Jobs · Information Technology · New Jersey

Senior Offensive Security Engineer - Pentester

Bank of America · Jersey City, NJ · 1 wk ago
Information TechnologyFull-time

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We drive Responsible Growth and deliver for our clients, teammates, communities, and shareholders every day. Our commitment to being an inclusive workplace includes supporting teammates’ physical, emotional, and financial wellness, recognizing and rewarding performance, and making an impact in the communities we serve.

About the role

The Cyber Security Assurance Division is looking for a Senior Full Stack Pentester to join a team of world-class offensive security professionals. In this role, you will diligently hunt for high-risk vulnerabilities across the bank’s global technology environment. You will lead and participate in collaborative, technical assessments that leverage a wide range of penetration testing techniques to identify and prove the concept of high-risk vulnerabilities across a variety of technologies. This senior technical role is responsible for leading and performing assessments of the bank's technologies, applications, and cyber security controls while adapting testing methods to evolving and emerging threats.

You will coordinate with senior leadership on development projects, mentor junior engineers, and assist with monitoring and response functions to help teams improve their capability to respond to realistic threat actors.

Responsibilities

  • Lead and perform research, understanding the bank's security policy, and work with appropriate partners to complete assessments.
  • Identify misconfigurations and vulnerabilities to achieve security impact and report on the associated risk.
  • Critically examine an organization and system through the perspective of a threat actor and articulate risk in clear, precise terms to technical and non-technical audiences.
  • Partner closely with security partners, CIO clients, and multiple lines of business.
  • Demonstrate knowledge of tactics, techniques, and procedures associated with malicious activity, industry classifications, and frameworks.
  • Chain vulnerabilities in the advanced exploitation of systems.
  • Deliver reports and technical documentation of vulnerabilities.

Requirements

  • Minimum of 5+ years of professional offensive security experience.
  • Proficient with common penetration testing tools (Burp Suite, Metasploit, nmap, etc.).
  • Solid understanding of voice and data networks, major operating systems, Active Directory, and associated peripherals.
  • Strong desire to learn new technologies and skill sets.
  • Proficient in coding in a programming or scripting language (Python, Java, C#, etc.).

Skills

  • Certifications: OSCP, GPEN, GXPN, OSED, OSEP, OSWE, OSCE, GWAPT (desirable).
  • Experience with hardware hacking, embedded systems analysis, and IoT hacking (desirable).
  • Previous experience working in the financial industry (desirable).
  • Ability to work remotely if/when necessary.

Schedule

  • Shift: 1st shift (United States of America).
  • Hours Per Week: 40.

Similar jobs