Talent.com
Sr Product Security Engineer / Pen Tester (Hybrid - Pleasanton, CA)
Sr Product Security Engineer / Pen Tester (Hybrid - Pleasanton, CA)Blackhawk Network • Pleasanton, CA, United States
[error_messages.no_longer_accepting]
Sr Product Security Engineer / Pen Tester (Hybrid - Pleasanton, CA)

Sr Product Security Engineer / Pen Tester (Hybrid - Pleasanton, CA)

Blackhawk Network • Pleasanton, CA, United States
[job_card.variable_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

About Blackhawk Network

Today, through BHN’s single global platform, businesses of all kinds can tap into the world’s largest network of branded payment solutions. BHN helps businesses grow revenue, increase loyalty, motivate and reward their teams, disburse funds and engage consumers. Branded payment solutions include the issuance and distribution of gift cards, egifts, corporate payouts and rewards, along with the technology to deliver these products in seamless, integrated ways. BHN’s network spans the globe with more than 400,000 consumer touchpoints. Learn more at BHN.com.

Overview

We’re hiring a Senior Penetration Tester to help defend our fintech platform against large-scale payment fraud, carding attacks, and other financially motivated threats. You’ll lead offensive security assessments targeting our transaction systems, authentication flows, and APIs — with a heavy focus on automation and scalability. Your work will directly impact our fraud defenses, detection strategy, and customer trust.

This is a highly technical, hands-on role for someone who thrives in a fast-paced, high-stakes fintech environment.

This position will be Hybrid (Tuesdays & Wednesdays) out of our Pleasanton, CA office.

Responsibilities

  • Lead penetration testing engagements focused on payment abuse, transaction manipulation, and business logic exploitation.
  • Design and execute automated attack simulations to test our defenses against :
  • Carding and BIN attacks
  • Credential stuffing and account takeovers
  • Checkout and payment flow abuse
  • API-level enumeration and fraud
  • Build custom tooling and frameworks to mimic the behavior of real-world fraudsters and cybercriminals.
  • Partner with fraud engineering, product security, and risk teams to identify weak points in our controls, detection systems, and architecture.
  • Conduct threat modeling and red teaming exercises related to payments, authentication, and user account abuse.
  • Document findings in technical reports with clear risk impact, exploitability, and remediation guidance.
  • Mentor junior testers and contribute to a culture of security innovation and continuous improvement.

Qualifications

  • 7+ years of experience in offensive security, penetration testing, or red teaming.
  • Strong background in payment systems, financial fraud tactics, and transaction-level attack surfaces.
  • Fluency in scripting and automation (e.g., Python, JavaScript, Go, Bash) to simulate attacker workflows at scale.
  • Familiarity with tools like Burp Suite Pro, Selenium, Scapy, ffuf, SQLMap, Metasploit, and bot automation frameworks.
  • In-depth knowledge of fintech technologies (e.g., tokenized payments, card vaulting, 3DS, ACH, real-time payment APIs).
  • Solid grasp of common attacker techniques : carding, fake identity generation, bypassing rate limits, evading fraud filters, and abusing web / app logic.
  • Strong communication skills for explaining findings to both technical and non-technical audiences.
  • Certifications : OSCP, OSEP, GWAPT, GPEN, GCPN, GXPN, GX-PT, CPSA / CRSA by CREST, CHECK, or TIGER.
  • Prior experience in a fintech, digital banking, or payment gateway environment.
  • Familiarity with OWASP Automated Threats, PCI DSS, MITRE ATT&CK for Financial Services, or fraud detection systems.
  • Experience building or testing real-time risk scoring engines and fraud defense pipelines.
  • We seek candidates who not only demonstrate curiosity and adaptability in emerging technologies but have also successfully implemented and utilized AI tools to enhance their work, improve processes, or deliver measurable results.  Our teams embrace continuous learning and the thoughtful integration of AI to create meaningful impact – for our employees and the future of work.

    Benefits

    Salary Range for California Residents Only : $157,030.00 - $212,000.00

    Pay is based on several factors including but not limited to education, work experience, certifications, etc. In addition to your salary, Blackhawk Network offers benefits including 401k with employer match, medical, dental, vision, 12 paid holidays in the year 2025, 1 hour of sick pay accrual for every 30 hours worked, parental leave, life insurance, disability insurance, accident and illness insurance, health and dependent care flexible spending accounts, wellness benefits, and flexible time off for all full-time employees.

    EEO Statement

    Blackhawk Network provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.  Blackhawk Network believes that diversity leads to strength. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.

    Blackhawk Network encourages applicants with previous criminal records to apply to all positions and, pursuant to the San Francisco and Los Angeles Fair Chance Acts (and other “Fair Chance” laws), Blackhawk Network will consider for employment qualified applicants with arrest and conviction records. For Philadelphia applicants or jobs, please see a copy of Philadelphia’s ordinance on this topic by clicking this link :

    [job_alerts.create_a_job]

    Sr Security Engineer • Pleasanton, CA, United States

    [internal_linking.related_jobs]
    Sr. Full Stack Software Engineer, Security (Starlink)

    Sr. Full Stack Software Engineer, Security (Starlink)

    職位申請 • Sunnyvale, California, USA
    [job_card.full_time] +1
    SpaceX was founded under the belief that a future where humanity is out exploring the stars is fundamentally more exciting than one where we are not. Today SpaceX is actively developing the technolo...[show_more]
    [last_updated.last_updated_1_day] • [promoted]
    Senior & Lead Application Security Engineer (Hayward)

