ingrid.fyi India's software hiring trends, explained.
Sign in to ingrid.fyi with Google
Your Google account
name@gmail.com
Continue with Google
Home / Product companies / I · Networking, infrastructure and security / Cybersecurity / Vulnerability management and penetration testing
On this page
Vulnerability management and penetration testing Finding the holes before attackers do Most successful attacks do not use anything clever. They use a known flaw in a piece of software. The software's maker fixed the flaw months ago, but the victim never got round to installing the fix, called a patch. Often the flaw sits on a server the victim did not even know it had.

Picture a 1,500-person online travel company in Gurugram. A team set up a booking server for a sale in 2022, and then forgot about it. The server still runs, and its web software has a flaw that was fixed eight months ago. Nobody patched it, because nobody remembers the server exists.

This Market Segment is about the companies that look at a company the way an attacker would, before the attacker does. Their buyers are the security teams of companies like the travel company. The work goes in steps:

  • Count every machine and application the company has.
  • Check each one against the public catalogue of known flaws, called the CVE list.
  • Work out which of the thousands of flaws found actually lead somewhere.
  • At the far end, pay real hackers to try to break in.

Industry Vertical 4's newest term, exposure management, is the promise to do all of this as one loop that never stops. Exposure means everything an attacker could reach and use.

The exposure loop. Count every machine and application the company has, check each one against the public catalogue of known flaws, called the CVE list, rank the flaws that actually lead somewhere, and invite hackers to try to break in. Then start again. Qualys, Rapid7, RedSeal, Safe Security, Bugcrowd and HackerOne each sell a part of it.The exposure loop. Count every machine and application the company has, check each one against the public catalogue of known flaws, called the CVE list, rank the flaws that actually lead somewhere, and invite hackers to try to break in. Then start again. Qualys, Rapid7, RedSeal, Safe Security, Bugcrowd and HackerOne each sell a part of it.

This is one of the Market Segments with the most job postings in Industry Vertical 4. Almost all of its postings come from two companies, Qualys and Rapid7. Their Pune engineering centres are among their biggest anywhere.

Every company named here has posted software engineering jobs in India. Famous companies that don't actively hire software engineers in India are left out.

This Market Segment has three sub-segments:

The scanner: finds the flaws, and more and more often fixes them too. The map and the number: decides which flaws matter. It models how an attacker would chain them together, and puts a figure on the risk. The hackers you invite: bug-bounty platforms, penetration-testing services and automated red teams, which test the defence by attacking it.

Keep reading, free

Three more sections are on this page: The scanner, The map and the number, and The hackers you invite. Sign in to read them here, in full.

Continue with Google
  • The scanner
  • The map and the number
  • The hackers you invite
The scanner Vulnerability management, asset discovery, patch management

Take the travel company from the start of this Market Segment. The scanner is what finally finds the forgotten booking server. It is the oldest product in this Market Segment, and the source of most of its job postings. It works in three steps:

  • It makes a list of every machine, container and cloud account the company has. This is called asset discovery.
  • It compares the software running on each against the catalogue of known flaws, called vulnerabilities.
  • It produces the list of flaws to fix.

The whole job is called vulnerability management. Installing the fixes is called patch management.

Qualyssells its scanner as a cloud service, and has engineers in Pune. The product has grown from the scanner into asset management, patching, cloud posture management and detection, all on the same agent. Rapid7also with engineers in Pune, sells the same kind of scanner, called InsightVM. It also sells a cloud posture product and a detection and response product. And it owns Metasploit, the open-source toolkit that attackers and testers both use. This gives Rapid7 a foot in every sub-segment here. SecPoda Bengaluru company, sells the version for small companies. Its Saner platform scans each device and applies the patch in the same product.
The map and the number Attack-path analysis, exposure management, cyber risk quantification, third-party risk

Back to the travel company from the start of this Market Segment. The scanner found the forgotten server, but it also found 40,000 other flaws. A large company has hundreds of thousands of open findings. Fixing them in the order the scanner lists them is a mistake, because most of them lead nowhere. The companies in this sub-segment decide which ones matter, in three different ways.

With a map. This is called attack-path analysis.

