Security Consultant

Open 19d posting dated 18 hours ago

Summary

Conducts security assessments of web applications and APIs, writes proof-of-concept exploits, and presents findings with remediation guidance to clients. Works on-site in Pune doing hands-on penetration testing, source code reviews, and continuous security research to stay current with latest vulnerabilities and exploits.

Payatu is hiring an Application Security Consultant who's genuinely good at breaking things by hand, not someone who lets a scanner do the thinking.

Who we are?

We are a service-based cybersecurity company, and pentesting is what we do all day, every day, across Web Apps, Mobile Apps, and Thick Clients. Our reputation is built on catching what automated scanners walk right past: business logic flaws and the application-specific bugs that only show up when someone sits down and thinks like an attacker instead of running through a checklist.

What we look for outside work parameters?

Your expertise is your primary qualification, not your degree or certification.

Your publicly known contributions are your credentials.

Papers you have written, tools you have developed are your references.

Your write-up reflects your interests and ethics.

Your published exploits, your CTF scores, and hall of fame listings are the testimonies of your work.

Your research paper was published and presented at conferences.

You are learning from the community and enthusiastically contributing back.

Certifications like OSCP, CREST, OSWE, and similar are a plus if you’ve got them, but we don’t gatekeep on degrees or certifications.

Bonus points for AI security skills, on either side of the fence - attacking AI systems or building smart automation around your own testing.

You are a perfect technical fit if:

2-5 years of hands-on Web Application pentesting experience (mobile and thick client experience is a strong plus).

Strong fundamental of application and network protocols.

Stronghold on Web application security concept and penetration testing skill.

Good command of at least one programming language.

Good understanding of OWASP Top 10 and other web-related vulnerabilities as well as logic flaws.

Hands-on experience in performing penetration testing of web-based applications preferably in the financial domain.

Good to have experience in working alongside the development/QA teams.

Good report writing and presentation skills.

Should be able to suggest optimum security improvements to application components.

Burp MCP is baked into our workflow, as part of your day-to-day testing.

Source Code and Config Review experience is a plus for engagements that go beyond Black-Box.

The instinct to poke at things until they break, and the patience to document exactly how.

You Have All Our Desired Qualities, if:

Experience in web application and web service security assessment.

You have a history of publishing or presenting good research.

You have the knack of finding security bugs in everything you touch.

You like automating stuff.

You like writing tools.

You have excellent written and verbal communication skills and the ability to express your thoughts clearly. You have the skill to articulate and present technical things in business language.

You can work independently as well as within a team and meet project schedules and deadlines.

You have strong problem solving, troubleshooting, and analysis skills.

You are passionate about your area of expertise and self-driven.

You are comfortable working in a dynamic and fast-paced work environment.

You are self-driven, proactive, hardworking, team-player.

You are working on something on your own in your field apart from official work.

Your everyday work will look like:

Manual penetration testing of Web Applications, Mobile Applications, and Thick Clients (automation is a starting point here, not the finish line).

Finding the business logic flaws and app-specific bugs that only show up when a human actually tries to break the app.

Security assessment of web application and web service on various platforms.

Back your findings with Proof-of-concept exploits.

Collect evidence and maintain a detailed write-up of the findings.

Understand and explain the results with impact on business and compliance status.

Explain and demonstrate vulnerabilities to application/system owners.

Provide appropriate remediation and mitigations of the identified vulnerabilities.

Individually or collaboratively review the system designs, source code, configurations, communications for security gaps.

Deliver results within stipulated timelines.

Sharpen your saw with continuous research, learning, training on the latest tools and techniques, keeping up with new research, and sharing the same with the ecosystem.

Communicate well using verbal and written skills, within and out of the team.

Reports detailed enough for a developer to fix it, clear enough for a stakeholder to get why it matters. Using automation and AI to work more efficiently, whether that means building tooling to speed up repetitive parts of testing or using AI to sharpen your workflow, all in service of delivering higher-quality work, not cutting corners on it.

Roughly 30% of your time is set aside for research. You choose the topic, and it’s treated as a real part of the job, not something squeezed in on the side.