Exploit Researcher

4 days ago


Delhi Division, India HACKELITE PRIVATE LIMITED Full time

Role summary : A hands-on Exploit Researcher with ~2 years of real-world experience who finds, analyzes, and weaponizes vulnerabilities responsibly. You'll turn complex bugs into repeatable Proof- of- Concepts (PoCs), collaborate with product teams to get fixes shipped, and help level up our offensive tooling and incident response. We're looking for someone who moves fast, documents crisply, and treats responsible disclosure as a professional craft.Key responsibilities- Perform vulnerability discovery across binaries, services, mobile platforms (Android), and network protocols using reverse engineering, dynamic analysis and fuzzing.- Develop stable, well-documented Proof- of- Concept exploits and test harnesses that demonstrate impact (RCE, privilege escalation, bypasses).- Reverse engineer applications, firmware, and OS components (Windows, Linux, Android) to identify root causes and attack surfaces.- Research and analyze malware behavior and persistence techniques to inform defensive controls and detection rules.- Develop exploit chains for bugs and demonstrate practical exploitability (memory corruption, logic flaws, auth bypasses).- Design and implement fuzzers, exploit chains, and automation to scale research efforts.- Triage incoming vulnerability reports and reproduce findings accurately and quickly.- Work with product/engineering teams to communicate root cause, risk, and mitigation strategies; validate fixes.- Contribute to internal exploit framework, tooling, playbooks, and knowledge base focused on OS-level and mobile exploitation.- Follow and drive responsible disclosure processes; prepare advisory drafts when required.- Mentor junior researchers and participate in internal red-team exercises / purple-team engagements.Must-have technical skills & experience : - 2 years of hands-on experience in vulnerability research, exploit development, or offensive security.- Strong reverse engineering skills - familiarity with IDA Pro, Ghidra, Binary Ninja or radare2.- Proficient in low-level languages : C/C++ and scripting with Python (pwntools experience is a plus).- Comfortable reading and reasoning about assembly (x86/x64; ARM a plus).- Practical experience with fuzzing (AFL, libFuzzer, Peach, honggfuzz) and designing fuzz targets.- Experience creating PoCs for memory-corruption (use-after-free, buffer overflow), logic bugs, or auth bypasses.- Solid understanding of OS internals (Windows, Linux, Android), process memory layout, and exploitation primitives.- Familiarity with common exploitation mitigations (ASLR, DEP/NX, stack canaries, Control Flow Guard) and bypass techniques.- Experience in Android vulnerability research and mobile exploit development (app sandboxing, binder, native components).- Experience analyzing malware and persistence mechanisms is a strong plus.- Version control (Git), Linux command line, build systems, and debugging (gdb, WinDbg, lldb).Nice-to-have : - Kernel exploit development (Windows/Linux/Android) or hypervisor/firmware research.- Prior bug bounty contributions, CVEs, or CTF wins (pwn/RE categories).- Familiarity with container escape vectors, cloud service misconfigurations, or WebAssembly exploitation.- Experience with exploit mitigation engineering or secure development lifecycle (SDL).- Knowledge of formal vulnerability reporting standards (CVE, CVSS) and disclosure coordination.Behavioural / soft skills : - Clear, concise technical writing - able to produce reproducible PoC write-ups and remediation steps.- Strong problem-solving, creativity, and persistence when debugging complex systems.- Team player : collaborates across product, engineering, and security teams while maintaining professional disclosure ethics.- High integrity and ownership over assigned findings and remediation lifecycle. (ref:hirist.tech)



  • New Delhi, India SquareX Full time

    Job description About SquareX: SquareX is a leading cybersecurity company that focuses on providing robust protection to users while ensuring their productivity remains unhampered. Our mission is to secure the internet for everyone, making our services invaluable to clients worldwide.We are seeking aCybersecurity Researcherto join our team to lead...


  • Bangalore Division, India AppSecure Security Full time

    Location: Fully Remote About Us Appsecure is a leading offensive cybersecurity and red-team services company trusted by Fortune 500s, high-growth startups, and global enterprises. Our team consists of top bug bounty hunters, seasoned red teamers, and security researchers who deliver high-impact security testing across web, mobile, API, and cloud...


  • New Delhi, India Repello AI Full time

    Who we are We're at an inflection point where AI adoption is accelerating faster than security solutions can keep pace. At Repello AI, we're reimagining AI security from the ground up - merging proactive adversarial testing with automated scale to preempt threats before they're exploited. We've raised $1.2M from top-tier investors including General Catalyst,...


  • Delhi, India MyRemoteTeam Inc Full time

    Hiring: AI Red Team EngineerWe're hiring security researchers and offensive engineers to stress-test AI models, agents, and ML systems — from prompt injections to creative exploit chains. If you think like an attacker and build like an engineer, keep reading.What you’ll doRun red-team engagements against AI models and autonomous agents (think advanced...


  • Delhi, India MyRemoteTeam Inc Full time

    Hiring: AI Red Team EngineerWe're hiring security researchers and offensive engineers to stress-test AI models, agents, and ML systems — from prompt injections to creative exploit chains. If you think like an attacker and build like an engineer, keep reading.What you’ll do- Run red-team engagements against AI models and autonomous agents (think advanced...


  • Delhi, India MyRemoteTeam Inc Full time

    Hiring: AI Red Team Engineer We're hiring security researchers and offensive engineers to stress-test AI models, agents, and ML systems — from prompt injections to creative exploit chains. If you think like an attacker and build like an engineer, keep reading. What you’ll do - Run red-team engagements against AI models and autonomous agents (think...


  • New Delhi, India Repello AI Full time

    Who we areWe're at an inflection point where AI adoption is accelerating faster than security solutions can keep pace. At Repello AI, we're reimagining AI security from the ground up - merging proactive adversarial testing with automated scale to preempt threats before they're exploited.We've raised $1.2M from top-tier investors including General Catalyst,...


  • Delhi, India Payatu Full time

    Are you a skilled penetration tester looking for an exciting new opportunity to take your career to the next level? Join our dynamic cybersecurity team, where you’ll have the chance to work on cutting-edge projects, including cloud security, reverse engineering, threat modelling, and product security .Who we are?Payatu is an ISO certified company where we...


  • New Delhi, India Art Technology and Software Full time

    Responsibilities- Client Engagement & Leadership - Act as a trusted security advisor for multiple high-value clients. - Manage end-to-end security assessment projects, including scoping, execution, reporting, and remediation guidance. - Conduct technical and executive-level briefings to communicate findings, risks, and strategic recommendations clearly. -...


  • New Delhi, India Art Technology and Software Full time

    ResponsibilitiesClient Engagement & Leadership Act as a trusted security advisor for multiple high-value clients. Manage end-to-end security assessment projects, including scoping, execution, reporting, and remediation guidance. Conduct technical and executive-level briefings to communicate findings, risks, and strategic recommendations clearly. Translate...