Talent.com
Senior Penetration Tester
Senior Penetration TesterU.S. Bank • Denver, CO, United States
Senior Penetration Tester

Senior Penetration Tester

U.S. Bank • Denver, CO, United States
1 hour ago
Job type
  • Full-time
Job description

At U.S. Bank, we're on a journey to do our best. Helping the customers and businesses we serve to make better and smarter financial decisions and enabling the communities we support to grow and succeed. We believe it takes all of us to bring our shared ambition to life, and each person is unique in their potential. A career with U.S. Bank gives you a wide, ever-growing range of opportunities to discover what makes you thrive at every stage of your career. Try new things, learn new skills and discover what you excel at-all from Day One.

Job Description

U.S. Bank is seeking a Senior Penetration Tester (Web / API / Mobile / ATM) with demonstrated competence and experience to contribute toward the success of our information security program. As a Senior Penetration Tester, you will be responsible for assessing the security of our web / mobile applications, APIs, and ATM platforms by identifying vulnerabilities, performing exploitations, and recommending mitigation strategies to enhance their resilience against cyber threats. This role requires a deep understanding of web / mobile application security principles, ATM hardware / software, advanced penetration testing techniques, and the ability to work collaboratively with cross-functional teams.

Responsibilities

  • Lead dynamic penetration testing against hardened web / API, mobile applications, and ATM systems to uncover vulnerabilities and leverage manual exploitation techniques, demonstrating business impact.
  • Deliver clear, actionable reports that include detailed findings, vulnerability scoring, and remediation guidance tailored to technical and non-technical teams.
  • Continuously evolve testing methodologies by researching emerging threats, tools, and techniques, applying them to improve assessment strategies and team capabilities.
  • Maintain a balance between hands-on testing and supporting broader team initiatives, including process optimization, tool / script development, and knowledge sharing.

Basic Qualifications

  • Bachelor's degree in Engineering or Science, or equivalent work experience
  • Eight or more years of experience in information security
  • Two or more years of experience in IT infrastructure management, application architecture, risk management, data architecture, middleware technology, IT operations and project management
  • Preferred Skills / Experience

  • Web & API Penetration Testing : 5+ years of hands-on experience with modern web applications and APIs. Deep understanding of OWASP Top 10, API Security Top 10, and SANS Top 25 vulnerabilities.
  • Manual Testing & Exploitation : Advanced proficiency in identifying and exploiting vulnerabilities in web apps and APIs using tools like Burp Suite Pro, Postman / Insomnia, and custom scripts; skilled in uncovering business logic flaws, access control issues, and chaining exploits to demonstrate real-world impact.
  • Mobile Application Security : Familiarity with Android and iOS testing methodologies and platform-specific risks, including OWASP MASVS and MASTG.
  • Technical Proficiency : Strong scripting skills (Python, PowerShell, Bash, Ruby, Go). Solid grasp of HTTP / S, authentication protocols (OAuth, SAML, JWT), and network fundamentals (TCP / IP, DNS, firewalls, IDS / IPS).
  • ATM Systems : Hands-on experience assessing ATM hardware / software security; skilled in reverse-engineering, protocol analysis, and exploiting ATM-specific attack vectors .
  • Cloud & Platform Fluency : Comfortable testing in cloud environments (AWS, Azure, containers / Kubernetes). Experienced across Linux, Windows, and macOS platforms. Familiarity with cloud-native security and assessment tools (e.g., AWS Inspector, Azure Defender, ScoutSuite,) and common misconfiguration exploitation techniques.
  • Tooling & Automation : Experience developing custom tools and scripts to automate testing workflows. Familiarity with tools such as Nmap, Metasploit, and Kali Linux.
  • Threat Modeling & Risk Assessment : Ability to perform threat modeling and risk assessments to prioritize testing efforts and communicate business impact.
  • Regulatory & Compliance Awareness : Understanding of compliance frameworks such as PCI-DSS, HIPAA, NIST 800-53, ISO 27001, and FedRAMP.
  • Communication & Documentation : Excellent written and verbal communication skills. Experienced in technical writing and clearly articulating findings to both technical and non-technical audiences, including executive leadership.
  • Leadership & Mentorship : Proven ability to lead engagements, manage stakeholder expectations, and mentor junior testers.
  • Certifications : OSWE, OSEP, OSCP, GWAPT, GPEN, GMOB, OSWA, or equivalent.
  • Additional Experience : Source code review, ServiceNow Application Vulnerability Response, and understanding of change control and security architecture.
  • Location expectations :

    This role requires working from a U.S. Bank location three (3) or more days a week .

    If there's anything we can do to accommodate a disability during any portion of the application or hiring process, please refer to our disability accommodations for applicants () .

