
Get paid to find the bugs






150+
10+
Flexible
150+
10+
Flexible
Open roles, right now.
Intern - Marketing (SM)
We seek a dynamic and motivated Social Media Marketing Intern to join our team.



Intern - Marketing (SM)
Who are you?
You are a charismatic young creative hustler who loves to learn and grow. You realize that business is more about helping a customer and solving their problem than only making a profit. You want to grow your career in the hyper-growing IT / Cybersecurity industry.
Your everyday work will look like:
Social Media Marketing (primary focus)
- Plan, create, and schedule engaging content for LinkedIn, X (Twitter), Instagram, and other relevant platforms, tailored to a B2B cybersecurity audience.
- Draft copy for posts, carousels, polls, and threads that translate technical security topics (CVEs, research findings, compliance updates) into audience friendly content.
- Use AI tools (e.g., ChatGPT, Claude, Canva AI) to speed up ideation, drafting, and repurposing of content while keeping Payatu's brand voice and factual accuracy intact.
- Actively monitor social media trends to create timely, relevant content.
- Coordinate with designers and subject matter experts to turn blogs, case studies, webinars, and research into social-ready assets.
- Monitor social channels daily, respond to comments/DMs, track mentions, and flag engagement opportunities.
- Track and report on social media performance (reach, engagement, follower growth, click-throughs) and suggest improvements based on data.
- Stay on top of platform trends, algorithm changes, and competitor social activity in the cybersecurity/IT space, including how competitors are using AI in their content.
- Support employer branding and event-related social content.
- Support basic SEO and AEO (Answer Engine Optimization) tasks such as keyword tagging and on-page optimization for social-linked content (blogs, landing pages), keeping in mind how AI search/answer engines surface content.
- Help maintain content calendars that align social media with broader digital marketing and campaign timelines.
- Explore and suggest AI-powered marketing tools/workflows (content generation, scheduling, analytics, image generation) that could improve team efficiency.
- Comfort experimenting with AI writing/design tools as part of the content workflow.
- Interest in cybersecurity and willingness to learn industry-specific terminology.
Eligibility Criteria:
- Currently pursuing or recently completed a degree in Marketing, Communications, or a related field.
- Strong interest in social media and digital marketing, with a desire to learn and grow in this field.
- Curiosity about AI tools and how they're changing content creation and marketing workflows.
- Familiarity with major social media platforms, content scheduling tools, and basic content management systems.
- Excellent written and verbal communication skills able to write crisp, engaging copy (with or without AI assistance).
- A good eye for content, trends, and what makes people stop scrolling.
- Strong attention to detail and ability to multitask across platforms and campaigns.
- Analytical mindset with the ability to interpret basic performance data and identify actionable insights.
- Proactive approach and eagerness to learn, especially in the fast-evolving fields of social media, AI, and cybersecurity.
- Ability to work collaboratively with cross-functional teams and adapt to a dynamic consulting environment.
- Creativity in problem-solving and proposing new ideas for social growth and engagement.
Tool Knowledge:
Proficiency or familiarity with:
- Social media platforms (LinkedIn, X/Twitter, Instagram) and native/third-party scheduling tools.
- AI tools for content/design (e.g., ChatGPT, Claude, Canva AI, or similar).
- Basic design tools (Canva or similar) for quick content mockups.
Embedded Security Consultant
We are seeking an embedded cybersecurity engineer to drive IEC 62443-4-2 compliance and remediation for NGSC, Ingersoll Rand's next-generation System Controller built on B&R Automation.



Embedded Security Consultant
Here are the details:
- Own and implement the open cybersecurity backlog on the C80 controller. Example tickets: least-privilege protocol control, HMI input validation, log security, session/authentication, input file integrity, etc.
- Perform and lead design reviews of security-critical subsystems.
- Write security design documentation that satisfies IEC 62443-4-2 evidence requirements.
- Work directly with the auditor evidence dossier: document findings, close CRs.
- Participate in the internal IEC 62443-4-2 gap assessment and execute remediation.
Must have:
- Hands-on B&R Automation Studio experience — HMI (mapp View or VC4), application framework.
- IEC 62443-4-1 or 4-2 project experience (gap assessment, CR-by-CR remediation, or formal audit participation).
- Embedded C/C++ secure coding: input validation, buffer management, SAST tooling (Checkmarx or equivalent).
- Practical knowledge of OT security: least privilege, audit logging, session management, file integrity.
Good to have:
- B&R POWERLINK (PLK) network architecture.
- Industrial protocols like Modbus, OPC/UA.
- OT security for compressor / industrial systems.
Secure Code Review Consultant
Are you interested in automating the build and deployment process of the application with ensuring the application security?



