Senior Technical Lead
India
Job Description
Senior Technical Lead
Chennai, Tamil Nadu

Job Summary

We are looking for a Security Engineer to join our Product Security Engineering
team. This role sits at the intersection of application security, cloud
security, and security tooling — you will work hands-on to secure products,
build internal security solutions, and drive vulnerability management programs
across multiple product lines.

This is not a pure compliance or audit role. You will be expected to think like
an attacker, build like an engineer, and communicate like a consultant.

Key Responsibilities

Secrets Management & Security Tooling
--------------------------------------
- Drive adoption and operationalization of enterprise secrets management
  solutions (e.g., HashiCorp Vault, credential managers)
- Design and implement secure credential distribution workflows for CI/CD
  pipelines (Jenkins, GitLab, container registries)
- Build and maintain internal security tools and automation that serve
  engineering teams at scale
- Evaluate, compare, and recommend security tools based on organizational needs
- Integrate authentication and access control (SSO, RBAC, Okta) into internal
  security platforms

Vulnerability Management & Triage
----------------------------------
- Manage and triage vulnerability findings from SAST tools (Coverity),
  container scanners (Trivy, Wiz), DAST, and AI-driven discovery tools
- Prioritize vulnerabilities based on exploitability, attack surface, CVSS
  analysis, and business context — not just severity scores
- Perform false positive analysis with source code evidence and contextual
  understanding
- Build automation for vulnerability classification, prioritization, and
  ticket management
- Track remediation progress across engineering teams and drive closure of
  high-priority findings

Penetration Testing Support & Security Reviews
-----------------------------------------------
- Coordinate with external penetration testing teams — define scope, share
  relevant findings, review interim and final reports
- Validate reported findings for real-world exploitability and accurate
  severity ratings
- Challenge and negotiate CVSS scores with evidence-based reasoning
- Perform security group reviews, network segmentation analysis, and
  infrastructure security assessments
- Review and assess debug API exposure, access control gaps, and input
  validation weaknesses

Cloud Security
--------------
- Assess and improve security posture of cloud environments (AWS, Azure, GCP)
- Work with cloud security platforms (Wiz, CyCognito, MS Defender) for
  vulnerability discovery and posture management
- Perform subscription ownership mapping, security group analysis, and
  network architecture reviews
- Support cloud migration security readiness assessments

Security Program Contributions
------------------------------
- Contribute to security programs including: Threat Modeling, SAST/DAST
  integration, Secure CI/CD, Infrastructure Security, and XSS Management
- Participate in CVE analysis and impact assessment for zero-day and emerging
  vulnerabilities
- Support PCI DSS, SOC2, and other compliance activities as they intersect
  with engineering
- Create and present security solutions and findings to engineering leadership

Skill Requirements

Must Have:
----------
- 6+ years in application security, product security, or security engineering
- Hands-on experience with at least one secrets management tool (HashiCorp
  Vault, CyberArk, AWS Secrets Manager, or similar)
- Experience with vulnerability management — SAST/DAST/SCA tool findings
  triage, prioritization, and remediation tracking
- Understanding of CI/CD pipelines and how to secure them (Jenkins, GitLab CI,
  GitHub Actions)
- Familiarity with cloud platforms (AWS/Azure/GCP) and cloud-native security
  tools
- Scripting/automation skills (Python, PowerShell, or Bash) for building
  security workflows
- Strong understanding of OWASP Top 10, CWE, CVE, and CVSS scoring
- Ability to read and understand code (Java, Python, Go) for vulnerability
  validation

Good to Have:
-------------
- Experience coordinating or participating in penetration tests
- Familiarity with Coverity, Black Duck, Trivy, or similar SAST/SCA tools
- Experience with Wiz, CyCognito, or similar CSPM platforms
- Understanding of network security concepts (security groups, VPCs,
  segmentation, boundary protection)
- Experience with SSO/IAM integration (Okta, LDAP, SAML)
- Exposure to compliance frameworks (PCI DSS, SOC2, NIST)
- Experience with Jira-based security defect management workflows
- Familiarity with AI/LLM security concepts is a plus

Other Requirements

- You can take a security tool from evaluation to production rollout with
  minimal hand-holding
- You can look at a vulnerability finding and determine its real-world
  exploitability
- You can build automation that saves the team hours of manual triage work
- You can review a pentest report and push back on inaccurate severity with
  technical evidence
- You can explain a security risk to an engineering director in 2 minutes and
  to a developer in 10 minutes with full technical detail
- You take ownership of problems end-to-end, from discovery to remediation
  validation

Information at a Glance

Why HCLTech?

At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.

HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026 totaled $14.8 billion.