Product Security Engineer

HCLTech

Jigani

Hybrid

INR 3,000,000 - 5,500,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Remote-friendly work environment
Competitive salary and growth

Job summary

HCL Software seeks skilled security professionals to lead penetration testing of AI-enabled applications and products across on‑premises, cloud, and containerized environments. You will identify complex vulnerabilities, design attack scenarios, and collaborate with AI/ML teams to embed secure development practices.

The role emphasizes testing for LLM abuses, data leakage, model extraction, and adversarial inputs while contributing to a robust security posture across HCL Software products.

Qualifications

  • Expert knowledge of OWASP Top 10 vulnerabilities, testing procedures, and remediation recommendations.
  • Strong experience with SAST, DAST, and IAST tools.
  • Advanced experience with BurpSuite a must.

Responsibilities

  • Perform penetration testing and security assessments of products and other applications to identify complex vulnerabilities and drive remediation.
  • Drive development of new vulnerability discovery and exploitation techniques.
  • Collaborate with stakeholders to create remediation strategies that will help improve security posture.
  • Write and deliver security assessment reports.
  • Oversee remediation of all findings and recommendations.

Skills

Application Security
Penetration Testing
Web Security Testing
Threat Modeling
AI/ML Security
Burp Suite
OWASP Top 10
Nmap

Education

Bachelor's in CS/Related

Tools

Burp Suite
OWASP ZAP
Metasploit
Nmap

Job description

Position Summary

HCL Software develops, markets, sells, and supports enterprise software solutions across multiple pillars including Customer Experience, Digital Solutions, Secure DevOps, and Security & Automation. As our products increasingly incorporate Artificial Intelligence and Machine Learning capabilities, ensuring the security of AI-driven systems has become a critical priority.

The Lead Product Engineer Security will be responsible for identifying and exploiting security weaknesses in AI/ML systems, applications, and models embedded within HCL Software products. This role focuses on evaluating the resilience of AI systems against emerging threats such as prompt injection, data poisoning, model manipulation, adversarial attacks, and LLM abuse scenarios.

The individual will work closely with AI/ML engineering teams, DevOps, and Product Development groups to design and execute advanced security testing strategies for AI-enabled applications. The role will also support the secure adoption of different types of AI technologies across the organization while ensuring adherence to secure development practices.

This position requires strong expertise in application security and AI system behaviour, along with the ability to simulate real-world attacks against AI-driven platforms.

What You Will Be Doing
  • Perform penetration testing of AI-powered applications and systems, including LLM-based applications, AI APIs, and ML pipelines
    Identify vulnerabilities such as prompt injection, data leakage, insecure model outputs, model extraction, and adversarial inputs
    Conduct red‑teaming exercises for generative AI systems to simulate abuse scenarios
    Evaluate AI systems for model integrity, training data risks, and inference security weaknesses
    Collaborate with AI/ML engineering teams to ensure security best practices are embedded in model development and deployment
    Develop attack methodologies and frameworks for AI security testing
    Assess security risks associated with AI model hosting platforms, APIs, and inference services
    Provide detailed vulnerability reports and remediation guidance to engineering teams
    Integrate AI security testing into the Secure SDLC process
    Research emerging threats in AI/ML security and adversarial machine learning
    Work with internal and external teams to enhance AI security posture across HCL Software products
Required Qualifications / Experience
Skills
  • Security requirements.
  • Threatmodeling.
  • SCA, SAST, DAST, VAPT & Exploitations
  • Market-leading tools: AppScan, Black Duck, Fortify, etc.
  • Implementation and usage of AI in the VAPT.
Must-Have Technical Skills
  • 58+ years of experience in Application Security, Penetration Testing, or Offensive Security
    Strong knowledge of web application and API security testing
    Experience with security testing tools such as **Burp Suite, OWASP ZAP, Metasploit, and Nmap**
    Understanding of AI/ML architectures including LLMs, ML pipelines, and model deployment environments
Must-Have Functional Skills
  • Ability to simulate attacks against AI models and AI-driven applications
    Strong knowledge of OWASP Top 10 and AI-specific security risks
    Experience working with development teams to remediate security vulnerabilities
    Strong analytical and problem-solving skills
Nice-to-Have Skills
  • Knowledge of LLM security risks (prompt injection, jailbreak attacks, hallucination exploitation)
    Familiarity with AI security frameworks such as OWASP Top 10 for LLM Applications
    Experience with Python-based AI/ML environments (TensorFlow, PyTorch, or similar frameworks)
    Understanding of Adversarial Machine Learning concepts
    Experience testing AI APIs or AI-powered SaaS platforms
    Knowledge of cloud platforms such as AWS, Azure, or GCP
Certifications (Preferred)
  • OSCP / OSWE / CEH
    AI or ML security related certifications (if available)
What We Offer
  • Remote-friendly work environment
    Competitive salary and performance incentives
    Strong learning opportunities in AI security and emerging technologies
    Career growth within HCL Software’s global product security organization
Role: Product Security
Job Description