    Benefits :

    Our approach to benefits and total rewards considers our team members' whole selves and what may be needed to thrive in and outside work. That's why our benefits are designed to help you and your family boost your health, protect your financial security and give you peace of mind. Our benefits include the following (some may vary based on role, location or hours) :

    Healthcare (medical, dental, vision)

    Basic term and optional term life insurance

    Short-term and long-term disability

    Pregnancy disability and parental leave

    401(k) and employer-funded retirement plan

    Paid vacation (from two to five weeks depending on salary grade and tenure)

    Up to 11 paid holiday opportunities

    Adoption assistance

    Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law

    U.S. Bank is an equal opportunity employer. We consider all qualified applicants without regard to race, religion, color, sex, national origin, age, sexual orientation, gender identity, disability or veteran status, and other factors protected under applicable law.

    E-Verify

    U.S. Bank participates in the U.S. Department of Homeland Security E-Verify program in all facilities located in the United States and certain U.S. territories. The E-Verify program is an Internet-based employment eligibility verification system operated by the U.S. Citizenship and Immigration Services. Learn more about the E-Verify program () .

    The salary range reflects figures based on the primary location, which is listed first. The actual range for the role may differ based on the location of the role. In addition to salary, U.S. Bank offers a comprehensive benefits package, including incentive and recognition programs, equity stock purchase 401(k) contribution and pension (all benefits are subject to eligibility requirements). Pay Range : $111,605.00 - $131,300.00

    U.S. Bank will consider qualified applicants with arrest or conviction records for employment. U.S. Bank conducts background checks consistent with applicable local laws, including the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act as well as the San Francisco Fair Chance Ordinance. U.S. Bank is subject to, and conducts background checks consistent with the requirements of Section 19 of the Federal Deposit Insurance Act (FDIA). In addition, certain positions may also be subject to the requirements of FINRA, NMLS registration, Reg Z, Reg G, OFAC, the NFA, the FCPA, the Bank Secrecy Act, the SAFE Act, and / or federal guidelines applicable to an agreement, such as those related to ethics, safety, or operational procedures.

    Applicants must be able to comply with U.S. Bank policies and procedures including the Code of Ethics and Business Conduct and related workplace conduct and safety policies.

    Posting may be closed earlier due to high volume of applicants.

    Create a job alert for this search

    Penetration Tester • Denver, CO, United States

    Related jobs
    Earn up to $25 per survey Online Survey Taker - high-paying, flexible hours (Hiring Immediately)

    Earn up to $25 per survey Online Survey Taker - high-paying, flexible hours (Hiring Immediately)

    Earn Haus • Castle Pines North, Colorado, US
    Full-time +1
    We are urgently looking for people interested in taking online surveys for Fortune 500 brands.If you are a self-starter, looking for flexible hours throughout the week, this may be for you! Earn up...Show more
    Last updated: 30+ days ago • Promoted
    Part Time Product Demonstrator

    Part Time Product Demonstrator

    Advantage Solutions • Castle Rock, CO, United States
    Part-time
    We want you to help us shape the future of shopping experiences and deliver on our purpose of connecting people with the products and experiences that enrich their lives. Joining Advantage Solutions...Show more
    Last updated: 30+ days ago • Promoted
    Earn up to $25 per survey Online Survey Taker - work-from-home opportunity (Hiring Immediately)

    Earn up to $25 per survey Online Survey Taker - work-from-home opportunity (Hiring Immediately)

    Earn Haus • Roxborough Park, Colorado, US
    Remote
    Full-time +1
    We are urgently looking for people interested in taking online surveys for Fortune 500 brands.If you are a self-starter, looking for flexible hours throughout the week, this may be for you! Earn up...Show more
    Last updated: 30+ days ago • Promoted
    Experienced Construction Material Tester

    Experienced Construction Material Tester

    REC • Denver, CO, US
    Full-time
    Quick Apply
    Experienced Geotechnical Material Tester •.Hours : Monday-Friday 40-50 hours+ / week (Overtime Paid at 1.Collecting samples of soils, concrete, asphalt, and other materials for various commercial, resi...Show more
    Last updated: 30+ days ago
    Lab and Field Construction Materials Tester (CMT)

    Lab and Field Construction Materials Tester (CMT)

    REC • Englewood, CO, US
    Full-time
    Quick Apply
    We are seeking soil and concrete Field Technicians in Centennial, CO.The successful candidate will have a thorough understanding of standard test methods and experience performing construction-rela...Show more
    Last updated: 30+ days ago
    Mobile Phlebotomist - (PRN-Flexible Hours)

    Mobile Phlebotomist - (PRN-Flexible Hours)

    CareSend • Castle Rock, CO, US
    Full-time
    Quick Apply
    Helping you deliver high-quality, in-home patient care.CareSend is a technology platform that makes lab draws more accessible, efficient, and affordable. We bring together the patient, provider, and...Show more
    Last updated: 30+ days ago
    Application Penetration Tester

