This position is no longer accepting applications
Closed on September 13, 2026.
This role is filled — get an email when new Information Security roles open on CybersecurityJobs.io:
Senior Penetration Tester - Web & Hardware/IoT
Get alerted when similar jobs are posted — set up a New Information Security jobs on CybersecurityJobs.io alert.
See other roles at JPMorganChase.
Job Description
As an Assessments & Exercises Vice President, you will plan, execute, and report penetration tests for critical banking applications and platforms, with a primary focus on web, APIs, cloud, and related environments, and a limited scope extending to banking hardware and IoT endpoints. This onsite role is based in Chicago, IL.
Key Responsibilities
- Plan, scope, and execute penetration testing engagements across web applications, APIs, cloud platforms, infrastructure, thick-client, and/or mobile applications, with a primary focus on thick-client and/or mobile application testing.
- Conduct security assessments of banking hardware and connected/IoT technologies, including ATMs, Point of Sale (POS) devices, and other embedded endpoints.
- Collect and validate engagement pre-requisites, including access, documentation, and approvals, and manage lab or onsite testing logistics and device access when applicable.
- Carry out manual and automated testing to identify vulnerabilities, misconfigurations, and security weaknesses, using industry-standard tools and custom scripts.
- Produce comprehensive penetration test reports that document technical details, risk assessments, and actionable remediation recommendations.
- Perform peer reviews of penetration test reports to support accuracy, consistency, and quality of deliverables.
- Partner with development, infrastructure, security, and device or product engineering teams to clarify findings, support remediation, and provide offensive security subject matter expertise.
- Keep current on emerging threats, vulnerabilities, and attack techniques through threat intelligence, security research, and active participation in relevant industry groups.
- Help improve penetration testing methodologies, tools, and frameworks to enhance effectiveness and alignment with firm strategy and regulatory requirements.
Required Qualifications
- 5+ years of hands-on penetration testing experience in offensive security, including demonstrated ability to scope, execute, and report on complex engagements.
- Expertise in manual penetration testing of web, API, cloud (AWS/Azure/GCP), infrastructure, thick-client, and/or mobile (Android/iOS) applications, including use of industry-standard tools such as Burp Suite, Nmap, and Metasploit.
- Working knowledge of testing approaches for connected devices/IoT and purpose-built banking devices (for example, ATMs and POS), including common attack surfaces such as exposed services, remote administration paths, authentication and authorization, hardening gaps, and insecure configurations.
- Strong familiarity with security assessment methodologies including OWASP Top Ten and the NIST Cybersecurity Framework, along with other relevant standards.
- Ability to identify and clearly articulate systemic security issues tied to threats, vulnerabilities, and risks, along with actionable remediation recommendations.
- Strong organizational and communication skills, including capability to write detailed technical reports and present findings to both technical and non-technical stakeholders.
- Experience conducting peer reviews of penetration test reports and mentoring junior testers.
- A continuous learning mindset to keep up with the latest offensive security trends, tools, and techniques.
Technologies
- Burp Suite
- Nmap
- Metasploit
- OWASP Top Ten
- NIST Cybersecurity Framework
- AWS, Azure, GCP
- Android, iOS
Preferred Qualifications
- Knowledge of cybersecurity practices, operational risk management, and incident response methodologies within the US financial services sector, including relevant regulations, threats, and risks.
- Proficiency in penetration testing and security concepts for both Windows and Unix-like operating systems.
- Experience conducting security-focused source code reviews using languages such as Python, Java, and Rust.
- Experience in reverse engineering thick-client and mobile applications to identify vulnerabilities.
- Experience assessing embedded systems and IoT devices in lab or onsite environments, including device interface review, firmware/configuration analysis, and network or service exposure testing relevant to ATM/POS ecosystems.
- Relevant certifications including OSWE, CREST (CRT, CCT), OSCP, OSCE, GXPN, GWAPT, GPEN, GMOB, or BSCP.
Location and Salary
Location: Chicago, IL (onsite)
Compensation: USD 133,000 - 225,000 per yearly
Additional Locations
This position is also open in:
- New York, NY
- Atlanta, FL
- Plano, TX
- Columbus, OH
- McLean, VA
- Wilmington, DE
- Jersey City, NJ
- Tampa, FL
- Brooklyn, NY
- Houston, TX
- Washington, DC
Benefits
- Base salary determined based on the role, experience, skill set, and location
- Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation
- Paid in the form of cash and/or forfeitable equity
- Comprehensive health care coverage
- On-site health and wellness centers
- Retirement savings plan
- Backup childcare
- Tuition reimbursement
- Mental health support
- Financial coaching
Position Opening
This role requires a minimum of 5 years of relevant experience.