The Hartford Financial Services Group, Inc. Logo

The Hartford Financial Services Group, Inc.

Sr. Web Application Penetration Tester

Posted 12 Days Ago
Be an Early Applicant
2 Locations
127K-191K Annually
Senior level
2 Locations
127K-191K Annually
Senior level
As a Senior Web Application Penetration Tester, you'll lead application penetration testing, document findings, and collaborate to address vulnerabilities across enterprise applications.
The summary above was generated by AI

Senior Security Engineer - IS07FE

We’re determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals – and to help others accomplish theirs, too. Join our team as we help shape the future.   

         

The Hartford’s Information Protection (THIP) organization is looking for a talented individual to join a high-performing team of Application Security Engineers responsible for governing, managing and delivering our company’s application cybersecurity defenses.  As a Senior Web Application Penetration Tester, you will have an opportunity to shape the direction of our company’s application penetration testing program by providing thought leadership, professional support, and valued contributions to our growing range of penetration testing activities.  This role provides the right person with the opportunity to use their skills and expertise to drive meaningful improvements into the security posture of all application portfolios across our company.

RESPONSIBILITIES:

  • Plan and perform penetration tests on applications spanning all enterprise lines of business and portfolios

  • Document findings and recommend remediation strategies

  • Collaborate with application teams to ensure vulnerabilities are addressed effectively

  • Develop exploits to demonstrate the potential impact of a successful attack

  • Participate in broader attack simulation activities assessing systems including infrastructure, network, cloud, and IoT services

  • Stay up to date with the latest technologies, testing methodologies, tools, security trends and threats

This role will have a Hybrid work schedule, with the expectation of working in an office location (Hartford, CT or Charlotte, NC) 3 days a week (Tuesday through Thursday).

QUALIFICATIONS:

Candidates will be evaluated based on their ability to perform the duties listed above while demonstrating the skills and competencies necessary to be highly effective in the role.  These skills and competencies include:

  • 5+ years’ experience assessing vulnerabilities across a large enterprise application portfolio

  • 3+ years’ experience performing application penetration testing to cover a broad range of enterprise web and mobile applications

  • Strong understanding of web and mobile architectures and technologies including Single Page Applications (SPA), Multi-Page Applications (MPA), APIs, OAuth 2.0, JavaScript, Java and .NET frameworks

  • Comprehensive knowledge of web and mobile application security vulnerabilities including OWASP Web Application, API and Mobile Top 10 lists

  • Ability to effectively extend testing scope to include infrastructure, network, cloud and IoT services

  • Strong reporting and communication skills

  • Strong commitment to legal and ethical standards and behaviors

  • Bachelor's degree from an accredited college or university in computer science, information security, or related field

  • Certifications such as Certified Information Systems Security Professional (CISSP), Offensive Security Certified Professional (OSCP) or Offensive Security Web Expert (OSWE) are highly desirable and preferred

Candidate must be authorized to work in the US without company sponsorship. The company will not support the STEM OPT I-983 Training Plan endorsement for this position.

Compensation

The listed annualized base pay range is primarily based on analysis of similar positions in the external market. Actual base pay could vary and may be above or below the listed range based on factors including but not limited to performance, proficiency and demonstration of competencies required for the role. The base pay is just one component of The Hartford’s total compensation package for employees. Other rewards may include short-term or annual bonuses, long-term incentives, and on-the-spot recognition. The annualized base pay range for this role is:

$127,200 - $190,800

Equal Opportunity Employer/Females/Minorities/Veterans/Disability/Sexual Orientation/Gender Identity or Expression/Religion/Age

About Us | Culture & Employee Insights | Diversity, Equity and Inclusion | Benefits

Top Skills

.Net
APIs
Java
JavaScript
Oauth 2.0

Similar Jobs

85K-200K Annually
Mid level
Consulting
Seeking a Penetration Tester focusing on web, API, and mobile app security to perform assessments, communicate risks, and provide remediation guidance.
Top Skills: ApktoolBurp Suite ProFridaMobsfObjectionOwasp ZapPostman
14 Days Ago
Remote
Hybrid
38 Locations
100K-150K Annually
Mid level
100K-150K Annually
Mid level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Analyze malware and detections, improve detection capabilities, and respond to internal inquiries regarding threat detection in cybersecurity. Requires understanding of malware functionality and experience with reverse engineering.
Top Skills: AssemblyCC++JavaLinuxmacOSPythonWindows Os
25 Days Ago
Hybrid
13 Locations
35K-65K Annually
Junior
35K-65K Annually
Junior
Cloud • Insurance • Professional Services • Analytics • Cybersecurity
Responsible for accurate data entry in legal matter referrals, coordinating with legal services, and validating financial information, while supporting litigation management processes.
Top Skills: Microsoft Office Suite

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account