Work with operators, not intermediaries.
We hire practitioners who teach, write, and ship. Open roles below — or reach out even if nothing fits.
Open roles
Lead web, API, and cloud engagements end to end. Deep WSTG / ASVS / ATT&CK chops expected.
Full kill-chain emulation — phishing through objective execution. EDR bypass and detection-engineering dialog.
Threat modeling, secure design review, SAST/DAST tuning, security-champion enablement with our customers' eng teams.
Prompt injection, agent tool-use exploitation, RAG data exfil, multi-agent compromise. Write, teach, publish.
AWS / Azure / GCP IAM graphing, Kubernetes RBAC / admission, policy-as-code for customer IaC.
Zero-day research, internal tooling, conference talks, CVE publication — 40% of time is dedicated research.
Don't see a fit? Send us a short note at careers@pentstark.com with your best published work.
How we support our team
M-series MacBook Pro, 4K external, ergonomic chair. Hardware is never the blocker.
$4,000/yr per engineer for courses, conferences, certs. SANS and Offensive Security as defaults.
Top-tier health insurance for you and immediate family in both India and US.
Offices are optional. We hire where the talent is — and we come together three times a year.
Fridays are for research. Published write-ups, OSS, CVE disclosures get bonus spiffs.
Banded, published, tied to level — no salary-negotiation theater.
Our hiring loop
Five steps. Typically two to three weeks end-to-end. We tell you where you stand at each one.
- Step 1Intro call
30 min with the hiring manager. Role scope, your trajectory, mutual fit.
- Step 2Technical deep-dive
90 min. Walk through a recent engagement, PoC code-read, methodology questions.
- Step 3Take-home exercise
A bounded scenario (CTF-adjacent). Your approach matters more than the flag.
- Step 4Culture interview
Two team members. Teaching, writing, and collaboration signals.
- Step 5Decision + offer
We decide within 3 business days. No ghosting. No BS.
Your next finding is one scoping call away.
Thirty minutes with a real operator tells us what you need and what we can deliver. No BDR handoff, no sales engineer theater — the person you talk to is the person who scopes the work.