Secure Code Review Consultant
What we look for outside work parameters?
- Your expertise is your primary qualification, not your degree or certification.
- Your publicly known contributions are your credentials.
- Papers you have written, tools you have developed are your references.
- Your write-up reflects your interests and ethics.
- Your published exploits, your CTF scores, and hall of fame listings are the testimonies of your work.
- Your research paper was published and presented at conferences.
- You are learning from the community and enthusiastically contributing back.
You are a perfect technical fit if you have:
- Strong fundamental of application and network protocols.
- Strong hold on Web application security concept and penetration testing skill.
- Good command of at least one programming language.
- Good understanding of basic coding and core concepts to understand the flow of code.
- Good understanding of OWASP Top 10 and other web-related vulnerabilities as well as logic flaws.
- Hands-on experience in performing penetration testing of web-based applications preferably in the financial domain.
- Good to have experience in working alongside the development/QA teams.
- Good report writing and presentation skills.
- Should be able to suggest optimum security improvements to application components.
You Have All Our Desired Qualities, if:
- You have experience in web application and web service security assessment.
- You have a history of publishing or presenting good research.
- You have the knack of finding security bugs in everything you touch.
- You like automating stuff.
- You like writing tools.
- You have excellent written and verbal communication skills and the ability to express your thoughts clearly.
- You have the skill to articulate and present technical things in business language.
- You can work independently as well as within a team and meet project schedules and deadlines.
- You have strong problem solving, troubleshooting, and analysis skills.
- You are passionate about your area of expertise and self-driven.
- You are comfortable working in a dynamic and fast-paced work environment.
- You are Self-driven, proactive, hardworking, team-player.
- You are working on something on your own in your field apart from official work.
Your everyday work will look like:
- Security assessment of web application and web service on various platforms.
- Back your findings with Proof-of-concept exploits.
- Collect evidence and maintain a detailed write-up of the findings.
- Understand and explain the results with impact on business and compliance status.
- Explain and demonstrate vulnerabilities to application/system owners.
- Provide appropriate remediation and mitigations of the identified vulnerabilities.
- Individually or collaboratively review the system designs, source code, configurations, communications for security gaps.
- Deliver results within stipulated timelines.
- Sharpen your saw with continuous research, learning, training on the latest tools and techniques, keeping up with new research, and sharing the same with the ecosystem.
- Communicate well using verbal and written skills, within and out of the team.
Red Team Security Consultant
Are you interested in automating the build and deployment process of the application while ensuring application security?



