GitHub, Inc. logo

Senior Penetration Tester

GitHub, Inc. • New Delhi, Delhi, India

remotefull-time
Posted Oct 3, 2026Apply by Apr 1, 2027

**Role & seniority: ** Ethical Hacker / Red Teamer / Security Researcher (highly skilled, experienced; not beginner/intermediate; “elite” team)

**Stack/tools (mentioned or implied): **

  • Advanced offensive security skills across Web/API, Network/Infrastructure, Cloud, Reverse Engineering, Binary Exploitation, Applied Cryptography, OS/Endpoint, Firmware/Boot, Runtime Analysis/Debugging, Red teaming/attack-chain development

  • Tooling not explicitly listed; expects ability to operate beyond automated scanners

  • Certifications (plus): OSCP, OSEP, OSWE, OSED, CRTO, PNPT, eCPPT, etc.

  • Top 3 responsibilities:

    • Conduct authorized security testing against real physical systems in a controlled lab

    • Perform advanced exploitation: web/API, network, cloud, binary/vulnerability research, reverse engineering, exploit development

    • Develop/execute attack chains via red teaming and runtime analysis; produce actionable findings

  • Must-have skills:

    • Several years of hands-on security experience

    • Proven professional penetration testing experience; discovered serious vulnerabilities

    • Ability to investigate systems beyond automated tools

    • Strong technical portfolio (GitHub/research/CTF) and/or published findings

    • Reverse engineering and/or exploit development capability

  • Nice-to-haves:

    • Published security research and/or CVE discoveries

    • Participation in advanced CTFs

    • Offensive tool devel

Full Description

HIRING: ELITE ETHICAL HACKERS / RED TEAMERS This could be the best hacking experience you’ll ever have. I am not looking for beginners. I am looking for highly skilled, experienced, and technically driven security professionals who have already spent years breaking systems, researching vulnerabilities, conducting penetration tests, and going beyond standard security assessments. I am building a small, elite ethical hacking team for a confidential cybersecurity project across Delhi / NCR / Uttar Pradesh / Haryana. This is an authorized security testing engagement where selected team members will get the opportunity to work with real physical systems in a controlled testing environment. Areas of expertise Advanced Web & API Penetration Testing Network & Infrastructure Security Cloud Security Reverse Engineering Binary Exploitation & Vulnerability Research Applied Cryptography OS Internals & Endpoint Security Firmware / Boot Security Advanced Application Security Runtime Analysis & Debugging Red Teaming & Attack-Chain Development Certifications Certifications are not mandatory. OSCP, OSEP, OSWE, OSED, CRTO, PNPT, eCPPT, or equivalent certifications are a plus. However, demonstrated technical ability matters far more than certifications. Who should apply?

I am particularly interested in individuals who have

  • Several years of hands-on cybersecurity experience
  • Conducted professional penetration tests
  • Discovered serious vulnerabilities
  • Published security research
  • Participated in advanced CTFs
  • Built offensive-security tools
  • Reverse-engineered software
  • Worked on exploit development
  • Discovered CVEs
  • A strong GitHub, research, or technical portfolio
  • A proven ability to investigate systems beyond automated tools
  • This is not a training program.
  • This is not a beginner internship.
  • This is not another CTF.
  • I am looking for people who already know how to hack and want to put those skills against a real-world system in a controlled and authorized environment.

Location: Delhi / NCR / Uttar Pradesh / Haryana

Project: Confidential

Roles: Ethical Hackers / Red Teamers / Security Researchers

Engagement: Authorized Security Testing If you believe you have the technical depth required, DM me with your profile, GitHub/portfolio/CTF profile, and your strongest area of expertise. Limited positions. If you have always wanted to test real systems in a real physical lab rather than another simulated environment, this is the kind of opportunity you have been waiting for.

Web And API Penetration TestingNetwork And Infrastructure SecurityCloud SecurityReverse EngineeringBinary ExploitationVulnerability ResearchApplied CryptographyOperating System InternalsEndpoint SecurityFirmware And Boot SecurityApplication SecurityRuntime Analysis And DebuggingRed TeamingExploit DevelopmentSecurity Researchmulti-location

Cookies & analytics consent

We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.

Read how we use data in our Privacy Policy and Terms of Service.