Senior Offensive Security Engineer - Pentester

Bank of America Bank of America · Banking · Denver, CO +7

Senior Offensive Security Engineer (Pentester) at Bank of America, focusing on identifying high-risk vulnerabilities in global technology environments. Requires deep technical knowledge, understanding of threats, and proficiency in penetration testing techniques and tools. Responsibilities include leading assessments, research, reporting, and mentoring junior engineers.

What you'd actually do

  1. diligently hunt for high-risk vulnerabilities across the bank’s global technology environment.
  2. lead and participate in collaborative, technical assessments that leverage a wide range of penetration testing techniques (reconnaissance, weaponization, delivery, exploitation) to identify and prove the concept of high-risk vulnerabilities across a variety of technologies.
  3. leading and performing assessments of the bank's technologies, applications, and cyber security controls while adapting testing methods to evolving and emerging threats.
  4. coordinate with senior leadership on development projects, share your knowledge and experience by mentoring junior engineers, and assist with monitoring and response functions, so those teams can practice and improve their capability to respond to a realistic threat actor.

Skills

Required

  • 5+ years of professional offensive security experience
  • Critical examination of organizations and systems from a threat actor perspective
  • Articulate risk in clear, precise terms to technical and non-technical audiences
  • Proficiency with penetration testing tools (Burp Suite, Metasploit, nmap, etc.)
  • Solid understanding of voice and data networks, major operating systems, active directory
  • Knowledge of tactics, techniques, and procedures associated with malicious activity
  • Understanding of industry classifications and frameworks
  • Ability to chain vulnerabilities in advanced exploitation
  • Proficiency in report delivery and technical documentation of vulnerabilities
  • Proficiency in a programming or scripting language (Python, Java, C#, etc.)

Nice to have

  • OSCP
  • GPEN
  • GXPN
  • OSED
  • OSEP
  • OSWE
  • OSCE
  • GWAPT
  • Ability to work remotely if/when necessary
  • Previous experience working in the financial industry
  • Experience with hardware hacking, embedded systems analysis, and IoT hacking

What the JD emphasized

  • identify exploitable vulnerabilities in critical systems
  • highly-technical role
  • broad technical knowledge
  • deep understanding of threats
  • hacker mentality
  • strong problem-solving skills
  • practical demonstration of technical competency
  • lateral thinking
  • evolving and emerging threats
  • must be able to critically examine an organization and system through the perspective of a threat actor
  • must be very proficient with the common tools associated with penetration testing
  • Must have a solid understanding of voice and data networks, major operating systems, active directory
  • Must demonstrate knowledge of tactics, techniques, and procedures associated with malicious activity
  • ability to chain vulnerabilities in the advanced exploitation of systems
  • Must be proficient in report delivery and technical documentation of vulnerabilities
  • Must be able to effectively code in a programming or scripting language