CybersecurityJobs.io
← Back to all jobs

Job Description

Truist Bank is looking for a Senior Penetration Tester to lead advanced penetration testing and security assessments across enterprise technologies, with a primary focus on mainframe (z/OS) environments. This role blends hands-on offensive testing with clear, defensible reporting, partnering with application teams and mainframe engineers to reduce risk through repeatable methodologies, tooling, and automation.

What you will do

  • Run black box, grey box, and assumed breach penetration tests of enterprise z/OS environments, including USS (Unix System Services), external security managers such as RACF, ACF2, and Top Secret, and key subsystems like CICS, IMS, db2, and MQ.
  • Assess batch processing and execution paths using JCL and JES2, along with TSO/ISPF, and test network facing services including TN3270, FTP, Z/OS Connect, and Rest APIs, plus NJE.
  • Use manual techniques and custom scripting with REXX, JCL, Assembler, and Python, and employ offensive tooling to enumerate users and resources, map datasets, identify unprotected spool and job output, and exploit misconfigured CICS transactions and insecure interfaces.
  • Evaluate exploitability and business impact, using judgment to determine finding severity and risk.
  • Document findings with reproduction steps, supporting evidence, impact statements, and practical remediation recommendations.
  • Present and defend technical findings in discussions with application teams, mainframe engineers, technology leaders, risk partners, and other stakeholders.
  • Perform validation and retesting to confirm remediation and risk reduction, and maintain testing evidence supporting audit, regulatory, and compliance needs such as PCI DSS and SOX.
  • Partner with internal and external testing teams to improve mainframe testing coverage, methodologies, playbooks, tooling, automation, and repeatable processes.
  • Conduct peer reviews of penetration testing reports and provide technical guidance and mentorship to other security professionals.
  • Keep current on mainframe attack techniques, security controls, platform changes, offensive security practices, and relevant industry threats.

Required qualifications

  • Bachelor’s degree or equivalent education, training, and work-related experience.
  • Minimum 7 years of experience in security engineering or related cybersecurity roles.
  • Deep specialized knowledge of cybersecurity principles, theories, and concepts.
  • Proven experience applying software development lifecycle security practices.
  • Deep knowledge of threat modeling, security testing, and penetration testing.
  • Experience implementing and managing complex information security technologies.

Technologies

  • z/OS; USS (Unix System Services); RACF; ACF2; Top Secret
  • CICS; IMS; db2; MQ; JCL; JES2; TSO/ISPF
  • TN3270; FTP; Z/OS Connect; Rest APIs; NJE
  • REXX; Assembler; Python

Compensation and workstyle

Annual base salary: $140,000 - $180,000. Additional incentive pay is available.

  • Location: Charlotte, NC (remote)
  • Telecommuting/Remote workstyle: Telecommuting/Remote workstyle may be considered for well-qualified individuals located outside of the Truist footprint, with work hours supporting Eastern Standard Time.
  • Work shift: 1st shift (United States of America)
  • Language: English (Required)

Benefits

  • All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, with specific eligibility determined by the division offering the position.
  • Medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan.
  • No less than 10 days of vacation (prorated based on date of hire and full-time or part-time status) during the first year, along with 10 sick days (also prorated), plus paid holidays.
  • Depending on position and division, may be eligible for a defined benefit pension plan, restricted stock units, and/or a deferred compensation plan.

Visa and employment authorization

Truist will not sponsor an applicant for work visa status or employment authorization for this opportunity, and will not offer immigration-related support for this position.

Preferred qualifications

  • Five or more years of penetration testing, red team, offensive security, vulnerability research, or related cybersecurity experience.
  • Hands-on experience assessing mainframe environments including z/OS and security components such as RACF, ACF2, or Top Secret.
  • Knowledge of mainframe architecture, identity and access management, privileged access, JCL, TSO/ISPF, CICS, Db2, network services, system configuration, and security hardening.
  • Experience identifying and validating mainframe vulnerabilities, misconfigurations, excessive access, insecure interfaces, and attack paths between mainframe and distributed environments.
  • Strong technical writing and communication skills, including the ability to explain and defend technical findings to technical and non-technical audiences.
  • Ability to independently manage multiple testing engagements, adjust approach as priorities and requirements evolve, and drive work to completion.
  • Experience developing scripts, automation, or AI-enabled tooling to streamline testing activities and improve repeatable processes.
  • Experience in banking, financial services, or another highly regulated industry.
  • Relevant offensive security certifications such as OSCP, OSEP, OSWE, GPEN, GXPN, or equivalent credentials.

Similar Jobs