Skip to content
securityjobs

Jobs /Threat Intelligence jobs in India /Security Researcher, ShadowMap Customer Engagements

ShadowMap· 150+

Security Researcher, ShadowMap Customer Engagements

  • Mumbai · Hybrid
  • full time
  • web application penetration testing
  • OWASP Top 10
  • burp suite
  • attack surface management
  • ShadowMap
  • vulnerability validation
  • proof-of-concept
  • remediation
  • client communication

About the role

Security Brigade is hiring a Security Researcher to work on ShadowMap, our attack surface management platform. You will analyse the alerts it raises across web and mobile applications, data leaks, dark-web exposure, and exposed code repositories, then confirm the ones that matter through hands-on penetration testing. The role is hybrid and sits in our ShadowMap managed services team, which looks after many customers over the long term: you will present findings, demonstrate proof-of-concept exploits, and work with each customer's developers until the issue is fixed. It suits someone one to three years into web application security who wants client-facing work, alongside and mentored by our senior ShadowMap researchers.

What you’ll work on

  • Analyse the alerts ShadowMap raises: web and mobile application exposure, data leaks, dark-web findings, and exposed code repositories
  • Validate findings through targeted manual penetration testing, separating real risk from noise
  • Prepare presentations that summarise findings, business impact, and remediation for each customer
  • Demonstrate proof-of-concept exploits to customers and work with their developers until the fixes ship
  • Retest fixes and track open findings across the customers you look after
  • Feed what you learn back into ShadowMap: new attack patterns, false-positive reduction, and new detection ideas

What we’re looking for

  • 1–3 years of hands-on web application penetration testing
  • Working knowledge of the OWASP Top 10 and the OWASP Top 10 Proactive Controls: how to find each issue and how to advise on fixing it
  • Practical lab experience on Hack The Box, TryHackMe, or PortSwigger Web Security Academy
  • Clear spoken and written English for customer presentations and reports
  • Comfortable looking after several customers at once, each over the long term
  • A web application penetration testing certification a plus
  • Familiarity with offensive toolkits for network and web application penetration testing a plus
  • Familiarity with offensive and defensive security concepts a plus
  • No degree required: passion, capability, and hands-on experience come first

Benefits

  • Competitive salary aligned to experience
  • Hybrid working in business hours, with no shift work
  • Sponsorship for OSCP, BSCP, or equivalent certifications
  • Mentorship from senior ShadowMap researchers
  • Internal lab environment and research time
  • Direct influence on ShadowMap, a platform in production with global enterprise customers

About ShadowMap

An external attack surface and threat intelligence platform: continuous discovery of exposed infrastructure, leaked credentials, dark web activity and brand abuse. A Security Brigade product, launched 2016.

Similar roles

  • ShadowMapVerified employer

    Senior Security Researcher, ShadowMap

    2 weeks ago
    • Mumbai · Hybrid
    • Threat Intelligence & Research
    • web application penetration testing
    • OWASP Top 10
    • burp suite
    • attack surface management
    • ShadowMap
    • +3

    258 views

  • ShadowMapVerified employer

    ShadowMap Tech Lead

    2 weeks ago
    • Mumbai · Hybrid
    • Security Engineering & Development
    • PHP
    • Python
    • Laravel
    • Django
    • MySQL
    • +7

    313 views

  • last week
    • Mumbai · Hybrid
    • Security Sales & Pre-Sales
    • 3–6 yrs

    44 views

  • G-Info Technology Solutions Pvt. Ltd.

    VAPT & Red Teaming: Trainee to Team Lead

    last week
    • Gurugram (Delhi NCR) · Hybrid
    • Penetration Testing
    • Freshers–10 yrs
    • Burp Suite
    • Nmap
    • Nessus
    • Metasploit
    • Kali Linux
    • +7

    103 views

Hiring for a security role? Post it free. No account, no card, reviewed by a person, usually within a working day.