Website:
bytoid.ai
Job details:
Bytoid India Private Limited
Security Researcher (Associate)
Team: Information Security / GRC
Location: Bangalore / Hybrid / Remote
Experience: 0–2 years
Reports to: Security Manager / CISO
About the role
You'll split your time between hands-on security research and helping us build out our ISO 27001 Information Security Management System (ISMS). This is a role for someone early in their career who wants breadth: one week you might be tearing apart a vendor's product in a lab, the next you're mapping Annex A controls to what we actually do and chasing down evidence for an audit. You'll get mentorship from senior security engineers and a direct line to how a real certification programme gets built.
What you'll do
Security research
- Research, test, and benchmark security tools (vulnerability scanners, SAST/DAST, EDR, SIEM, secrets detection, cloud posture tooling) and write up clear recommendations on what we should adopt and why.
- Set up and run proof-of-concept deployments in a lab environment, including breaking things to see how the tooling responds.
- Track CVEs, advisories, and threat intelligence relevant to our tech stack; assess real-world impact and flag what needs action.
- Perform security reviews of third-party and open-source tools before they enter the environment, covering dependencies, permissions, data flows, and vendor security posture.
- Reproduce and validate published vulnerabilities in a controlled setting to understand exploitability in our context.
- Document findings in short, readable reports that a non-specialist stakeholder can act on.
ISO 27001 implementation support
- Support the rollout of the ISMS against ISO 27001:2022, including scoping, the Statement of Applicability, and the 93 Annex A controls.
- Draft and maintain policies, standards, procedures, and records under the guidance of the ISMS owner.
- Help maintain the risk register: assist with risk identification, assessment, treatment plans, and periodic review.
- Collect, organise, and validate evidence for internal audits, management reviews, and external certification audits.
- Track corrective actions and nonconformities to closure, and chase control owners where needed.
- Assist with gap assessments, supplier security assessments, and security awareness training material.
What we're looking for
- 0–2 years in security, IT, or a related technical role. Internships, co-ops, lab work, CTFs, bug bounty, and serious self-study all count.
- Working understanding of core security concepts: the CIA triad, common vulnerability classes (OWASP Top 10), authentication and access control, encryption basics, and network fundamentals.
- Comfortable in Linux and with at least one scripting language (Python preferred) for automating repetitive analysis.
- Familiarity with ISO 27001, or with any comparable control framework (SOC 2, NIST CSF, CIS Controls). Deep experience isn't expected; genuine interest is.
- Strong written English. A good portion of this job is turning technical findings into documents other people can use.
- Organised and able to track many small open items without dropping them, which is most of what audit readiness is.
- Curiosity and a willingness to say "I don't know yet, let me go find out."
Nice to have
- Certifications such as ISO 27001 Foundation or Lead Implementer, CompTIA Security+, eJPT, or a cloud security associate cert.
- Exposure to cloud environments (AWS, Azure, or GCP) and CI/CD pipelines.
- Experience with a GRC platform, or with tools like Burp Suite, Nmap, Wireshark, Nessus/OpenVAS.
- A home lab, personal write-ups, CTF placings, or open-source contributions.
What we offer
Competitive Salary along with benefits.
How to apply
Submit your CV. If you have write-ups, a blog, a GitHub profile, or CTF results, include them. A short note about a security topic you've recently gone down a rabbit hole on is welcome and will be read.
Click on Apply to know more.