Senior Web Application Penetration Tester
Job Description
Advance web application security with a role focused on finding vulnerabilities, validating risk, and driving practical mitigation. This Senior Web Application Penetration Tester position supports the information security program through rigorous testing and collaboration with cross-functional partners. You can work in a hybrid environment, with in-office expectations of 3+ days per week and flexibility for additional time at select locations in the U.S.
What you’ll do
- Assess the security of web applications by identifying vulnerabilities and recommending mitigation strategies to enhance resilience against cyber threats.
- Contribute toward the success of the organization’s information security program.
- Collaborate with cross-functional teams to support effective security outcomes.
Requirements
- Bachelor’s degree in Engineering or Science, or equivalent work experience.
- 8+ years of experience in information security.
- 2+ years experience in areas such as IT infrastructure management, application architecture, risk management, data architecture, middleware technology, and IT operations and project management.
- 5+ years performing web application and/or API penetration testing.
- 3-5 years or more of technical writing and documentation experience.
- Familiarity with and understanding of information security architecture.
- 3+ years experience with and understanding of IT standards, procedures, and policies.
- Subject matter expertise (5+ years) in information security technologies, including Burp Suite Pro and OWASP Zap.
- Strong knowledge of web application security principles, OWASP Top 10, and industry best practices for secure web application development.
- Hands-on manual testing experience, including SQL injection, cross-site scripting (XSS), CSRF, and other common web application vulnerabilities.
- Excellent written and verbal communication skills, with the ability to explain technical concepts to both technical and non-technical stakeholders.
Tools and focus areas
- Burp Suite Pro
- OWASP Zap
- OWASP Top 10
- SQL injection, cross-site scripting (XSS), CSRF
Helpful qualifications (preferred)
- Offensive Security Web Assessor Certification (OSWA), GIAC Web Application Penetration Tester (GWAPT), or similar (plus).
- Offensive Security Certified Professional (OSCP) (plus).
- Experience with ServiceNow Application Vulnerability Response (plus).
- Understanding and experience with change control (plus).
- Product and vendor evaluation experience (plus).
Hybrid schedule and location
Charlotte, NC (hybrid). In-office expectation is 3 or more days per week. Flexibility for other days is available at one of the following locations: Cincinnati, OH or Minneapolis, MN or Charlotte, NC.
Compensation
USD 111,605 - 131,300 per year.
Benefits
- Healthcare (medical, dental, vision)
- Basic term and optional term life insurance
- Short-term and long-term disability
- Pregnancy disability and parental leave
- 401(k) and employer-funded retirement plan
- Paid vacation (from two to five weeks depending on salary grade and tenure)
- Up to 11 paid holiday opportunities
- Adoption assistance
- Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law
Equal opportunity, background checks, and eligibility
- U.S. Bank is an Equal Opportunity Employer, considering all qualified applicants without regard to protected characteristics under applicable law.
- E-Verify: U.S. Bank participates in the U.S. Department of Homeland Security E-Verify program in all facilities located in the United States and certain U.S. territories.
- Background checks / Fair Chance: U.S. Bank will consider qualified applicants with arrest or conviction records and conducts background checks consistent with applicable local laws and federal requirements.
- Certain roles may be subject to additional regulatory requirements depending on the position.
Disability accommodations
If you need accommodations during any portion of the application or hiring process, please refer to U.S. Bank’s disability accommodations for applicants.