Skip to main content
Posted 22 August, 2026

Security Research Engineer

Cowbell Cyber Inc.
Pune (India) Full Time
Reference: 102_698883_7802307003

Cowbell Cyber is hiring a Cyber Security Researcher to join our Data Science team.

Key Responsibilities

  • Security Research & Testing: Conduct in-depth security assessments and manual penetration testing of web apps, APIs, and cloud services. Perform source code reviews and analyze proprietary applications for flaws (e.g., injection, authorization issues, business logic abuse, misconfigurations). Develop custom tooling and Proof-of-Concept (POC) exploits to validate findings.
  • Vulnerability Discovery: Research emerging attack techniques, exploit chains, and zero-day vulnerabilities in internal applications and supporting systems. Conduct threat modeling and evaluate software supply chain and dependency risks.
  • Engineering Collaboration: Partner with engineering teams throughout the SDLC to provide secure coding guidance, support architecture reviews, and integrate security testing into CI/CD pipelines. Contribute to internal security standards.
  • Reporting: Document vulnerabilities, exploitability, and remediation guidance in clear reports. Present findings to stakeholders, track remediation efforts, and verify fixes.

Required Qualifications

  • 5+ years of experience in application security, vulnerability research, or offensive security.
  • Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, or equivalent practical experience.
  • Strong knowledge of secure development practices, manual security assessments, and source code reviews.
  • Deep understanding of: OWASP Top 10, API Security Top 10, modern web application architectures, secure authentication and authorization models, and cloud security fundamentals.
  • Proficiency with one or more programming languages (Python, Java, JavaScript/TypeScript).
  • Strong understanding of Linux, networking, and web protocols; experience using common security testing tools.

    Preferred Qualifications

    • Experience discovering novel vulnerabilities, participating in bug bounty/disclosure programs, or background in exploit development/reverse engineering.
    • Knowledge of modern cloud environments (AWS, Azure, GCP), container security/Kubernetes, and building custom security tooling.
    • Experience with current vulnerability research tools ( i.e. Burp Suite, Nuclei, Ghidra).
    • Public vulnerability research, conference presentations, blog posts, or published CVEs.

    Preferred Certifications

    One or more of the following:

    • OSCP
    • OSWE
    • OSEP
    • GXPN
    • Relevant GIAC certifications

    Success Metrics (Within the first 12 months)

    • Identify and validate critical and high-risk vulnerabilities before production impact.
    • Improve application security posture through proactive research and testing.
    • Reduce vulnerability remediation timelines through effective collaboration.
    • Develop repeatable testing methodologies and security automation.
    • Contribute meaningful research into emerging threats.

Sign up for Job Alerts