06 Sep
|
ISECURION
|
Bengaluru
06 Sep
ISECURION
Bengaluru
Company Description ISECURION is a CERT-In empanelled and ISO 27001:2022 certified cybersecurity consulting company that helps organizations stay secure in an increasingly complex digital environment. The team focuses on strengthening security posture, meeting compliance requirements, and building long-term cyber resilience for clients across industries. Services include Vulnerability Assessment & Penetration Testing (VAPT), compliance audits, cloud security, DFIR, risk assessments, and managed security services. ISECURION is known for a practical, business-focused approach that goes beyond identifying vulnerabilities to help clients understand impact, prioritize remediation, and align with best practices and regulatory standards. The company is driven by a team passionate about cybersecurity, research, innovation, and delivering meaningful security outcomes.
Role Description
ISECURION Technology & Consulting Pvt. Ltd. is looking for a Security Researcher to identify emerging vulnerabilities, zero-day threats, novel attack vectors, and evolving attacker tactics, techniques, and procedures (TTPs). The successful candidate will study real-world threat actors and reproduce their attack patterns to strengthen the organisation's product and service capabilities.
This role works closely with both the Red Team and Product teams, converting original security research into realistic attack simulations and new product capabilities.
Key Responsibilities
• Independent research: Has conducted security research outside of academic or professional requirements.
• Published work: Blogs, technical writeups, tutorials, GitHub projects, research notes, conference submissions, CTF writeups, vulnerability research, or similar evidence of learning and experimentation.
• Genuine cybersecurity passion: Actively follows emerging threats, vulnerabilities, exploitation techniques, operating-system internals, and security research — cybersecurity isn't simply a job for them.
• Windows internals: Strong interest in or demonstrated exploration of areas such as memory management, processes/threads, PE structures,
system calls, kernel/user-mode boundaries, authentication mechanisms, Windows security architecture, or reverse engineering.
• Modern threat research: Demonstrated interest in emerging attack techniques, malware behaviour, exploitation trends, ransomware, identity attacks, cloud threats, supply-chain attacks, or other evolving areas of offensive/defensive security.
• Language agnostic: Comfortable with C, C++, Rust, Python, Go, PowerShell, Assembly, JavaScript, or any other language — what matters is the ability to learn whatever the problem requires.
• First-principles thinker: Doesn't simply rely on tools, frameworks, or “this is how it's normally done”; tries to understand why something works.
• Strong fundamentals: Understands computers beyond the abstraction layer — operating systems, networking, memory, processes, protocols, filesystems, authentication, and system architecture.
• Experimentation mindset: Comfortable building things, breaking things, testing hypotheses, and learning from failure.
• Self-directed learner: Can identify something they don't understand, research it independently, build a mental model, experiment, and explain it to someone else.
• Intellectual humility: Comfortable saying “I don't know” and then going away and figuring it out.
Qualifications
• Strong foundation in offensive security, vulnerability research, and adversary emulation.
• Experience with web/API, network, cloud, Windows/Linux, identity, or application security.
• Strong scripting/programming skills in Python, Go, C/C++, PowerShell, or Bash.
• Curiosity to understand how systems can be broken, not just how they are supposed to work.
Experience with Red Teaming, Bug Bounty, CTFs, exploit research, malware analysis, or BAS is a solid plus.
6 Months -2 Years of Experience as Security Researcher and experience of publishing research and project findings.
Experience in Bug Bounty.
What We Don't Want
We explicitly avoid making this a checklist-driven security hiring process. We are not primarily looking for someone who:
• has certifications as their primary qualification.
• has only performed repetitive VAPT/SOC activities.
• knows a particular security tool but doesn't understand what happens underneath it.
• is a “Python security engineer” or “Burp Suite specialist” who struggles outside their familiar ecosystem.
• needs a predefined learning path.
• is primarily motivated by compensation or title progression.
• can reproduce commands from tutorials but cannot explain why they work.
• follows security trends without actually experimenting with them.
Our Hiring Philosophy
We hire for curiosity, not credentials.
We are looking for people who spend their free time asking “How does this actually work?” and then go deep enough to find the answer.
You don't need to know everything — in fact, you probably shouldn't. What matters is that when you encounter something you don't understand, your instinct is to investigate it, experiment with it, break it apart, understand it from first principles, and eventually explain what you learned.
Your GitHub repositories, research notes, blogs, writeups, experiments, CTF work, tooling, vulnerability research, or other independent projects may tell us more about you than your résumé ever could.
How We Evaluate Candidates
The interview process is designed to match this philosophy, and is deliberately language-agnostic. Rather than “write this function in Python,” candidates are asked to solve a technical problem using whatever language or tooling they prefer, with abstractions progressively removed as the discussion goes deeper.
📌 Security Researcher (Bengaluru)
🏢 ISECURION
📍 Bengaluru