Penetration Tester
Build, Review & Tailor Your Resume with AI (Create an ATS-friendly resume, improve it, and tailor it for this job instantly.)
Senior Penetration Tester
HCL Software | Office of the CISO
Location: India - Bangalore / Noida / Remote
Type: Full-time
About the Role
HCL Software is seeking a Senior Penetration Tester to perform Continuous Threat Exposure
Management (CTEM) and offensive security testing across our products and infrastructure. This
role focuses on continuous attack surface discovery, attack path analysis, and risk-based
prioritization to identify and remediate weaknesses across our application, cloud, and identity attack
surface before they can be exploited.
We are looking for a tester who produces findings engineering teams can actually act on, and who
cares about whether issues get fixed rather than only whether they get reported.
You will work with Product Security, PSIRT, Security Operations, and engineering teams, and your
findings will feed directly into remediation roadmaps and customer-facing assurance.
Key Responsibilities
• Plan and execute penetration tests across web and thick-client applications, APIs, cloud
environments, internal networks, and identity infrastructure.
• Perform deep manual testing that goes well beyond automated tooling, including business logic
abuse, authorization flaws, and chained exploitation.
• Develop custom tooling, scripts, and proof-of-concept exploits where off-the-shelf tooling is
insufficient.
• Define scope, rules of engagement, and safety controls, and operate within them rigorously.
Continuous Threat Exposure Management (CTEM) & Attack Path Analysis
Offensive Testing & Execution
• Lead continuous attack surface discovery across cloud, on-prem, identity, and application
environments to identify exposed assets and security misconfigurations.
• Perform attack path analysis to map potential exploitation chains across AWS, Azure, GCP,
and hybrid environments, evaluating identity-based lateral movement and privilege escalation
risks.
• Prioritize discovered exposures based on business impact, asset criticality, threat intelligence,
and real-world exploitability to drive risk-based remediation.
• Validate exposure remediation and efficacy of defensive controls through targeted offensive
verification and continuous exposure validation.
Adversary Emulation and Purple Teaming
• Run scenario-based exercises informed by threat intelligence relevant to enterprise software
companies.
• Work jointly with the SOC to validate detection coverage, improve content, and close visibility
gaps discovered during testing.
• Emulate specific adversary tradecraft mapped to MITRE ATT&CK and document detection
outcomes alongside exploitation outcomes.
AI and Emerging Attack Surface
• Test AI-enabled product features and internal AI integrations for prompt injection, unsafe tool
invocation, data leakage, and authorization bypass.
• Assess agentic workflows and connector integrations for excessive privilege and untrusted
input handling.
• Keep current with emerging offensive techniques and bring them into the testing program
deliberately.
Reporting and Remediation
• Write reports that a developer can act on: reproducible steps, accurate severity, business
impact, and concrete fix guidance.
• Brief engineering and executive audiences with equal clarity, and defend severity ratings on the
technical merits.
• Retest fixes and track findings through to closure rather than handing off a PDF.
• Feed recurring finding patterns back into secure design standards, training, and pipeline
controls.
Required Qualifications
• 6+ years of hands-on penetration testing or offensive security experience, including lead
responsibility on engagements.
• Demonstrated depth in application and API security testing, including manual exploitation of
authorization, business logic, and injection classes.
• Strong cloud penetration testing experience in at least one major provider, including
identity-based attack paths.
• Practical exploit development or custom tooling ability, with fluency in at least one scripting or
programming language.
• Working command of MITRE ATT&CK and the ability to map testing activity to real adversary
tradecraft.
• Report writing that stands up to engineering scrutiny: precise, reproducible, and free of inflated
severity.
• Sound ethical judgment and disciplined adherence to scope, authorization, and data handling
requirements.
Preferred Qualifications
• Experience testing commercial software products rather than only internal enterprise
environments.
• Red team or adversary emulation experience, including evasion and detection-aware
operating.
• Purple team experience working directly with defenders to improve detection content.
• Experience testing AI and LLM systems, with familiarity with the OWASP LLM Top 10 and
MITRE ATLAS.
• Published research, CVE credits, tooling contributions, or conference presentations.
• Certifications valued but not required: OSCP, OSWE, OSEP, OSCE3, CRTO, GPEN, GXPN, or
GWAPT.
Build Your Resume for Free in Minutes
Create ATS-friendly resumes with modern templates and AI-powered suggestions.
Professional Summary
Experience
Get Your Resume
Reviewed for Free
Discover missing skills, ATS issues, and get personalized suggestions to improve your chances.
Tailor Your Resume for This Job
Match your resume to this job's requirements in one click.