Senior Manual Ethical Hacker

Bank of America Bank of America · Banking · Denver, CO +7

Senior Manual Ethical Hacker role within Bank of America's Cyber Security Assurance Offensive Security group, focusing on assessing the security resilience of the bank's applications through ethical hacking, research, and vulnerability identification.

What you'd actually do

  1. Perform assigned analysis of internal and external threats on information systems and predict future threat behavior.
  2. Incorporate threat actors' tactics, techniques, and procedures into offensive security testing to identify high-value vulnerabilities/chained attacks.
  3. Developing Proof-of-concepts for exploitation.
  4. Perform assessments of the security, effectiveness, and practicality of multiple technology systems.
  5. Leverage innovative thinking to help solve problems or introduce new ideas to processes or products applicable to offensive security.

Skills

Required

  • security engineering
  • application architecture
  • authentication and security protocols
  • application session management
  • applied cryptography
  • common communication protocols
  • mobile frameworks
  • single sign-on technologies
  • exploit automation platforms
  • Web APIs
  • Cloud environments
  • LLM security
  • Mobile application analysis
  • manual web application assessments
  • manual code reviews
  • DAST and SAST tools
  • network and Web related protocols/technologies (e.g., UNIX/LINUX, TCP/IP, Cookies)
  • vulnerability assessment tools
  • penetration testing techniques
  • programming/debugging skills
  • development frameworks
  • CVE and CWE research/reproduction
  • Threat Analysis
  • threat modelling
  • SBOM analysis
  • Innovative thinking
  • threat actor simulation
  • Technology Systems Assessment
  • Technical Documentation
  • Advisory

Nice to have

  • CEH, OSCP/OSCE/OSWE/GXPN/GPEN/GWAPT/GMOB/All Practitioner Certs [Port Swigger BSP Academy]/Cloud Cert(s)/ eWPT; eWPTX; eMAPT [INE Pentester Academy]
  • Strong programming/scripting skills
  • Frida
  • Binary analysis (disassembly skills)

What the JD emphasized

  • Minimum of 5+ years of professional pentesting, application security or ethical hacking experience, preferably in a large, complex, enterprise environment