Skip to content
Talk to a Security Expert
// CAREERS AT TMG SECURITY

Build security for what comes next.

Join TMG Security and work alongside security practitioners, engineers, researchers, trainers and consultants solving real-world cybersecurity challenges across offensive security, defensive security, cloud, application security, AI, GRC and security education.

We are looking for experienced professionals who can think beyond checklists, investigate real problems and help organizations build security that works in practice.

CANDIDATE
ENGINEERING
SECURITY
RESEARCH
CONSULTING
ORGANIZATIONS
TMG
SECURITY
OPERATIONS

CONCEPTUAL DIAGRAM · HOW WORK MOVES FROM A CANDIDATE THROUGH OUR TEAMS TO THE ORGANIZATIONS WE SUPPORT

// WHY TMG

Security is changing. So is the work.

At TMG Security, professionals work across multiple layers of cybersecurity rather than being restricted to a single discipline.

01

REAL SECURITY PROBLEMS

Work on practical security challenges across applications, infrastructure, cloud and emerging technologies.

02

CROSS-DISCIPLINARY WORK

Collaborate across offensive, defensive, engineering, consulting, research and training teams.

03

CONTINUOUS LEARNING

Security changes constantly. We expect our people to keep learning, testing and improving.

04

BUILD & TEACH

Our work isn't limited to finding vulnerabilities. We also build solutions, create research and help others develop security capabilities.

  • Offensive Security
  • Defensive Security
  • Cloud & Infrastructure
  • Application Security
  • AI / LLM Security
  • GRC & Compliance
  • Security Consulting
  • Cybersecurity Research
  • Cybersecurity Training
// OPEN POSITIONS

Where your expertise fits.

We are building teams across security engineering, offensive security, cloud, governance, research and cybersecurity education.

SHOWING ALL 10 OPEN POSITIONS

GRC & COMPLIANCE01

GRC Auditor

Support organizations in evaluating, strengthening and improving their governance, risk and compliance programs across established security and privacy frameworks.

EXPERIENCE
4+ years
EMPLOYMENT TYPE
Full-time
LOCATION / MODE
India / Hybrid or Remote
DEPARTMENT
GRC & COMPLIANCE
Full job description

ROLE OVERVIEW

Support organizations in evaluating, strengthening and improving their governance, risk and compliance programs across established security and privacy frameworks.

RESPONSIBILITIES

  • Conduct security and compliance assessments
  • Review organizational policies, procedures and controls
  • Assess evidence against applicable requirements
  • Identify control gaps and areas of non-conformity
  • Prepare audit and assessment documentation
  • Support remediation planning
  • Work with clients to understand business and regulatory requirements
  • Assist with readiness assessments and internal audits
  • Contribute to risk and compliance reporting

REQUIRED EXPERIENCE

  • 4+ years of experience in GRC, information security audit or compliance
  • Strong understanding of security controls and risk management
  • Experience with frameworks such as ISO 27001, SOC 2, PCI DSS, HIPAA or GDPR
  • Strong documentation and communication skills
  • Experience interacting with clients and stakeholders
  • Ability to independently manage assessment activities
SECURITY CONSULTING02

Senior CISO / vCISO

Lead cybersecurity strategy and advisory engagements for organizations looking to establish, mature or transform their security programs.

EXPERIENCE
8+ years
EMPLOYMENT TYPE
Full-time / Consulting
LOCATION / MODE
India / Remote
DEPARTMENT
SECURITY CONSULTING
Full job description

ROLE OVERVIEW

Lead cybersecurity strategy and advisory engagements for organizations looking to establish, mature or transform their security programs.

