We evaluate candidates through two distinct pathways. Meeting the criteria in either pathway demonstrates the depth of skill we're looking for.
Type I
For candidates who demonstrate strong offensive security credentials and proven research ability.
OSCP (Offensive Security Certified Professional) certification
An active and strong Hack The Box profile showcasing consistent performance
CPTS (Certified Penetration Testing Specialist) from Hack The Box is considered a valid alternative to OSCP
CRT (CREST Registered Tester) or relevant certifications are also recognized
Type II
For candidates with real-world bug hunting experience and a security researcher mindset.
An active HackerOne profile with demonstrated bug bounty findings and reputation
Published CVE(s) demonstrating original vulnerability research
Strong source code review skills — ability to identify vulnerabilities through manual code auditing across multiple languages
If you fit into any of the two types, please specify.
Mobile Security Pathway (For Mobile-Focused Applicants)
Candidates applying specifically for mobile penetration testing should hold the following:
CAPT (Certified Android Penetration Tester) from Mobile Hacking Lab
CIPT (Certified iOS Penetration Tester) from Mobile Hacking Lab
CMSE (Certified Mobile Security Expert) from 8kSec is accepted as an alternative
Certification Verification & Preparation Documentation
To maintain the integrity of our hiring process and ensure fairness to all applicants, Brainstation-23 takes certification validation seriously. We have observed cases across the industry where certifications are proxy-passed, forged, or otherwise misrepresented, and we are committed to verifying that every credential reflects the candidate's own genuine effort and knowledge.
What We Require From Candidates
Verifiable Certification Records — Provide official verification links, credential IDs, or digital badges for every certification listed on your resume. Screenshots alone will not be accepted.
Preparation Journey Document — Submit a short write-up (1–3 pages) outlining your preparation path for each major certification claimed. This should include:
Practice platforms (HTB, TryHackMe, PortSwigger Web Security Academy, PentesterLab, VulnHub, etc.) and notable boxes/labs completed
Key challenges faced and how you overcame them
Personal notes, blog posts, GitHub repos, or write-ups created during preparation (if any)
Public Footprint — Where possible, share links to your Hack The Box, TryHackMe, HackerOne, Bugcrowd, GitHub, or personal blog profiles that reflect ongoing engagement with the craft.
Zero-Tolerance Policy
Any candidate found to have submitted forged certificates, proxy-passed exams, plagiarized write-ups, or misrepresented credentials will be immediately disqualified and permanently blacklisted from future opportunities at Brainstation-23.
Certifications Not Accepted
Certifications from the following providers will not be considered as qualifying credentials for this role:
eLearnSecurity (eJPT, eWPT, eMAPT etc.)
EC-Council (CEH, CPENT, LPT etc.)
CompTIA (Security+, PenTest+ etc.)
CWL Certifications (CRTA, CRT-ID e.t.c)