    Application Penetration Tester

    ASM Research, An Accenture Federal Services Company • Denver, CO, United States
    Full-time
    As an Application Security Penetration Tester, you will be entrusted with the critical responsibility of safeguarding web applications and REST APIs from potential threats.Your role will require a ...Show more
    Last updated: 5 days ago • Promoted
    Security Consultant - Penetration Testing

    Security Consultant - Penetration Testing

    SHI GmbH • Denver, CO, United States
    Full-time
    Since 1989, SHI International Corp.We've grown every year since, and today we're proud to be a $16 billion global provider of IT solutions and services. Over 17,000 organizations worldwide rely on S...Show more
    Last updated: 7 days ago • Promoted
    Travel Cath Lab Technologist - $3,002 per week

    Travel Cath Lab Technologist - $3,002 per week

    Host Healthcare • Castle Rock, CO, United States
    Full-time
    Host Healthcare is seeking a travel Cath Lab Technologist for a travel job in Castle Rock, Colorado.Job Description & Requirements. Host Healthcare Job ID #a1fVJ0000074If3YAE.Pay package is based on...Show more
    Last updated: 30+ days ago • Promoted
    Earn up to $25 per survey Online Survey Taker (Hiring Immediately)

    Earn up to $25 per survey Online Survey Taker (Hiring Immediately)

    Earn Haus • Castle Pines North, Colorado, US
    Full-time +1
    We are urgently looking for people interested in taking online surveys for Fortune 500 brands.If you are a self-starter, looking for flexible hours throughout the week, this may be for you! Earn up...Show more
    Last updated: 30+ days ago • Promoted
    Experienced Materials Tester

    Experienced Materials Tester

    REC • Centennial, CO, US
    Full-time
    Quick Apply
    We are seeking soil and concrete Field Technicians in Centennial, CO.The successful candidate will have a thorough understanding of standard test methods and experience performing constru...Show more
    Last updated: 30+ days ago
    Travel Cath Lab Technologist

    Travel Cath Lab Technologist

    Host Healthcare • Castle Rock, CO, US
    Full-time
    Host Healthcare is seeking a travel Cath Lab Technologist for a travel job in Castle Rock, Colorado.Job Description & Requirements. Pay package is based on 10 hour shifts and 40 hours per week (...Show more
    Last updated: 30+ days ago • Promoted
    Earn up to $25 per survey Online Survey Taker - Work-from-home flexibility (Hiring Immediately)

    Earn up to $25 per survey Online Survey Taker - Work-from-home flexibility (Hiring Immediately)

    Earn Haus • Castle Rock, Colorado, US
    Remote
    Full-time +1
    We are urgently looking for people interested in taking online surveys for Fortune 500 brands.If you are a self-starter, looking for flexible hours throughout the week, this may be for you! Earn up...Show more
    Last updated: 30+ days ago • Promoted
    Sr. Security Consultant - Penetration Testing

    Sr. Security Consultant - Penetration Testing

    SHI GmbH • Denver, CO, United States
    Full-time
    As a digital and cybersecurity services company, Stratascale exists to help the Fortune 1000 transform the way they use technology to advance the business, generate revenue, and respond quickly to ...Show more
    Last updated: 14 days ago • Promoted
    Experienced Tax Preparer

    Experienced Tax Preparer

    Jackson Hewitt COO • Castle Rock, CO, United States
    Full-time +1
    Leverage your tax expertise, business background, and knowledge of tax laws to propel you to the next level.You will provide exceptional client service while. Don't miss out on this opportunity to.S...Show more
    Last updated: 15 days ago • Promoted
    Test Technician

    Test Technician

    Jobot • Littleton, CO, United States
    Full-time
    With numerous offices across the country we are an industry leading Space Hardware Development company.We specialize in the design, manufacture, integration, and test of critical spacecraft compone...Show more
    Last updated: 5 days ago • Promoted
    Senior Security Engineer - Penetration Testing

    Senior Security Engineer - Penetration Testing

    Rubix Recruiting • Denver, CO, United States
    Full-time
    Our company is extremely passionate about security and the benefit it brings to our customers.We are aiming to bring in a mutli-tasking leader to direct and influence the next stage in our success....Show more
    Last updated: 19 days ago • Promoted
    Sterile Processing Tech Cert

    Sterile Processing Tech Cert

    AdventHealth • Louisville, CO, United States
    Full-time
    All the benefits and perks you need for you and your family : .Student Loan Repayment Program.Whole Person Wellbeing Resources. Joining AdventHealth is about being part of something bigger.Its about b...Show more
    Last updated: 30+ days ago • Promoted