RESPONSIBILITIES

  • Develop enterprise cybersecurity strategies
  • Lead security program assessments
  • Advise leadership and executive stakeholders
  • Build security roadmaps
  • Define security governance models
  • Support risk management initiatives
  • Review security architecture and controls
  • Guide incident preparedness and resilience programs
  • Advise on security investment priorities
  • Lead client-facing security consulting engagements

REQUIRED EXPERIENCE

  • 8+ years in cybersecurity
  • Previous leadership or security management experience
  • Strong understanding of enterprise security architecture
  • Experience with security governance and risk
  • Strong understanding of frameworks and regulatory requirements
  • Excellent executive communication skills
  • Ability to translate technical risk into business impact
APPLICATION SECURITY03

Application Security Engineer

Work with engineering and security teams to identify and reduce vulnerabilities throughout the application development lifecycle.

EXPERIENCE
4+ years
EMPLOYMENT TYPE
Full-time
LOCATION / MODE
India / Hybrid or Remote
DEPARTMENT
APPLICATION SECURITY
Full job description

ROLE OVERVIEW

Work with engineering and security teams to identify and reduce vulnerabilities throughout the application development lifecycle.

RESPONSIBILITIES

  • Perform application security assessments
  • Conduct secure code reviews
  • Identify vulnerabilities across web applications and APIs
  • Support SAST and DAST programs
  • Perform threat modeling
  • Review authentication and authorization mechanisms
  • Work with development teams on remediation
  • Integrate security into CI/CD pipelines
  • Create technical security reports
  • Support secure SDLC initiatives

REQUIRED EXPERIENCE

  • 4+ years in application security or security engineering
  • Strong knowledge of web application security
  • Strong understanding of OWASP methodologies
  • Experience with APIs and modern application architectures
  • Familiarity with SAST, DAST and software composition analysis
  • Experience with Burp Suite or comparable tooling
  • Strong understanding of secure development practices
EMERGING TECHNOLOGY SECURITY04

Web3 Security Engineer / Developer

Work on security assessments and engineering initiatives involving Web3 applications, blockchain infrastructure and decentralized applications.

EXPERIENCE
4+ years
EMPLOYMENT TYPE
Full-time
LOCATION / MODE
India / Remote
DEPARTMENT
EMERGING TECHNOLOGY SECURITY
Full job description

ROLE OVERVIEW

Work on security assessments and engineering initiatives involving Web3 applications, blockchain infrastructure and decentralized applications.

RESPONSIBILITIES

  • Assess Web3 applications and decentralized systems
  • Review smart contract implementations
  • Identify security weaknesses in blockchain-based applications
  • Perform security testing of APIs and supporting infrastructure
  • Review wallet and authentication flows
  • Analyze attack surfaces across decentralized applications
  • Assist with security research
  • Document vulnerabilities and remediation recommendations
  • Work with engineering teams to improve secure development practices

REQUIRED EXPERIENCE

  • 4+ years of software development or security engineering
  • Strong understanding of blockchain technologies
  • Experience with Web3 application architectures
  • Experience with Solidity or equivalent smart-contract technologies
  • Understanding of common smart contract security issues
  • Strong programming and debugging skills
  • Security research mindset
DEFENSIVE SECURITY / SOC05

Security Analyst

Monitor, investigate and respond to security events while helping organizations improve their detection and response capabilities.

EXPERIENCE
3+ years
EMPLOYMENT TYPE
Full-time
LOCATION / MODE
India / Hybrid or Remote
DEPARTMENT
DEFENSIVE SECURITY / SOC
Full job description

ROLE OVERVIEW

Monitor, investigate and respond to security events while helping organizations improve their detection and response capabilities.

RESPONSIBILITIES

  • Monitor security events and alerts
  • Investigate suspicious activity
  • Perform alert triage
  • Conduct log analysis
  • Support incident response
  • Investigate endpoint and network activity
  • Assist with threat hunting
  • Develop and improve detection logic
  • Document incidents
  • Support security reporting

REQUIRED EXPERIENCE

  • 3+ years of SOC or security operations experience
  • Experience with SIEM platforms
  • Understanding of networking and operating systems
  • Knowledge of incident response methodologies
  • Familiarity with threat intelligence
  • Strong analytical and investigative skills
  • Ability to work with security logs and alerts
CYBERSECURITY TRAINING06

Defensive Security Trainer

Deliver practical cybersecurity training for professionals and organizations across defensive security, SOC operations and incident response.

