Manual Ethical Hacker
Bank of America · Denver, CO · 2 wk ago
EngineeringFull-time
Key Responsibilities
- Perform assigned analysis of internal and external threats on information systems and predict future threat behavior
- Incorporate threat actors' tactics, techniques, and procedures into offensive security testing
- Perform assessments of the security, effectiveness, and practicality of multiple technology systems
- Leverage innovative thinking to help solve problems or introduce new ideas to processes or products applicable to offensive security
- Prepare and present detailed technical information for various media including documents, reports, and notifications
- Provide clear and practical advice regarding managed risks
Required Skills
- Minimum of 4 years of professional pentesting, application security or ethical hacking experience, preferably in a large, complex, enterprise environment
- Detailed technical knowledge in at least 3 of the following areas: security engineering; application architecture; authentication and security protocols; application session management; applied cryptography; common communication protocols; mobile frameworks; single sign-on technologies; exploit automation platforms; RESTful web services; SQL injection/XSS attack without the use of tools
- Experience performing manual code reviews for security relevant issues
- Experience working with SAST tools to identify vulnerabilities
- Able to manually identify and reproduce findings, discuss remediation concepts, develop PoCs for vulnerabilities, use scripting/coding techniques, proficiently execute common penetration testing tools, triage, and support incidents, and produce high value findings
- Experience performing manual web application assessments i.e., must be able to simulate a
- Knowledge of network and Web related protocols/technologies (e.g., UNIX/LINUX, TCP/IP, Cookies)
- Experience with vulnerability assessment tools and penetration testing techniques
- Solid programming/debugging skills
- Experience of using a variety of tools, included, but not limited to, IBM AppScan, Burp and SQL Map
Desired
- CISSP, CEH, OSCP, OSWE, GPEN, PenTest+
- Strong programming/scripting skills
- Mobile application analysis
- Frida
- Binary analysis (disassembly skills)
Skills
- Advisory
- Innovative Thinking
- Technical Documentation
- Technology System Assessment
- Threat Analysis
- Adaptability
- Collaboration
- Executive Presence
- Scenario Planning and Analysis
- Test Engineering
- Controls Management
- Information Systems Management
- Issue Management
- Mentoring
- Presentation Skills