Our vision is to be the
Champions of a Safer Digital Future and be the
Champions of Change. We believe in empowering individuals and teams with freedom and responsibility to align their goals such that we all row in the same direction. We are uncomfortably transparent, autonomous & accountable, we have zero tolerance for brilliant jerks, we have unlimited vacation policy and more. For us our
Culture Is Our Strategy - check out our Culture Memo for more details and surprises.Location: Delhi/ BengaluruExperience: 6 to 8 years
Core Responsibilities
- The primary role is to work with the Threat Research team on the security and risk quantification research work
- The secondary role of this profile is to conduct the Red Team exercise for various Safe Security customers in order to emulate the real-world adversaries
- Research historic and new security breaches to identify attacker behavior based on ATT&CK as well as its detective controls based on D3FEND
- Continuous research on the latest security trends and novel attacks based on Threat & Vulnerability feeds
- Contribute the research work to MITRE and CTID initiatives
- Closely work with the Integration team to identify requirements of risk signals
- Lead a team of 4-5 Threat Researchers
- Review the outcome from SAFE to fine-tune the risk prioritization model
- Proactively collaborate with the engineering and the program management team
- Review the deliverables of other team members to ensure the delivery quality
Essential Skills/ Qualifications/ Experience
- M.Tech or B.Tech / B.E. / BCA in Computer Science or Information Technology
- Must have hands-on experience in Red Team exercises
- Well-versed in Phishing Simulation and C2 Frameworks as well as Vulnerability Management tools, CSPM/CWPP tools, besides other essential security tools such as Burp Suite Professional, Enumeration, and Bruteforce tools
- Extensive Knowledge of defending/compensating/remediating security issues that result from the network security assessment
- Familiarity with MITRE CVE/NVD, CWE, CAPEC, and ATT&CK framework
- Experience in Cloud Workload and SaaS Application Security
- Research work around Threat Adversaries would be a plus
- Working knowledge of code repository solutions
- Working knowledge of scripting language (Python, Shell Script, JS, etc.) for automation
- Able to manage and guide a team
- Experience with Agile Scrum Methodology
- Effective documentation, communication, and interpersonal skills
Any of the following certifications would be preferred: - OSCP
- OSCE
- CRTE
- CRTO
Join our rocket ship if you want to learn, make your mark and work with incredible talent!