14 Sep
|
HCLSoftware
|
Bengaluru
14 Sep
HCLSoftware
Bengaluru
Job Description
Senior Penetration Tester
n
HCL Software | Office of the CISO
n
Location: India - Bangalore / Noida / Remote
n
Type: Full-time
n
About the Role
n
HCL Software is seeking a Senior Penetration Tester to perform Continuous Threat Exposure
n
Management (CTEM) and offensive security testing across our products and infrastructure. This
n
role focuses on continuous attack surface discovery, attack path analysis, and risk-based
n
prioritization to identify and remediate weaknesses across our application, cloud, and identity attack
n
surface before they can be exploited.
n
We are looking for a tester who produces findings engineering teams can actually act on, and who
n
cares about whether issues get fixed rather than only whether they get reported.
n
You will work with Product Security, PSIRT, Security Operations, and engineering teams, and your
n
findings will feed directly into remediation roadmaps and customer-facing assurance.
n
Key Responsibilities
n
• Plan and execute penetration tests across web and thick-client applications, APIs, cloud
n
environments, internal networks, and identity infrastructure.
n
• Perform deep manual testing that goes well beyond automated tooling, including business logic
n
abuse, authorization flaws, and chained exploitation.
n
• Develop custom tooling, scripts, and proof-of-concept exploits where off-the-shelf tooling is
n
insufficient.
n
• Define scope, rules of engagement, and safety controls, and operate within them rigorously.
n
Continuous Threat Exposure Management (CTEM) & Attack Path Analysis
n
Offensive Testing & Execution
n
• Lead continuous attack surface discovery across cloud, on-prem, identity, and application
n
environments to identify exposed assets and security misconfigurations.
n
• Perform attack path analysis to map potential exploitation chains across AWS, Azure, GCP,
n
and hybrid environments, evaluating identity-based lateral movement and privilege escalation
n
risks.
n
• Prioritize discovered exposures based on business impact, asset criticality, threat intelligence,
n
and real-world exploitability to drive risk-based remediation.
n
• Validate exposure remediation and efficacy of defensive controls through targeted offensive
n
verification and continuous exposure validation.
n
Adversary Emulation and Purple Teaming
n
• Run scenario-based exercises informed by threat intelligence relevant to enterprise software
n
companies.
n
• Work jointly with the SOC to validate detection coverage, improve content, and close visibility
n
gaps discovered during testing.
n
• Emulate specific adversary tradecraft mapped to MITRE ATT&CK; and document detection
n
outcomes alongside exploitation outcomes.
n
AI and Emerging Attack Surface
n
• Test AI-enabled product features and internal AI integrations for prompt injection, unsafe tool
n
invocation, data leakage, and authorization bypass.
n
• Assess agentic workflows and connector integrations for excessive privilege and untrusted
n
input handling.
n
• Keep current with emerging offensive techniques and bring them into the testing program
n
deliberately.
n
Reporting and Remediation
n
• Write reports that a developer can act on: reproducible steps, accurate severity, business
n
impact, and concrete fix guidance.
n
• Brief engineering and executive audiences with equal clarity,
and defend severity ratings on the
n
technical merits.
n
n
- Retest fixes and track findings through to closure rather than handing off a PDF.
n
- Feed recurring finding patterns back into secure design standards, training, and pipeline
n
n
controls.
n
Required Qualifications
n
• 6+ years of hands-on penetration testing or offensive security experience, including lead
n
responsibility on engagements.
n
• Demonstrated depth in application and API security testing, including manual exploitation of
n
authorization, business logic, and injection classes.
n
• Solid cloud penetration testing experience in at least one major provider, including
n
identity-based attack paths.
n
• Practical exploit development or custom tooling ability, with fluency in at least one scripting or
n
programming language.
n
• Working command of MITRE ATT&CK; and the ability to map testing activity to real adversary
n
tradecraft.
n
• Report writing that stands up to engineering scrutiny: precise, reproducible, and free of inflated
n
severity.
n
• Sound ethical judgment and disciplined adherence to scope, authorization, and data handling
n
requirements.
n
Preferred Qualifications
n
• Experience testing commercial software products rather than only internal enterprise
n
environments.
n
• Red team or adversary emulation experience, including evasion and detection-aware
n
operating.
n
n
- Purple team experience working directly with defenders to improve detection content.
n
- Experience testing AI and LLM systems, with familiarity with the OWASP LLM Top 10 and
n
n
MITRE ATLAS.
n
n
- Published research, CVE credits, tooling contributions, or conference presentations.
n
- Certifications valued but not required: OSCP, OSWE, OSEP, OSCE3, CRTO, GPEN, GXPN, or
n
n
GWAPT.
📌 Penetration Tester (Bengaluru)
🏢 HCLSoftware
📍 Bengaluru