23 Sep
|
Manticoreai
|
Bengaluru
23 Sep
Manticoreai
Bengaluru
Senior Penetration Tester (Remote, India)
ManticoreAI. Backed by leading US cybersecurity investors. Remote. Full time.
We're an AI-native offensive security company. Pentesting today is slow, manual, and stale the day the report lands. We rebuilt it from the ground up: AI agents that reason through vulnerabilities like an elite operator, prove what's actually exploitable instead of pattern-matching, and produce audit-grade findings in 48 hours that Big 4 auditors accept for SOC 2, PCI DSS, and ISO 27001.
Then we close the loop no one else closes. We don't just find the exploit. We generate the virtual patch that blocks it and the code fix that removes it. Prove, protect, fix.
The Job
Our operating model is "Auditor, not Author." The AI authors findings. A consultant decides whether they are true, and nothing reaches a customer until one does.
You are that consultant. You decide what is real, you prove it by hand when it is unclear, and your judgment is what stands behind a report an auditor reads.
Read this before you apply. This is a wide role. In the same week you might sign off a customer report, hand-exploit something to settle a question, and run a manual engagement end to end. If you want a narrow queue handed to you, this isn't the seat.
What You'd Own
- Validating and signing off findings before any customer sees them. Real, false positive, or needs rework.
- Settling it by hand when the answer is unclear. You have our attack infrastructure and lab targets, and no client authorisation form standing between you and them.
- Retests. Customers get unlimited retests for twelve months. You confirm a fix is actually a fix.
- Full manual engagements, including scoping,
where a customer wants a human-led test.
- Report quality. Our deliverables have to survive an auditor, a customer's engineering team, and occasionally their own consultants.
- Feedback to the people who build the agents. What was missed, what was noise. You are ground truth.
Who You Are
Must have:
- OSCP. Not negotiable.
- 4+ years of professional hands-on offensive security, on authorised engagements against systems that mattered.
- Deep web and API work. REST, GraphQL, SOAP. Authentication logic, access control, business logic flaws, chained exploits.
- You can write. A finding is done when a developer who has never met you can reproduce it and fix it. Most testers are weak here. It is half the job.
- Judgment about false positives. You can decide a claimed finding doesn't hold, and defend that to someone senior who disagrees.
Nice to have:
- CREST CRT. Strongly preferred. If you don't hold it, we pay for the exam and the preparation time.
- CPSA, CCT, OSWE, OSEP, or comparable
- Cloud or container security depth
- Active Directory and internal network testing
- Enough Python to automate your own work
- Public writeups, CVEs, or bug bounty history
Filters:
- Strong written English. The team is async and every deliverable you produce is writing.
- Comfortable being wrong in public. You'll overturn the AI's conclusions and it will occasionally overturn yours.
- Curious about AI tooling rather than threatened by it.
What This Isn't
- Not a queue of findings to click approve on. If you can't reproduce it, it doesn't ship.
- Not blue team. No SOC shifts, no alert triage.
- Not report writing. You're testing.
📌 Senior Penetration Tester (Remote, India) (Bengaluru)
🏢 Manticoreai
📍 Bengaluru