CAREERS · POCFORGE

Test systems that matter — with people who care about proof.

PoCForge (Cyber Security) is a boutique, human-led offensive security practice. We help product and security teams find exploitable weaknesses across web, API, cloud, mobile, infrastructure and AI — then prove impact and retest fixes. If you would rather ship honest findings than theatre, we should talk.

Practice shapeBoutique · senior-led · short communication paths
Delivery modelRemote-first · India-friendly · worldwide clients
Craft barProof-of-exploit · business-logic focus · retest
HonestyNo fake logos, badges or headcount theatre

Why PoCForge (Cyber Security)

We are not a scanner farm and not a rotating ticket queue. Engagements are led by practitioners who talk to your counterparts, write evidence that engineers can use, and retest what gets fixed. The same honesty we publish for buyers applies to how we hire: clear expectations, realistic openings, no invented prestige.

Human-led offensive testing Evidence over theatre Remote-first collaboration Research that stays practical Buyer-honest tone Small team, high ownership

How we work

What working here is like — adapted from how we actually deliver, not a generic culture deck.

01

Findings, not checklists

We prioritise reproducible impact over volume. Authorisation, workflow abuse and tenant boundaries matter as much as classic OWASP classes.

02

Hands-on from day one

You contribute to scoped testing, research notes or delivery artefacts early — with review, not abandonment.

03

Short paths to clients

Product and security teams talk to the people doing the work. We keep communication paths short on purpose.

04

Write like a practitioner

Reports and research should be clear enough for engineering to act — and honest about uncertainty.

05

Automation as a tool

Targeted automation helps coverage and speed. It does not replace reasoning about attack paths.

06

Always learning

New surfaces — Electron, agentic AI, cloud identity paths — show up in real scopes. Curiosity is part of the job.

Open roles

Current openings for consulting, research and internship tracks. Roles are remote-first with India-friendly hours unless noted.

Track
Location

Offensive Security Consultant

ConsultingRemoteIndia-friendlyFull-time

Lead human-led assessments across web, API and related attack surfaces. Own scope clarity, proof-of-exploit evidence and remediation retests.

You would work on

  • Scoped penetration tests for SaaS, fintech and product teams
  • Authorisation, business-logic and chained attack-path analysis
  • Clear reports with reproduction steps and remediation guidance
  • Retesting in-scope fixes and keeping client communication tight

What we look for

  • Demonstrable offensive-security craft (labs, write-ups, prior engagements or strong home labs)
  • Comfort explaining impact to both engineers and security buyers
  • Honest scoping instincts — tell clients when a lighter test is enough
  • Reliable written English (en-GB preferred for published work)

Nice to have

  • Depth in one or more of: API authz, cloud identity paths, mobile, Electron/desktop, AI/LLM agent surfaces
  • Prior boutique consultancy or specialist product-security experience

Location: Remote-first. India time zones work well for many clients; worldwide collaboration is normal.

Security Researcher

ResearchRemoteIndia-friendlyFull-time / flexible

Turn real attack paths into practical methodology, labs and research that defenders and testers can use — without exploit theatre.

You would work on

  • Technical research drafts aligned with PoCForge (Cyber Security)’s research library tone
  • Lab notes and checklists for surfaces we actually test
  • Supporting consultants with deep-dive methodology when scopes need it
  • Keeping public writing honest: sources, caveats, no fabricated metrics

What we look for

  • Ability to explain attack paths and defensive priorities clearly
  • Comfort reading vendor advisories, KEV notes and primary sources
  • Strong writing discipline — structure, citations and restraint
  • Curiosity across application, cloud, desktop or AI security

Nice to have

  • Published blogs, conference notes, or open technical write-ups
  • Lab harness or tooling experience for authorised training environments

Location: Remote. Async-friendly with India-overlapping hours preferred.

Offensive Security Intern

InternshipRemoteIndia-friendlyFixed term

A supervised path into offensive security craft — labs, report support, research assistance and careful exposure to real engagement hygiene.

You would work on

  • Structured lab exercises and methodology notes
  • Assisting with recon hygiene, evidence organisation and draft report sections under review
  • Research support: source gathering, outline checks, diagram drafts
  • Learning how scope, rules of engagement and client communication actually work

What we look for

  • Foundational web/network security curiosity and a learning portfolio (labs, CTF notes, course projects — quality over brand names)
  • Willingness to be corrected and to write carefully
  • Reliability with deadlines and confidentiality
  • Based in or comfortable overlapping India working hours

Honest expectations

  • This is not unsupervised production pentesting on day one
  • Duration and stipend (if any) are confirmed per intake — ask in your application email

No listing that fits? We’re always open to exceptional talent.

If you have shipped strong offensive work, clear writing, or deep specialism in a surface we care about — send a short note with what you have built and where you fit. We read serious profiles even when a role is not posted.

Write to [email protected] →

Ways of working

Benefits for a small boutique look different from enterprise packages. Here is what we can speak to honestly today:

  • Remote-first delivery — most testing and research is remote; on-site only when a scope truly needs it.
  • High ownership — you see work reach real clients, not an anonymous backlog.
  • Craft time — room to deepen a surface (API authz, cloud identity, Electron, AI agents) and contribute to research.
  • Direct feedback — short loops with senior practitioners instead of multi-layer review theatre.
  • Transparent public voice — we do not decorate careers or marketing pages with credentials we cannot substantiate.

Compensation, equipment and leave details are shared during a real conversation for the role you apply to — not invented as marketing copy here.

Application process

01

Send a profile

Use the careers application form below, or email [email protected] with CV or portfolio links, preferred role, and a short note on recent work.

02

Async screen

We review writing, technical signal and fit. Expect a short reply if there is a match — silence may mean no current fit.

03

Practical conversation

A scoped technical discussion or take-home style exercise relevant to the role — never unpaid production client work.

04

Mutual decision

Clear next steps on scope of work, cadence and start timing. No badge theatre required.

Ready to apply?

Tell us the role, what you have built, and your preferred working hours. Use the careers form below — or email directly.

Open application form → Email [email protected]

Apply to PoCForge (Cyber Security)

Dedicated careers application — not the client scope form. Submissions go to [email protected] with a CAREERS subject line.

Or email [email protected] with subject CAREERS.