Svp; Senior Offensive Security Professional

Bank of America Bank of America · Banking · Charlotte, NC

This role is for a Senior Offensive Security Professional at Bank of America, focusing on identifying and mitigating security vulnerabilities in web and mobile applications. Responsibilities include manual assessments, code analysis, using various security tools, and collaborating with leadership on risk management initiatives. The role requires significant experience in penetration testing, vulnerability assessment, and secure coding practices within a financial services context.

What you'd actually do

  1. Monitor metrics, ensure process adherence, review and revise process standards, engage with stakeholders, handle process level escalations & automation of tasks.
  2. Create and maintain multiple tools which support the execution of the function and collectively save the organization thousands of person hours per year.
  3. Coordinate with senior leadership on development projects.
  4. Assist the application stakeholders understand the vulnerabilities identified and articulate the risk in salient business terms.
  5. Partner with information security and technology senior leadership on application security risk management initiatives.

Skills

Required

  • Applied Computer Science, CIS, MIS, Engineering, or related Bachelor's degree or equivalent
  • 5 years of IT experience
  • Manual vulnerability identification and reproduction
  • Developing Proofs of Concept (PoCs)
  • Scripting/coding techniques
  • Penetration testing tools
  • Triage and incident support
  • High value finding production
  • Manual web application assessments
  • Simulating OWASP Top 10 vulnerabilities
  • Source code analysis (Java, .Net, Python, Android, Objective C, Swift)
  • Vulnerability assessment tools (Checkmarx, Burp, Invicti, SOAP UI)
  • Penetration testing techniques
  • Exploit crafting
  • Programming/debugging skills
  • Development frameworks
  • CVE and CWE research/reproduction

What the JD emphasized

  • 5 years of progressively responsible experience
  • 5 years of experience in each of the following
  • Manually identifying and reproducing findings, discussing remediation concepts, developing PoCs for vulnerabilities, using scripting/coding techniques, proficiently executing common penetration testing tools, triage, and support incidents, and producing high value findings
  • Performing manual web application assessments including simulating a OWASP Top 10 vulnerabilities without the use of tools
  • Assessing & analyzing source codes for web and mobile applications for identifying vulnerabilities using Java, .Net, Python, Android, Objective C, Swift, etc
  • Utilizing vulnerability assessment tools including Checkmarx, Burp, Invicti, SOAP UI, and penetration testing techniques for exploring, corelating & crafting successful exploits as part of the correlational effort pertaining to source code and manual ethical hacking vulnerability assessments
  • Using solid programming/debugging skills, development frameworks, CVE and CWE research/reproduction towards identifying security vulnerabilities in web and mobile applications and corelate in manual ethical hacking vulnerability assessment