Penetration Testing Cyber security Engineer

HCLTech

Hyderabad, Chennai District

On-site

INR 1,800,000 - 3,000,000

Full time

9 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

HCLTech in India is seeking an experienced IT & Information Security professional to join our security-focused team. You will drive application security integration across CI/CD, implement SSDLC, and automate security tests (SAST/DAST/IAST) while managing vulnerabilities in web, mobile, and cloud-native apps.

You will train developers, collaborate with engineering and operations, and apply OWASP/NIST/CIS controls to secure microservices and cloud deployments.

Qualifications

  • 3+ years of experience in DevSecOps, application security, or software security roles.
  • Strong knowledge of application security principles, including secure coding practices, threat modeling, secure architecture, and vulnerability management.
  • Experience with security tools such as SAST, DAST, SCA, container security, and vulnerability management platforms.
  • Proficient in DevOps tools: Jenkins, GitLab CI, Docker, Kubernetes.
  • Familiarity with security frameworks and standards: OWASP Top 10, NIST, CIS benchmarks.
  • Strong scripting skills in Python, Bash, PowerShell, or Go.
  • Experience with cloud platforms such as AWS, Azure, or GCP and understanding of cloud security.
  • Hands-on experience with containerization (Docker, Kubernetes) and securing microservices.
  • Excellent problem-solving and collaborative skills across cross-functional teams.
  • Strong communication skills to explain security concepts to non-technical stakeholders.

Responsibilities

  • Application Security Integration: Automate security scans and policy enforcement in CI/CD pipelines.
  • SSDLC: Ensure secure coding standards are followed across development, staging, and production environments.
  • Security Automation: Develop automated security tests (SAST/DAST/IAST) and remediation processes.
  • Application Security Assessment: Assess security of web, thick, and mobile apps (Android & IOS).
  • Collaboration & Training: Liaise between development, security, and operations; conduct developer security trainings.
  • Excellent communication and collaboration with stakeholders.

Skills

Penetration Testing
VAPT
OWASP
Application Security Testing
Vulnerability Assessment
Network Penetration Testing

Education

Bachelor's degree in Computer Science, Cybersecurity, or related field
Any Graduate

Tools

SAST
DAST
SCA
Container security
Jenkins
GitLab CI
Docker
Kubernetes
AWS
Azure
GCP

Job description

Job description
Role & responsibilities:-
  • Application Security Integration: Implement and manage security tools and controls within the CI/CD pipeline to automate security scans, vulnerability management, and policy enforcement for applications in development, staging, and production environments.
  • Secure Software Development Lifecycle (SSDLC): Collaborate with software engineers to ensure code is secure by default and follows secure coding standards.
  • Security Automation: Develop and maintain automated security tests for applications, such as static application security testing (SAST), dynamic application security testing (DAST), and interactive application security testing (IAST), as well as vulnerability management and remediation processes.
  • Application Security Assessment: perform security assessments on web, thick and mobile applications (Both Android & IOS).
  • Collaboration & Training: Act as a liaison between development, security, and operations teams to ensure security practices are well understood and integrated into the existing workflows. Conduct security training sessions for developers to increase awareness of secure coding practices.
  • Excellent communication and collaboration skills.
Preferred candidate profile:-
  • Experience with Cloud security, Container security and Red-Teaming practices is desirable.
  • Experience in scripting and automation (e.g., Python, PowerShell).
Qualifications:
  • Bachelors degree in Computer Science, Cybersecurity, or related field (or equivalent work experience).
  • 3+ years of experience in DevSecOps, application security, or software security roles.
  • Strong knowledge of application security principles, including secure coding practices, threat modeling, secure architecture, and vulnerability management.
  • Experience with security tools such as static code analysis (SAST), dynamic analysis (DAST), software composition analysis (SCA), container security, and vulnerability management platforms.
  • Proficient in DevOps tools: Jenkins, GitLab CI, Docker, Kubernetes etc.
  • Familiarity with security frameworks and standards, such as OWASP Top 10, NIST, and CIS benchmarks.
  • Strong scripting skills in languages like Python, Bash, PowerShell, or Go.
  • Experience with cloud platforms such as AWS, Azure, or GCP and understanding of cloud security principles.
  • Hands-on experience with containerization (Docker, Kubernetes) and securing microservices.
  • Excellent problem-solving skills and the ability to work collaboratively in cross-functional teams.
  • Strong communication skills, including the ability to explain technical security concepts to non-technical stakeholders.
Certification:
Mandatory:
  • Certifications such as Certified Red Team Operator (CRT), Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), or GIAC Penetration Tester (GPEN) are highly desirable.
Good to have:
  • Certifications such as CREST Practitioner Security Analyst (CPSA), Certified Expert Penetration Tester (CEPT) etc.

Role: IT & Information Security - OtherIndustry Type: IT Services & ConsultingDepartment: IT & Information SecurityEmployment Type: Full Time, PermanentRole Category: IT & Information Security - OtherEducationUG: Any GraduateKey SkillsSkills highlighted with ‘ are preferred keyskillsPenetration TestingVaptOWASPApplication Security TestingVulnerability AssessmentNetwork Penetration Testing


Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Specialist
Cyber Security Specialist

Muthoot FinCorp (MFL) • Thiruvananthapuram

On-site
INR 900,000 - 1,300,000
Penetration Tester ME
Penetration Tester ME

BreachLock, Inc. • Dadri

On-site
INR 900,000 - 1,500,000
Private Health Insurance
Senior Penetration Tester
Senior Penetration Tester

Jobtailor • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Cybersecurity Engineer - VAPT
Cybersecurity Engineer - VAPT

V2 Solutions • Ernakulam

On-site
INR 1,200,000 - 1,800,000
Senior Security Testing Engineer
Senior Security Testing Engineer

Allied Boston Consultants India • Dadri

On-site
INR 900,000 - 1,300,000
Senior Penetration Tester
Senior Penetration Tester

NTT DATA BUSINESS SOLUTIONS • Hyderabad

Hybrid
INR 2,500,000 - 4,000,000
Hybrid Working
Penetration Tester
Penetration Tester

VikingCloud • India

On-site
INR 700,000 - 900,000
Penetration Testing Manager
Penetration Testing Manager

Jobtailor • Thiruvananthapuram

On-site
INR 1,400,000 - 2,200,000
Senior Penetration Tester
Senior Penetration Tester

Tekskills • Bengaluru

On-site
INR 350,000 - 650,000
Senior Penetration Testing Consultant
Senior Penetration Testing Consultant

EY • Bengaluru

On-site
INR 1,800,000 - 3,200,000