11 Sep
|
HCLSoftware
|
Bangalore Metropolitan Area
11 Sep
HCLSoftware
Bangalore Metropolitan Area
Senior Penetration Tester
HCL Software | Office of the CISO
Location: India - Bangalore / Noida / Remote
Type: Full-time
About the Role
HCL Software is seeking a Senior Penetration Tester to perform Continuous Threat Exposure
Management (CTEM) and offensive security testing across our products and infrastructure. This role focuses on continuous attack surface discovery, attack path analysis, and risk-based prioritization to identify and remediate weaknesses across our application, cloud, and identity attack surface before they can be exploited.
We are looking for a tester who produces findings engineering teams can actually act on, and who cares about whether issues get fixed rather than only whether they get reported.
You will work with Product Security, PSIRT, Security Operations, and engineering teams, and your findings will feed directly into remediation roadmaps and customer-facing assurance.
Key Responsibilities
- Plan and execute penetration tests across web and thick-client applications, APIs, cloud environments, internal networks, and identity infrastructure.
- Perform deep manual testing that goes well beyond automated tooling, including business logic abuse, authorization flaws, and chained exploitation.
- Develop custom tooling, scripts, and proof-of-concept exploits where off-the-shelf tooling is insufficient.
- Define scope, rules of engagement, and safety controls, and operate within them rigorously.
Continuous Threat Exposure Management (CTEM) & Attack Path Analysis
Offensive Testing & Execution
- Lead continuous attack surface discovery across cloud, on-prem, identity, and application environments to identify exposed assets and security misconfigurations.
- Perform attack path analysis to map potential exploitation chains across AWS, Azure, GCP,
and hybrid environments, evaluating identity-based lateral movement and privilege escalation risks.
- Prioritize discovered exposures based on business impact, asset criticality, threat intelligence,
and real-world exploitability to drive risk-based remediation.
- Validate exposure remediation and efficacy of defensive controls through targeted offensive verification and continuous exposure validation.
Adversary Emulation and Purple Teaming
- Run scenario-based exercises informed by threat intelligence relevant to enterprise software companies.
- Work jointly with the SOC to validate detection coverage, improve content, and close visibility gaps discovered during testing.
- Emulate specific adversary tradecraft mapped to MITRE ATT&CK; and document detection outcomes alongside exploitation outcomes.
AI and Emerging Attack Surface
- Test AI-enabled product features and internal AI integrations for prompt injection, unsafe tool invocation, data leakage, and authorization bypass.
- Assess agentic workflows and connector integrations for excessive privilege and untrusted input handling.
- Keep current with emerging offensive techniques and bring them into the testing program deliberately.
Reporting and Remediation
- Write reports that a developer can act on: reproducible steps, accurate severity, business impact, and concrete fix guidance.
- Brief engineering and executive audiences with equal clarity,
and defend severity ratings on the technical merits.
- Retest fixes and track findings through to closure rather than handing off a PDF.
- Feed recurring finding patterns back into secure design standards, training, and pipeline controls.
Required Qualifications
- 6+ years of hands-on penetration testing or offensive security experience, including lead responsibility on engagements.
- Demonstrated depth in application and API security testing, including manual exploitation of authorization, business logic, and injection classes.
- Solid cloud penetration testing experience in at least one major provider, including identity-based attack paths.
- Practical exploit development or custom tooling ability, with fluency in at least one scripting or programming language.
- Working command of MITRE ATT&CK; and the ability to map testing activity to real adversary tradecraft.
- Report writing that stands up to engineering scrutiny: precise, reproducible, and free of inflated severity.
- Sound ethical judgment and disciplined adherence to scope, authorization, and data handling requirements.
Preferred Qualifications
- Experience testing commercial software products rather than only internal enterprise environments.
- Red team or adversary emulation experience, including evasion and detection-aware operating.
- Purple team experience working directly with defenders to improve detection content.
- Experience testing AI and LLM systems, with familiarity with the OWASP LLM Top 10 and
MITRE ATLAS.
- Published research, CVE credits, tooling contributions, or conference presentations.
- Certifications valued but not required: OSCP, OSWE, OSEP, OSCE3, CRTO, GPEN, GXPN, or
GWAPT.
📌 Penetration Tester (Bangalore Metropolitan Area)
🏢 HCLSoftware
📍 Bangalore Metropolitan Area