Talent.com
Bank of America
Senior Manual Ethical HackerBank of America • Seattle
Senior Manual Ethical Hacker

Senior Manual Ethical Hacker

Bank of America • Seattle
30+ days ago
Salary
$160,000.00 yearly
Job type
  • Full-time
Job description

Description

:

Manual Ethical Hacking is part of the Application Development Security Framework Program within Bank of America’s Cyber Security Assurance Offensive Security group. The program provides services to assess the security resilience of the bank’s applications to malicious hacking activity.

This senior technical role is responsible performing and leading ethical hacking assessments of the bank's technologies, applications, and cyber security controls while adapting testing methods to evolving and emerging threats. Key responsibilities include leading and performing research, understanding the bank's security policies, working with appropriate partners to complete assessments and simulations, identifying misconfigurations and vulnerabilities, and reporting on associated risk. These individuals partner closely with security partners, CIO clients and multiples lines of business. These individuals are expected to perform application security-oriented dynamic and static assessments across a multitude of technologies including web UI, web APIs, mobile and cloud, including associated source code.

Key Responsibilities in order of importance:

  • Perform assigned analysis of internal and external threats on information systems and predict future threat behavior.

  • Incorporate threat actors' tactics, techniques, and procedures into offensive security testing to identify high-value vulnerabilities/chained attacks.

  • Developing Proof-of-concepts for exploitation.

  • Perform assessments of the security, effectiveness, and practicality of multiple technology systems.

  • Leverage innovative thinking to help solve problems or introduce new ideas to processes or products applicable to offensive security.

  • Prepare and present detailed technical information for various media including documents, reports, and notifications.

  • Provide clear and practical advice regarding managing risks.

  • Learn and develop advanced technical and leadership skills, mentor Junior and Intermediate assessors in technical tradecraft and soft skills.

  • Respond to security incidents and provide technical assistance to leadership across the Information Security organization.

Required Skills:

  • Minimum of 5+ years of professional pentesting, application security or ethical hacking experience, preferably in a large, complex, enterprise environment

  • Detailed technical knowledge in at least 5 of the following areas:

    security engineering

    application architecture

    authentication and security protocols

    application session management

    applied cryptography

    common communication protocols

    mobile frameworks

    single sign-on technologies

    exploit automation platforms

    Web APIs

    Cloud environments

    LLM security

    Mobile application analysis

  • Able to manually identify and reproduce findings, discuss remediation concepts, develop PoCs for vulnerabilities, use scripting/coding techniques, proficiently execute common penetration testing tools, triage, and support incidents, and produce high value findings

  • Experience performing manual web application assessments i.e., must be able to simulate a OWASP Top 10 vulnerabilities without the use of tools

  • Experience performing manual code reviews for security relevant issues

  • Experience working with DAST and SAST tools to identify vulnerabilities

  • Knowledge of network and Web related protocols/technologies (e.g., UNIX/LINUX, TCP/IP, Cookies)

  • Experience with vulnerability assessment tools and penetration testing techniques.

  • Solid programming/debugging skills, development frameworks, CVE and CWE research/reproduction

  • Threat Analysis, threat modelling and SBOM analysis

  • Innovative thinking, threat actor simulation

  • Technology Systems Assessment

  • Technical Documentation

  • Advisory

Desired:

  • CEH, OSCP/OSCE/OSWE/GXPN/GPEN/GWAPT/GMOB/All Practitioner Certs [Port Swigger BSP Academy]/Cloud Cert(s)/ eWPT; eWPTX; eMAPT [INE Pentester Academy]

  • Strong programming/scripting skills

  • Frida

  • Binary analysis (disassembly skills)

Skills:

  • Advisory

  • Innovative Thinking

  • Technical Documentation

  • Technology System Assessment

  • Threat Analysis

  • Adaptability

  • Collaboration

  • Scenario Planning and Analysis

  • Test Engineering

  • Written Communications

  • Attention to Detail

  • Information Systems Management

  • Issue Management

  • Presentation Skills

  • Prioritization

This job will be open and accepting applications for a minimum of seven days from the date it was posted.

Shift:

1st shift (United States of America)

Hours Per Week:

40

Pay Transparency details

US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540), US - MA - Boston - 100 Federal St - 100 Federal St Lp (MA5100), US - NJ - Jersey City - 101 Hudson St - 101 Hudson (NJ2101), US - WA - Seattle - 401 Union St - Rainier Square (WA1510)Pay and benefits informationPay range$160,000.00 - $205,000.00 annualized salary, offers to be determined based on experience, education and skill set.Discretionary incentive eligibleThis role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.BenefitsThis role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.
Create a job alert for this search

Senior Manual Ethical Hacker • Seattle

Similar jobs

Senior ML Engineer: End-to-End Production & Impact

Calendly, LLCSeattle, WA, United States
Full-time

A leading productivity solutions company is seeking a Machine Learning Engineer to drive innovative data and analytics solutions.The role involves owning ML features from design to deployment, coll... Show more

 • Promoted

Senior Staff ML Engineer – Underwriting & ML Platform

AffirmSeattle, WA, United States
Full-time

A financial technology company based in Seattle is seeking a Senior Staff Machine Learning Engineer to lead innovations in machine learning.This role involves driving technical strategy, implementi... Show more

 • Promoted

Senior Mobile Engineer, React Native Ad Tech & Monetization

Dotdash MeredithSeattle, WA, United States
Full-time

A prominent media company in Seattle is looking for a Senior Software Engineer 1, specializing in mobile development using React Native.The role involves building scalable mobile ad experiences and... Show more

