Ethical Hacker jobs in Delhi at CryptoMize are open on a rolling, always-hiring basis — the security practice runs authorized-offense work continuously for clients across every sector we serve. This is a full-time, permanent position with immediate joining, based at our New Delhi HQ: white-hat hacking in the strict sense — vulnerability assessment, authorized exploitation, and risk assessment under written scope, for clients whose defenses genuinely depend on the answers. Below is the complete posting — responsibilities, requirements, the seniority ladder, and the selection process. Hackers whose ethics are load-bearing should read to the end.
LOCATION New Delhi (HQ)
EMPLOYMENT Full-time · Permanent
AVAILABILITY Immediate · Rolling intake
COMPENSATION Discussed at screening
TRACKS ON THIS DESK25
CRAFT SKILLS NAMED12
TOOLS & SYSTEMS5
PATH STAGES4
01
01The actual work
What will you actually do as a Ethical Hacker at CryptoMize?
01
Execute vulnerability assessments and authorized penetration engagements across web applications, mobile stacks, networks, and Active Directory environments
02
Create the scripts and tooling that test for vulnerabilities — automation for the repetitive mechanics, hand-work for the chains scanners cannot see
03
Perform risk assessment across client environments, translating findings into likelihood-and-impact terms their leadership decisions on
04
Work inside compliance-heavy client contexts — PCI-DSS, HIPAA, and ISO 27001 environments where findings speak auditor language
05
Research emerging threats and vulnerability classes, folding them into the practice’s testing methodology
06
Support SIEM-relevant detection engineering conversations — your offense makes their detection better
07
Mentor ethical hacker and pentest interns on engagement work — the practice’s pipeline runs through your review discipline
ROLE RESPONSIBILITIES
As an Ethical Hacker at CryptoMize you will apply hacking skills for defensive purposes — the white hat in its strict definition. You will create scripts that test for vulnerabilities including penetration testing and risk assessment, perform risk assessment across client environments, and document what a determined adversary would actually reach, always under written authorization.
The work is standards-adjacent by nature: our clients audit against PCI-DSS, HIPAA, and ISO 27001-class frameworks, and findings that cannot speak compliance language do not get remediated. You will frame vulnerability reality in the vocabulary of the client’s auditors while keeping the technical proof underneath it rigorous — SIEM-relevant, reproducible, and prioritized by genuine risk rather than scanner confidence.
Ethical hackers here also carry the research and teaching duties that keep the practice ahead: tracking emerging adversary techniques, folding them into methodology, and mentoring the intern bench. The term white hat refers to exactly this arrangement — skill deployed inside authorization, for the defense of the party that granted it — and the practice defends that arrangement as its defining product.
02
02Capability profile
What skills and tools does a Ethical Hacker need?
astro-island,astro-slot,astro-static-slot{display:contents}
Craft skills12 Tools & systems5 Offer standards4
Advanced web and network exploitation — chained, novel attack paths, not checklist outputActive Directory and enterprise-environment attack expertiseScripting mastery — Python and Bash tooling built per engagementRisk assessment methodology — CVSS-class severity reasoning with business translationCompliance-context fluency — PCI-DSS, HIPAA, ISO 27001, COBIT, NIST frameworksSIEM awareness — how findings become detectionsThreat research — tracking emerging vulnerability classes and adversary techniquesReport craft — reproducible findings, prioritized remediation, zero noiseRules-of-engagement discipline under complex scope boundariesClient communication at technical and executive altitudeMentorship of juniors and internsClearable background and absolute discretion
Kali Linux full toolchainBurp Suite Professional and NmapMetasploit Framework with custom module developmentPython/Bash automation toolingMITRE ATT&CK-mapped adversary-technique frameworks
Depth of demonstrated skill in the specific role disciplineClassification and scope of the client engagement the role supportsUrgency and time-sensitivity of active project requirementsTrack record built across CryptoMize engagements
Also known as: ethical hacker jobs · white hat hacker vacancy · security researcher · vulnerability tester
03
03Seniority ladder
Ethical Hacker — seniority path at CryptoMize
White-hat advancement follows engagement quality and research contribution — the findings that held, the detections they improved, the juniors they trained. The ladder below is how the security practice is actually organized.
Ethical Hacker
Owns assessments on assigned engagements with findings sign-off and risk-translation duties.
1/4
Senior Ethical Hacker
Leads complex multi-surface engagements, directs methodology and threat research, mentors hackers and interns.
2/4
Offensive Security Lead
Runs the authorized-offense capability — adversary simulation programs, standards, and staffing across the practice.
3/4
Security Practice Principal
The crossover track: white hats who graduate into principal-level client counsel across the five domains, where the offense-informed judgment defends strategy itself.
4/4
04
04The engagement surface
CryptoMize work a Ethical Hacker touches
Every role plugs into live engagements across the five Penta-P domains — these are the services your work feeds.
Ethical Hacker · Job Opening
This seat plugs into 6 live CryptoMize services across the five Penta-P domains — the work below is where yours lands.
6 SERVICESPENTA-P
Vulnerability Assessment
Penetration Testing
Cyber Threat Intelligence
Cybersecurity
Network Security
Security Training
WHAT DOES ETHICAL HACKER COMPENSATION DEPEND ON?
Compensation is discussed during screening — never a fixed public figure, because it varies per person and per engagement. It depends on:
# OFFER CONSTRUCTION FACTOR
01 Depth of demonstrated skill in the specific role discipline
02 Classification and scope of the client engagement the role supports
03 Urgency and time-sensitivity of active project requirements
04 Track record built across CryptoMize engagements