
Austin · Texas, USA

Careers

Pentesters publish CVEs. Engineers build BugDazz Autonomous. Engagement leads scope the work. Sales names the threat. Operations keeps researchers in flight. Every role ends in the same artifact: an exploit, a patch, a receipt.
The work —
Six disciplines, one proof chain — research to retest, exploit to patch, sale to renewal.
Reverse-engineer software no one else looked at this year. Chain primitives into working exploits. Publish CVEs that name us. Researchers chained CVE-2024-3400 three weeks before public disclosure — the day-one standard.
Build BugDazz Autonomous — the pentest engine that runs web apps, APIs, and Active Directory on a customer-set schedule. Tools, infra, integrations, plumbing.
Run kickoffs with CISOs and platform leads. Translate findings into language regulators sign off on. Pruthvi and Munmun own this — calls, SOWs, the memo that goes to the board.
Open conversations with security leads at fintechs, banks, healthcare, telecoms, SaaS. The buyers who want artifacts, not templated PDFs.
Equipment. Visas. Conference travel — DEF CON, Black Hat, OWASP, BSides. The work needs the room to happen.
The report lands as work in the right team's queue. The retest passes. The next engagement is scoped before the renewal.
Open positions —
Live from our hiring portal. Apply opens the role on sechire.net — resume, scheduling, references handled there.
5 of 5 roles
Job Role - As part of our offensive security team, you’ll work with cutting-edge tools, innovative techniques, and an experienced team to challenge the status quo and strengthen the digital landscape.…
Security Consultant
Pune, India
onsite · full-time
We send a signal - “w00t w00t” whenever we find a critical vulnerability. Our vision brings the most talented & experienced security consultants in the industry & this right opportunity to grow professionally. We have a…
Security Consultant
Pune
hybrid · full-time
Role Overview: - We are looking for a skilled Application Security Specialist responsible for conducting web, API, and source code security assessments. The candidate should possess strong manual testing capabilities and…
General
Thane/ Belapur
onsite · full-time
Requirement: • Minimum 1-3 years of experience in cybersecurity domain. • Candidate should have CVE IDs or Research Paper Submission on the National & International Conferences. • Candidate should have Bug Bounty or hall…
General
Pune
hybrid · full-time
About the Role SecureLayer7 is expanding its BFSI cybersecurity vertical in 2026. We have been serving leading Banking & Financial Services organizations for the past 4 years and are now scaling aggressively. We are look…
General
Mumbai
hybrid · full-time
Hiring process —
Thirty minutes. Why us, why now, what you have shipped. A pod lead listens more than they ask.
Original CTF for security · code review for engineering · scoping sim for engagement · discovery practice for sales. Two hours.
Talk through your exercise with the team you would work alongside.
Meet the adjacent team — the discipline-gap test.
Sandeep and leadership. Offer within five business days.
Median timeline: two weeks. Two-and-a-half for sales and engagement.
What you get —
Standard line items, written so you know what the offer actually means before you walk into the founders chat.
Benchmarked to local market data, reviewed yearly. Equity for senior hires.
Security track: DEF CON, Black Hat, OWASP, BSides — registration and travel covered. Engineering: pick the technical conferences. Other tracks: same per-head budget, your call on the event.
Pentesters get protected weeks each quarter for original research that ships as a CVE or a public writeup.
A working laptop. Lab hardware for IoT and hardware research. Replaced on the team's standard refresh cycle.
Medical, dental, vision in each office. Parental leave, PTO, sick leave on each office's local policy.
People show up. Specific roles are remote — that is noted on the role itself.
The offer letter spells every line out as a number or a policy reference.
Third-party signal —
Public, anonymous, third-party. Numbers come from Glassdoor's own dashboard for SecureLayer7.
Where we work —
Austin and Pune. Pentesters, researchers, and engagement leads work from both — local hires, local hours.

Austin · Texas, USA

Pune · Maharashtra, India
On record —
14 years of offensive research. Every claim backed by a live CVE or a proven exploit.



Mapped to engagement requirements across
SOC 2 Type IIPCI DSSHIPAAISO 27001GDPRNIST CSFFedRAMPand others
FAQ —
Don't see your role? Tell us what you would build here. info@securelayer7.net