IND Lead Engineer, Security - GCC041
We’re determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals – and to help others accomplish theirs, too. Join our team as we help shape the future.
Job: Senior Red Team Engineer, Endpoint TTPs & Malware Development
DESCRIPTION:
We're hiring a senior offensive security engineer to join our growing Adversary Simulation (AdSim) team. We are looking for our first endpoint and malware development specialist: someone who can own initial access, persistence, payload development, evasion research, offensive tooling, and assist with hands-on execution during AdSim exercises.
WHAT YOU’LL DO:
You’re someone who is excited to reverse engineer security products, develop custom malware and endpoint tradecraft, and assist with operating those capabilities during exercises while evading live defenders. You’ll help provide insights into improved prevention and detection strategies for our defenders to consider.
Specifically, you will:
-
Design, develop, and maintain custom offensive tooling, malware, loaders, implants, payloads, Beacon Object Files (BOFs), endpoint persistence mechanisms, and supporting operational infrastructure.
-
Conduct malware development, malware analysis, reverse engineering, exploit development, and offensive security research inspired by Threat Intelligence, real-world adversary TTPs, and the candidate’s own research and development.
-
Operate hands-on during AdSim exercises, including covert, purple team, and targeted exercises.
-
Evaluate and challenge common EDR/AV platforms, log collection, behavioral analysis, network monitoring, identity protection, and other detective and preventative controls.
-
Partner with SOC, Incident Response, Threat Intelligence, and Detection Engineering teams to improve prevention, detection, and response capabilities.
-
Translate technical findings into business risk and deliver actionable detection and remediation guidance.
-
Use and develop AI-assisted testing, automation, perform adversarial LLM research, and build offensive security workflows to accelerate capability development and operational effectiveness.
-
Help shape the future direction of AI-enabled adversary simulation, endpoint tradecraft, malware development, and AdSim exercises.
WHAT YOU BRING:
Candidates will be evaluated based on their ability to perform the duties listed above while demonstrating the required skills and competencies necessary to be highly effective in the role. Preferred experience and certifications are nice to have, not required.
Required experience and skills
-
5+ years of experience in red teaming, adversary simulation, offensive security engineering, malware development, exploit development, or advanced penetration testing.
-
Demonstrated experience operating against mature enterprise environments protected by modern security controls.
-
Strong software development skills in C, C++, C#, Rust, Go, Python, or similar languages, with demonstrated experience building offensive or security tooling.
-
Proven experience developing or modifying custom malware, loaders, implants, payloads, BOFs, endpoint persistence techniques, evasions, ETW patching, AMSI bypass, and operational tooling.
-
Strong reverse engineering, malware analysis, and exploit development capabilities, including analyzing malware, operating system components, and commercial security products.
-
Deep understanding of Windows internals, Active Directory, authentication protocols, endpoint telemetry, and modern defensive technologies.
-
Strong understanding of how EDR/AV, log collection, behavioral analysis, network monitoring, identity protections, and other detective and preventative controls identify adversary activity.
-
Experience using AI-driven tools and workflows to accelerate software development, research, automation, and offensive security activity, including interest in adversarial use of LLMs.
-
Ability to communicate effectively with both technical and non-technical stakeholders and collaborate closely with defensive teams.
Nice-to-have experience
-
Broader red teaming knowledge in one or more additional areas such as cloud security across Azure, AWS, or GCP; application security; web application testing; phishing and social tradecraft; identity attack paths; Active Directory tradecraft; Linux or macOS endpoint internals and tradecraft, including macOS SIP, execution, persistence, telemetry, and security control behavior; wireless or physical security; exploit development; vulnerability research; custom C2 framework development; C2 extension, module, or profile development; or large-scale offensive infrastructure.
-
Game hacking, game security, or anti-cheat bypass research against EAC, BattlEye, Vanguard, or similar platforms, with experience in internal/external tooling, Ring 3/Ring 0 tradecraft, manual mapping, injection, hooking/unhooking, kernel callbacks, memory scanning, overlays, driver-assisted tooling, and detection-surface reduction.
-
Public research, conference presentations, blogs, tool releases, or open-source contributions.
-
Experience with kernel development, kernel security research, advanced vulnerability research, or commercial security product research.
-
Nice-to-have certifications include OSEP, OSED, OSCP, CRTO, GXPN, GREM, or equivalent hands-on offensive security certifications. No certifications are required.
WHY THIS ROLE:
The AdSim Team is building the team we know sets the bar: sharp enough to evade mature defenses, malleable enough to simulate a range of adversaries, and technical enough to build the capabilities other offensive teams dream about. You’ll build custom tooling, develop endpoint tradecraft, operate during realistic exercises, and chase the research that matters. If you want challenging work and the chance to help build one of the best AdSim teams in the space, help us build it at The Hartford