Pen Tester / SOC Analyst

PRA ·www.pra.com.au

Location US
Type Full time
Level Mid
Source Shazamme
Operations Security IT & Infrastructure
Apply direct
About the opportunity

Our client is looking for a security professional who doesn't want to choose between offence and defence. Sitting within its cyber security operations team, this role splits time roughly evenly between authorised penetration testing and Security Operations Centre work.

What makes it different is the feedback loop. The weaknesses you find in testing don't just go into a report; you'll map them to MITRE ATT&CK and use them to validate and improve the telemetry, detections and playbooks the SOC relies on every day. It's a complex, multi-platform environment with a strong Microsoft identity footprint, offering real breadth across applications, infrastructure, identity and cloud.

The role
  • Plan and deliver authorised penetration tests across web apps, APIs, infrastructure, identity services and cloud platforms, under defined Rules of Engagement
  • Monitor and triage alerts across SIEM, EDR and XDR platforms, investigating and escalating confirmed incidents
  • Develop, tune and validate detection rules, use cases, dashboards and response playbooks
  • Run proactive threat hunts using telemetry, threat intelligence and known adversary behaviour
  • Report findings with evidence, risk ratings, remediation advice and re-test outcomes
What you'll bring
  • Proven experience in both penetration testing and security operations within complex enterprise environments
  • Hands-on SIEM, EDR or XDR experience, including triage, incident analysis and escalation
  • Detection engineering experience using KQL, SPL, Sigma or equivalent, and a strong grasp of MITRE ATT&CK
  • Solid knowledge of Active Directory, Entra ID, Microsoft 365, Windows and Linux security
  • A relevant tertiary qualification and current industry security accreditation
Recognised pen testing, SOC, incident response or cloud security certifications are highly regarded, as is Agile delivery experience.

Culture
  • Close collaboration with security engineering, infrastructure, cloud, application, identity, architecture and risk teams
  • A disciplined approach: controlled testing in production under change, escalation and safety requirements
  • An individual contributor role with genuine breadth rather than a narrow specialism
If this sounds like you please apply for the role right away!

Frequently asked questions

Who is hiring for the Pen Tester / SOC Analyst role?
PRA is hiring for the Pen Tester / SOC Analyst position, a Shazamme client. Apply directly on the employer's career site.
Where is the Pen Tester / SOC Analyst job located?
The Pen Tester / SOC Analyst role with PRA is based in US.
Is the Pen Tester / SOC Analyst role full-time or contract?
This is a full time position at PRA.
What experience level is the Pen Tester / SOC Analyst role?
The Pen Tester / SOC Analyst position is aimed at mid-level candidates.
How do I apply for the Pen Tester / SOC Analyst role at PRA?
Apply directly on PRA's career page via the Apply button on this listing. ZammeJobs links straight through to the employer's ATS — no third-party form, no resume database.
Apply direct