Penetration Tester (India)

Penetration Tester (India)

13 Sep
|
HCLSoftware
|
India

13 Sep

HCLSoftware

India

Job Type: Full-time

Remote: Hybrid

Senior Penetration TesterHCL Software | Office of the CISOLocation: India - Bangalore / Noida / RemoteType: Full-timeAbout the RoleHCL Software is seeking a Senior Penetration Tester to perform Continuous Threat ExposureManagement (CTEM) and offensive security testing across our products and infrastructure. Thisrole focuses on continuous attack surface discovery, attack path analysis, and risk-basedprioritization to identify and remediate weaknesses across our application, cloud, and identity attacksurface before they can be exploited.We are looking for a tester who produces findings engineering teams can actually act on, and whocares about whether issues get fixed rather than only whether they get reported.You will work with Product Security, PSIRT, Security Operations, and engineering teams, and yourfindings will feed directly into remediation roadmaps and customer-facing assurance.Key Responsibilities• Plan and execute penetration tests across web and thick-client applications, APIs, cloudenvironments, internal networks, and identity infrastructure.• Perform deep manual testing that goes well beyond automated tooling, including business logicabuse, authorization flaws, and chained exploitation.• Develop custom tooling, scripts, and proof-of-concept exploits where off-the-shelf tooling isinsufficient.• Define scope, rules of engagement, and safety controls, and operate within them rigorously.Continuous Threat Exposure Management (CTEM) & Attack Path AnalysisOffensive Testing & Execution• Lead continuous attack surface discovery across cloud, on-prem, identity, and applicationenvironments to identify exposed assets and security misconfigurations.• Perform attack path analysis to map potential exploitation chains across AWS, Azure,



GCP,and hybrid environments, evaluating identity-based lateral movement and privilege escalationrisks.• Prioritize discovered exposures based on business impact, asset criticality, threat intelligence,and real-world exploitability to drive risk-based remediation.• Validate exposure remediation and efficacy of defensive controls through targeted offensiveverification and continuous exposure validation.Adversary Emulation and Purple Teaming• Run scenario-based exercises informed by threat intelligence relevant to enterprise softwarecompanies.• Work jointly with the SOC to validate detection coverage, improve content, and close visibilitygaps discovered during testing.• Emulate specific adversary tradecraft mapped to MITRE ATT&CK; and document detectionoutcomes alongside exploitation outcomes.AI and Emerging Attack Surface• Test AI-enabled product features and internal AI integrations for prompt injection, unsafe toolinvocation, data leakage, and authorization bypass.• Assess agentic workflows and connector integrations for excessive privilege and untrustedinput handling.• Keep current with emerging offensive techniques and bring them into the testing programdeliberately.Reporting and Remediation• Write reports that a developer can act on: reproducible steps, accurate severity, businessimpact,



and concrete fix guidance.• Brief engineering and executive audiences with equal clarity, and defend severity ratings on thetechnical merits.• Retest fixes and track findings through to closure rather than handing off a PDF.• Feed recurring finding patterns back into secure design standards, training, and pipelinecontrols.Required Qualifications• 6+ years of hands-on penetration testing or offensive security experience, including leadresponsibility on engagements.• Demonstrated depth in application and API security testing, including manual exploitation ofauthorization, business logic, and injection classes.• Strong cloud penetration testing experience in at least one major provider, includingidentity-based attack paths.• Practical exploit development or custom tooling ability, with fluency in at least one scripting orprogramming language.• Working command of MITRE ATT&CK; and the ability to map testing activity to real adversarytradecraft.• Report writing that stands up to engineering scrutiny: accurate, reproducible, and free of inflatedseverity.• Sound ethical judgment and disciplined adherence to scope, authorization, and data handlingrequirements.Preferred Qualifications• Experience testing commercial software products rather than only internal enterpriseenvironments.• Red team or adversary emulation experience, including evasion and detection-awareoperating.• Purple team experience working directly with defenders to improve detection content.• Experience testing AI and LLM systems, with familiarity with the OWASP LLM Top 10 andMITRE ATLAS.• Published research, CVE credits, tooling contributions, or conference presentations.• Certifications valued but not required: OSCP, OSWE, OSEP, OSCE3, CRTO, GPEN, GXPN, orGWAPT.

📌 Penetration Tester (India)
🏢 HCLSoftware
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: penetration tester (india) / india