Senior Offensive Security Engineer – Pentester
Confidential
About this job
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We are committed to an inclusive workplace that attracts and develops exceptional talent, supports physical, emotional, and financial wellness, and recognizes and rewards performance.
The Cyber Security Assurance Division is seeking a Senior Offensive Security Engineer – Pentester to join our team of world-class offensive security professionals. In this highly-technical role, you will diligently hunt for high-risk vulnerabilities across the global technology environment, identifying exploitable weaknesses in critical systems and adopting a hacker mentality to protect against sophisticated threats.
Key responsibilities include:
- Leading and performing technical assessments of technologies, applications, and cyber security controls using reconnaissance, weaponization, delivery, and exploitation techniques.
- Adapting testing methods to evolving and emerging threats, identifying misconfigurations, and reporting on associated risks to technical and non-technical audiences.
- Partnering closely with security teams, CIO clients, and multiple lines of business to complete security assessments.
- Mentoring junior engineers, sharing knowledge and experience, and coordinating with senior leadership on development projects.
- Assisting with monitoring and response functions to help teams practice and improve their capability to respond to realistic threat actors.
Required qualifications include:
- Minimum of 5+ years of professional offensive security experience.
- Ability to critically examine organizations and systems through the perspective of a threat actor and articulate risk clearly.
- High proficiency with common penetration testing tools such as Burp Suite, Metasploit, and nmap.
- Solid understanding of voice and data networks, major operating systems, active directory, and associated peripherals.
- Knowledge of tactics, techniques, and procedures associated with malicious activity, industry classifications, and advanced vulnerability chaining.
- Proficiency in technical documentation and report delivery.
- Ability to effectively code in a programming or scripting language such as Python, Java, or C#.
Desirable skills and qualifications include industry certifications such as OSCP, GPEN, GXPN, OSED, OSEP, OSWE, OSCE, or GWAPT, as well as previous experience in the financial industry, hardware hacking, embedded systems analysis, and IoT hacking.
This is a full-time, 40-hour per week position on the 1st shift, located across multiple available office hubs including Denver, Washington D.C., Chicago, Boston, Jersey City, and Seattle. Bank of America supports an in-office culture with specific requirements for office-based attendance alongside appropriate flexibility based on role considerations.
The annualized salary range for this position is $160,000.00 to $205,000.00, with final offers determined based on experience, education, and skill set. This role is also discretionary incentive eligible, allowing participation in the annual discretionary plan based on individual, business, and company performance. Comprehensive benefits and paid time off are provided.
Apply
Hiring process handled by the employer