EXPERIENCE
4+ years
EMPLOYMENT TYPE
Full-time / Contract
LOCATION / MODE
India / Remote
DEPARTMENT
CYBERSECURITY TRAINING
Full job description

ROLE OVERVIEW

Deliver practical cybersecurity training for professionals and organizations across defensive security, SOC operations and incident response.

RESPONSIBILITIES

  • Design practical training content
  • Deliver instructor-led cybersecurity sessions
  • Teach SOC operations and defensive security concepts
  • Conduct hands-on labs
  • Create realistic security scenarios
  • Develop exercises and assessments
  • Support corporate security training programs
  • Stay current with security tools and attack techniques
  • Mentor learners
  • Improve course material based on industry developments

REQUIRED EXPERIENCE

  • 4+ years of professional cybersecurity experience
  • Strong defensive security knowledge
  • SOC / SIEM experience
  • Practical incident response experience
  • Excellent communication and presentation skills
  • Ability to explain complex concepts clearly
  • Training or mentoring experience preferred
CYBERSECURITY TRAINING / CLOUD SECURITY07

Cloud Security Trainer

Deliver practical cloud security training covering secure cloud architecture, identity, infrastructure security and cloud-native security practices.

EXPERIENCE
4+ years
EMPLOYMENT TYPE
Full-time / Contract
LOCATION / MODE
India / Remote
DEPARTMENT
CYBERSECURITY TRAINING / CLOUD SECURITY
Full job description

ROLE OVERVIEW

Deliver practical cloud security training covering secure cloud architecture, identity, infrastructure security and cloud-native security practices.

RESPONSIBILITIES

  • Develop cloud security curriculum
  • Deliver practical cloud security training
  • Teach AWS, Azure and/or GCP security concepts
  • Create hands-on cloud security labs
  • Teach IAM and identity security
  • Cover cloud logging and monitoring
  • Explain cloud configuration risks
  • Develop practical exercises
  • Mentor learners
  • Support corporate cloud security training

REQUIRED EXPERIENCE

  • 4+ years in cloud security, cloud engineering or cybersecurity
  • Strong experience with AWS, Azure or GCP
  • Strong IAM knowledge
  • Understanding of cloud-native security
  • Experience with security architecture
  • Excellent communication and teaching skills
  • Practical hands-on experience preferred
OFFENSIVE SECURITY08

Senior Penetration Tester

Conduct advanced penetration testing and security assessments across web applications, APIs, mobile applications, infrastructure and cloud environments.

EXPERIENCE
5+ years
EMPLOYMENT TYPE
Full-time
LOCATION / MODE
India / Hybrid or Remote
DEPARTMENT
OFFENSIVE SECURITY
Full job description

ROLE OVERVIEW

Conduct advanced penetration testing and security assessments across web applications, APIs, mobile applications, infrastructure and cloud environments.

RESPONSIBILITIES

  • Plan and execute penetration tests
  • Assess web applications and APIs
  • Perform infrastructure security assessments
  • Conduct mobile application security testing
  • Identify complex security vulnerabilities
  • Validate security findings
  • Develop technical reports
  • Provide remediation guidance
  • Participate in client calls and technical discussions
  • Support advanced security research

REQUIRED EXPERIENCE

  • 5+ years in penetration testing
  • Strong web and API security knowledge
  • Strong understanding of OWASP methodologies
  • Experience with Burp Suite and security testing tools
  • Strong networking knowledge
  • Experience with manual testing
  • Strong report-writing skills
  • Relevant security certifications are a plus
AI SECURITY / RESEARCH09

AI / LLM Security Researcher

Research emerging security risks affecting AI applications, LLMs, agents, RAG systems and AI-enabled enterprise platforms.