Red Team Security Consultant
What we look for outside work parameters:
- Your expertise is your primary qualification, not your degree or certification.
- Your publicly known contributions are your credentials.
- Papers you have written, tools you have developed are your references.
- Your write-up reflects your interests and ethics.
- Your published exploits, CTF rankings, and Hall of Fame listings are testimonies of your work.
- Original tools or scripts you've open-sourced count in your favor.
- Your research paper was published and/or presented at a conference.
- You are learning from the community and enthusiastically contributing back.
You are a perfect technical fit if
- Strong fundamentals of application, network, and Windows/Active Directory protocols.
- Design and execute advanced penetration testing, vulnerability assessments, and simulated attack scenarios (Red Team, Purple Team) to identify security weaknesses across an organization's systems, networks, cloud, and applications.
- Utilize a variety of tools and techniques to develop and implement sophisticated attack strategies, mimicking the tactics, techniques, and procedures used by real-world adversaries.
- Collaborate with the Blue Team to test and enhance incident response capabilities through Red vs. Blue exercises and Purple Team workshops, identifying gaps and recommending detection/mitigation improvements.
- Document and communicate detailed findings — vulnerabilities, exploit chains, and remediation guidance — in clear, actionable reports for technical and executive stakeholders.
- Stay current with emerging threats and attack vectors; develop or customize tools, scripts, and techniques to enhance Red Team capabilities.
- Strong planning and execution of social engineering attacks — phishing, vishing, pretexting, baiting, and tailgating — to assess human vulnerabilities and insider-threat risk.
- Solid grounding in web application security with hands-on pentesting experience, preferably including regulated or financial-domain applications.
- Good command of at least one programming/scripting language for tooling and automation.
- Should be able to suggest optimum security improvements to application and infrastructure components.
You Have All Our Desired Qualities, if
- Hands-on Active Directory exploitation and lateral movement experience, including credential attacks, privilege escalation, and abuse of trust relationships.
- Comfortable with attack-path mapping tools and holds a recognized AD-focused certification.
- Offensive experience across major cloud and identity platforms, including privilege escalation, token/credential abuse, and misconfiguration exploitation.
- Ability to assess cloud landing zones and enterprise perimeter/identity infrastructure end-to-end.
- Named, hands-on experience with command-and-control frameworks — not just conceptual familiarity.
- Practical defense-evasion skills against modern endpoint protection and detection controls.
- Understanding of C2 infrastructure design and operational security practices.
- Experience threat-modeling and adversarially testing AI/LLM-powered applications and agentic systems.
- Exposure to building or red-teaming AI-augmented offensive tooling or automation pipelines.
- Deep web and API security expertise, including chained and business-logic vulnerabilities.
- Track record of vulnerability discovery and/or public bug bounty program participation.
- Comfortable with large-scale reconnaissance, source/asset analysis, and secrets exposure hunting.
- Experience running or supporting Purple Team exercises that translate red findings into detection improvements.
- Threat hunting fundamentals, including log/telemetry analysis and familiarity with detection/monitoring platforms.
- Security assessment experience with CI/CD pipelines and build/release infrastructure.
- Container and orchestration security experience.
- You like automating stuff and writing your own tools to scale assessments.
- Experience with distributed or large-scale scanning infrastructure is a strong plus.
- Excellent written and verbal communication; able to translate technical impact into business/compliance language for non-technical stakeholders.
- Comfortable quantifying impact rather than describing findings only qualitatively.
- Can work independently and within a team, meet deadlines in a dynamic, fast-paced environment, and is self-driven, proactive, and hardworking.
- Actively working on something in the field outside of official work.
Your everyday work will look like
- Security assessment of web applications, APIs, networks, Active Directory, and cloud environments across various platforms.
- Design and execution of full-scope red team engagements — initial access through internal compromise to objective completion.
- Back your findings with working proof-of-concept exploits and reproducible attack chains.
- Collect evidence and maintain a detailed write-up of findings, mapped to relevant industry frameworks.
- Understand and explain results in terms of business and compliance impact.
- Explain and demonstrate vulnerabilities to application/system owners; run purple-team sessions with Blue Team counterparts.
- Provide appropriate remediation and mitigation guidance for identified vulnerabilities.
- Individually or collaboratively review system designs, source code, pipeline configurations, and communications for security gaps.
- Deliver results within stipulated timelines.
- Sharpen your saw with continuous research, learning, and training on the latest tools and techniques; share the same with the ecosystem.
- Communicate well using verbal and written skills, within and outside the team.
IoT Firmware Security Consultant
Is Firmware IOT Security that excites you the most? We are looking for cyber experts who will find vulnerability in IoT device firmware.



IoT Firmware Security Consultant
You are a perfect technical fit if:
- You have strong understanding on Embedded firmware security.
- You have deep understanding and hands on with doing firmware reversing for ARM, MIPS and x86 for(either of it) OS based and BareMetal firmware.
- You have very good understanding of ARM and x86 architecture assembly language.
- You have deep concepts of Linux internals.
- You have understanding of Operating systems in detail.
- You have good knowledge of internal working of C programming.
- You must be good with at least one scripting language.
- You must have knowledge on embedded protocols such as UART, I2C, SPI, JTAG, SWD.
- You must have knowledge on Radio protocol internals such as BLE, WIFI.
What we look for outside work parameters?
- Your expertise is your primary qualification, not your degree or certification.
- Your publicly known contributions are your credentials.
- Papers/blogs you have written, tools you have developed are your references.
- You are learning from the community and enthusiastically contributing back.
You Have All Our Desired Qualities, if:
- You have the technical skills mentioned above.
- You have Passion for doing firmware reversing.
- You have a history of publishing or presenting good research.
- You have excellent written and verbal communication skills and ability to express your thoughts clearly.
- You can work independently as well as within a team and meet project schedule and deadlines.
- You are a creative individual to think out of the box for creating different firmware attacks on product.
Your everyday work will look like:
- Find vulnerability in IoT device firmware.
- Sharpen your saw with continuous research, learning, training on the latest tools and techniques, keeping up with new research and sharing the same with the ecosystem.
- Communicate well using verbal and written skills, within and out of the team.
GRC Intern
Are you curious about cybersecurity, governance, risk, and compliance? We are looking for enthusiastic and motivated GRC Interns.



