Talent.com
Senior Offensive Security Engineer - Pentester
Senior Offensive Security Engineer - PentesterBank of America • Jersey City
Senior Offensive Security Engineer - Pentester

Senior Offensive Security Engineer - Pentester

Bank of America • Jersey City
30+ days ago
Job type
  • Full-time
Job description

Description

:

Are you passionate about cybersecurity and looking to work with some of the best information security professionals in the world in challenging environments? Bank of America is hiring top talent to join our team. You bring your talent and passion, and we’ll provide you with an opportunity to shine and grow.

The Cyber Security Assurance Division is looking for a Senior Full Stack Pentester to join a team of world-class offensive security professionals. In this role, you will diligently hunt for high-risk vulnerabilities across the bank’s global technology environment. Understanding security policy and compliance is important, but in this role your focus is to identify exploitable vulnerabilities in critical systems; ones that can bring about that “nightmare scenario.”

This is a highly-technical role that requires broad technical knowledge, a deep understanding of threats, and a hacker mentality. You will lead and participate in collaborative, technical assessments that leverage a wide range of penetration testing techniques (reconnaissance, weaponization, delivery, exploitation) to identify and prove the concept of high-risk vulnerabilities across a variety of technologies. Your strong problem-solving skills, practical demonstration of technical competency, and lateral thinking will contribute to our team-first culture of collaboration and impactful findings.

This senior technical role is responsible for leading and performing assessments of the bank's technologies, applications, and cyber security controls while adapting testing methods to evolving and emerging threats. Key responsibilities include leading and performing research, understanding the bank's security policy, working with appropriate partners to complete assessments, identifying misconfigurations and vulnerabilities to achieve security impact, and reporting on the associated risk. These individuals partner closely with security partners, CIO clients, and multiple lines of business.

You will coordinate with senior leadership on development projects, share your knowledge and experience by mentoring junior engineers, and assist with monitoring and response functions, so those teams can practice and improve their capability to respond to a realistic threat actor.

Required Skills:

  • Minimum of 5+ years of professional offensive security experience
  • Must be able to critically examine an organization and system through the perspective of a threat actor and articulate risk in clear, precise terms to technical and non-technical audiences.
  • Must be very proficient with the common tools associated with penetration testing (Burp Suite, Metasploit, nmap, etc.).
  • Must have a solid understanding of voice and data networks, major operating systems, active directory, their associated peripherals, and a strong desire to learn new technologies and skill sets.
  • Must demonstrate knowledge of tactics, techniques, and procedures associated with malicious activity, an understanding of industry classifications and frameworks, and the ability to chain vulnerabilities in the advanced exploitation of systems.
  • Must be proficient in report delivery and technical documentation of vulnerabilities.
  • Must be able to effectively code in a programming or scripting language (Python, Java, C#, etc.)

Desirable Skills:

  • Certifications: OSCP, GPEN, GXPN, OSED, OSEP, OSWE, OSCE, GWAPT
  • Ability to work remotely if/when necessary
  • Previous experience working in the financial industry
  • Experience with hardware hacking, embedded systems analysis, and IoT hacking

This job will be open and accepting applications for a minimum of seven days from the date it was posted.

Shift:

1st shift (United States of America)

Hours Per Week:

40

Pay Transparency details

US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540), US - MA - Boston - 100 Federal St - 100 Federal St Lp (MA5100), US - NJ - Jersey City - 101 Hudson St - 101 Hudson (NJ2101), US - WA - Seattle - 401 Union St - Rainier Square (WA1510)Pay and benefits informationPay range$160,000.00 - $205,000.00 annualized salary, offers to be determined based on experience, education and skill set.Discretionary incentive eligibleThis role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.BenefitsThis role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.
Create a job alert for this search

Senior Offensive Security Engineer - Pentester • Jersey City

Similar jobs

Cyber Security Detection Engineer - (Fulltime)100% Remote

ICONMAJersey City, NJ, United States
Remote
Full-time

Over 8 years of Information Security or Intelligence experienceDeep experience as a Cyber Security Detection Engineer focusing on Microsoft Azure.To include experience with Defender for Cloud, Entr...Show more

 • Promoted

Senior Forensic Engineer

The Vertex Companies, LLCNew York, NY, US
Full-time +1

The Vertex Companies, LLC (VERTEX) is a global $150M professional services firm that offers integrated forensic consulting, expert witness services, construction project advisory, and compliance an...Show more

Staff Security Engineer - Corporate Security

RipplingNew York, New York, United States, 10007
Full-time
Quick Apply

Rippling gives businesses one place to run HR, IT, and Finance.It brings together all of the workforce systems that are normally scattered across a company, like payroll, expenses, benefits, and co...Show more

