Senior Penetration Tester - Web & Hardware/IoT
JPMorganChase · Chicago, IL · 1 mo ago
On-siteInformation TechnologyFull-time
Job Responsibilities
- Plan, scope, and execute penetration testing engagements across a variety of environments, including web applications, APIs, cloud platforms, infrastructure, thick-client, and/or mobile applications (primary focus).
- Perform security assessments of banking hardware and connected/IoT technologies (limited but expected), such as ATMs, Point of Sale (POS) devices, and other embedded endpoints.
- Collect and validate pre-requisites for each engagement, ensuring all necessary access, documentation, and approvals are in place (including lab/onsite testing logistics and device access where applicable).
- Perform manual and automated testing to identify vulnerabilities, misconfigurations, and security weaknesses, leveraging industry-standard tools and custom scripts.
- Document and communicate findings through comprehensive reports that include technical details, risk assessments, and actionable remediation recommendations.
- Conduct peer reviews of penetration test reports to ensure accuracy, consistency, and quality of deliverables.
- Collaborate with development, infrastructure, security, and device/product engineering teams to clarify findings, support remediation efforts, and provide subject matter expertise on offensive security.
- Stay current with emerging threats, vulnerabilities, and attack techniques by leveraging threat intelligence, security research, and participation in relevant industry groups.
- Contribute to the continuous improvement of penetration testing methodologies, tools, and frameworks to enhance effectiveness and alignment with firm strategy and regulatory requirements.
Required Qualifications, Capabilities, And Skills
- 5+ years of hands-on penetration testing experience in offensive security, with a proven track record of scoping, executing, and reporting on complex engagements.
- Expertise in manual penetration testing of web, API, cloud (AWS/Azure/GCP), infrastructure, thick-client, and/or mobile (Android/iOS) applications, including the use of industry-standard tools (e.g., Burp Suite, Nmap, Metasploit, etc.).
- Working knowledge of testing approaches for connected devices/IoT and purpose-built banking devices (e.g., ATMs, POS), including common attack surfaces such as exposed services, remote administration paths, authentication/authorization, hardening gaps, and insecure configurations.
- Strong understanding of security assessment methodologies such as OWASP Top Ten, NIST Cybersecurity Framework, and other relevant standards.
- Exceptional organizational and communication skills, including the ability to write detailed technical reports and present findings to both technical and non-technical stakeholders.
- Experience conducting peer reviews of penetration test reports and mentoring junior testers.
- Continuous learner who keeps up with the latest offensive security trends, tools, and techniques.
Preferred Qualifications, Capabilities, And Skills
- Knowledge of cybersecurity practices, operational risk management, and incident response methodologies within the US financial services sector, including relevant regulations, threats, and risks.
- Proficiency in penetration testing and security concepts for both Windows and Unix-like operating systems.
- Experience conducting security-focused source code reviews (e.g., Python, Java, Rust).
- Experience in reverse engineering thick-client and mobile applications to identify vulnerabilities.
- Experience assessing embedded systems / IoT devices in lab or onsite environments (e.g., device interface review, firmware/configuration analysis, and network/service exposure testing) relevant to ATM/POS ecosystems.
- Relevant certifications such as OSWE, CREST (CRT, CCT), OSCP, OSCE, GXPN, GWAPT, GPEN, GMOB, or BSCP.