GRC Intern
You Are a Perfect Fit If You Have
- Holds a relevant degree or diploma or pursuing a degree in Information Security, Cybersecurity, IT, Computer Science, Engineering, Law or a related discipline.
- Basic understanding of Information Security and cybersecurity concepts.
- Willingness to learn and work with new cybersecurity frameworks and standards.
- Strong documentation and attention-to-detail skills.
- Ability to research and make efforts to understand security standards, frameworks, regulations, and compliance requirements.
- Good written and verbal communication skills (public speaking would be plus) and willingness to read long documents.
- Ability to work independently as well as collaborate with technical and consulting teams.
- Understanding of concepts such as security controls, risk assessment, policies, procedures, audits, and compliance.
- Strong interest in Governance, Risk & Compliance (GRC) and cybersecurity.
- Basic knowledge or academic exposure to ISO/IEC 27001 and Information Security Management Systems (ISMS).
What You Will Learn & Work On
As a GRC Intern, you will work closely with experienced GRC consultants and gain hands-on exposure to:
- Supporting ISO/IEC 27001:2022 ISMS implementation and audit-readiness activities.
- Assisting with gap assessments and control assessments.
- Understanding and documenting ISO 27001 Annex A controls.
- Supporting preparation and maintenance of policies, procedures, SOPs, and ISMS documentation.
- Assisting in risk assessments and maintaining risk registers, internal audit activities and evidence collection.
- Researching regulatory and industry requirements such as DPDP Act, GDPR, SOC 2, PCI DSS, HIPAA, and NIST.
- Opportunity to learn and implement new standards and frameworks.
- Working with technical cybersecurity teams to understand how security assessments and findings relate to compliance requirements.
Nice to Have
- Academic/project experience with ISO 27001, ISO 27002, ISO 17025, SOC 2, GDPR, DPDP, NIST, PCI DSS, or other security frameworks.
- Any relevant certification or training in: ISO 27001, Cybersecurity, Information Security, GRC, Risk Management.
- Exposure to risk assessment, audit, compliance, or information security projects.
- Familiarity with GRC tools or platforms such as Scrut, Sprinto, ServiceNow GRC, Archer, or MetricStream.
- Basic understanding of cloud security, VAPT reports, cybersecurity controls, or security operations.
- Participation in cybersecurity competitions, CTFs, projects, workshops, internships, or research activities.
Equal Opportunity
Payatu is committed to creating an inclusive workplace. We celebrate diversity and are committed to building a team that represents a variety of backgrounds, perspectives, and skills.
Pre Sales Executive
Does Sales excite you? If yes, then Payatu is the place for you.



Pre Sales Executive
Who are you?
You are a charismatic young creative hustler who loves to meet and engage with people. You understand that sales are all about building trust and rapport. You realize that business is more about helping a customer and solving their problem then only making a profit. You want to grow your career in the hyper growing cyber security industry.
You are a perfect fit for this if:
- You have 1-3 years of experience in "Pre Sales" in IT industry.
- You are passionate about Cybersecurity.
- You have updated knowledge about what is happening in Cybersecurity domain.
- Your knowledge of Penetration Testing and Cyber Security more generally, desire and aptitude of learn more and develop skills in area of cybersecurity.
- You are a good communicator who should be able to explain technical jargons in a simplified way to non-technical people.
- You have good presentation skills – Should be able to speak confidently and articulate thoughts well virtually and in person meetings.
- You have proved your skills then your degree can be overlooked.
- You have undertaken relevant cybersecurity courses.
Your everyday work will look like:
- Understand and capture the Client requirements clearly.
- Draft Statement of Work (SoW) / Proposal for Clients.
- Identify RFP leads, respond to RFP, complete the Bidding process.
- Conduct Technical, Techno Commercial discussion and presentations with the Client.
- Respond to queries (mostly technical) the client many have based on the presentation walkthrough.
- Coordinate internally with team during unique service offering presentations with the client.
Business Development Executive
Payatu is a leading cybersecurity services and research company known for delivering high-impact security assessments, innovative solutions, and valuable insights to enterprises worldwide.