 • Promoted

Senior Embedded Medical Sales Executive - Americas

Tuxera IncSeattle, Washington, United States
Full-time

A leading technology firm is seeking an experienced Americas Embedded (Sr.Account Executive for Medical in Seattle.This role involves driving growth in the healthcare technology sector by developin... Show more

 • Promoted

Manual Machinist

Integrated Power ServicesTukwila, WA, US
$28.50 hourly
Full-time

At IPS, we're all about exceptional service and exceptional people.We're looking for a passionate In-Shop Technician who loves hands-on work, takes pride in their craft, and wants to have a meaning... Show more

Senior ML Engineer - Monetization & Personalization

PinterestSeattle, WA, United States
Full-time

A leading social media company in Seattle is seeking a Machine Learning Engineer to build personalized experiences and optimize Ad technology using advanced ML and deep learning.The ideal candidate... Show more

 • Promoted

Senior Release Engineer — Diagnostics Systems QA & Release

TechDigital GroupSeattle, WA, United States
Full-time

An innovative firm is looking for a Development Scientist with a strong Medical Technologist background to join their dynamic team.This role involves performing clinical laboratory tests and ensuri... Show more

 • Promoted

ML Engineer: Risk & Fraud Detection

TikTokSeattle, WA, United States
Full-time

A leading social media platform is seeking a Machine Learning Engineer to build and enhance solutions that mitigate business risks.Responsibilities include improving modeling infrastructures and de... Show more

 • Promoted

Senior ML Software Engineer

LyftSeattle, WA, United States
Full-time

At Lyft, our purpose is to serve and connect.We aim to achieve this by cultivating a work environment where all team members belong and have the opportunity to thrive.With over half a billion rides... Show more

 • Promoted

Technical Recruiter, Specialized

AnthropicSeattle, WA, United States
Full-time

Technical Recruiter, Specialized/h2pSan Francisco, CA | Seattle, WA/ph3About Anthropic/h3pAnthropics mission is to create reliable, interpretable, and steerable AI systems.We want AI to be safe and... Show more

 • Promoted

Senior Manager, Paid Search

New EngenSeattle, WA, US
$95,000.00 yearly
Full-time
Quick Apply

At New Engen, we help brands grow—not just bigger, but smarter.We’re a digital marketing agency built to drive meaningful impact across the entire customer journey, blending media, crea... Show more

Travel Nuclear Medicine Technologist - $2369.64 / Week

Preferred Healthcare StaffingTacoma, WA, US
Full-time

Preferred Healthcare Staffing is seeking an experienced Nuclear Medicine Technologist for an exciting Travel Allied job in Tacoma, WA.Shift: 8 hr days Start Date: ASAP Duration: 13 weeks Pay: $2369... Show more

 • Promoted

Senior Manager, Mergers & Acquisitions (exit readiness) Chicago; Dallas; Los Angeles; Minneapol[...]

West Monroe Partners, LLCSeattle, WA, United States
Full-time

Senior Manager, Mergers & Acquisitions (exit readiness).Are you ready to make an impact?.Our expert and award-winning Mergers & Acquisitions (M&A) practice seeks a Senior Manager to join our rapidl... Show more

 • Promoted

Solutions Architect - (Machine Learning)

JobotSeattle, WA, United States
Full-time

Design, deploy, and scale machine learning systems that power modern data platforms.This Jobot Job is hosted by: Robert Donohue.Easy Apply now by clicking the "Easy Apply" button and sending us you... Show more

 • Promoted

Senior Staff Machine Learning Engineer - Trusted Identity

UberSeattle, WA, United States
Full-time

We are looking for an experienced Senior Staff Machine Learning Engineer to join the Account Integrity team within Trusted Identity engineering org at Uber.The Trusted Identity org plays a crucial ... Show more

 • Promoted

Senior Acquisition Professional

General Services AdministrationTacoma, WA, United States
Full-time

Serves as an advisor to program officials in procurement planning meetings, identifying the procurement objectives and methodologies to be used and provides expert technical guidance in the prepara... Show more

 • Promoted

Travel Medical Technologist - $3,051 per week in Ilwaco, WA

AlliedTravelCareersTacoma, Washington, US
Full-time

AlliedTravelCareers is working with OneStaff Medical to find a qualified Medical Technologist in Ilwaco, Washington, 98624!.An independently-owned, nationally-recognized and amazingly awesome staff... Show more

 • Promoted

Locum Physician (MD/DO) - Occupational Medicine in Everett, WA

LocumJobsOnlineEverett, WA, US
$131,227.20 yearly
Full-time

Doctor of Medicine | Occupational Medicine.Competitive weekly pay (inquire for details) .LocumJobsOnline is working with Rhino Medical to find a qualified Occupational Medicine MD in Everett, Washi... Show more

 • Promoted

Senior Android Engineer – FinTech Impact & Autonomy

GridSeattle, WA, United States
Full-time

An innovative firm is seeking a passionate Android Engineer to join their dynamic team in Seattle.In this role, you will design and maintain the Android app, contributing to a mission that empowers... Show more

 • Promoted

Senior ML Scientist — Travel Fraud & Risk Innovator

Work180Seattle, WA, United States
Full-time

A leading technology company is seeking a Senior Machine Learning Engineer to develop and deploy machine learning models that solve complex business challenges.You will lead projects through their ... Show more