Subject Matter Expert (Support&Ops)
India
Job Description
Subject Matter Expert (Support&Ops)
Noida, Uttar Pradesh

Job Summary

Job Summary : Job Title: Vulnerability Management & Penetration Testing Specialist (with CSPM) Department: Information Security / Cyber Security Experience Level: Mid–Senior (3–6+ Years) Location: Role Overview We are seeking an experienced Vulnerability Management (VM) & Penetration Testing Specialist to lead end-to-end vulnerability assessments, dynamic application scanning, and penetration testing across on-premises and cloud environments. In this role, you will be responsible for managing enterprise VM tooling, executing Web Application Security (WAS) scans, validating vulnerabilities through manual penetration testing, and securing multi-cloud posture via Cloud Security Posture Management (CSPM).

Key Responsibilities

Job Responsibilities : End-to-End Vulnerability Management: ○ Deploy, configure, and maintain enterprise Vulnerability Management platforms (e.g., Qualys or similar). ○ Manage scan schedules, credentialed scanning, asset discovery, and target grouping across hybrid infrastructure. ○ Triage, prioritize, and track vulnerabilities from identification through to remediation and re-validation. ● Web Application Scanning (WAS): ○ Configure and execute automated dynamic application security scans (DAST/WAS) for web applications and APIs. ○ Analyze scan findings, eliminate false positives, and deliver clear remediation steps to application owners. ● Penetration Testing & Validation: ○ Perform network, infrastructure, and web application penetration testing based on OWASP Top 10, NIST, and PTES standards. ○ Manually validate critical scanner findings via exploit verification and proof-of-concept testing. ○ Deliver comprehensive assessment reports detailing business impact, risk ratings, and actionable remediation guidance. ● Cloud Security Posture Management (CSPM): ○ Monitor and manage CSPM tooling (e.g., Wiz, AWS Security Hub). ○ Identify cloud misconfigurations, IAM risks, compliance drifts, and unmanaged exposure across multi-cloud environments. ○ Collaborate with Cloud and DevOps teams to enforce security guardrails and remediation playbooks.

Skill Requirements

Skill Requirement : Core Technical Expertise: ○ Proven hands-on experience running enterprise VM tools end-to-end (Qualys VMDR). ○ Deep understanding of web application vulnerabilities (SQLi, XSS, SSRF, IDOR, authentication flaws) and automated WAS tools. ○ Solid background in manual penetration testing for web apps, APIs, and network systems (using tools like Burp Suite Professional, Metasploit, Nmap). ○ Practical knowledge of major cloud platforms (AWS/Azure/GCP) and hands-on exposure to CSPM solutions. ○ Strong grasp of vulnerability scoring systems (CVSS v3/v4), CWE, CVE, and compliance benchmarks (CIS, ISO 27001). ● Preferred Certifications: ○ Penetration Testing: OSCP, eWPT / eCPPT, CEH (Practical), GPEN. ○ Vulnerability & Cloud Security: Qualys Certified Specialist, Tenable Certified, AWS Certified Security - Specialty, or CCSP.

Other Requirements

Other Requirement : Soft Skills: ○ Strong communication skills to articulate technical security risks to both technical teams and non-technical stakeholders. ○ Solid analytical and troubleshooting mindset with high attention to detail.
Key Sourcing Information :
Information at a Glance

Why HCLTech?

At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.

HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026 totaled $14.8 billion.