Business Development Executive
Key Responsibilities
- Identify and qualify new business opportunities in target sectors and markets.
- Generate, nurture, and track leads through outbound outreach (calls, emails, LinkedIn).
- Build and maintain strong relationships with prospective clients and stakeholders.
- Conduct product/service presentations and tailored solution pitches.
- Meet and exceed individual sales targets and contribute to revenue growth.
- Work closely with delivery, marketing, and technical teams to ensure smooth proposals and conversions.
- Maintain accurate CRM records and prepare sales reports.
Qualifications
- Bachelor's degree in Business, Marketing, IT, or a related field.
- 2+ years of proven experience in B2B sales or business development (preferably in IT, tech, cybersecurity or SaaS).
- Strong communication, negotiation, and relationship-building skills.
- Comfortable with outbound prospecting, presentations, and closing deals.
- Experience with CRM tools and sales pipeline management.
- Ability to thrive in a fast-paced, target-driven environment.
What We Offer
- Competitive salary with performance-based incentives.
- Opportunity to work in a rapidly growing domain (cybersecurity).
- Professional growth and exposure to global clients.
Customer Success Manager
We are looking for a hungry, ambitious, and resourceful sales professional who wants to be an integral part of this challenging and fascinating journey.



Customer Success Manager
Who are you?
You are a charismatic young creative hustler who loves to meet and engage with people. You straddle the gap between service and sales, between company interest and customer interest. You realize that business is more about helping a customer and solving their problem then only making a profit. You want to grow your career in the hyper growing cyber security industry.
You are a perfect fit for this if:
- You should have an experience in cyber security world.
- You have minimum of 2-4 years of experience in customer success, account management or related roles.
- You have demonstrated track record of managing customer relationships and driving customer satisfaction and retention.
- You are a team player who gels well in the team.
- You are a technology enthusiast and stay updated about new technology innovations.
- You have the tenacity to develop ideas independently and thrive in a fast-paced startup environment.
- You have the ability to apply significant knowledge of industry trends and developments to improve services to clients.
- You should have strong communication, negotiation, and presentation skills.
Your everyday work will look like:
- Learn about company product and service offerings.
- Incorporating strategies, themes, and other material into response sections.
- Proposal development, review and feedback incorporation based on various interactions with different stakeholders.
- Giving product demonstrations to prospects and answering their queries.
- You should have an excellent understanding of client's need and generating solutions of how our organization can provide that.
- Assisting clients through each step of the post-sales process, solution handling and helping them resolve any concerns or questions they may have while processing, tracking and completing sales efficiently.
- Develop a growth strategy focused both on financial gain and customer satisfaction.
- Build long-term relationships with new prospects and existing customers.
- Create contract-winning proposals for current and prospective clients.
- Attend weekly sales team meetings and provide information to management about sales figures, KPI, goals, and obstacles.
- Identifies trendsetter ideas by researching industry and related events, publications, and announcements.
- Update job knowledge by participating in educational opportunities, reading professional publications, maintaining personal network.
- Actively engage with customers to understand their goals, challenges, and key performance indicators (KPIs).
- Provide timely responses to customer inquiries, troubleshooting technical issues, and escalating when necessary.
- Conduct regular check-ins and account reviews with customers to assess satisfaction levels and identify areas for improvement.
- Collaborate with cross-functional teams to address customer feedback and drive product improvements.
GRC Consultant
Are you passionate about building resilient security programs? Do you think in frameworks, speak in controls, and dream in compliance matrices?



