16 Sep
|
HCLSoftware
|
Bengaluru
16 Sep
HCLSoftware
Bengaluru
Senior Penetration Tester /n HCL Software | Office of the CISO /n Location: India - Bangalore / Noida / Remote /n Type: Full time /n About the Role /n HCL Software is seeking a Senior Penetration Tester to perform Continuous Threat Exposure /n Management (CTEM) and offensive security testing across our products and infrastructure. This /n role focuses on continuous attack surface discovery, attack path analysis, and risk-based /n prioritization to identify and remediate weaknesses across our application, cloud, and identity attack /n surface before they can be exploited. /n We are looking for a tester who produces findings engineering teams can actually act on, and who /n cares about whether issues get fixed rather than only whether they get reported. /n You will work with Product Security, PSIRT, Security Operations, and engineering teams, and your /n findings will feed directly into remediation roadmaps and customer-facing assurance. /n Key Responsibilities /n • Plan and execute penetration tests across web and thick-client applications, APIs, cloud /n environments, internal networks, and identity infrastructure. /n • Perform deep manual testing that goes well beyond automated tooling, including business logic /n abuse, authorization flaws, and chained exploitation. /n • Develop custom tooling, scripts, and proof-of-concept exploits where off-the-shelf tooling is /n insufficient. /n • Define scope, rules of engagement, and safety controls, and operate within them rigorously. /n Continuous Threat Exposure Management (CTEM) & Attack Path Analysis /n Offensive Testing & Execution /n • Lead continuous attack surface discovery across cloud, on-prem, identity, and application /n environments to identify exposed assets and security misconfigurations. /n • Perform attack path analysis to map potential exploitation chains across AWS, Azure, GCP, /n and hybrid environments,
evaluating identity-based lateral movement and privilege escalation /n risks. /n • Prioritize discovered exposures based on business impact, asset criticality, threat intelligence, /n and real-world exploitability to drive risk-based remediation. /n • Validate exposure remediation and efficacy of defensive controls through targeted offensive /n verification and continuous exposure validation. /n Adversary Emulation and Purple Teaming /n • Run scenario-based exercises informed by threat intelligence relevant to enterprise software /n companies. /n • Work jointly with the SOC to validate detection coverage, improve content, and close visibility /n gaps discovered during testing. /n • Emulate specific adversary tradecraft mapped to MITRE ATT&CK; and document detection /n outcomes alongside exploitation outcomes. /n AI and Emerging Attack Surface /n • Test AI-enabled product features and internal AI integrations for prompt injection, unsafe tool /n invocation, data leakage, and authorization bypass. /n • Assess agentic workflows and connector integrations for excessive privilege and untrusted /n input handling. /n • Keep current with emerging offensive techniques and bring them into the testing program /n deliberately. /n Reporting and Remediation /n • Write reports that a developer can act on: reproducible steps, accurate severity, business /n impact, and concrete fix guidance. /n • Brief engineering and executive audiences with equal clarity,
and defend severity ratings on the /n technical merits. /n /n
- Retest fixes and track findings through to closure rather than handing off a PDF.
/n
- Feed recurring finding patterns back into secure design standards, training, and pipeline
/n /n controls. /n Required Qualifications /n • 6+ years of hands-on penetration testing or offensive security experience, including lead /n responsibility on engagements. /n • Demonstrated depth in application and API security testing, including manual exploitation of /n authorization, business logic, and injection classes. /n • Strong cloud penetration testing experience in at least one major provider, including /n identity-based attack paths. /n • Practical exploit development or custom tooling ability, with fluency in at least one scripting or /n programming language. /n • Working command of MITRE ATT&CK; and the ability to map testing activity to real adversary /n tradecraft. /n • Report writing that stands up to engineering scrutiny: precise, reproducible, and free of inflated /n severity. /n • Sound ethical judgment and disciplined adherence to scope, authorization, and data handling /n requirements. /n Preferred Qualifications /n • Experience testing commercial software products rather than only internal enterprise /n environments. /n • Red team or adversary emulation experience, including evasion and detection-aware /n operating. /n /n
- Purple team experience working directly with defenders to improve detection content.
/n
- Experience testing AI and LLM systems, with familiarity with the OWASP LLM Top 10 and
/n /n MITRE ATLAS. /n /n
- Published research, CVE credits, tooling contributions, or conference presentations.
/n
- Certifications valued but not required: OSCP, OSWE, OSEP, OSCE3, CRTO, GPEN, GXPN, or
/n /n GWAPT.
📌 Penetration Tester (Bengaluru)
🏢 HCLSoftware
📍 Bengaluru