The Hartford logo

IND Staff Associate Penetration Tester 

The Hartford Hyderabad, Telangana, India

onsitefull-time
Posted Sep 1, 2026Apply by Oct 1, 2026

**Role & seniority: ** Staff Associate Penetration Tester (Security Engineer) — 6–9 years experience

**Location & work type: ** Hyderabad, IndiaFull-Time

**Stack/tools (from posting): **

  • Offensive/security tools (unspecified)

  • Scripting/automation: multiple languages (unspecified)

  • Web/mobile/appsec technologies: JavaScript, Java, .NET, SPAs/MPAs, APIs, OAuth 2.0

  • Security frameworks/knowledge: OWASP Web/API/Mobile Top 10, MITRE ATT&CK, ICS ATT&CK

**Top 3 responsibilities: **

  1. Plan and execute penetration testing campaigns across infrastructure devices (including multi-phase attack chains: lateral movement, privilege escalation).

  2. Create/extend offensive methods (custom exploits, payloads, evasion) and run threat emulation using real-world TTPs.

  3. Report and drive remediation: document findings, attack graphs, and recommend fixes; collaborate with application teams.

**Must-have skills: **

  • 6–9 years in penetration testing/ethical hacking/red teaming

  • 3+ years application penetration testing (enterprise web + mobile)

  • Strong grasp of web/mobile architectures and security vulnerabilities (OWASP Top 10s)

  • Ability to extend scope to infrastructure/network/cloud/IoT

  • Strong MITRE ATT&CK / ICS ATT&CK and OWASP knowledge

  • Competence with offensive toolsets, plus scripting/automation

  • Clear **documentatio

Full Description

IND Staff Engineer, Security - GCC042

We’re determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals – and to help others accomplish theirs, too. Join our team as we help shape the future.

Job Description: Staff Associate Penetration Tester

Location: Hyderabad, India

Employment Type: Full-Time

Experience Level: 6 -9 Years

Position Overview

We are looking for a talented individual to join a high-performing team of Security Engineers responsible for governing, managing and delivering our company’s cybersecurity defenses. As a Staff Associate Penetration Tester, you will have an opportunity to shape the direction of our company’s penetration testing program by providing thought leadership, professional support, and valued contributions to our growing range of penetration testing and Red Team Operations. This role provides the right person with the opportunity to use their skills and expertise to drive meaningful improvements into the security posture of our organization.

Key Responsibilities

Develop and execute penetration testing campaigns targeting various infrastructure devices. Document findings and recommend remediation strategies. Collaborate with application teams to ensure vulnerabilities are addressed effectively. Simulate realistic, multi-phase attack chains including lateral movement, privilege escalation, and multiple specific threat vectors. Create custom exploits, payloads, and evasion techniques against emulated and physical assets. Conduct threat emulation using TTPs based on real-world APTs and adversaries. Define offensive toolkits and infrastructure within the environment. Document post-exercise findings, attack graphs, and defensive recommendations.

Required Skills & Experience

6-9 years’ experience in penetration testing, ethical hacking and/or red team operations. 3+ years’ experience performing application penetration testing to cover a broad range of enterprise web and mobile applications. Strong understanding of web and mobile architectures and technologies including Single Page Applications (SPA), Multi-Page Applications (MPA), APIs, OAuth 2.0, JavaScript, Java and .NET frameworks. Comprehensive knowledge of web and mobile application security vulnerabilities including OWASP Web Application, API and Mobile Top 10 lists. The ability to effectively extend testing scope to include infrastructure, network, cloud and IoT services. Strong understanding of the MITRE ATT&CK and ICS ATT&CK, and OWASP frameworks Comfort using offensive security tools Proficiency with scripting and automation in multiple languages Ability to document complex attacks with clear objectives and results for both technical and non-technical audiences Strong reporting and communication skills Strong commitment to legal and ethical standards and behaviors Bachelor's degree from an accredited college or university in computer science, information security, or related field

Nice To Have Skills

Certifications like OSCP, OSEP, GPEN, GXPN, or GRPT Experience simulating APT behavior and running attack plans Familiarity with threat intelligence integration

What We Offer

Collaborative and innovative work environment. Competitive compensation and comprehensive benefits. Continuous learning and professional development opportunities.

Penetration TestingEthical HackingRed Team OperationsApplication SecurityWeb Application TestingMobile Application TestingInfrastructure SecurityCloud SecurityIoT SecurityScriptingAutomationThreat EmulationVulnerability AssessmentMITRE ATT&CKOWASPReportingmulti-location

Cookies & analytics consent

We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.

Read how we use data in our Privacy Policy and Terms of Service.