  • IAST
  • OWASP Top 10
  • Vulnerability scanner

Benefits

  • Unlimited and mandatory PTO for healthy work/life balance
  • Company matched 401k with immediate eligibility
  • 75% company contribution for health insurance for employees and 50% for dependents
  • 100% company contribution for dental and vision
  • Flexible working hours
  • Hardware and tools of your choice
  • Paid training, conferences, and certifications to support career development

Mission and Product Context

  • Company mission: help secure as many companies as possible by prioritizing penetration testing
  • Emphasis: offensive security for enterprises, building robust defense strategies based on individual business risk
  • Platform approach: an expert-driven Continuous Penetration Testing platform combining automated and manual testing
  • Your role: the human judgment layer who decides what is real, calibrates severity, and ensures findings read in the Sprocket voice before client delivery

Preferred

  • Security+, eJPT, CPTS, PNPT, or similar foundational credential
  • CTF achievements (HackTheBox, TryHackMe, PortSwigger Academy)
  • Degree in computer science, engineering, or IT
  • Interest in working toward OSCP or an equivalent hands-on certification over time

Location: Madison, WI (onsite)

Similar Jobs