IND Staff Associate Penetration Tester

thehartford

Hyderabad

Hybrid

INR 4,000,000 - 7,000,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Collaborative culture
Competitive compensation
Professional development

Job summary

The Hartford in Hyderabad is seeking a Staff Associate Penetration Tester to join a high-performing Security Engineering team. You will lead penetration testing campaigns across infrastructure and applications, assess risks, and collaborate with development teams to drive secure design and remediation.

This role requires 6–9 years of hands-on security experience, strong scripting and reporting skills, and knowledge of OWASP Top 10, MITRE ATT&CK, and red team operations.

Qualifications

  • 6–9 years of experience in penetration testing, ethical hacking, or red team operations.
  • 3+ years in application penetration testing for enterprise web/mobile apps.
  • Strong knowledge of SPA/MPA architectures, APIs, OAuth 2.0, JavaScript, Java and .NET.
  • Comprehensive knowledge of web, API and Mobile Top 10 OWASP lists.
  • Ability to extend testing scope to infrastructure, network, cloud and IoT.
  • Strong understanding of MITRE ATT&CK, ICS ATT&CK, and OWASP frameworks.
  • Proficiency with scripting and automation in multiple languages.
  • Excellent reporting and communication skills.
  • Commitment to legal and ethical standards and behaviors.

Responsibilities

  • Develop and execute penetration testing campaigns targeting various infrastructure devices.
  • Document findings and recommend remediation strategies.
  • Collaborate with application teams to ensure vulnerabilities are addressed effectively.
  • Simulate realistic, multi-phase attack chains including lateral movement and privilege escalation.
  • Create custom exploits, payloads, and evasion techniques against emulated and physical assets.
  • Conduct threat emulation using TTPs based on real-world APTs and adversaries.
  • Define offensive toolkits and infrastructure within the environment.
  • Document post-exercise findings, attack graphs, and defensive recommendations.

Skills

Penetration testing
Red team operations
Application pen testing
Web/mobile security
Scripting & automation
Threat modeling
Communication skills
MITRE ATT&CK
OWASP Top 10

Education

Bachelor's in CS/Info Security

Job description

IND Staff Engineer, Security - GCC042

We're determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals - and to help others accomplish theirs, too. Join our team as we help shape the future.

Job Description: Staff Associate Penetration Tester

Location: Hyderabad, India

Employment Type: Full-Time

Experience Level: 6 -9 Years

Position Overview

We a r e looking for a talented individual to join a high-performing team of Security Engineers responsible for governing, managing and delivering our company's cybersecurity defenses. As a Staff Associate Penetration Tester, you will have an opportunity to shape the direction of our company's penetration testing program by providing thought leadership, professional support, and valued contributions to our growing range of penetration testing and Red Team Operations . This role provides the right person with the opportunity to use their skills and expertise to drive meaningful improvements into the security posture of our organization .

Key Responsibilities
  • Develop and execute penetration testing campaigns targeting various infrastructure devices.
  • Document findings and recommend remediation strategies.
  • Collaborate with application teams to ensure vulnerabilities are addressed effectively.
  • Simulate realistic, multi-phase attack chains including lateral movement, privilege escalation, and multiple specific threat vectors.
  • Create custom exploits, payloads, and evasion techniques against emulated and physical assets.
  • Conduct threat emulation using TTPs based on real-world APTs and adversaries.
  • Define offensive toolkits and infrastructure within the environment.
  • Document post-exercise findings, attack graphs, and defensive recommendations.
Required Skills & Experience
  • 6 -9 years ' experience in penetration testing, ethical hacking and/or red team operations.
  • 3+ years' experience performing application penetration testing to cover a broad range of enterprise web and mobile applications.
  • Strong understanding of web and mobile architectures and technologies including Single Page Applications (SPA), Multi-Page Applications (MPA), APIs, OAuth 2.0, JavaScript, Java and .NET frameworks.
  • Comprehensive knowledge of web and mobile application security vulnerabilities including OWASP Web Application, API and Mobile Top 10 lists.
  • The ability to effectively extend testing scope to include infrastructure, network, cloud and IoT services.
  • Strong understanding of the MITRE ATT&CK andICS ATT&CK, and OWASP frameworks
  • Comfort using offensive security tools
  • Proficiency with scripting and automation in multiple languages
  • Ability to document complex attacks with clear objectives and results for both technical and non-technical audiences
  • Strong reporting and communication skills
  • Strong commitment to legal and ethical standards and behaviors
  • Bachelor's degree from an accredited college or university in computer science, information security, or related field
Nice to Have Skills
  • Certifications like OSCP, OSEP, GPEN, GXPN, or GRPT
  • Experience simulating APT behavior and running attack plans
  • Familiarity with threat intelligence integration
What We Offer
  • Collaborative and innovative work environment.
  • Competitive compensation and comprehensive benefits.
  • Continuous learning and professional development opportunities.

About Us | Our Culture | What It's Like to Work Here

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IND Staff Associate Penetration Tester
IND Staff Associate Penetration Tester

The Hartford • Hyderabad

On-site
INR 2,000,000 - 4,200,000
Penetration Tester
Penetration Tester

VikingCloud • India

On-site
INR 700,000 - 900,000
Senior Penetration Tester
Senior Penetration Tester

NTT DATA BUSINESS SOLUTIONS • Hyderabad

Hybrid
INR 2,500,000 - 4,000,000
Hybrid Working
SISA Information Security - Network Security Engineer
SISA Information Security - Network Security Engineer

SISA • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Hiring For Penetration Tester - Mumbai
Hiring For Penetration Tester - Mumbai

Saint Gobain • Mumbai, Navi Mumbai

On-site
INR 4,000,000 - 8,000,000
Red Team Specialist – I
Red Team Specialist – I

TalaKunchi Networks Pvt Ltd • Mumbai

On-site
INR 800,000 - 1,200,000
Opportunity to work on cutting-edge projects
Collaborative environment with continuous learning
Exposure to advanced security engagements
Penetration Tester
Penetration Tester

NTT DATA BUSINESS SOLUTIONS • Hyderabad

Hybrid
INR 1,200,000 - 2,200,000
Hybrid Working
Application Penetration Tester
Application Penetration Tester

Cortex Consultants LLC • Chennai District

On-site
INR 500,000 - 700,000
Senior Penetration Testing Specialist
Senior Penetration Testing Specialist

ETT CareerMove • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Senior Penetration Tester (12-Month Contract)
Senior Penetration Tester (12-Month Contract)

Sectigo • Chennai District

Hybrid
INR 1,200,000 - 1,800,000