Penetration Tester (Bengaluru)

Penetration Tester (Bengaluru)

14 Sep
|
HCLSoftware
|
Bengaluru

14 Sep

HCLSoftware

Bengaluru

Senior Penetration Tester

nHCL Software | Office of the CISO

nLocation: India - Bangalore / Noida / Remote

nType: Full time

nAbout the Role

nHCL Software is seeking a Senior Penetration Tester to perform Continuous Threat Exposure

nManagement (CTEM) and offensive security testing across our products and infrastructure. This

nrole focuses on continuous attack surface discovery, attack path analysis, and risk-based

nprioritization to identify and remediate weaknesses across our application, cloud, and identity attack

nsurface before they can be exploited.

nWe are looking for a tester who produces findings engineering teams can actually act on, and who

ncares about whether issues get fixed rather than only whether they get reported.

nYou will work with Product Security, PSIRT, Security Operations, and engineering teams, and your

nfindings will feed directly into remediation roadmaps and customer-facing assurance.

nKey Responsibilities

n• Plan and execute penetration tests across web and thick-client applications, APIs, cloud

nenvironments, internal networks, and identity infrastructure.

n• Perform deep manual testing that goes well beyond automated tooling, including business logic

nabuse, authorization flaws, and chained exploitation.

n• Develop custom tooling, scripts, and proof-of-concept exploits where off-the-shelf tooling is

ninsufficient.

n• Define scope, rules of engagement, and safety controls, and operate within them rigorously.

nContinuous Threat Exposure Management (CTEM) & Attack Path Analysis

nOffensive Testing & Execution

n• Lead continuous attack surface discovery across cloud, on-prem, identity, and application

nenvironments to identify exposed assets and security misconfigurations.

n• Perform attack path analysis to map potential exploitation chains across AWS, Azure, GCP,

nand hybrid environments,



evaluating identity-based lateral movement and privilege escalation

nrisks.

n• Prioritize discovered exposures based on business impact, asset criticality, threat intelligence,

nand real-world exploitability to drive risk-based remediation.

n• Validate exposure remediation and efficacy of defensive controls through targeted offensive

nverification and continuous exposure validation.

nAdversary Emulation and Purple Teaming

n• Run scenario-based exercises informed by threat intelligence relevant to enterprise software

ncompanies.

n• Work jointly with the SOC to validate detection coverage, improve content, and close visibility

ngaps discovered during testing.

n• Emulate specific adversary tradecraft mapped to MITRE ATT&CK; and document detection

noutcomes alongside exploitation outcomes.

nAI and Emerging Attack Surface

n• Test AI-enabled product features and internal AI integrations for prompt injection, unsafe tool

ninvocation, data leakage, and authorization bypass.

n• Assess agentic workflows and connector integrations for excessive privilege and untrusted

ninput handling.

n• Keep current with emerging offensive techniques and bring them into the testing program

ndeliberately.

nReporting and Remediation

n• Write reports that a developer can act on: reproducible steps, accurate severity, business

nimpact, and concrete fix guidance.

n• Brief engineering and executive audiences with equal clarity,



and defend severity ratings on the

ntechnical merits.

n

n
- Retest fixes and track findings through to closure rather than handing off a PDF.
n
- Feed recurring finding patterns back into secure design standards, training, and pipeline
n

ncontrols.

nRequired Qualifications

n• 6+ years of hands-on penetration testing or offensive security experience, including lead

nresponsibility on engagements.

n• Demonstrated depth in application and API security testing, including manual exploitation of

nauthorization, business logic, and injection classes.

n• Strong cloud penetration testing experience in at least one major provider, including

nidentity-based attack paths.

n• Practical exploit development or custom tooling ability, with fluency in at least one scripting or

nprogramming language.

n• Working command of MITRE ATT&CK; and the ability to map testing activity to real adversary

ntradecraft.

n• Report writing that stands up to engineering scrutiny: precise, reproducible, and free of inflated

nseverity.

n• Sound ethical judgment and disciplined adherence to scope, authorization, and data handling

nrequirements.

nPreferred Qualifications

n• Experience testing commercial software products rather than only internal enterprise

nenvironments.

n• Red team or adversary emulation experience, including evasion and detection-aware

noperating.

n

n
- Purple team experience working directly with defenders to improve detection content.
n
- Experience testing AI and LLM systems, with familiarity with the OWASP LLM Top 10 and
n

nMITRE ATLAS.

n

n
- Published research, CVE credits, tooling contributions, or conference presentations.
n
- Certifications valued but not required: OSCP, OSWE, OSEP, OSCE3, CRTO, GPEN, GXPN, or
n

nGWAPT.

📌 Penetration Tester (Bengaluru)
🏢 HCLSoftware
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: penetration tester (bengaluru) / bengaluru