Cybersecurity Red Team-Penetration Tester
Job Description
Zions Bancorporation offers a hybrid Cybersecurity Red Team-Penetration Tester role in Midvale, UT that emphasizes proactive defense and real-world impact. You will identify and exploit complex vulnerabilities across enterprise infrastructure, applications, and cloud environments, design and execute simulated attacks, and collaborate with Incident Response and development teams to strengthen security posture from day one.
Benefits
- Medical, Dental and Vision Insurance starting on Day One
- Life and Disability Insurance, Paid Parental Leave and Adoption Assistance
- Health Savings (HSA), Flexible Spending (FSA), and dependent care accounts
- P aid Training, Paid Time Off (PTO) and 11 Paid Federal Holidays
- 401(k) plan with company match, Profit Sharing, competitive compensation aligned with experience
- Mental health benefits including coaching and therapy sessions
- Tuition Reimbursement for qualifying employees
- Employee Ambassador preferred banking products
Work Location
This position offers a hybrid work from home arrangement with a minimum of three days per week in the office at the new Zions Technology Center in Midvale, UT. The 400,000-square-foot campus sits on the former Sharon Steel Mill superfund site and serves as the company’s primary technology and operations hub. Key features include:
- Electric vehicle charging stations and proximity to Historic Gardner Village UTA TRAX station
- At least 75% of building power from on-site renewable solar energy
- Access to outdoor recreation, parks, trails, shareable bikes and locker rooms
- Large modern cafe with a healthy and diverse menu
- Healthy indoor environment with ample natural light and fresh air
- LEED-certified sustainable building with low VOC-emitting construction materials
Responsibilities
- Emulate Advanced Adversaries: Lead comprehensive red team operations and objective-based testing to simulate real-world cyberattacks, evaluating technical controls and incident response readiness
- Conduct Multidisciplinary Testing: Perform manual and automated penetration testing across web applications, APIs, cloud environments (AWS/Azure/Kubernetes), internal/external networks, and operating systems (Windows, Active Directory, Linux)
- Audit and Attack AI Systems: Design and execute adversarial simulations against Large Language Models and machine learning pipelines to identify enterprise vulnerabilities and ensure resilience of AI applications
- Develop Custom Exploits: Create, modify, and optimize scripts and tools to bypass modern EDR agents and navigate restricted environments
- Deliver Clear Reporting: Translate complex findings into detailed remediation reports and present risk impact clearly to technical developers and non-technical stakeholders
- Collaborate for Remediation: Partner with Cyber Threat Intelligence, Incident Response, Detection Engineering and development teams to provide post-assessment debriefs, validate remediation efforts, and strengthen overall security posture
Requirements
- Adversarial Frameworks: Deep practical knowledge of MITRE ATT&CK, OWASP Top 10, and NIST
- AI & LLM Vulnerability Exploitation: Practical understanding of LLM top risks and hands-on experience with prompt injection, training data poisoning, model inversion, and API-based data exfiltration
- Commercial & Custom Tooling: Proficient use of offensive security suites and platforms such as Cobalt Strike, Burp Suite, Nessus, Nmap, Metasploit, BAS, and related tooling
- Active Directory Domain Dominance: Proven experience exploiting AD environments including Kerberos roasting, AS-REP roasting, pass-the-hash, golden/silver tickets, and domain delegation flaws
- Scripting & Automation: Strong programming skills in Python, PowerShell, Bash, or Go to automate tasks and build tooling
- Cloud Security: Experience identifying misconfigurations and exploiting AWS, Azure, or Kubernetes/Docker environments
- Professional Experience: 5+ years focusing on network penetration testing, application security testing, or red teaming
- Educational Background: Bachelor's degree in Computer Science, Cybersecurity, Information Security, or related field, or equivalent hands-on experience
- Certifications: OSCP or OSCE/OSEP; SANS/GIAC certifications (GPEN, GXPN, GWAPT); HTB CPTS
Technologies
- Python, PowerShell, Bash, Go
- Cobalt Strike, Burp Suite, Nessus, Nmap, Metasploit, BAS
- AWS, Azure, Kubernetes, Docker
- Windows, Active Directory, Linux
- Large Language Models (LLMs)
- MITRE ATT&CK, OWASP Top 10, NIST