About the Role
We are looking for a Security Engineer – Offensive Security who is passionate about breaking things, understanding how they can be exploited, and helping build stronger security defenses.
You will work on real-world security assessments across web applications, APIs, networks, cloud environments, and infrastructure. The role involves hands-on penetration testing, vulnerability research, exploitation, security testing, and developing practical proof-of-concepts.
We value technical ability and curiosity over certifications alone.
Responsibilities
- Perform penetration testing of web applications, APIs, networks, and infrastructure.
- Identify, validate, and exploit security vulnerabilities.
- Conduct vulnerability assessments and security reviews.
- Develop Proofs of Concept (PoCs) for identified vulnerabilities.
- Perform security testing against authentication, authorization, business logic, and API functionality.
- Conduct reconnaissance and attack-surface analysis.
- Assist with Red Teaming and adversary simulation activities.
- Perform source-code and application security reviews where required.
- Develop scripts and tools to automate security testing and research.
- Prepare detailed technical reports with impact, evidence, and remediation recommendations.
- Work closely with engineering teams to reproduce and remediate security issues.
- Continuously research emerging vulnerabilities, attack techniques, and offensive-security methodologies.
Requirements
- 1–4 years of hands-on experience in penetration testing or offensive security.
- Strong understanding of OWASP Top 10 and API Security.
- Good understanding of HTTP, TCP/IP, DNS, networking, Linux, and web technologies.
- Hands-on experience with tools such as Burp Suite, Nmap, Metasploit, Wireshark, or equivalent.
- Strong ability to manually identify and exploit vulnerabilities rather than relying solely on automated scanners.
- Scripting/programming experience with Python, Bash, JavaScript, Go, or similar.
- Strong analytical and problem-solving skills.
- Ability to clearly document and communicate technical findings.
Nice to Have
- Experience with Red Teaming or Adversary Simulation.
- Cloud security experience with AWS, Azure, or GCP.
- Mobile application security testing.
- Active Directory / Windows security experience.
- Experience with exploit development or vulnerability research.
- Bug bounty or CTF experience.
- Certifications such as OSCP, OSWE, OSEP, CRTO, PNPT, or equivalent practical experience. Not mandatory.
What We Look For
We are looking for people who don't stop at:
“The scanner found a vulnerability.”
We want engineers who ask:
“How can this actually be exploited, what is the real impact, and how can we prove it?”
If you enjoy breaking applications, investigating attack paths, building PoCs, researching vulnerabilities, and thinking like an attacker, we'd love to hear from you.
₹4,00,000 – ₹6,00,000 per annum, depending on experience, technical skills, and demonstrated offensive-security capability.
Exceptional candidates with strong practical experience may be considered outside this range.
Pay: ₹400,000.00 - ₹600,000.00 per year
Benefits:
- Flexible schedule
- Health insurance
- Internet reimbursement
- Paid time off
- Work from home
Ability to commute/relocate:
- Guwahati, Assam: Reliably commute or planning to relocate before starting work (Required)
Experience:
- Information security: 1 year (Required)
Shift availability:
- Day Shift (Required)
- Night Shift (Required)
- Overnight Shift (Required)
Work Location: Hybrid remote in Guwahati, Assam