EXPERIENCE
3+ years
EMPLOYMENT TYPE
Full-time
LOCATION / MODE
India / Remote
DEPARTMENT
AI SECURITY / RESEARCH
Full job description

ROLE OVERVIEW

Research emerging security risks affecting AI applications, LLMs, agents, RAG systems and AI-enabled enterprise platforms.

RESPONSIBILITIES

  • Research AI and LLM security vulnerabilities
  • Assess AI application attack surfaces
  • Study prompt injection and indirect prompt injection
  • Analyze agentic AI security risks
  • Research model and application-level weaknesses
  • Evaluate tool and API interactions
  • Analyze RAG security risks
  • Develop security testing methodologies
  • Create technical research and advisories
  • Contribute to AI security labs and training content

REQUIRED EXPERIENCE

  • 3+ years in cybersecurity, application security, AI security or related fields
  • Strong understanding of LLM applications
  • Knowledge of AI security concepts
  • Strong application/API security fundamentals
  • Research-oriented mindset
  • Strong technical writing skills
  • Programming experience preferred
CLOUD & INFRASTRUCTURE SECURITY10

Cloud Security Engineer

Design, assess and improve security controls across cloud infrastructure and cloud-native environments.

EXPERIENCE
4+ years
EMPLOYMENT TYPE
Full-time
LOCATION / MODE
India / Hybrid or Remote
DEPARTMENT
CLOUD & INFRASTRUCTURE SECURITY
Full job description

ROLE OVERVIEW

Design, assess and improve security controls across cloud infrastructure and cloud-native environments.

RESPONSIBILITIES

  • Perform cloud security assessments
  • Review cloud architecture
  • Assess IAM configurations
  • Review cloud networking
  • Identify configuration weaknesses
  • Support cloud security monitoring
  • Develop security recommendations
  • Work with DevOps and engineering teams
  • Improve cloud security posture
  • Support security automation

REQUIRED EXPERIENCE

  • 4+ years in cloud security or cloud engineering
  • Strong AWS, Azure or GCP knowledge
  • Cloud networking knowledge
  • Strong IAM understanding
  • Infrastructure security experience
  • Familiarity with containers and Kubernetes
  • Understanding of cloud security best practices

EACH ROLE IS ASSESSED ON EXPERIENCE, TECHNICAL DEPTH AND FIT WITH THE TEAM

// HIRING PROCESS

How the process works.

Four stages, run in order. Each one is a conversation about the work itself.

01

Profile Review

Your profile and CV are reviewed against the role and the wider needs of the team.

02

Technical Discussion

A working conversation about how you approach security problems in practice.

03

Role / Team Interview

A discussion with the team you would join, covering scope, ways of working and expectations.

04

Final Decision

The outcome is confirmed and next steps are shared with you directly.

// WHAT WE LOOK FOR

We hire for depth, not for keywords.

Six things carry more weight than anything else on a CV.

Technical DepthReal, demonstrable understanding of the systems you work on — not just familiarity with tools.
CuriosityA habit of asking why something behaves the way it does, and following that question through.
Problem SolvingThe ability to work through unclear, messy problems where no checklist covers the answer.
CommunicationExplaining findings and risk clearly to engineers, stakeholders and non-technical audiences.
OwnershipTaking a piece of work from start to finish and standing behind the result.
Continuous LearningKeeping pace with a field that changes faster than any single certification can cover.
// JOIN TMG SECURITY

Don't see the right role?

We are always interested in meeting experienced security professionals who can bring strong technical skills, practical experience and a willingness to solve difficult problems.

Choose a file or drag it here PDF, DOC OR DOCX · UP TO 8 MB
Your details and CV go to the TMG Security hiring team only.
Uploaded CVs are stored privately and are never published or linked publicly.
APPLICATION RECEIVED

Thank you for your interest in TMG Security.

Our hiring team will review your profile and contact you if your experience aligns with a current or future opportunity.

Prefer email? Send your CV and profile directly to [email protected]. Email HR →

Not applying, but want to talk security?

If you are looking for security support rather than a role, the TMG Security team is the right place to start.