Senior Security Researcher — ShadowMap

Security Brigade

Mumbai

On-site

INR 1,200,000 - 1,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive salary + performance-linked variable
Sponsorship for offensive-security certifications
Internal research time

Job summary

Security Brigade is looking for a Senior Security Researcher to join our team in Mumbai. As part of your role, you will work on our proprietary platform, ShadowMap, analysing alerts, conducting penetration tests, and guiding customers through remediation.

You should have over 4 years of experience in web application testing, excellent communication skills, and a good understanding of the OWASP guidelines. The position offers a competitive salary and hybrid work options.

Qualifications

  • 4+ years of hands-on web application penetration testing experience.
  • Deep knowledge of OWASP Top 10 and Proactive Controls.
  • Excellent written communication for client-facing reports.

Responsibilities

  • Analyse attack surface intelligence from ShadowMap.
  • Validate findings through manual penetration testing.
  • Lead client-facing remediation discussions.

Skills

Web application penetration testing
OWASP Top 10 knowledge
Client-facing communication
Hands-on validation techniques
Mentorship

Job description

Lead exploitation, validation, and customer-facing remediation work on ShadowMap — Security Brigade's proprietary attack surface management platform.

Security Brigade is hiring a Senior Security Researcher to work alongside ShadowMap, our proprietary attack surface management platform. You will analyse alerts the platform surfaces — web and mobile application exposure, data leaks, dark-web findings, and exposed code repositories — validate them through hands‑on penetration testing, and drive remediation conversations directly with customer engineering and security teams. You will own customer‑facing technical engagements end‑to‑end: scoping the validation, demonstrating proof‑of‑concept, helping the customer fix what we found, and contributing back research that improves the platform itself.

What You’ll Do
  • Analyse the attack surface intelligence ShadowMap surfaces — web/mobile alerts, data leaks, dark‑web exposure, code‑repo leakage, exposed services
  • Validate findings through targeted manual penetration testing; produce proof‑of‑concept exploits where customers need evidence
  • Lead client‑facing remediation conversations including executive summaries, technical walkthroughs, and follow‑up validation
  • Collaborate with customer engineering teams to ship fixes and revalidate them
  • Feed research back into ShadowMap — new attack patterns, false‑positive reduction, scoring improvements, new detection ideas
  • Mentor junior researchers and contribute to internal knowledge‑sharing
What We’re Looking For
  • 4+ years of hands‑on web application penetration testing experience
  • Deep working knowledge of OWASP Top 10 and the OWASP Top 10 Proactive Controls — both how to attack and how to advise on remediation
  • Comfortable working customer‑side: presenting findings to engineering teams, demonstrating exploits live, and walking remediation owners through fixes
  • Track record on practical labs (Hack The Box, TryHackMe, PortSwigger Web Security Academy) is a strong signal even without enterprise experience
  • Excellent written communication for client‑facing reports and executive summaries
What We Offer
  • Competitive salary + performance‑linked variable
  • Hybrid + remote‑friendly
  • Sponsorship for relevant offensive‑security certifications (OSCP, OSWE, OSCE, CRTO, BSCP)
  • Internal research time and dedicated lab environment
  • Direct authorship influence on a real product (ShadowMap) shipping to enterprise customers
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Researcher (Web Application)
Security Researcher (Web Application)

Security Brigade • Mumbai

Hybrid
INR 1,000,000 - 1,500,000
Competitive salary
Sponsorship for certifications
Internal lab environment for research
ShadowMap Tech Lead
ShadowMap Tech Lead

Security Brigade • Mumbai

Hybrid
INR 1,200,000 - 1,800,000
Competitive salary + benefits package
Sponsorship for relevant technical certifications
Strong internal R&D culture
Associate Cybersecurity Consultant
Associate Cybersecurity Consultant

Security Brigade • Mumbai

Hybrid
INR 800,000 - 1,200,000
Competitive salary aligned to experience
Hybrid + remote-friendly
Sponsorship for offensive security certifications
+2
Senior Penetration Tester
Senior Penetration Tester

AppSecure Security • Bengaluru Urban

Remote
INR 1,500,000 - 2,100,000
Competitive compensation package
Comprehensive health insurance
Company-sponsored off-sites
+2
Application Security Consultant
Application Security Consultant

Securityboat • Mumbai

On-site
INR 1,200,000 - 2,000,000
Flexible engagements
Competitive compensation
Collaborative cybersecurity team
+1
Sr. Security Consultant
Sr. Security Consultant

Eventussecurity • Mumbai

On-site
INR 1,200,000 - 2,000,000
Senior Vulnerability Management Engineer
Senior Vulnerability Management Engineer

LSEG • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Senior Security Research Engineer
Senior Security Research Engineer

Jobgether • India

On-site
INR 1,200,000 - 1,800,000
Competitive salary
Fully remote work
Open vacation policy
+3
Offensive Security Services, Senior Consultant
Offensive Security Services, Senior Consultant

UltraViolet Cyber • Bengaluru

On-site
INR 1,500,000 - 3,000,000
Application Security Engineer
Application Security Engineer

DigiCert • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Generous time off policies
Top shelf benefits
Education, wellness, and lifestyle support