Salary
💰 ₹6,612,600 per year
Tech Stack
CloudCyber SecurityGoJavaScriptOpen SourcePythonRubyWeb3
About the role
- Lead and conduct internal penetration testing engagements on web and mobile applications and services.
- Lead and conduct Red Team operations to test the resiliency of our security protections.
- Document and report findings from security assessments and pentests.
- Collaborate with engineering teams to prioritize and remediate known vulnerabilities.
- Participate in the triage and validation of bug bounty submissions.
- Contribute to the development of security tools and automation.
- Contribute to the development and improvement of security testing methodologies.
- Provide on-call support for product security incidents.
- Lead and participate in red team activities to identify weaknesses in security controls, as well as network and application-level security boundaries.
Requirements
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Software Engineering, or a related field
- Have at least one relevant security certification (e.g., OSCP, GPEN).
- 5+ years of experience in application security, penetration testing, bug bounty triage, or other offensive security roles.
- 3+ years of Red Team experience, with a track record of breaking complex systems using novel techniques
- Experience with programming languages such as Go, JavaScript, Python or Ruby.
- Expert understanding of Web2 security concepts and common vulnerabilities (e.g., OWASP Top 10, SANS Top 25)
- Experience with bug bounty programs and platforms.
- Strong analytical skills to identify trends and patterns in penetration testing findings.
- Excellent communication skills to effectively communicate with researchers and internal teams.
- Energy and self-drive for continuous learning as crypto is a constantly and rapidly changing space.
- Ability to work independently, take ownership of penetration testing and red team engagements as well as oversee the work of junior engineers.
- Experience in building relationships with product, engineering, and other security teams