About the role
Security Brigade is hiring a Security Researcher to work on ShadowMap, our attack surface management platform. You will analyse the alerts it raises across web and mobile applications, data leaks, dark-web exposure, and exposed code repositories, then confirm the ones that matter through hands-on penetration testing. The role is hybrid and sits in our ShadowMap managed services team, which looks after many customers over the long term: you will present findings, demonstrate proof-of-concept exploits, and work with each customer's developers until the issue is fixed. It suits someone one to three years into web application security who wants client-facing work, alongside and mentored by our senior ShadowMap researchers.
What you’ll work on
- Analyse the alerts ShadowMap raises: web and mobile application exposure, data leaks, dark-web findings, and exposed code repositories
- Validate findings through targeted manual penetration testing, separating real risk from noise
- Prepare presentations that summarise findings, business impact, and remediation for each customer
- Demonstrate proof-of-concept exploits to customers and work with their developers until the fixes ship
- Retest fixes and track open findings across the customers you look after
- Feed what you learn back into ShadowMap: new attack patterns, false-positive reduction, and new detection ideas
What we’re looking for
- 1–3 years of hands-on web application penetration testing
- Working knowledge of the OWASP Top 10 and the OWASP Top 10 Proactive Controls: how to find each issue and how to advise on fixing it
- Practical lab experience on Hack The Box, TryHackMe, or PortSwigger Web Security Academy
- Clear spoken and written English for customer presentations and reports
- Comfortable looking after several customers at once, each over the long term
- A web application penetration testing certification a plus
- Familiarity with offensive toolkits for network and web application penetration testing a plus
- Familiarity with offensive and defensive security concepts a plus
- No degree required: passion, capability, and hands-on experience come first
Benefits
- Competitive salary aligned to experience
- Hybrid working in business hours, with no shift work
- Sponsorship for OSCP, BSCP, or equivalent certifications
- Mentorship from senior ShadowMap researchers
- Internal lab environment and research time
- Direct influence on ShadowMap, a platform in production with global enterprise customers


