J
Senior Penetration Tester - Web & Hardware/IoT
Senior
Application Security
Cloud Platforms
Cybersecurity Analysis
Cybersecurity Tools
Device Testing
Embedded Testing
Ethical Hacking
Information Security
InfoSec
Metasploit
Offensive Security
Owasp
Owasp Top Ten
Penetration Testing
Security
Security Standards
Security Testing
Vulnerability Assessment
Job Description
As an Assessments & Exercises Vice President, you will plan, execute, and report penetration tests for critical banking applications and platforms, with a primary focus on web, APIs, cloud, and related environments, and a limited scope extending to banking hardware and IoT endpoints. This onsite role is based in Chicago, IL.
Key Responsibilities
- Plan, scope, and execute penetration testing engagements across web applications, APIs, cloud platforms, infrastructure, thick-client, and/or mobile applications, with a primary focus on thick-client and/or mobile application testing.
- Conduct security assessments of banking hardware and connected/IoT technologies, including ATMs, Point of Sale (POS) devices, and other embedded endpoints.
- Collect and validate engagement pre-requisites, including access, documentation, and approvals, and manage lab or onsite testing logistics and device access when applicable.
- Carry out manual and automated testing to identify vulnerabilities, misconfigurations, and security weaknesses, using industry-standard tools and custom scripts.
- Produce comprehensive penetration test reports that document technical details, risk assessments, and actionable remediation recommendations.
- Perform peer reviews of penetration test reports to support accuracy, consistency, and quality of deliverables.
- Partner with development, infrastructure, security, and device or product engineering teams to clarify findings, support remediation, and provide offensive security subject matter expertise.
- Keep current on emerging threats, vulnerabilities, and attack techniques through threat intelligence, security research, and active participation in relevant industry groups.
- Help improve penetration testing methodologies, tools, and frameworks to enhance effectiveness and alignment with firm strategy and regulatory requirements.
Required Qualifications
- 5+ years of hands-on penetration testing experience in offensive security, including demonstrated ability to scope, execute, and report on complex engagements.
- Expertise in manual penetration testing of web, API, cloud (AWS/Azure/GCP), infrastructure, thick-client, and/or mobile (Android/iOS) applications, including use of industry-standard tools such as Burp Suite, Nmap, and Metasploit.
- Working knowledge of testing approaches for connected devices/IoT and purpose-built banking devices (for example, ATMs and POS), including common attack surfaces such as exposed services, remote administration paths, authentication and authorization, hardening gaps, and insecure configurations.
- Strong familiarity with security assessment methodologies including OWASP Top Ten and the NIST Cybersecurity Framework, along with other relevant standards.
- Ability to identify and clearly articulate systemic security issues tied to threats, vulnerabilities, and risks, along with actionable remediation recommendations.
- Strong organizational and communication skills, including capability to write detailed technical reports and present findings to both technical and non-technical stakeholders.
- Experience conducting peer reviews of penetration test reports and mentoring junior testers.
- A continuous learning mindset to keep up with the latest offensive security trends, tools, and techniques.
Technologies
- Burp Suite
- Nmap
- Metasploit
- OWASP Top Ten
- NIST Cybersecurity Framework
- AWS, Azure, GCP
- Android, iOS
Preferred Qualifications
- Knowledge of cybersecurity practices, operational risk management, and incident response methodologies within the US financial services sector, including relevant regulations, threats, and risks.
- Proficiency in penetration testing and security concepts for both Windows and Unix-like operating systems.
- Experience conducting security-focused source code reviews using languages such as Python, Java, and Rust.
- Experience in reverse engineering thick-client and mobile applications to identify vulnerabilities.
- Experience assessing embedded systems and IoT devices in lab or onsite environments, including device interface review, firmware/configuration analysis, and network or service exposure testing relevant to ATM/POS ecosystems.
- Relevant certifications including OSWE, CREST (CRT, CCT), OSCP, OSCE, GXPN, GWAPT, GPEN, GMOB, or BSCP.
Location and Salary
Location: Chicago, IL (onsite)
Compensation: USD 133,000 - 225,000 per yearly
Additional Locations
This position is also open in:
- New York, NY
- Atlanta, FL
- Plano, TX
- Columbus, OH
- McLean, VA
- Wilmington, DE
- Jersey City, NJ
- Tampa, FL
- Brooklyn, NY
- Houston, TX
- Washington, DC
Benefits
- Base salary determined based on the role, experience, skill set, and location
- Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation
- Paid in the form of cash and/or forfeitable equity
- Comprehensive health care coverage
- On-site health and wellness centers
- Retirement savings plan
- Backup childcare
- Tuition reimbursement
- Mental health support
- Financial coaching
Position Opening
This role requires a minimum of 5 years of relevant experience.
Similar Jobs
J