08 Aug
|
HDFC Bank
|
Mumbai
Role Overview:
We are seeking a highly skilled and hands-on cybersecurity professional to join our Offensive Security team. The role focuses on assessing the security posture of the bank's traditional technology landscape as well as emerging AI-powered systems and applications.
The successful candidate will be responsible for designing and executing advanced adversarial simulations, building attack chains, identifying exploitable attack paths, and conducting both manual and agentic attack campaigns against enterprise and AI environments. This role requires deep technical expertise, an attacker mindset, and the ability to emulate sophisticated threat actors across complex infrastructures.
Key Responsibilities
- Conduct Red Team assessments against enterprise, cloud, application, and AI-based environments.
- Perform advanced penetration testing of internal, external, web, API, and AI/LLM-based systems.
- Design, develop, and execute complex attack chains that simulate real-world adversary tactics, techniques, and procedures (TTPs).
- Identify and exploit vulnerabilities across traditional and AI-enabled systems to assess security effectiveness.
- Execute human-in-the-loop and agentic adversarial attack campaigns against AI applications, models, and supporting infrastructure.
- Evaluate security controls, detection capabilities, and incident response readiness through realistic attack simulations.
- Map findings to MITRE ATT&CK; and MITRE ATLAS frameworks and provide actionable recommendations.
- Develop custom tools, scripts, payloads, and attack methodologies to support Red Team operations.
- Collaborate with security engineering, application security, AI security, and blue teams to improve overall cybersecurity resilience.
- Produce detailed technical reports and executive summaries highlighting attack paths, risks, and remediation recommendations.
Required Skills
- Robust expertise in:
- Red Team Operations
- Offensive Security Assessments
- Penetration Testing
- Application Security (AppSec)
- Adversary Emulation
- Attack Path & Attack Chain Analysis
- Vulnerability Assessment and Exploitation
- Deep knowledge of:
- MITRE ATT&CK; Framework
- MITRE ATLAS Framework
- OWASP Testing Methodologies
- OSSTM (Open Source Security Testing Methodology Manual)
Experience in:
- Web Application Security Testing
- API Security Testing
- Active Directory Attacks
- Cloud Security Assessments
- AI/LLM Security Testing
- Threat Modeling and Adversary Simulation
Preferred Qualifications:
- Experience conducting security assessments of AI/ML systems, Generative AI applications, and LLM-based platforms.
- Ability to create and execute agentic attack strategies against AI systems.
- Knowledge of detection engineering and security validation methodologies.
- Scripting and automation experience using Python, PowerShell, Bash, or similar technologies.
Certifications: One or more of the following industry-recognized certifications are preferred:
- OSCP (Offensive Security Certified Professional)
- OSCE
- OSWE
- CRTP
- CRTO
- CRTL
- CEPT
- CRTM
- ARTOC
- GWAPT
- GCPN
- GX-PT
- GRTP
- GOAA
- Equivalent offensive security, red teaming, or adversarial AI certifications
What Success Looks Like:
- Demonstrated ability to identify sophisticated attack paths across traditional and AI environments.
- Execution of realistic Red Team campaigns that improve the organization's security posture.
- Delivery of high-quality technical findings and actionable remediation guidance.
- Continuous innovation in offensive security techniques, particularly within emerging AI security domains.
📌 Red Team & Security Manager (Mumbai)
🏢 HDFC Bank
📍 Mumbai