GRC Consultant
You are a perfect fit if you have:
- 2–4 years of hands-on experience in GRC, compliance management, security audit, or quality assurance roles within cybersecurity or IT consulting environments.
- Bachelor's degree in Information Security, IT, Computer Science, Engineering, Law or related disciplines.
- Proven experience implementing and maintaining ISO/IEC 27001:2022 ISMS frameworks, including gap analysis, control implementation, and internal/external audit support.
- Strong working knowledge of ISO/IEC 27001 Annex A controls and their practical application across diverse organizational contexts.
- Real-world audit implementation experience—you've been on the ground during certification/accreditation cycles, not just supported from the sidelines.
- Strong documentation skills and attention to detail in drafting policies, SOPs, control evidence, and audit-ready documentation.
- Hands-on experience working with managing risk registers, CAPA (Corrective and Preventive Action) logs, nonconformance reports (NCR), and internal audit evidence.
Good To Have:
- Demonstrated/ Experience with ISO/IEC 17025 (Testing and Calibration Laboratories).
- Demonstrated/ Experience with ISO/IEC 17020 (Inspection Bodies), or ISO/IEC 17021-1 (Certification Bodies) frameworks.
- Familiarity with other regulatory compliance requirements such as DPDP Act 2023, GDPR, ISO 27701, ISO 22301, RBI cybersecurity guidelines, SEBI IT framework, or sector-specific mandates.
- Ability to interpret standards independently—you can read a framework document and translate it into actionable controls and evidence requirements.
- Strong communication skills with the ability to translate technical security findings into business risk language for leadership and clients.
- Self-driven learner with the curiosity and discipline to master new frameworks, regulations, and compliance requirements as business needs evolve.
You have all our desired qualities if you have:
- Professional certifications such as ISO 27001 Lead Auditor/ Implementer, ISO 9001 Lead Auditor, CISA, or other relevant Lead Implementer certifications (certifications will help streamline our filtering process, but real implementation experience matters most).
- Exposure to or working knowledge of GDPR, CCPA, NIS Directive 2.0, SOC 2, or NIST frameworks (we don't expect you to know them all; what matters is your ability to learn, interpret, and implement standards you haven't worked with before).
- Familiarity with GRC platforms (e.g., Scrut, Sprinto, ServiceNow GRC, Archer, MetricStream) tools.
What you'll do at Payatu:
- Lead various implementation and audit readiness programs for clients and internal operations around ISO 27001, ISO 27701, ISO 17025, ISO 17020, ISO 17021-1, and SOC 2, GDPR, DPDPA.
- Conduct gap assessments, control maturity evaluations, and compliance roadmaps aligned with client business objectives.
- Own and maintain risk registers, treatment plans, audit logs, and compliance dashboards.
- Support pre-sales and client engagement by scoping GRC projects, drafting compliance proposals, and presenting audit findings.
- Collaborate with technical teams (VAPT, Red Team, IoT Security) to ensure security findings are contextualized within compliance frameworks.
- Prepare and present evidence packages for external audits, certification renewals, and regulatory inspections.
- Stay current on evolving regulations, frameworks, and industry best practices in the Indian and global compliance landscape.
Why Payatu?
Join a team that treats compliance not as a checklist, but as a strategic enabler. Work alongside India's top offensive security researchers while building frameworks that protect critical infrastructure, secure sensitive data, and empower clients to meet the highest assurance standards. Grow your expertise across diverse sectors, frameworks, and emerging regulations in one of India's most respected cybersecurity consulting firms.
Equal Opportunity
Payatu is committed to creating an inclusive environment for all employees. We celebrate diversity and are committed to building a team that represents a variety of backgrounds, perspectives, and skills.
IoT Radio Frequency Security Consultant
If you are someone who has the skills and the ability to design and conduct radio, IoT hardware attacks, then we are looking for you.



