Senior Offensive Security Engineer - Pentester
Bank of America · Seattle, WA · 1 mo ago
Information TechnologyFull-time
About the role
The Cyber Security Assurance Division at Bank of America is seeking a Senior Full Stack Pentester to join a team of world-class offensive security professionals. This role involves identifying exploitable vulnerabilities in critical systems and reporting on the associated risk.
Responsibilities
- Diligently hunt for high-risk vulnerabilities across the bank’s global technology environment.
- Lead and participate in collaborative, technical assessments using a wide range of penetration testing techniques.
- Identify misconfigurations and vulnerabilities to achieve security impact.
- Report on the associated risk to senior leadership and other relevant stakeholders.
- Partner closely with security partners, CIO clients, and multiple lines of business.
- Coordinate with senior leadership on development projects.
- Mentor junior engineers and assist with monitoring and response functions.
Requirements
- Minimum of 5+ years of professional offensive security experience.
- Proficient with common penetration testing tools (Burp Suite, Metasploit, nmap, etc.).
- Strong understanding of voice and data networks, major operating systems, active directory, and a willingness to learn new technologies.
- Knowledge of tactics, techniques, and procedures associated with malicious activity, industry classifications, and frameworks.
- Proficiency in report delivery and technical documentation of vulnerabilities.
- Ability to code in a programming or scripting language (Python, Java, C#, etc.).
Desirable Skills
- Certifications: OSCP, GPEN, GXPN, OSED, OSEP, OSWE, OSCE, GWAPT.
- Experience with hardware hacking, embedded systems analysis, and IoT hacking.