14 Sep
|
HCLSoftware
|
Bengaluru
14 Sep
HCLSoftware
Bengaluru
Senior Penetration Tester
nHCL Software | Office of the CISO
nLocation: India - Bangalore / Noida / Remote
nType: Full time
nAbout the Role
nHCL Software is seeking a Senior Penetration Tester to perform Continuous Threat Exposure
nManagement (CTEM) and offensive security testing across our products and infrastructure. This
nrole focuses on continuous attack surface discovery, attack path analysis, and risk-based
nprioritization to identify and remediate weaknesses across our application, cloud, and identity attack
nsurface before they can be exploited.
nWe are looking for a tester who produces findings engineering teams can actually act on, and who
ncares about whether issues get fixed rather than only whether they get reported.
nYou will work with Product Security, PSIRT, Security Operations, and engineering teams, and your
nfindings will feed directly into remediation roadmaps and customer-facing assurance.
nKey Responsibilities
n• Plan and execute penetration tests across web and thick-client applications, APIs, cloud
nenvironments, internal networks, and identity infrastructure.
n• Perform deep manual testing that goes well beyond automated tooling, including business logic
nabuse, authorization flaws, and chained exploitation.
n• Develop custom tooling, scripts, and proof-of-concept exploits where off-the-shelf tooling is
ninsufficient.
n• Define scope, rules of engagement, and safety controls, and operate within them rigorously.
nContinuous Threat Exposure Management (CTEM) & Attack Path Analysis
nOffensive Testing & Execution
n• Lead continuous attack surface discovery across cloud, on-prem, identity, and application
nenvironments to identify exposed assets and security misconfigurations.
n• Perform attack path analysis to map potential exploitation chains across AWS, Azure, GCP,
nand hybrid environments,
evaluating identity-based lateral movement and privilege escalation
nrisks.
n• Prioritize discovered exposures based on business impact, asset criticality, threat intelligence,
nand real-world exploitability to drive risk-based remediation.
n• Validate exposure remediation and efficacy of defensive controls through targeted offensive
nverification and continuous exposure validation.
nAdversary Emulation and Purple Teaming
n• Run scenario-based exercises informed by threat intelligence relevant to enterprise software
ncompanies.
n• Work jointly with the SOC to validate detection coverage, improve content, and close visibility
ngaps discovered during testing.
n• Emulate specific adversary tradecraft mapped to MITRE ATT&CK; and document detection
noutcomes alongside exploitation outcomes.
nAI and Emerging Attack Surface
n• Test AI-enabled product features and internal AI integrations for prompt injection, unsafe tool
ninvocation, data leakage, and authorization bypass.
n• Assess agentic workflows and connector integrations for excessive privilege and untrusted
ninput handling.
n• Keep current with emerging offensive techniques and bring them into the testing program
ndeliberately.
nReporting and Remediation
n• Write reports that a developer can act on: reproducible steps, accurate severity, business
nimpact, and concrete fix guidance.
n• Brief engineering and executive audiences with equal clarity,
and defend severity ratings on the
ntechnical merits.
n
n
- Retest fixes and track findings through to closure rather than handing off a PDF.
n
- Feed recurring finding patterns back into secure design standards, training, and pipeline
n
ncontrols.
nRequired Qualifications
n• 6+ years of hands-on penetration testing or offensive security experience, including lead
nresponsibility on engagements.
n• Demonstrated depth in application and API security testing, including manual exploitation of
nauthorization, business logic, and injection classes.
n• Strong cloud penetration testing experience in at least one major provider, including
nidentity-based attack paths.
n• Practical exploit development or custom tooling ability, with fluency in at least one scripting or
nprogramming language.
n• Working command of MITRE ATT&CK; and the ability to map testing activity to real adversary
ntradecraft.
n• Report writing that stands up to engineering scrutiny: precise, reproducible, and free of inflated
nseverity.
n• Sound ethical judgment and disciplined adherence to scope, authorization, and data handling
nrequirements.
nPreferred Qualifications
n• Experience testing commercial software products rather than only internal enterprise
nenvironments.
n• Red team or adversary emulation experience, including evasion and detection-aware
noperating.
n
n
- Purple team experience working directly with defenders to improve detection content.
n
- Experience testing AI and LLM systems, with familiarity with the OWASP LLM Top 10 and
n
nMITRE ATLAS.
n
n
- Published research, CVE credits, tooling contributions, or conference presentations.
n
- Certifications valued but not required: OSCP, OSWE, OSEP, OSCE3, CRTO, GPEN, GXPN, or
n
nGWAPT.
📌 Penetration Tester (Bengaluru)
🏢 HCLSoftware
📍 Bengaluru