IoT Radio Frequency Security Consultant
You are a perfect technical fit if:
- Strong understanding on Radio Protocol security.
- Familiar with the tools for the radio protocol assessment.
- Hands on with radio attacks on the BLE, ZIGBEE, SDR.
- Experience with Radio protocol attack such as BLE, WIFI, LoRa, DSP, SDR.
- Good to have knowledge on MQTT, CoAP and one programming language.
What we look for outside parameters:
- Your publicly known contributions are your credentials.
- Papers/blogs you have written, tools you have developed are your references.
- You are learning from the community and enthusiastically contributing back.
You Have All Our Desired Qualities, if:
- You have the technical skills mentioned above.
- You have Passion for attacking hardware.
- You have a history of publishing or presenting good research.
- You have excellent written and verbal communication skills and ability to express your thoughts clearly.
- You can work independently as well as within a team and meet project schedule and deadlines.
- You are a creative individual to think out of the box for creating different hardware attacks on product.
Your Everyday work will look like:
- Create radio attacks on existing IoT products and find vulnerability.
- Breaking the IoT product for finding security issues in radio protocols.
- Sharpen your saw with continuous research, learning, training on the latest tools and techniques, keeping up with new research and sharing the same with the ecosystem.
- Communicate well using verbal and written skills, within and out of the team.
IoT Hardware Security Consultant
If you are someone who has the skills and the ability to design and conduct radio, IoT hardware attacks, paired.



IoT Hardware Security Consultant
If you are someone who has the skills and the ability to design and conduct radio, IoT hardware attacks, paired with the knowledge and expertise of hardware attacks such as PCB reversing, Component identification, Side channel attacks, memory extraction methods, then we are looking for you. Not all superheroes wear capes, but if you do wear the cape of embedded protocols such as UART, I2C, SPI, JTAG, SWD and possible attacks on them, then don't forget to reach out to us. If you have knowledge of wireless communication, including expertise in radio protocols such as BLE and ZIGBEE, as well as familiarity with SDR and understanding of the associated attack surfaces pertaining to these wireless communication protocols, coupled with proficiency in MQTT and CoAP, along with knowledge on penetration testing of these protocols.
You are a perfect technical fit if you have:
- Strong understanding on Radio Protocol security.
- Familiar with the tools for the radio protocol assessment.
- Hands on with radio attacks on the BLE, ZIGBEE, SDR.
- Experience with Radio protocol attack such as BLE, WIFI, LoRa, DSP, SDR.
- Good to have knowledge on MQTT, CoAP and one programming language.
What we look for outside parameters:
- Your publicly known contributions are your credentials.
- Papers/blogs you have written, tools you have developed are your references.
- You are learning from the community and enthusiastically contributing back.
You have all our desired qualities, if:
- You have the technical skills mentioned above.
- You have Passion for attacking hardware.
- You have a history of publishing or presenting good research.
- You have excellent written and verbal communication skills and ability to express your thoughts clearly.
- You can work independently as well as within a team and meet project schedule and deadlines.
- You are a creative individual to think out of the box for creating different hardware attacks on product.
Your everyday work will look like:
- Create radio attacks on existing IoT products and find vulnerability.
- Breaking the IoT product for finding security issues in radio protocols.
- Sharpen your saw with continuous research, learning, training on the latest tools and techniques, keeping up with new research and sharing the same with the ecosystem.
- Communicate well using verbal and written skills, within and out of the team.
HR Specialist
We are looking for an experienced and proactive HR Lead to oversee and drive the organization's human resources functions.



HR Specialist
We are looking for an experienced and proactive HR Lead to oversee and drive the organization's human resources functions. The ideal candidate will manage end-to-end HR operations, talent acquisition, employee engagement, performance management, policy implementation, compliance, and HR strategy while partnering with business leaders to build a high-performing workforce.
Key Responsibilities
- Talent Acquisition
- Lead end-to-end recruitment for technical and non-technical roles.
- Develop hiring strategies to attract top talent.
- Partner with hiring managers on workforce planning.
- Optimize recruitment metrics such as time-to-hire, cost-per-hire, and quality-of-hire.
- Employee Lifecycle Management
- Manage onboarding and offboarding processes.
- Ensure a seamless employee experience throughout the employee lifecycle.
- Maintain accurate employee records and HR documentation.
- Performance Management
- Drive goal-setting and performance review cycles.
- Support managers with performance improvement plans (PIPs).
- Identify high-potential employees and succession planning opportunities.
- Employee Engagement
- Design and execute engagement initiatives.
- Conduct employee satisfaction surveys and action planning.
- Resolve employee grievances professionally and confidentially.
- HR Operations & Compliance
- Ensure compliance with labor laws and company policies.
- Maintain HR policies, SOPs, and employee handbook.
Application Security (AppSec) Consultant
Payatu is hiring an Application Security Consultant who's genuinely good at breaking things by hand, not someone who lets a scanner do the thinking.