    Senior & Lead Application Security Engineer (Hayward)

    Verticalmove, Inc • Hayward, CA, US
    [job_card.part_time]
    ATTN - PLEASE READ CAREFULLY : WE CAN NOT SPONSOR NEW VISAS OR TRANSFER EXISTING VISAS.AT THIS TIME WE'RE ONLY CONSIDERING US CITIZENS OR GC HOLDERS. WERE LOOKING FOR SOMEONE WHO HAS SIGNIFICANT APPL...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    AppSec Trailblazer : Principal Product Security Engineer

    AppSec Trailblazer : Principal Product Security Engineer

    Elastic • Mountain View, CA, United States
    [job_card.full_time]
    A leading technology company in Mountain View, CA is searching for a Principal Product Security Engineer to enhance security practices across its products. This role involves acting as a principal a...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Sr Security Engineer

    Sr Security Engineer

    Uber • Sunnyvale, CA, US
    [job_card.full_time]
    About the Role We are seeking a talented and experienced Sr Security Engineer to join our Threat Defense and Response team and help drive the next generation of AI-powered cyber defense capabilitie...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Sr. Software Security Engineer

    Sr. Software Security Engineer

    Cadence Design Systems, Inc. • San Jose, CA, United States
    [job_card.full_time]
    At Cadence, we hire and develop leaders and innovators who want to make an impact on the world of technology.Cadence’s Information Security team is seeking a Sr. This role will focus on Cloud and on...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Physical Security Enablement IV

    Physical Security Enablement IV

    Equinix • San Jose, CA, US
    [job_card.full_time]
    Security Operations Specialist.Equinix is the world's digital infrastructure company, shortening the path to connectivity to enable the innovations that enrich our work, life and planet.A place whe...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Sr. Software Security Engineer

    Sr. Software Security Engineer

    Cadence Design Systems • San Jose, CA, United States
    [job_card.full_time]
    Software Security Engineer page is loaded## Sr.Software Security Engineerlocations : SAN JOSEtime type : Full timeposted on : Posted Yesterdayjob requisition id : R50299## • •At Cadence, we hire...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Penetration Tester

    Penetration Tester

    Harvey Nash • Pleasanton, CA, United States
    [job_card.full_time]
    Web Application Penetration Tester.Extensive knowledge of and proven experience with penetration testing of web applications, and methods and frameworks for identifying and remediating vulnerabilit...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Offensive Security Lead — Threat & Pen Tests

    Senior Offensive Security Lead — Threat & Pen Tests

    Ernst & Young Oman • San Jose, CA, United States
    [job_card.full_time]
    A global consulting firm is seeking a Senior Consultant in Offensive Security to enhance client security through threat assessments and proactive measures. The role requires leading a team of cybers...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Sr. Software Security Engineer

    Sr. Software Security Engineer

    Cadence • San Jose, CA, United States
    [job_card.full_time]
    Be among the first 25 applicants.At Cadence, we hire and develop leaders and innovators who want to make an impact on the world of technology. Cadence’s Information Security team is seeking a Sr.Thi...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior Penetration Tester, Android Security

    Senior Penetration Tester, Android Security

    Samsung Electronics GmbH • Mountain View, CA, United States
    [job_card.full_time]
    Development Quality Innovation.The Development Quality Innovation(DQI) lab in Mountain View has a dual role that is first to research new automation tools as well as take current tools and refine t...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Sr.Test Development Engineer (Hybrid)

    Sr.Test Development Engineer (Hybrid)

    Cisco Systems, Inc. • San Jose, CA, United States
    [job_card.full_time]
    The application window is expected to close on 12 / 23 / 2025.This role is a hybrid role with three days per week at Cisco's San Jose office. Job posting may be removed earlier if the position is filled...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior Penetration Tester, Android Security

    Senior Penetration Tester, Android Security

    Samsung Electronics America • Mountain View, CA, United States
    [job_card.full_time]
    The Development Quality Innovation(DQI) lab in Mountain View has a dual role that is first to research new automation tools as well as take current tools and refine them to our needs.Second, act as...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Senior Security Engineer

    Senior Security Engineer

    Adobe • San Jose, California, USA
    [job_card.full_time]
    Changing the world through digital experiences is what Adobes all about.We give everyonefrom emerging artists to global brandseverything they need to design and deliver exceptional digital experien...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Penetration Tester

    Penetration Tester

    Intelliswift - An LTTS Company • Pleasanton, California, United States
    [job_card.full_time]
    Job Title : Web Application Penetration Tester.Location : Pleasanton, CA / Hybrid.Conduct details penetration tests using common frameworks such as OWASP to Client vulnerabilities.Work closely with the...[show_more]
    [last_updated.last_updated_variable_hours] • [promoted] • [new]
    Sr. Security Engineer

    Sr. Security Engineer

    IBM • San Jose, CA, United States
    [job_card.full_time]
    A career in IBM Software means you’ll be part of a team that transforms our customer’s challenges into solutions.Seeking new possibilities and always staying curious, we are a team dedicated to cre...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Sr. Security Engineer

    Sr. Security Engineer

    IBM Computing • San Jose, CA, United States
    [job_card.full_time]
    A career in IBM Software means you’ll be part of a team that transforms our customer’s challenges into solutions.Seeking new possibilities and always staying curious, we are a team dedicated to cre...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Security Engineer

    Security Engineer

    F5 Networks • San Jose, CA, United States
    [job_card.full_time]
    At F5, we strive to bring a better digital world to life.Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]