IND Staff Associate Penetration Tester
Hartford Financial
- Location
- India GCC-Puppalaguda Village
- Work model
- On-Site
- Level
- Entry
- Posted
- Sep 1, 2026
Skills
About this role
IND Staff Engineer, Security - GCC042 We’re determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals – and to help others accomplish theirs, too. Join our team as we help shape the future.
Job Description
Staff Associate Penetration Tester Location: Hyderabad, India Employment Type: Full-Time Experience Level: 6 -9 Years Position Overview We a r e looking for a talented individual to join a high-performing team of Security Engineers responsible for governing, managing and delivering our company’s cybersecurity defenses. As a Staff Associate Penetration Tester, you will have an opportunity to shape the direction of our company’s penetration testing program by providing thought leadership, professional support, and valued contributions to our growing range of penetration testing and Red Team Operations . This role provides the right person with the opportunity to use their skills and expertise to drive meaningful improvements into the security posture of our organization .
Key Responsibilities
Develop and execute penetration testing campaigns targeting various infrastructure devices. Document findings and recommend remediation strategies. Collaborate with application teams to ensure vulnerabilities are addressed effectively. Simulate realistic, multi-phase attack chains including lateral movement, privilege escalation, and multiple specific threat vectors. Create custom exploits, payloads, and evasion techniques against emulated and physical assets. Conduct threat emulation using TTPs based on real-world APTs and adversaries. Define offensive toolkits and infrastructure within the environment. Document post-exercise findings, attack graphs, and defensive recommendations. Required Skills & Experience 6 -9 years ’ experience in penetration testing, ethical hacking and/or red team operations. 3+ years’ experience performing application penetration testing to cover a broad range of enterprise web and mobile applications. Strong understanding of web and mobile architectures and technologies including Single Page Applications (SPA), Multi-Page Applications (MPA), APIs, OAuth 2.0, JavaScript, Java and .NET frameworks. Comprehensive knowledge of web and mobile application security vulnerabilities including OWASP Web Application, API and Mobile Top 10 lists. The ability to effectively extend testing scope to include infrastructure, network, cloud and IoT services. Strong understanding of the MITRE ATT&CK and ICS ATT&CK, and OWASP frameworks Comfort using offensive security tools Proficiency with scripting and automation in multiple languages Ability to document complex attacks with clear objectives and results for both technical and non-technical audiences Strong reporting and communication skills Strong commitment to legal and ethical standards and behaviors Bachelor's degree from an accredited college or university in computer science, information security, or related field Nice to Have Skills Certifications like OSCP, OSEP, GPEN, GXPN, or GRPT Experience simulating APT behavior and running attack plans Familiarity with threat intelligence integration What We Offer Collaborative and innovative work environment. Competitive compensation and comprehensive benefits. Continuous learning and professional development opportunities. About Us | Our Culture | What It’s Like to Work Here