Skip to main content

We are hiring

Build the defences a country runs on.

Threatsys secures platforms serving crores of citizens, banks moving a billion dollars a year, and governments across three continents. If you want your work to matter outside a slide deck, this is the place.

The Threatsys team
  • 3,00,000+

    Bugs found & reported

  • 150+

    Skilled experts

  • 15+

    Countries with presence

  • 150+

    Hall of Fame entries

Why here

We invest in the people doing the work.

  • Certifications paid for

    OSCP, C|PENT, CISSP, CIPP and cloud certifications funded, with study time built into your schedule.

  • Real engagements from week one

    National scale government platforms, banks and fintechs. You will not be shadowing for six months.

  • Research time

    Dedicated time for security research, CVE hunting and conference submissions. 150+ Hall of Fame entries and counting.

  • Health cover for you and family

    Comprehensive medical insurance covering you, your spouse, children and parents.

  • Flexible and hybrid

    Hybrid working for most roles, with genuine flexibility around delivery windows and client commitments.

  • Conference and community

    Support to speak and attend: NASSCOM, TEDx, national CERT forums and the wider Indian security community.

Open roles

6 positions open right now.

  • Offensive SecurityFull time

    Senior Penetration Tester

    Lead web, mobile, API and network engagements for banks, government departments and enterprises. You will own scope, execution and the client conversation.

    • Bhubaneswar or Noida
    • 4 to 8 years
    • Full time
    Apply

    What you will do

    • Run manual exploitation across web, mobile, API and network targets
    • Chain findings into realistic attack paths and prove business impact
    • Write reports both a board and a developer can act on
    • Support clients through remediation and re-testing
    • Mentor junior testers and review their findings

    What we look for

    • OSCP, C|PENT, CREST or equivalent hands-on certification
    • Demonstrable experience with Burp Suite, custom tooling and scripting
    • Comfortable testing regulated environments under strict rules of engagement
    • Clear written English; the report is the deliverable
  • Compliance & AdvisoryFull time

    GRC Consultant, ISO 27001 and SOC 2

    Take clients from gap assessment to certified across ISO 27001, SOC 2, PCI DSS and the DPDP Act, and keep their evidence current between audits.

    • Bhubaneswar
    • 3 to 6 years
    • Full time
    Apply

    What you will do

    • Run gap assessments and build costed remediation roadmaps
    • Design ISMS documentation, policies and control libraries
    • Prepare clients for external audit and attend as their advisor
    • Operate continuous evidence collection in GRC 360

    What we look for

    • ISO 27001 Lead Auditor or Lead Implementer certification
    • Working knowledge of at least two of SOC 2, PCI DSS, DPDP, RBI or SEBI
    • Confident presenting to CXO and audit committee audiences
  • Managed Detection & ResponseFull time

    SOC Analyst, Level 2

    Triage, investigate and respond to alerts across client estates on the AI SOC 360 platform. Escalate what matters, close what does not.

    • Bhubaneswar, rotating shifts
    • 2 to 5 years
    • Full time
    Apply

    What you will do

    • Investigate escalated alerts and determine true positives
    • Drive containment and coordinate client response
    • Tune detections to cut noise and improve fidelity
    • Contribute to threat hunting hypotheses

    What we look for

    • Hands-on SIEM experience, ideally with detection engineering exposure
    • Solid grasp of MITRE ATT&CK and Windows or Linux internals
    • Willing to work a rotating 24x7 shift pattern
  • Cloud & InfrastructureFull time

    Cloud Security Engineer

    Assess and harden AWS, Azure and GCP estates, and build the posture management that keeps them that way.

    • Noida or remote in India
    • 3 to 7 years
    • Full time
    Apply

    What you will do

    • Run cloud configuration reviews and IAM privilege analysis
    • Perform cloud-native exploitation and lateral movement testing
    • Implement CSPM tooling and wire drift detection into client change process
    • Harden Kubernetes and container pipelines

    What we look for

    • AWS Security Specialty, AZ-500 or equivalent
    • Infrastructure as code experience: Terraform, CloudFormation or Bicep
    • Scripting in Python or Go
  • Privacy & Data ProtectionFull time

    Privacy Consultant, DPDP Act

    Build DPDP Act programmes end to end: consent, data principal rights, grievance SLAs, notices, DPIAs and vendor risk.

    • Bhubaneswar or Noida
    • 2 to 6 years
    • Full time
    Apply

    What you will do

    • Map data flows and build records of processing
    • Design consent and rights fulfilment workflows in DPDP 360
    • Run DPIAs and advise on cross-border transfer
    • Train client teams on their obligations

    What we look for

    • CIPP, CIPM or equivalent privacy certification, or strong practical experience
    • Working knowledge of the DPDP Act 2023 and GDPR
    • Ability to translate legal text into engineering requirements
  • Threatsys Educational WingInternship, 6 months

    Cyber Security Intern

    A structured six month programme across testing, compliance and SOC operations, with a mentor and a real project from month two.

