Senior Penetration Tester / Offensive Security Specialist (Red Team)Role OverviewHCLTech is seeking an experienced Penetration Testing and Offensive Security Specialist to lead and execute advanced adversarial simulations across enterprise environments.
The role focuses on identifying exploitable weaknesses across network, application, cloud, human, and physical layers, emulating real-world attacker techniques.The ideal candidate will bring hands-on expertise in multi-vector penetration testing, red teaming, exploit development, and adversarial simulation, with the ability to provide actionable remediation insights to strengthen enterprise security posture.Key Responsibilities1. Penetration Testing & Red Team OperationsConduct end-to-end penetration testing engagements, including: Internal network assessmentsExternal perimeter testingWeb application and API security testingCloud and container security testingMobile (iOS) and thick client application assessmentsWireless infrastructure testingExecute advanced attack simulations to emulate real-world adversary tactics2. Exploitation & Vulnerability AnalysisIdentify, validate, and exploit vulnerabilities using techniques such as: SQL InjectionCross-Site Scripting (XSS)Privilege EscalationCredential harvesting and manipulationPerform: Vulnerability chaining and lateral movement simulationsPost-exploitation persistence and privilege escalationProvide risk-rated findings with clear remediation guidance3. Social Engineering & Human Layer TestingDesign and execute social engineering campaigns, including: Phishing and spear-phishingSmishing and pretextingAssess organizational resilience to human-centric attacks4. Red Team Automation & Tool DevelopmentDevelop and maintain: Custom exploitation scripts and toolkitsAutomation workflows for reconnaissance and exploitationLeverage: Python scripting and Linux toolchainsAI/GenAI-assisted tooling for attack simulation and reconnaissance5. Offensive Intelligence & ReconnaissancePerform OSINT-based reconnaissance, including: Target profiling and attack surface discoveryDark web and surface web intelligence gatheringUtilize tools such as: Nmap, WiresharkThreat intelligence platforms (e.g., Recorded Future or equivalents)6. Purple Teaming & Validation SupportCollaborate with defensive teams to: Validate detection and response capabilitiesSimulate attack scenarios and measure control effectivenessSupport: Breach simulationsRansomware scenario testingRequired Skills & ExperienceCore Technical SkillsProven experience in: Multi-vector penetration testing (Network, Web, Cloud, Mobile, Wireless, Physical)Red teaming and adversary emulationExploit execution and vulnerability validationStrong understanding of: MITRE ATT&CK frameworkModern attack techniques and threat actor TTPsTools & TechnologiesHands-on expertise with: Nmap, Wireshark, Burp Suite, Metasploit (or similar toolsets)Experience with: Web application security toolsNetwork and protocol analysis toolsAutomation & ScriptingStrong development experience in: PythonLinux environmentsAbility to build: Custom scripts, payloads, and automation frameworksComplementary Experience (Preferred)Exposure to: Investigations and compromise assessmentsThreat Intelligence and IOC analysisExperience participating in: Red Team vs Blue Team or Purple Team exercisesCertifications (Preferred)Offensive Security Certified Professional (OSCP)Certified Ethical Hacker (CEH)GIAC Security Essentials (GSEC)Other advanced Red Team or exploit development certifications are a plusSoft Skills & AttributesStrong analytical and problem-solving skillsAbility to think like an adversary and simulate realistic attack pathsClear communication skills for delivering executive-ready risk reports
Senior Penetration Tester / Offensive Security Specialist in ca at Unknown Company
This position is listed as full time and onsite.