Product · ShadowMap
Security Researcher, ShadowMap Customer Engagements
Validate what ShadowMap finds through hands-on penetration testing, then help customers fix it as part of our ShadowMap managed services team.
📍 Mumbai / Remote
🗓 Full-time
📊 Junior
web application penetration testingOWASP Top 10burp suiteattack surface managementShadowMapvulnerability validationproof-of-conceptremediationclient communication
Ready to apply?
Send us your CV and a short note on why this role excites you.
Apply Now →Usually responds within 2 business days
About the Role
Security Brigade is hiring a Security Researcher to work on ShadowMap, our attack surface management platform. You will analyse the alerts it raises across web and mobile applications, data leaks, dark-web exposure, and exposed code repositories, then confirm the ones that matter through hands-on penetration testing. The role is hybrid and sits in our ShadowMap managed services team, which looks after many customers over the long term: you will present findings, demonstrate proof-of-concept exploits, and work with each customer's developers until the issue is fixed. It suits someone one to three years into web application security who wants client-facing work, alongside and mentored by our senior ShadowMap researchers.
What You'll Do
- ▸ Analyse the alerts ShadowMap raises: web and mobile application exposure, data leaks, dark-web findings, and exposed code repositories
- ▸ Validate findings through targeted manual penetration testing, separating real risk from noise
- ▸ Prepare presentations that summarise findings, business impact, and remediation for each customer
- ▸ Demonstrate proof-of-concept exploits to customers and work with their developers until the fixes ship
- ▸ Retest fixes and track open findings across the customers you look after
- ▸ Feed what you learn back into ShadowMap: new attack patterns, false-positive reduction, and new detection ideas
What We're Looking For
- ✓ 1–3 years of hands-on web application penetration testing
- ✓ Working knowledge of the OWASP Top 10 and the OWASP Top 10 Proactive Controls: how to find each issue and how to advise on fixing it
- ✓ Practical lab experience on Hack The Box, TryHackMe, or PortSwigger Web Security Academy
- ✓ Clear spoken and written English for customer presentations and reports
- ✓ Comfortable looking after several customers at once, each over the long term
- ✓ A web application penetration testing certification a plus
- ✓ Familiarity with offensive toolkits for network and web application penetration testing a plus
- ✓ Familiarity with offensive and defensive security concepts a plus
- ✓ No degree required: passion, capability, and hands-on experience come first
What We Offer
- ✓ Competitive salary aligned to experience
- ✓ Hybrid working in business hours, with no shift work
- ✓ Sponsorship for OSCP, BSCP, or equivalent certifications
- ✓ Mentorship from senior ShadowMap researchers
- ✓ Internal lab environment and research time
- ✓ Direct influence on ShadowMap, a platform in production with global enterprise customers
Quick Facts
Team Product · ShadowMap
Product ShadowMap
Location Mumbai / Remote
Type Full-time
Level Junior
Posted 29 Sept 2026