Manual Ethical Hacker

Bank of America Bank of America · Banking · Denver, CO +7

This role performs manual ethical hacking and application security assessments within Bank of America's Cyber Security Assurance group. Responsibilities include researching threats, identifying vulnerabilities and misconfigurations, and reporting on associated risks to protect the bank's applications and technologies. The role requires a minimum of 4 years of professional pentesting or ethical hacking experience and detailed technical knowledge in security engineering, application architecture, and related protocols.

What you'd actually do

  1. Perform assigned analysis of internal and external threats on information systems and predict future threat behavior
  2. Incorporate threat actors' tactics, techniques, and procedures into offensive security testing
  3. Perform assessments of the security, effectiveness, and practicality of multiple technology systems
  4. Leverage innovative thinking to help solve problems or introduce new ideas to processes or products applicable to offensive security.
  5. Prepare and present detailed technical information for various media including documents, reports, and notifications

Skills

Required

  • pentesting
  • application security
  • ethical hacking
  • security engineering
  • application architecture
  • authentication and security protocols
  • application session management
  • applied cryptography
  • common communication protocols
  • mobile frameworks
  • single sign-on technologies
  • exploit automation platforms
  • RESTful web services
  • SQL injection
  • XSS attack
  • manual code reviews
  • SAST tools
  • vulnerability assessment tools
  • penetration testing techniques
  • programming
  • debugging
  • IBM AppScan
  • Burp
  • SQL Map
  • Threat Analysis
  • Innovative Thinking
  • Technology Systems Assessment
  • Technical Documentation
  • Advisory

Nice to have

  • CISSP
  • CEH
  • OSCP
  • OSWE
  • GPEN
  • PenTest+
  • scripting
  • Mobile application analysis
  • Frida
  • Binary analysis
  • disassembly skills

What the JD emphasized

  • Minimum of 4 years of professional pentesting, application security or ethical hacking experience, preferably in a large, complex, enterprise environment
  • Detailed technical knowledge in at least 3 of the following areas: security engineering; application architecture; authentication and security protocols; application session management; applied cryptography; common communication protocols; mobile frameworks; single sign-on technologies; exploit automation platforms; RESTful web services
  • SQL injection/XSS attack without the use of tools
  • Experience performing manual code reviews for security relevant issues
  • Experience performing manual web application assessments i.e., must be able to simulate a