RedSeala US company with engineers in Pune, reads the settings of every firewall, router and cloud network. From them it builds a model of what can reach what. Then it simulates an attacker's path from the internet to the company's most valuable systems and data. A serious flaw on a server nobody can reach drops to the bottom of the list. The forgotten booking server, open to the internet, rises to the top. Which flaw matters? Attack-path analysis, as RedSeal sells it, asks whether an attacker can reach a flaw. The forgotten booking server is open to the internet and leads on to valuable systems and customer data, so it goes to the top of the list. A serious flaw on a server nobody can reach goes to the bottom.Which flaw matters? Attack-path analysis, as RedSeal sells it, asks whether an attacker can reach a flaw. The forgotten booking server is open to the internet and leads on to valuable systems and customer data, so it goes to the top of the list. A serious flaw on a server nobody can reach goes to the bottom.

One company here builds the same kind of map for a different user:

Forward Networksbuilds a digital twin of a network, a complete software copy of it, for network engineers. It has engineers in Bengaluru. The same model answers RedSeal's security question: does a path exist?

Forward Networks is covered mainly in Market Segment 1.3, Network testing, visibility and monitoring (in Industry Vertical 1, Networking and telecom), and RedSeal also appears there.

With intelligence about the flaws

Securinfrom Albuquerque with engineers in Chennai, tracks which flaws in the catalogue attackers are actually using right now. The industry calls this being exploited in the wild. Securin combines that with finding everything the company has exposed to the internet.

With a number. This is called cyber risk quantification.

Safe Securityan Indian-founded company with teams in Bengaluru and Delhi, sells a platform called SAFE One. It turns the findings, the protections in place and the current threats into a single figure: how likely a breach is, and what it would cost. That is a figure a company's board and its insurer can act on. It extends the same score to a company's suppliers, which is called third-party risk. (More on third-party risk in Market Segment 4.12, Threat intelligence and attack surface management.) Balbixnow part of Safe Security, built a competing exposure-management platform. It has engineers in Delhi NCR. Continuous exposure management.

The ambition of this sub-segment, and the name the market has settled on, is continuous exposure management. It replaces the scan every three months and the spreadsheet of findings with a loop that never stops. The loop finds, maps, ranks and tests, over and over. Every company here, and both big scanner companies, Qualys and Rapid7, now sell under that name.

You're reading as a guest. Sign in free to follow links for five minutes, once an hour. The hackers you invite Bug bounties, penetration testing as a service, breach and attack simulation, automated red teaming

Back to the travel company from the start of this Market Segment. The scanner and the map are models of an attack. This sub-segment runs a real one. The travel company invites outside hackers to attack its systems, with its permission, and pays them for every flaw they find. (Testing one application as it is built is covered in Market Segment 4.7, Application and API security.)

Bugcrowdwith engineers in Bengaluru, and HackerOne, with engineers in Pune, are two such platforms. Each connects a company with a crowd of checked, trusted hackers, and pays them for the flaws they find. The reward is called a bug bounty. The platforms also run the channel through which any outsider can report a flaw safely, called a vulnerability disclosure programme. Both have added penetration testing as a service: a scheduled test by named testers, delivered through the same platform. NetSPIa US company with engineers in Pune, sells that testing as its main business. It also sells attack-surface management, and breach and attack simulation. In breach and attack simulation, known attacker techniques are replayed safely against the company's own defences, to see which defences react. In September 2026, NetSPI agreed to merge with Synack. Neova Solutionsfrom Santa Clara with its development centre in Pune, shows the next step. It sells an automated red-team agent, which plans and runs the attack simulation itself. A red team is a group that attacks its own side to test the defence. Neova also sells a compliance agent and a threat-analysis agent. Hackers you invite. The travel company sets the rules and the rewards on a platform such as Bugcrowd or HackerOne, which connects it with a crowd of checked, trusted hackers. They attack with permission, report each flaw they find, and the company pays a bug bounty for every one.Hackers you invite. The travel company sets the rules and the rewards on a platform such as Bugcrowd or HackerOne, which connects it with a crowd of checked, trusted hackers. They attack with permission, report each flaw they find, and the company pays a bug bounty for every one. The red team as a model.

Penetration testing is expensive because it takes skilled human time. The newest products here aim to have an AI model do the scouting and the first attempts. The human hacker is kept for what the model cannot find. Neova's agent is one example. The automation that both bounty platforms are building is another.

So the travel company from the start of this Market Segment finds its forgotten server three ways. The scanner lists it. The map shows that an attacker could reach it. And an invited hacker proves it, before a real attacker does.
Who they hire

Who these companies hire, and for what, is on What cybersecurity hires for.

Privacy Terms Refunds and cancellation Shipping and delivery © 2026 ingrid.fyi · Payments by Razorpay
You're browsing as a guest. Sign in free to follow links for five minutes, once an hour.