Application Security (AppSec) Consultant
What we look for outside work parameters?
- Your expertise is your primary qualification, not your degree or certification.
- Your publicly known contributions are your credentials.
- Papers you have written, tools you have developed are your references.
- Your write-up reflects your interests and ethics.
- Your published exploits, your CTF scores, and hall of fame listings are the testimonies of your work.
- Your research paper was published and presented at conferences.
- You are learning from the community and enthusiastically contributing back.
- Certifications like OSCP, CREST, OSWE, and similar are a plus if you’ve got them, but we don’t gatekeep on degrees or certifications.
- Bonus points for AI security skills, on either side of the fence - attacking AI systems or building smart automation around your own testing.
You are a perfect technical fit if:
- 2-5 years of hands-on Web Application pentesting experience (mobile and thick client experience is a strong plus).
- Strong fundamental of application and network protocols.
- Strong hold on Web application security concept and penetration testing skill.
- Good command of at least one programming language.
- Good understanding of OWASP Top 10 and other web-related vulnerabilities as well as logic flaws.
- Hands-on experience in performing penetration testing of web-based applications preferably in the financial domain.
- Good to have experience in working alongside the development/QA teams.
- Good report writing and presentation skills.
- Should be able to suggest optimum security improvements to application components.
- Burp MCP is baked into our workflow, as part of your day-to-day testing.
- Source Code and Config Review experience is a plus for engagements that go beyond Black-Box.
- The instinct to poke at things until they break, and the patience to document exactly how.
You Have All Our Desired Qualities, if:
- You have experience in web application and web service security assessment.
- You have a history of publishing or presenting good research.
- You have the knack of finding security bugs in everything you touch.
- You like automating stuff.
- You like writing tools.
- You have excellent written and verbal communication skills and the ability to express your thoughts clearly.
- You have the skill to articulate and present technical things in business language.
- You can work independently as well as within a team and meet project schedules and deadlines.
- You have strong problem solving, troubleshooting, and analysis skills.
- You are passionate about your area of expertise and self-driven.
- You are comfortable working in a dynamic and fast-paced work environment.
- You are self-driven, proactive, hardworking, team-player.
- You are working on something on your own in your field apart from official work.
Your everyday work will look like:
- Manual penetration testing of Web Applications, Mobile Applications, and Thick Clients (automation is a starting point here, not the finish line).
- Finding the business logic flaws and app-specific bugs that only show up when a human actually tries to break the app.
- Security assessment of web application and web service on various platforms.
- Back your findings with Proof-of-concept exploits.
- Collect evidence and maintain a detailed write-up of the findings.
- Understand and explain the results with impact on business and compliance status.
- Explain and demonstrate vulnerabilities to application/system owners.
- Provide appropriate remediation and mitigations of the identified vulnerabilities.
- Individually or collaboratively review the system designs, source code, configurations, communications for security gaps.
- Deliver results within stipulated timelines.
- Sharpen your saw with continuous research, learning, training on the latest tools and techniques, keeping up with new research, and sharing the same with the ecosystem.
- Communicate well using verbal and written skills, within and out of the team.
- Reports detailed enough for a developer to fix it, clear enough for a stakeholder to get why it matters.
- Using automation and AI to work more efficiently, whether that means building tooling to speed up repetitive parts of testing or using AI to sharpen your workflow, all in service of delivering higher-quality work, not cutting corners on it.
- Roughly 30% of your time is set aside for research. You choose the topic, and it’s treated as a real part of the job, not something squeezed in on the side.
Don't see your role?
What being a Bandit gets you

Services, framed by your problem.

You would be working with the people who find the bugs


.png)
What to expect when you apply
Apply
Send your CV and anything that shows how you think CVEs, tools, writeups, CTF profiles.
Technical chat
A conversation with the team you'd join less quiz, more "how would you approach this?"
Practical task
A hands-on exercise close to real work, so you see us and we see you at your best.
Offer
A final chat on growth and fit, then an offer. Clear timelines throughout no ghosting.
Questions Web Application teams ask us.


Ready to be a Bandit?
Browse the open roles and apply or send us your best work and start a conversation.