Enterprise Information Security Engineer

Church Pension Group Services CorporationNew York, New York, United States
Full-time

BA/BS or combination of education and experience.Church Pension Group (CPG) is a financial services organization that serves the Episcopal Church, located in Midtown Manhattan.CPG was founded in 19...Show more

 • Promoted

PT Overnight Surveillance Security Agent

GardaWorldNeptune City, NJ, United States
Part-time

GardaWorld Security Services is Now Hiring a Surveillance Security Officer! Ready to suit up as a Surveillance Security Guard? What matters most about a role like this is your sharp eye, capturing ...Show more

 • Promoted

Security Operations Center Operator - Transportation Infrastructure Facility

Allied Universal SecurityThe Bronx, NY, United States
Full-time

Company Overview: Allied Universal, North America's leading security and facility services company, offers rewarding careers that provide you a sense of purpose.While working in a dynamic, welcomin...Show more

 • Promoted

Senior Security Architect

TradeJobsWorkForce10701 Yonkers, NY, US
Full-time

Senior Security Architect Job Duties: Enhances security team accomplishments and competence by planning delivery of solutions; answering technical and procedural questions for less experienced team...Show more

 • Promoted

Senior Security Engineer Remote, Equity & Benefits

GoFundMeNew York City, NY, United States
Remote
Full-time

A leading charitable organization in New York is seeking a Senior Security Engineer to ensure a secure giving platform.The role involves conducting application security assessments, collaborating w...Show more

 • Promoted

Security Operation Engineer - Remote

Nava Software SolutionsJersey City, NJ, United States
Remote
Full-time

NAVA Software solutions is looking for a Security Operations EngineerDetails :Security Operations EngineerLocation :RemoteDuration :6-12 monthsSecurity Operations Engineer to join our cybersecurity...Show more

 • Promoted

Saviynt Security Engineer

OpenkyberNY, United States
Full-time
Quick Apply

Title: Infrastructure Security Engineer Location: New York & San Jose - Hybrid About OpenKyber: Started in 2006 and headquartered in Connecticut, OpenKyber is one of the fastest growing digital tec...Show more

Senior Rust Engineer - Web3 Security

Remote IT WorldNew York City, NY, United States
Full-time

Senior Rust Engineer - Web3 SecurityWe're a small, mission-driven team building critical infrastructure to make crypto safer and more resilient.Our work focuses on enabling protocols to define and ...Show more

 • Promoted

Senior Threat Detection Content Engineer - Remote

BlueVoyantNew York City, NY, United States
Remote
Full-time

A cybersecurity firm is seeking a Security Consultant for a fully remote position focused on developing automated security analysis solutions.The role requires expertise in detection logic and coll...Show more

 • Promoted

Azure Cloud Security Engineer

MedReviewNew York, NY, US
Full-time
Quick Apply

Position Summary The AI/Cloud Security Engineer is responsible for implementing, configuring, and maintaining cloud security tools that protect MedReview's cloud and AI infrastructure.This role wil...Show more

Application Security Engineer

Open Systems TechnologiesNew York, NY, United States
Full-time

A financial firm is looking for an.Perform Application Security scans (e.DAST and SCA) on applications and APIs to identify security vulnerabilities and weaknesses.Triage security findings and coll...Show more

 • Promoted

Bilingual [JP/EN] Senior Security Engineer

Cinter CareerNew York, NY, US
Full-time
Quick Apply

Job Details ・ Job Title:.Senior Security Engineer / Advanced Security Engineer ・ Client: Japanese IT Company ・ Working Location: New York, NY 10022 ・ Working Style: Onsite / Hybrid ・ Employment Typ...Show more

Security Engineer

Shyft6New York, NY, us
Full-time
Quick Apply

This role will focus on protecting systems built on.AWS, Azure, Tableau, Power BI, and DealCloud CRM.This is a hands-on technical role ideal for someone with strong.Support integration security for...Show more

Senior Cloud Security Engineer Remote (Kubernetes & IaC)

Promote ProjectNew York City, NY, United States
Remote
Full-time

An established industry player is seeking a Cloud Security Engineer to enhance the security posture of its cloud environments.In this role, youll be a key contributor to the security team, responsi...Show more

 • Promoted

Director, Cyber Security

BlueGreen Alliance IncMontvale, NJ, United States
Full-time

JobTarget helps you cut through the noise to reach and convert the best candidates.Our unified platform uses data and automated technology to help you efficiently manage applications and connect wi...Show more