Senior Penetration Tester (Mobile, API, Cloud)
Job Description
U.S. Bank National Association is looking for a Senior Penetration Tester to drive advanced offensive security assessments across mobile, API, web, and cloud environments. This onsite role in Irving, TX focuses on uncovering security weaknesses, validating real-world business impact through controlled exploitation, and partnering with engineering teams to strengthen the enterprise security posture.
What you’ll do
- Lead penetration testing engagements spanning mobile applications, APIs, web applications, cloud platforms, and supporting infrastructure.
- Conduct manual security testing and controlled exploitation to identify vulnerabilities, validate risk, and demonstrate business impact.
- Evaluate application security against frameworks including OWASP Top 10, OWASP API Security Top 10, OWASP MASVS, and MASTG.
- Assess security controls within AWS, Azure, containerized environments, and Kubernetes platforms.
- Perform threat modeling and risk assessments to prioritize testing activities and remediation focus.
- Produce detailed security reporting with vulnerability analysis, risk ratings, attack paths, and remediation recommendations.
- Build and improve security testing tools, scripts, and automation to increase operational effectiveness and assessment coverage.
- Mentor junior testers, support knowledge-sharing, and collaborate with stakeholders to improve enterprise security practices.
What you bring
- Bachelor’s degree in Engineering or Science, or equivalent work experience.
- Eight or more years of experience in information security.
- Two or more years of experience in IT infrastructure management, application architecture, risk management, data architecture, middleware technology, and IT operations and project management.
- 8+ years of information security experience with proven offensive security and penetration testing expertise.
- 5+ years of hands-on mobile application security testing for Android and iOS platforms.
- Strong knowledge of OWASP Top 10, API Security Top 10, SANS Top 25, OWASP MASVS, and MASTG.
- Advanced experience with manual penetration testing, exploit chaining, business logic testing, and access control assessments.
- Expert proficiency with Burp Suite Pro, Postman, Insomnia, Nmap, Metasploit, Kali Linux, and related security testing tools.
- Experience assessing security within AWS, Azure, Kubernetes, containerized environments, and cloud-native security platforms.
- Strong scripting and automation skills using Python, PowerShell, Bash, Ruby, or Go.
- Deep understanding of HTTP/S, REST APIs, OAuth, SAML, JWT, TCP/IP, DNS, firewalls, and IDS/IPS, plus application architecture.
- Knowledge of AI and machine learning security risks, including prompt injection, insecure model access, API abuse, and data leakage concerns.
- Familiarity with security and compliance frameworks including PCI-DSS, HIPAA, NIST 800-53, ISO 27001, FedRAMP, and other security compliance frameworks.
- Excellent communication skills to present findings to technical teams, business stakeholders, and executive leadership.
Tools and technologies you’ll work with
- OWASP Top 10, OWASP API Security Top 10, OWASP MASVS, MASTG
- AWS, Azure, Kubernetes, containerized environments
- Burp Suite Pro, Postman, Insomnia, Nmap, Metasploit, Kali Linux
- Python, PowerShell, Bash, Ruby, Go
- HTTP/S, REST APIs, OAuth, SAML, JWT, TCP/IP, DNS, firewalls, IDS/IPS
- PCI-DSS, HIPAA, NIST 800-53, ISO 27001, FedRAMP, SANS Top 25
- AI and machine learning security
Compensation and location
- Location: Irving, TX (onsite)
- Salary: USD 119,765 to 140,900 per year
- Onsite expectation: Working from a U.S. Bank location three (3) or more days per week is required.
Benefits
- Healthcare (medical, dental, vision)
- Basic term and optional term life insurance
- Short-term and long-term disability
- Pregnancy disability and parental leave
- 401(k) and employer-funded retirement plan
- Paid vacation (from two to five weeks depending on salary grade and tenure)
- Up to 11 paid holiday opportunities
- Adoption assistance
- Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law