This position is no longer accepting applications
Closed on September 12, 2026.
This role is filled — get an email when new Information Security roles open on CybersecurityJobs.io:
J
Senior Penetration Tester
Senior
Application Security
Burp Suite
Cloud Platforms
Cybersecurity Tools
Information Security
InfoSec
Metasploit
Offensive Security
Owasp
Owasp Top Ten
Penetration Testing
Pentesting Tools
Security Standards
Security Testing
Software Security
View similar jobs
Get alerted when similar jobs are posted — set up a New Information Security jobs on CybersecurityJobs.io alert.
See other roles at JPMorganChase.
Job Description
The role focuses on planning, executing, and reporting penetration tests for high-impact banking applications, platforms, and services. You will partner with internal teams to identify vulnerabilities, support remediation, and improve the firm’s security posture.
Penetration Testing Scope
- Plan, scope, and execute penetration testing engagements across web applications, APIs, cloud platforms, infrastructure, thick-client applications, and/or mobile applications.
- Collect and validate engagement pre-requisites, ensuring required access, documentation, and approvals are in place.
- Perform manual and automated testing to identify vulnerabilities, misconfigurations, and security weaknesses using industry-standard tools and custom scripts.
Reporting and Peer Review
- Document and communicate findings through comprehensive reports including technical details, risk assessments, and actionable remediation recommendations.
- Conduct peer reviews of penetration test reports to ensure accuracy, consistency, and overall quality of deliverables.
Collaboration and Offensive Security Expertise
- Collaborate with development, infrastructure, and security teams to clarify findings and support remediation efforts.
- Provide subject matter expertise on offensive security during vulnerability resolution and related security activities.
Staying Current and Improving Methodologies
- Stay current with emerging threats, vulnerabilities, and attack techniques using threat intelligence, security research, and participation in relevant industry groups.
- Contribute to continuous improvement of penetration testing methodologies, tools, and frameworks to enhance effectiveness and alignment with firm strategy and regulatory requirements.
Required Qualifications
- 5+ years of hands-on penetration testing experience in offensive security, including proven ability to scope, execute, and report on complex engagements.
- Expertise in manual penetration testing across web, API, cloud (AWS/Azure/GCP), infrastructure, thick-client, and/or mobile applications (android/iOS), using tools such as Burp Suite, Nmap, Metasploit, and other industry-standard solutions.
- Strong understanding of security assessment methodologies such as OWASP Top Ten, NIST Cybersecurity Framework, and other relevant standards.
- Ability to identify and explain systemic security issues tied to threats, vulnerabilities, and risks, with clear remediation recommendations.
- Exceptional organizational and communication skills, including detailed technical report writing and presenting findings to both technical and non-technical stakeholders.
- Experience conducting peer reviews of penetration test reports and mentoring junior testers.
- Demonstrated commitment to continuous learning across offensive security trends, tools, and techniques.
Technologies
- Burp Suite, Nmap, Metasploit
- OWASP Top Ten, NIST Cybersecurity Framework
- AWS, Azure, GCP
- android, iOS
- Python, Java, Rust
- Windows, Unix-like operating systems
- OSWE, CREST (CRT, CCT), OSCP, OSCE
- GXPN, GWAPT, GPEN, GMOB, BSCP
Preferred Qualifications
- Knowledge of cybersecurity practices, operational risk management, and incident response methodologies within the US financial services sector, including relevant regulations, threats, and risks.
- Proficiency in penetration testing and security concepts for both Windows and Unix-like operating systems.
- Experience conducting security-focused source code reviews (e.g., Python, Java, Rust).
- Experience in reverse engineering thick-client and mobile applications to identify vulnerabilities.
- Relevant certifications such as OSWE, CREST (CRT, CCT), OSCP, OSCE, GXPN, GWAPT, GPEN, GMOB, or BSCP.
Compensation and Benefits
- Base salary determined based on the role, experience, skill set, and location.
- Commission-based pay and/or discretionary incentive compensation in the form of cash and/or forfeitable equity, based on eligible roles and individual achievements.
- Comprehensive health care coverage and on-site health and wellness centers.
- A retirement savings plan.
- Backup childcare and tuition reimbursement.
- Mental health support and financial coaching.
About the Team
- Consumer & Community Banking serves customers with services including personal banking, credit cards, mortgages, auto financing, investment advice, small business loans, and payment processing.
- The division supports digital solutions and customer satisfaction, including leadership in credit card sales and deposit growth.
Role Details
- Location: New York, NY (onsite)
- Salary: USD 156,750 - 260,000 per year
- Experience: 5+ years