24 Aug
|
Security Brigade
|
Mumbai
24 Aug
Security Brigade
Mumbai
Senior Security Researcher - ShadowMap
Lead exploitation, validation, and customer-facing remediation work on ShadowMap - Security Brigades proprietary attack surface management platform.
web application penetration testing OWASP Top 10 attack surface management Senior Security Researcher - ShadowMap | Security Brigade
AI Threat Era
Senior Security Researcher - ShadowMap
Lead exploitation, validation, and customer-facing remediation work on ShadowMap - Security Brigades proprietary attack surface management platform.
web application penetration testing OWASP Top 10 attack surface management Ready to apply
Send us your CV and a short note on why this role excites you.
Usually responds within 2 business days
About the Role
Security Brigade is hiring a Senior Security Researcher to work alongside ShadowMap, our proprietary attack surface management platform. You will analyse alerts the platform surfaces - web and mobile application exposure, data leaks, dark-web findings, and exposed code repositories - validate them through hands-on penetration testing, and drive remediation conversations directly with customer engineering and security teams. You will own customer-facing technical engagements end-to-end: scoping the validation, demonstrating proof-of-concept, helping the customer fix what we found, and contributing back research that improves the platform itself.
What Youll Do
- Analyse the attack surface intelligence ShadowMap surfaces - web/mobile alerts, data leaks, dark-web exposure, code-repo leakage, exposed services
- Validate findings through targeted manual penetration testing; produce proof-of-concept exploits where customers need evidence
- Lead client-facing remediation conversations including executive summaries, technical walkthroughs, and follow-up validation
- Collaborate with customer engineering teams to ship fixes and revalidate them
- Feed research back into ShadowMap - new attack patterns, false-positive reduction, scoring improvements, current detection ideas
- Mentor junior researchers and contribute to internal knowledge-sharing
What Were Looking For
- 4+ years of hands-on web application penetration testing experience
- Deep working knowledge of OWASP Top 10 and the OWASP Top 10 Proactive Controls - both how to attack and how to advise on remediation
- Comfortable working customer-side: presenting findings to engineering teams, demonstrating exploits live, and walking remediation owners through fixes
- Track record on practical labs (Hack The Box, TryHackMe, PortSwigger Web Security Academy) is a strong signal even without enterprise experience
- Excellent written communication for client-facing reports and executive summaries
What We Offer- Sponsorship for relevant offensive-security certifications (OSCP, OSWE, OSCE, CRTO, BSCP)
- Direct authorship influence on a real product (ShadowMap) shipping to enterprise customers
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Sr Security Researcher - ShadowMap (Mumbai)
🏢 Security Brigade
📍 Mumbai