H
H

Penetration Tester

HCLSoftware
Bengaluru, KA, IN
Full-timeHybrid6+ yrs
1d ago0 view0 clicked apply

Build, Review & Tailor Your Resume with AI (Create an ATS-friendly resume, improve it, and tailor it for this job instantly.)

Senior Penetration Tester

HCL Software | Office of the CISO

Location: India - Bangalore / Noida / Remote

Type: Full-time

About the Role

HCL Software is seeking a Senior Penetration Tester to perform Continuous Threat Exposure

Management (CTEM) and offensive security testing across our products and infrastructure. This

role focuses on continuous attack surface discovery, attack path analysis, and risk-based

prioritization to identify and remediate weaknesses across our application, cloud, and identity attack

surface before they can be exploited.


We are looking for a tester who produces findings engineering teams can actually act on, and who

cares about whether issues get fixed rather than only whether they get reported.

You will work with Product Security, PSIRT, Security Operations, and engineering teams, and your

findings will feed directly into remediation roadmaps and customer-facing assurance.


Key Responsibilities


• Plan and execute penetration tests across web and thick-client applications, APIs, cloud

environments, internal networks, and identity infrastructure.

• Perform deep manual testing that goes well beyond automated tooling, including business logic

abuse, authorization flaws, and chained exploitation.

• Develop custom tooling, scripts, and proof-of-concept exploits where off-the-shelf tooling is

insufficient.

• Define scope, rules of engagement, and safety controls, and operate within them rigorously.

Continuous Threat Exposure Management (CTEM) & Attack Path Analysis


Offensive Testing & Execution


• Lead continuous attack surface discovery across cloud, on-prem, identity, and application

environments to identify exposed assets and security misconfigurations.

• Perform attack path analysis to map potential exploitation chains across AWS, Azure, GCP,

and hybrid environments, evaluating identity-based lateral movement and privilege escalation

risks.

• Prioritize discovered exposures based on business impact, asset criticality, threat intelligence,

and real-world exploitability to drive risk-based remediation.

• Validate exposure remediation and efficacy of defensive controls through targeted offensive

verification and continuous exposure validation.


Adversary Emulation and Purple Teaming


• Run scenario-based exercises informed by threat intelligence relevant to enterprise software

companies.

• Work jointly with the SOC to validate detection coverage, improve content, and close visibility

gaps discovered during testing.

• Emulate specific adversary tradecraft mapped to MITRE ATT&CK and document detection

outcomes alongside exploitation outcomes.


AI and Emerging Attack Surface


• Test AI-enabled product features and internal AI integrations for prompt injection, unsafe tool

invocation, data leakage, and authorization bypass.

• Assess agentic workflows and connector integrations for excessive privilege and untrusted

input handling.

• Keep current with emerging offensive techniques and bring them into the testing program

deliberately.


Reporting and Remediation


• Write reports that a developer can act on: reproducible steps, accurate severity, business

impact, and concrete fix guidance.

• Brief engineering and executive audiences with equal clarity, and defend severity ratings on the

technical merits.

• Retest fixes and track findings through to closure rather than handing off a PDF.

• Feed recurring finding patterns back into secure design standards, training, and pipeline

controls.


Required Qualifications


• 6+ years of hands-on penetration testing or offensive security experience, including lead

responsibility on engagements.

• Demonstrated depth in application and API security testing, including manual exploitation of

authorization, business logic, and injection classes.

• Strong cloud penetration testing experience in at least one major provider, including

identity-based attack paths.

• Practical exploit development or custom tooling ability, with fluency in at least one scripting or

programming language.

• Working command of MITRE ATT&CK and the ability to map testing activity to real adversary

tradecraft.

• Report writing that stands up to engineering scrutiny: precise, reproducible, and free of inflated

severity.

• Sound ethical judgment and disciplined adherence to scope, authorization, and data handling

requirements.


Preferred Qualifications


• Experience testing commercial software products rather than only internal enterprise

environments.

• Red team or adversary emulation experience, including evasion and detection-aware

operating.

• Purple team experience working directly with defenders to improve detection content.

• Experience testing AI and LLM systems, with familiarity with the OWASP LLM Top 10 and

MITRE ATLAS.

• Published research, CVE credits, tooling contributions, or conference presentations.

• Certifications valued but not required: OSCP, OSWE, OSEP, OSCE3, CRTO, GPEN, GXPN, or

GWAPT.

RESUME BUILDER

Build Your Resume for Free in Minutes

Create ATS-friendly resumes with modern templates and AI-powered suggestions.

ATS Friendly
Rohan SharmaMarketing Manager

Professional Summary

Experience

ATS Friendly
RESUME REVIEW

Get Your Resume
Reviewed for Free

Discover missing skills, ATS issues, and get personalized suggestions to improve your chances.

Secure
92%
ATS Score
Review SummaryGood keywordsWell-structuredAdd metrics
Improve your score with the suggestions.
RESUME TAILORING

Tailor Your Resume for This Job

Match your resume to this job's requirements in one click.

96%Match