Bank of America

Senior Manual Ethical Hacker

Bank of America

full-time

Posted on:

Location Type: Office

Location: DenverColoradoDistrict of ColumbiaUnited States

Visit company website

Explore more

AI Apply
Apply

Salary

💰 $98,000 - $134,200 per year

Job Level

About the role

  • Manual Ethical Hacking is part of the Application Development Security Framework Program within Bank of America’s Cyber Security Assurance Offensive Security group.
  • Responsible for performing and leading ethical hacking assessments of the bank's technologies, applications, and cyber security controls.
  • Key responsibilities include leading and performing research, understanding the bank's security policies, and identifying misconfigurations and vulnerabilities.
  • Develop Proof-of-concepts for exploitation.
  • Prepare and present detailed technical information for various media including documents, reports, and notifications.
  • Mentor Junior and Intermediate assessors in technical tradecraft and soft skills.
  • Respond to security incidents and provide technical assistance to leadership across the Information Security organization.

Requirements

  • Minimum of 5+ years of professional pentesting, application security or ethical hacking experience, preferably in a large, complex, enterprise environment.
  • Detailed technical knowledge in at least 5 of the following areas: security engineering, application architecture, authentication and security protocols, application session management, applied cryptography, common communication protocols, mobile frameworks, single sign-on technologies, exploit automation platforms, Web APIs, Cloud environments, LLM security, Mobile application analysis.
  • Able to manually identify and reproduce findings, discuss remediation concepts, develop PoCs for vulnerabilities, use scripting/coding techniques, proficiently execute common penetration testing tools, triage, and support incidents, and produce high-value findings.
  • Experience performing manual web application assessments i.e., must be able to simulate OWASP Top 10 vulnerabilities without the use of tools.
  • Experience performing manual code reviews for security relevant issues.
  • Experience working with DAST and SAST tools to identify vulnerabilities.
  • Knowledge of network and Web related protocols/technologies (e.g., UNIX/LINUX, TCP/IP, Cookies).
  • Experience with vulnerability assessment tools and penetration testing techniques.
Benefits
  • This role is currently benefits eligible.
  • We provide industry-leading benefits.
  • Access to paid time off.
  • Resources and support to our employees.
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills & Tools
ethical hackingpentestingapplication securitysecurity engineeringapplication architectureauthentication protocolsapplied cryptographyexploit automationmanual web application assessmentsmanual code reviews
Soft Skills
mentoringtechnical tradecraftcommunicationresearchproblem-solving