Skip to content
securityjobs

Jobs /Threat Intelligence jobs in India /Senior Security Researcher, ShadowMap

ShadowMap· 150+

Senior Security Researcher, ShadowMap

  • Mumbai · Hybrid
  • full time
  • web application penetration testing
  • OWASP Top 10
  • burp suite
  • attack surface management
  • ShadowMap
  • exploitation
  • remediation
  • client management

About the role

Security Brigade is hiring a Senior Security Researcher to work alongside ShadowMap, our proprietary attack surface management platform. You will analyse the alerts the platform surfaces, validate them through hands-on penetration testing, and drive remediation conversations directly with customer engineering and security teams. Those alerts cover web and mobile application exposure, data leaks, dark-web findings, and exposed code repositories. You will own customer-facing technical engagements end-to-end: scoping the validation, demonstrating proof-of-concept, helping the customer fix what we found, and contributing back research that improves the platform itself.

What you’ll work on

  • Analyse the attack surface intelligence ShadowMap produces: web/mobile alerts, data leaks, dark-web exposure, code-repo leakage, exposed services
  • Validate findings through targeted manual penetration testing; produce proof-of-concept exploits where customers need evidence
  • Lead client-facing remediation conversations including executive summaries, technical walkthroughs, and follow-up validation
  • Collaborate with customer engineering teams to ship fixes and revalidate them
  • Feed research back into ShadowMap: new attack patterns, false-positive reduction, scoring improvements, new detection ideas
  • Mentor junior researchers and contribute to internal knowledge-sharing

What we’re looking for

  • 4+ years of hands-on web application penetration testing experience
  • Deep working knowledge of OWASP Top 10 and the OWASP Top 10 Proactive Controls: both how to attack and how to advise on remediation
  • Comfortable working customer-side: presenting findings to engineering teams, demonstrating exploits live, and walking remediation owners through fixes
  • Track record on practical labs (Hack The Box, TryHackMe, PortSwigger Web Security Academy) counts, even without enterprise experience
  • Excellent written communication for client-facing reports and executive summaries

Benefits

  • Competitive salary + performance-linked variable
  • Hybrid + remote-friendly
  • Sponsorship for relevant offensive-security certifications (OSCP, OSWE, OSCE, CRTO, BSCP)
  • Internal research time and dedicated lab environment
  • Direct influence on a product (ShadowMap) shipping to enterprise customers

About ShadowMap

An external attack surface and threat intelligence platform: continuous discovery of exposed infrastructure, leaked credentials, dark web activity and brand abuse. A Security Brigade product, launched 2016.

Similar roles

Hiring for a security role? Post it free. No account, no card, reviewed by a person, usually within a working day.