Senior Web Application Penetration Tester
About the role
U.S. Bank is seeking a Senior Web Application Penetration Tester with demonstrated competence and experience to contribute toward the success of our information security program. As a Senior Penetration Tester, you will assess the security of our web applications by identifying vulnerabilities and recommending mitigation strategies to enhance their resilience against cyber threats. This role requires a deep understanding of web application security principles, advanced web application penetration testing techniques, and the ability to work collaboratively with cross-functional teams.
The role offers a hybrid/flexible schedule, with an in-office expectation of 3 or more days per week and the flexibility to work remotely for the remaining days. Available locations include Cincinnati, OH; Minneapolis, MN; and Charlotte, NC.
Responsibilities
- Perform web application and API penetration testing to identify vulnerabilities.
- Recommend mitigation strategies to enhance application security.
- Collaborate with cross-functional teams to improve security posture.
- Document findings and produce technical reports for both technical and non-technical stakeholders.
Requirements
- Bachelor's degree in Engineering or Science, or equivalent work experience.
- Eight or more years of experience in information security.
- Two or more years of experience in IT infrastructure management, application architecture, risk management, data architecture, middleware technology, and IT operations and project management.
Preferred Qualifications & Skills
- At least five years performing web application and/or API penetration testing.
- 3-5 years or more experience in technical writing and documentation.
- Familiarity with information security architecture and IT standards, procedures, and policies.
- Offensive Security Web Assessor Certification (OSWA), GIAC Web Application Penetration Tester (GWAPT), or similar certification is a plus.
- Offensive Security Certified Professional Certification (OSCP) is a plus.
- Experience with ServiceNow Application Vulnerability Response, change control, product and vendor evaluation is a plus.
- Subject matter expertise (5+ years) in information security technologies including Burp Suite Pro and OWASP Zap.
- Strong knowledge of web application security principles, OWASP Top 10, and industry best practices for secure web application development.
- Hands-on experience with manual testing techniques, including SQL injection, cross-site scripting (XSS), CSRF, and other common web application vulnerabilities.
- Excellent written and verbal communication skills, with the ability to convey technical concepts effectively to both technical and non-technical stakeholders.
Benefits
- Healthcare (medical, dental, vision).
- Basic term and optional term life insurance.
- Short-term and long-term disability.
- Pregnancy disability and parental leave.
- 401(k) and employer-funded retirement plan.
- Paid vacation (from two to five weeks depending on salary grade and tenure).
- Up to 11 paid holiday opportunities.
- Adoption assistance.
- Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law.
Review our full benefits available by employment status here.