Senior Manual Ethical Hacker

Job Type: Full Time
Job Location: United States
Company Name: Bank of America

Job Description:

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.

One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. We’re devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being.

Bank of America believes both in the importance of working together and offering flexibility to our employees. We use a multi-faceted approach for flexibility, depending on the various roles in our organization.

Working at Bank of America will give you a great career with opportunities to learn, grow and make an impact, along with the power to make a difference. Join us!

Key Responsibilities in order of importance:

  • Perform assigned analysis of internal and external threats on information systems and predict future threat behavior.
  • Incorporate threat actors’ tactics, techniques, and procedures into offensive security testing to identify high-value vulnerabilities/chained attacks.
  • Developing Proof-of-concepts for exploitation.
  • Perform assessments of the security, effectiveness, and practicality of multiple technology systems.
  • Leverage innovative thinking to help solve problems or introduce new ideas to processes or products applicable to offensive security.
  • Prepare and present detailed technical information for various media including documents, reports, and notifications.
  • Provide clear and practical advice regarding managing risks.
  • Learn and develop advanced technical and leadership skills, mentor Junior and Intermediate assessors in technical tradecraft and soft skills.
  • Respond to security incidents and provide technical assistance to leadership across the Information Security organization.

Required Skills:

  • Minimum of 5+ years of professional pentesting, application security or ethical hacking experience, preferably in a large, complex, enterprise environment
  • Detailed technical knowledge in at least 5 of the following areas:
    • security engineering
    • application architecture
    • authentication and security protocols
    • application session management
    • applied cryptography
    • common communication protocols
    • mobile frameworks
    • single sign-on technologies
    • exploit automation platforms
    • Web APIs
    • Cloud environments
    • LLM security

      APPLY

Apply for this position

Allowed Type(s): .pdf, .doc, .docx