    • Bhubaneswar
    • Final year students and fresh graduates
    • Internship, 6 months
    Apply

    What you will do

    • Shadow senior engineers on live engagements
    • Build and present a security research project
    • Support report writing and evidence collection

    What we look for

    • Studying computer science, IT or a related discipline
    • Demonstrable curiosity: CTFs, home lab, write-ups or open source
    • Available full time for the six month period

Apply

One form. A human reads it.

No applicant tracking black hole. Applications go straight to the team lead for the role you pick.

  1. 01Application reviewWithin five working days, from the team you applied to.
  2. 02Technical conversationSixty minutes on what you have actually built or broken.
  3. 03Practical exerciseA realistic, time-boxed task. No trick questions, no unpaid work.
  4. 04Team and offerMeet the people you would work with, then a decision either way.

Apply now

Tell us who you are and what you want to work on. Every application is read by a human on the team you are applying to.

Optional, but it helps a lot.

Optional.

Email your CV instead

We keep applications for twelve months so we can come back to you when something opens up. See our privacy policy.

What the work is actually like

Security work is sold to candidates on its most dramatic ten per cent. The honest description of a week is more mixed and, if it appeals to you, more interesting.

A meaningful part of any engagement is careful, repetitive and unglamorous: enumerating an authorisation matrix by hand across every role because automated tooling cannot know that two beneficiary records belong to different people, or reading configuration until something does not fit. The findings that matter are found this way far more often than by a clever exploit.

The rest is judgement. Deciding whether something is a finding or an observation. Arguing severity with a client's engineers who know their architecture better than you do and are sometimes right. Writing a paragraph that an executive will act on and a developer will not resent.

You will also write. Everyone who tests, writes. There is no report writing team here, which means the quality of your prose is part of the quality of your work, and we will help you get better at it.

How we hire, step by step

A conversation first, about what you have actually done, in whatever detail you are permitted to give. We are more interested in one system you understand deeply than in a list of tools you have run.

Then a technical session built around a deliberately ambiguous finding, one where the impact genuinely depends on context we have not supplied. We are watching whether you ask for the context or rate it confidently. The confident rating is the wrong answer and it is the answer most people give, because certainty feels like competence.

Then a written exercise, because writing is the job. A short finding, reproduction steps, and the executive line. We are looking for whether a non-specialist could act on it.

Then a conversation with the practice lead you would work under, which runs both ways. Ask them what went wrong on their last engagement. If they cannot answer, that is information about us.

What we look for, and what we do not require

  • Curiosity that predates employment: something you took apart because you wanted to know
  • Intellectual honesty, specifically the ability to say you do not know yet
  • Writing that a non-specialist can act on, which we will help you develop
  • Comfort being argued with by a client who knows their system better than you
  • No requirement for a specific degree, and no requirement to already hold certifications
  • No requirement to have worked at a well-known firm, or in a metro

How we support people once they are here

Certification training and examination costs sit with us, not with you. An engineer funding the firm's credibility out of their own salary is an arrangement that quietly fails, and we would rather not pretend otherwise.

Research time is protected rather than notional. It appears in capacity planning, which is the only test of whether a benefit is real.

Everyone is paired on their first engagements, and everyone's reports are reviewed before they go out, at every level of seniority. Review is not a probationary condition here; it is how the standard is maintained.

Career progression runs along the practitioner track as far as it goes. You do not have to stop testing to be promoted, and the practice leads still take engagements, which is the proof that this is real rather than a line in a handbook.

The parts you should weigh before applying

The work has real deadlines set by other people's regulators, and there are weeks that are genuinely demanding. Testing windows for production systems are set by change control, which occasionally means unsociable hours. We schedule around it and compensate for it, and we are not going to claim it does not happen.

We are based in Bhubaneswar and a meaningful share of the engineering happens there. If you are looking for a fully distributed role with no expectation of ever being in an office, we are probably not the right fit and it is better to know now.

We are a small firm. That means unusual access, real responsibility early, and the absence of the structure a large organisation provides. Some people find that liberating and some find it exposed. Both reactions are reasonable.

If there is no role listed that fits you

Write anyway. Our hiring is more often driven by meeting somebody worth hiring than by a vacancy opening, and several of our engineers arrived that way.

What helps: something you have actually done, described in enough detail to show how you think. A disclosure you made, a system you took apart, a write-up you are proud of. What helps less is a list of tools and a summary of a course.

We answer applications, including the ones we decline. Being ignored after making an effort is a small unkindness that this industry commits constantly, and we would rather not.