HCL Software is an exciting place to work, with a wide variety of applications developed across multiple global geographic locations.
We are seeking multiple Application Penetration testers for our Product and Infrastructure Security team. The qualified candidate will be responsible for collaborating with product development teams to find
and document security vulnerabilities through approved testing efforts of a wide variety of products. Essential functions include security assessments and penetration tests for mobile, web, and desktop applications that are deployed on-prem, on-cloud, or containerized.
The various types of product suites include commerce and marketing, security, endpoint management, value stream mapping, online meeting clients, workflow productivity, collaboration, and much more. As a
penetration tester of all these products, you will never get bored!

Key Responsibilities

Support the companys commitment to protect the confidentiality, integrity, and availability of systems and data.
Perform penetration testing and security assessments of products and other applications to identify complex vulnerabilities and drive through to remediation.
Drive development of new vulnerability discovery and exploitation techniques.
Collaborate with stakeholders to create remediation strategies that will help improve the overall security posture.
Write and deliver security assessment reports.
Oversee remediation of all findings and recommendations.
Help develop security practices and provide guidance to security teams for implementation.
Additional security tasks as needed.

Skills and Qualifications

Expert knowledge of OWASP Top 10 vulnerabilities, testing procedures, and remediation recommendations.
Strong experience with SAST, DAST, and IAST tools.
Advanced experience with BurpSuite a must.
Experience working with information security frameworks such as SANS and NIST.
Programming experience in one or more of the following languages: Ruby, Python, Perl, C, C#, or Java.
Strong knowledge of penetration test and assessment procedures, as well as expert knowledge of remediation best practices.
Good knowledge of TCP/IP, networking, web applications,databases, mobile, desktop, containerized applications, and cloud applications.
Ability to communicate technically with software engineers and development leads, and effectively translate issues and risks into clear and understandable business language.
Ability to build network and foster an atmosphere of teamwork within the larger security team and across various business units.
Bachelor of Science in Computer Science or related field.
GWAPT or OSCP or CEH certification strongly preferred.
Strong troubleshooting and analytical skills.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

Ecolab Global Services • Bengaluru

On-site
INR 3,500,000 - 6,500,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 3,000,000
Cyber Penetration Tester
Cyber Penetration Tester

Alignity Solutions • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Product Security Engineer (Vulnerability Management)
Product Security Engineer (Vulnerability Management)

JUARA IT SOLUTIONS • Chennai District

On-site
INR 2,500,000 - 4,000,000
Cyber security - Penetration Testing
Cyber security - Penetration Testing

Cloudxtreme • Hyderabad, Bengaluru

Hybrid
INR 1,200,000 - 1,800,000
CyberSecurity
CyberSecurity

Cloudxtreme • Hyderabad, Bengaluru

On-site
INR 170,000 - 210,000
Security Tester
Security Tester

Paramount Computer Systems LLC • Coimbatore District

On-site
INR 900,000 - 1,300,000
Senior Security Specialist
Senior Security Specialist

Lennox • Chennai District

On-site
INR 3,000,000 - 4,200,000
TEST MODULE LEAD - Penetration Testing
TEST MODULE LEAD - Penetration Testing

Happiest Minds Technologies • Bengaluru

On-site
INR 1,674,000 - 2,344,000