
Senior Manual Ethical Hacker
Bank of America
full-time
Posted on:
Location Type: Office
Location: Denver • Colorado • District of Columbia • United States
Visit company websiteExplore more
Salary
💰 $98,000 - $134,200 per year
Job Level
Tech Stack
About the role
- Manual Ethical Hacking is part of the Application Development Security Framework Program within Bank of America’s Cyber Security Assurance Offensive Security group.
- Responsible for performing and leading ethical hacking assessments of the bank's technologies, applications, and cyber security controls.
- Key responsibilities include leading and performing research, understanding the bank's security policies, and identifying misconfigurations and vulnerabilities.
- Develop Proof-of-concepts for exploitation.
- Prepare and present detailed technical information for various media including documents, reports, and notifications.
- Mentor Junior and Intermediate assessors in technical tradecraft and soft skills.
- Respond to security incidents and provide technical assistance to leadership across the Information Security organization.
Requirements
- Minimum of 5+ years of professional pentesting, application security or ethical hacking experience, preferably in a large, complex, enterprise environment.
- Detailed technical knowledge in at least 5 of the following areas: security engineering, application architecture, authentication and security protocols, application session management, applied cryptography, common communication protocols, mobile frameworks, single sign-on technologies, exploit automation platforms, Web APIs, Cloud environments, LLM security, Mobile application analysis.
- Able to manually identify and reproduce findings, discuss remediation concepts, develop PoCs for vulnerabilities, use scripting/coding techniques, proficiently execute common penetration testing tools, triage, and support incidents, and produce high-value findings.
- Experience performing manual web application assessments i.e., must be able to simulate OWASP Top 10 vulnerabilities without the use of tools.
- Experience performing manual code reviews for security relevant issues.
- Experience working with DAST and SAST tools to identify vulnerabilities.
- Knowledge of network and Web related protocols/technologies (e.g., UNIX/LINUX, TCP/IP, Cookies).
- Experience with vulnerability assessment tools and penetration testing techniques.
Benefits
- This role is currently benefits eligible.
- We provide industry-leading benefits.
- Access to paid time off.
- Resources and support to our employees.
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
ethical hackingpentestingapplication securitysecurity engineeringapplication architectureauthentication protocolsapplied cryptographyexploit automationmanual web application assessmentsmanual code reviews
Soft Skills
mentoringtechnical tradecraftcommunicationresearchproblem-solving