Skip to main content
A platform from Security Brigade

Careers at ShadowMap.

ShadowMap is a product of Security Brigade, not a separate company. Roles on the platform are Security Brigade roles, hired and employed by the same firm that has run penetration tests, red teams and audits since 2006. This page lists the openings on ShadowMap itself; the wider set sits with the parent company.

All Security Brigade openings →

The work

What working on ShadowMap involves

ShadowMap shipped in 2016 out of tooling the Security Brigade team built for its own engagements. It still works that way: the people who run red teams use the platform, and what they need next is what gets built.

Attribution and discovery

Working out which assets belong to an organisation from registrar records, DNS, certificate transparency and reverse-DNS, then keeping that inventory correct as it changes daily. Attribution is the hard part, and everything downstream inherits its mistakes.

Collection at scale

Stealer-log ingestion, ransomware leak-site scraping, paste-site and public-repository collection. The engineering problem is steady throughput and clean parsing against sources that change format without notice.

Analyst-grade triage

Turning raw findings into something a security team can act on: severity that reflects real impact, ownership traced back to a person or account, and enough context to justify waking someone up.

Takedown operations

Filing with registrars, hosts and platforms, chasing SLAs, and building the evidence packs that make a filing succeed rather than bounce. Part workflow engineering, part knowing how each counterparty behaves.

More on the company behind the platform is on the about page, and the platform overview covers what the product does in detail.

Not quite the right role? Say so anyway.

If none of these fit but the platform does, tell us which part of it you want to work on and what you have built.