19 Aug
|
C3iHub, IIT Kanpur
|
Delhi
19 Aug
C3iHub, IIT Kanpur
Delhi
Description
We are seeking a highly skilled Windows Security Engineer to join our advanced offensive security research team. The ideal candidate will have deep expertise in Windows internals , strong C/C++ development skills , and hands-on experience conducting low-level attack research , kernel exploitation , and evasion of modern Windows defenses .
This role focuses on adversary simulation , Windows kernel attack surface research , and offensive tooling development to assess and improve the resilience of enterprise Windows environments.
Responsibilities
Offensive Security Research & Exploitation
- Research historical and emerging Windows vulnerabilities (CVE analysis, exploitability assessment)
- Analyze Windows kernel attack surfaces including:
- System calls
- Drivers
- Object manager
- Memory manager
- System calls
- Drivers
- Object manager
- Memory manager
- Develop proof-of-concept exploits for Windows kernel and privileged components (controlled research environment)
- Study and bypass modern Windows exploit mitigations (DEP, ASLR, CFG, KASLR)
- Research historical and emerging Windows vulnerabilities (CVE analysis, exploitability assessment)
- Analyze Windows kernel attack surfaces including:
- System calls
- Drivers
- Object manager
- Memory manager
- Develop proof-of-concept exploits for Windows kernel and privileged components (controlled research environment)
- Study and bypass modern Windows exploit mitigations (DEP, ASLR, CFG, KASLR)
Kernel & Low-Level Tooling
- Build low-level tooling in C/C++ for:
- Privilege escalation
- Kernel callback abuse
- Token manipulation
- Privilege escalation
- Kernel callback abuse
- Token manipulation
- Develop user-mode to kernel-mode interaction tools using IOCTL interfaces
- Build low-level tooling in C/C++ for:
- Privilege escalation
- Kernel callback abuse
- Token manipulation
- Develop user-mode to kernel-mode interaction tools using IOCTL interfaces
Evasion & Defense Bypass Research
- Research and simulate EDR / AV evasion techniques
- Analyze and bypass:
- PatchGuard (Kernel Patch Protection)
- Driver Signature Enforcement (DSE)
- AMSI and ETW-based detections
- PatchGuard (Kernel Patch Protection)
- Driver Signature Enforcement (DSE)
- AMSI and ETW-based detections
- Research and simulate EDR / AV evasion techniques
- Analyze and bypass:
- PatchGuard (Kernel Patch Protection)
- Driver Signature Enforcement (DSE)
- AMSI and ETW-based detections
Adversary Simulation & Red Team Operations
- Simulate advanced persistent threat (APT) techniques targeting Windows environments
- Conduct privilege escalation and post-exploitation research on Windows systems
- Emulate real-world attack chains from userland to kernel
Documentation & Reporting
- Document vulnerabilities, exploitation paths, and attack methodologies clearly
- Produce technical reports for internal stakeholders and leadership
- Contribute to internal red team playbooks and attack frameworks
Eligibility
Education
- Bachelor’s degree in Computer Science, Cybersecurity, or related field
- Equivalent hands-on offensive security experience will be considered
Technical Skills
Windows Internals
Strong understanding of Windows architecture, including:
- Windows kernel architecture
- Process, thread, and token internals
- Virtual memory management
- System Service Descriptor Table (SSDT) concepts
Programming
- Proficiency in C and C++ (kernel-mode and user-mode)
- Experience developing Windows drivers and low-level tools
- Familiarity with inline assembly and reverse engineering concepts
Offensive Security Experience
- Experience with:
- Windows vulnerability research and exploit development
- Privilege escalation techniques
- Kernel exploitation fundamentals
- Windows vulnerability research and exploit development
- Privilege escalation techniques
- Kernel exploitation fundamentals
- Strong understanding of:
- Windows security boundaries
- Attack surface reduction strategies
- Red team tradecraft at OS level
- Windows security boundaries
- Attack surface reduction strategies
- Red team tradecraft at OS level
- Experience with:
- Windows vulnerability research and exploit development
- Privilege escalation techniques
- Kernel exploitation fundamentals
- Solid understanding of:
- Windows security boundaries
- Attack surface reduction strategies
- Red team tradecraft at OS level
Tools & Platforms Experience with offensive and analysis tools such as:
- Debuggers - WinDbg , x64Dbg , GDB
- IDA Pro / Ghidra
- Sysinternals Suite
- Process Monitor / Process Explorer
- Custom exploit frameworks and fuzzers
Certifications (Preferred)
- OSCP, OSEP, OSED, CRTO, or equivalent offensive certifications
- Any advanced Windows or red team–focused certifications are a plus
Required Skills Cyber-security windows
📌 Windows Security Research Engineer (Delhi)
🏢 C3iHub, IIT Kanpur
📍 Delhi