Map external attack surface and exposure for our clients, hunt leaked assets and credentials, and turn open-source signal into intelligence the offense can act on. You will see clients the way an attacker does, before the attacker does.
What you will do
Discover and map a client's external attack surface across domains, subdomains, IPs, and cloud assets
Hunt exposed credentials, leaked data, and secrets across paste sites, repos, and breach corpora
Run deep reconnaissance on people, infrastructure, and third parties to seed engagements
Correlate findings into a prioritized exposure picture that feeds red-team and VAPT operations
Write clear intelligence reports that turn scattered signal into decisions clients can act on
Build and maintain recon tooling and automation to keep coverage broad and repeatable
What we are looking for
3+ years in OSINT, reconnaissance, attack-surface management, or threat intelligence
Hands-on mastery of recon tooling such as Amass, Subfinder, Shodan, Censys, SpiderFoot, and Maltego
Strong scripting in Python to automate collection, enrichment, and correlation at scale
Practical experience with credential-leak and breach-data hunting and dark-web sourcing
Sharp source evaluation, OPSEC discipline, and structured analytic rigor
Excellent written communication that lands with both technical and executive readers
Nice to have
GOSI, OSCP, or other relevant intelligence or offensive certifications
Cloud asset discovery and exposure analysis across AWS, Azure, or GCP
Geolocation, imagery, or social media investigation depth
Get ahead of zero
Ready to see yourself the way an adversary would?
Book a scoped assessment - we will map what is reachable, prove what is exploitable, and give you a ranked path to closing it before someone finds it first.