CybersecurityJobs.io
← Back to all jobs

Job Description

As an Assessments & Exercises Vice President, you will plan, execute, and report penetration tests for critical banking applications and platforms, with a primary focus on web, APIs, cloud, and related environments, and a limited scope extending to banking hardware and IoT endpoints. This onsite role is based in Chicago, IL.

Key Responsibilities

  • Plan, scope, and execute penetration testing engagements across web applications, APIs, cloud platforms, infrastructure, thick-client, and/or mobile applications, with a primary focus on thick-client and/or mobile application testing.
  • Conduct security assessments of banking hardware and connected/IoT technologies, including ATMs, Point of Sale (POS) devices, and other embedded endpoints.
  • Collect and validate engagement pre-requisites, including access, documentation, and approvals, and manage lab or onsite testing logistics and device access when applicable.
  • Carry out manual and automated testing to identify vulnerabilities, misconfigurations, and security weaknesses, using industry-standard tools and custom scripts.
  • Produce comprehensive penetration test reports that document technical details, risk assessments, and actionable remediation recommendations.
  • Perform peer reviews of penetration test reports to support accuracy, consistency, and quality of deliverables.
  • Partner with development, infrastructure, security, and device or product engineering teams to clarify findings, support remediation, and provide offensive security subject matter expertise.
  • Keep current on emerging threats, vulnerabilities, and attack techniques through threat intelligence, security research, and active participation in relevant industry groups.
  • Help improve penetration testing methodologies, tools, and frameworks to enhance effectiveness and alignment with firm strategy and regulatory requirements.

Required Qualifications

  • 5+ years of hands-on penetration testing experience in offensive security, including demonstrated ability to scope, execute, and report on complex engagements.
  • Expertise in manual penetration testing of web, API, cloud (AWS/Azure/GCP), infrastructure, thick-client, and/or mobile (Android/iOS) applications, including use of industry-standard tools such as Burp Suite, Nmap, and Metasploit.
  • Working knowledge of testing approaches for connected devices/IoT and purpose-built banking devices (for example, ATMs and POS), including common attack surfaces such as exposed services, remote administration paths, authentication and authorization, hardening gaps, and insecure configurations.
  • Strong familiarity with security assessment methodologies including OWASP Top Ten and the NIST Cybersecurity Framework, along with other relevant standards.
  • Ability to identify and clearly articulate systemic security issues tied to threats, vulnerabilities, and risks, along with actionable remediation recommendations.
  • Strong organizational and communication skills, including capability to write detailed technical reports and present findings to both technical and non-technical stakeholders.
  • Experience conducting peer reviews of penetration test reports and mentoring junior testers.
  • A continuous learning mindset to keep up with the latest offensive security trends, tools, and techniques.

Technologies

  • Burp Suite
  • Nmap
  • Metasploit
  • OWASP Top Ten
  • NIST Cybersecurity Framework
  • AWS, Azure, GCP
  • Android, iOS

Preferred Qualifications

  • Knowledge of cybersecurity practices, operational risk management, and incident response methodologies within the US financial services sector, including relevant regulations, threats, and risks.
  • Proficiency in penetration testing and security concepts for both Windows and Unix-like operating systems.
  • Experience conducting security-focused source code reviews using languages such as Python, Java, and Rust.
  • Experience in reverse engineering thick-client and mobile applications to identify vulnerabilities.
  • Experience assessing embedded systems and IoT devices in lab or onsite environments, including device interface review, firmware/configuration analysis, and network or service exposure testing relevant to ATM/POS ecosystems.
  • Relevant certifications including OSWE, CREST (CRT, CCT), OSCP, OSCE, GXPN, GWAPT, GPEN, GMOB, or BSCP.

Location and Salary

Location: Chicago, IL (onsite)

Compensation: USD 133,000 - 225,000 per yearly

Additional Locations

This position is also open in:

  • New York, NY
  • Atlanta, FL
  • Plano, TX
  • Columbus, OH
  • McLean, VA
  • Wilmington, DE
  • Jersey City, NJ
  • Tampa, FL
  • Brooklyn, NY
  • Houston, TX
  • Washington, DC

Benefits

  • Base salary determined based on the role, experience, skill set, and location
  • Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation
  • Paid in the form of cash and/or forfeitable equity
  • Comprehensive health care coverage
  • On-site health and wellness centers
  • Retirement savings plan
  • Backup childcare
  • Tuition reimbursement
  • Mental health support
  • Financial coaching

Position Opening

This role requires a minimum of 5 years of relevant experience.

Similar Jobs