Security Engineer I is an early-career, hands-on cybersecurity engineering role for candidates with strong technical depth in VAPT, reverse engineering, vulnerability research, and attacker-style problem-solving. The candidate must have practical penetration testing experience across web applications, APIs, and mobile applications, with the ability to validate vulnerabilities, understand root causes, assess exploitability, and think from an attacker's perspective.
The role also requires a strong foundation in reverse engineering, vulnerability analysis, Python scripting, and security research. Working knowledge of cloud security and exposure to defensive technologies such as EDR, SIEM, and DLP are expected. Published technical research, GitHub projects, responsible disclosures, CTFs, or meaningful bug bounty experience will be highly valued.
Responsibilities:
- Perform VAPT and penetration testing across web applications, APIs, and mobile applications.
- Identify, validate, and demonstrate vulnerabilities through manual testing and exploitation techniques.
- Perform reverse engineering and technical analysis of binaries, applications, scripts, malware samples, or proof-of-concept code.
- Analyze application and system behavior using static analysis, dynamic analysis, debugging, and research techniques.
- Investigate vulnerabilities at a technical level and determine practical exploitability, attack paths, and security impact.
- Write Python scripts and lightweight tooling to automate security testing, analysis, data extraction, and repetitive validation activities.
- Modify existing internal or open-source security tools to improve research, testing, and validation workflows.
- Document technical findings with reproduction steps, exploit conditions, impact, evidence, and remediation guidance.
- Support security engineering activities involving cloud security, EDR, SIEM, DLP, and other defensive security technologies.
- Work with senior security engineers to expand capabilities across cloud security, SecOps, incident response, and defensive engineering.
Requirements:
- 2+ years of hands-on experience in cybersecurity, VAPT, penetration testing, vulnerability research, reverse engineering, or a closely related technical role.
- Mandatory hands-on penetration testing experience across web, API, and mobile applications.
- Strong understanding of VAPT methodologies, vulnerability validation, exploitation, and attacker-style problem-solving.
- Strong reverse engineering aptitude, including analysis of code flow, software behavior, execution logic, and attack surfaces.
- Good understanding of common vulnerability classes across web, API, mobile, software, and infrastructure environments.
- Ability to write and understand Python for security automation, scripting, and technical analysis.
- Basic understanding of Linux, operating system behavior, networking, debugging, and security analysis workflows.
- Working knowledge of cloud security concepts across one or more major cloud platforms.
- Exposure to defensive security technologies such as EDR, SIEM, and DLP.
- Strong analytical mindset, attention to detail, curiosity, and ability to perform deep technical investigations.
Preferred Qualifications:
- Strong bug bounty experience, responsible disclosures, or demonstrated vulnerability research.
- Published security research, tools, PoCs, write-ups, or technical projects on GitHub.
- Experience with malware analysis, binary analysis, exploit development, or vulnerability research.
- CTF participation with demonstrated technical depth.
- Familiarity with decompilers, disassemblers, debuggers, system internals tools, sandboxing, and traffic analysis tools.
- Strong understanding of OWASP Top 10 API security and mobile application security.
- Experience with tools such as Burp Suite, Frida, JADX, Ghidra, IDA, Wireshark, or equivalent security testing/research tools.
- Exposure to cloud security testing and cloud-native security controls.
- Exposure to security monitoring, EDR/SIEM investigation, DLP, or incident response workflows.
- Security certifications such as Security+, eJPT, OSCP, CEH, or equivalent hands-on credentials.

