Talent.com
Senior Manual Ethical Hacker
Senior Manual Ethical HackerBank of America • Jersey City
Senior Manual Ethical Hacker

Senior Manual Ethical Hacker

Bank of America • Jersey City
[job_card.30_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

Description

:

Manual Ethical Hacking is part of the Application Development Security Framework Program within Bank of America’s Cyber Security Assurance Offensive Security group. The program provides services to assess the security resilience of the bank’s applications to malicious hacking activity.

This senior technical role is responsible performing and leading ethical hacking assessments of the bank's technologies, applications, and cyber security controls while adapting testing methods to evolving and emerging threats. Key responsibilities include leading and performing research, understanding the bank's security policies, working with appropriate partners to complete assessments and simulations, identifying misconfigurations and vulnerabilities, and reporting on associated risk. These individuals partner closely with security partners, CIO clients and multiples lines of business. These individuals are expected to perform application security-oriented dynamic and static assessments across a multitude of technologies including web UI, web APIs, mobile and cloud, including associated source code.

Key Responsibilities in order of importance:

  • Perform assigned analysis of internal and external threats on information systems and predict future threat behavior.

  • Incorporate threat actors' tactics, techniques, and procedures into offensive security testing to identify high-value vulnerabilities/chained attacks.

  • Developing Proof-of-concepts for exploitation.

  • Perform assessments of the security, effectiveness, and practicality of multiple technology systems.

  • Leverage innovative thinking to help solve problems or introduce new ideas to processes or products applicable to offensive security.

  • Prepare and present detailed technical information for various media including documents, reports, and notifications.

  • Provide clear and practical advice regarding managing risks.

  • Learn and develop advanced technical and leadership skills, mentor Junior and Intermediate assessors in technical tradecraft and soft skills.

  • Respond to security incidents and provide technical assistance to leadership across the Information Security organization.

Required Skills:

  • Minimum of 5+ years of professional pentesting, application security or ethical hacking experience, preferably in a large, complex, enterprise environment

  • Detailed technical knowledge in at least 5 of the following areas:

    security engineering

    application architecture

    authentication and security protocols

    application session management

    applied cryptography

    common communication protocols

    mobile frameworks

    single sign-on technologies

    exploit automation platforms

    Web APIs

    Cloud environments

    LLM security

    Mobile application analysis

  • Able to manually identify and reproduce findings, discuss remediation concepts, develop PoCs for vulnerabilities, use scripting/coding techniques, proficiently execute common penetration testing tools, triage, and support incidents, and produce high value findings

  • Experience performing manual web application assessments i.e., must be able to simulate a OWASP Top 10 vulnerabilities without the use of tools

  • Experience performing manual code reviews for security relevant issues

  • Experience working with DAST and SAST tools to identify vulnerabilities

  • Knowledge of network and Web related protocols/technologies (e.g., UNIX/LINUX, TCP/IP, Cookies)

  • Experience with vulnerability assessment tools and penetration testing techniques.

  • Solid programming/debugging skills, development frameworks, CVE and CWE research/reproduction

  • Threat Analysis, threat modelling and SBOM analysis

  • Innovative thinking, threat actor simulation

  • Technology Systems Assessment

  • Technical Documentation

  • Advisory

Desired:

  • CEH, OSCP/OSCE/OSWE/GXPN/GPEN/GWAPT/GMOB/All Practitioner Certs [Port Swigger BSP Academy]/Cloud Cert(s)/ eWPT; eWPTX; eMAPT [INE Pentester Academy]

  • Strong programming/scripting skills

  • Frida

  • Binary analysis (disassembly skills)

Skills:

  • Advisory

  • Innovative Thinking

  • Technical Documentation

  • Technology System Assessment

  • Threat Analysis

  • Adaptability

  • Collaboration

  • Scenario Planning and Analysis

  • Test Engineering

  • Written Communications

  • Attention to Detail

  • Information Systems Management

  • Issue Management

  • Presentation Skills

  • Prioritization

This job will be open and accepting applications for a minimum of seven days from the date it was posted.

Shift:

1st shift (United States of America)

Hours Per Week:

40

Pay Transparency details

US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540), US - MA - Boston - 100 Federal St - 100 Federal St Lp (MA5100), US - NJ - Jersey City - 101 Hudson St - 101 Hudson (NJ2101), US - WA - Seattle - 401 Union St - Rainier Square (WA1510)Pay and benefits informationPay range$160,000.00 - $205,000.00 annualized salary, offers to be determined based on experience, education and skill set.Discretionary incentive eligibleThis role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.BenefitsThis role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.
[job_alerts.create_a_job]

Senior Manual Ethical Hacker • Jersey City

[internal_linking.similar_jobs]

Manager, MedTech Agile Procurement

Johnson & JohnsonBogota, NJ, United States
[job_card.full_time]

At Johnson & Johnson, we believe health is everything.Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments a...[internal_linking.show_more]

 • [job_card.promoted]

Senior GTM Recruiter

SuperblocksNew York, NY, United States
[job_card.full_time]

Superblocks is reimagining software development for a billion builders.Our mission is to help every team build, deploy, and manage AI-powered software with full control and flexibility.We're one of...[internal_linking.show_more]

 • [job_card.promoted] • [job_card.new]

Senior Director of Software Eng – Digital Assets Blockchain

J.P. MorganNew York, NY, United States
[job_card.full_time]

A leading global financial institution is seeking a Senior Director of Software Engineering to drive blockchain innovations and develop scalable solutions.In this key role, you'll lead multiple tec...[internal_linking.show_more]

 • [job_card.promoted]

Senior Technical Recruiter

TriEdge InvestmentsNew York, NY, United States
[job_card.full_time]

We're looking for a Senior Technical Recruiter to help scale our growing portfolio of engineering, AI, and product hires across multiple early-stage companies.You'll play a pivotal role in building...[internal_linking.show_more]

 • [job_card.promoted]

Senior Tech Recruiter

CloakedNew York, NY, United States
[job_card.full_time]

Cloaked is a privacy startup dedicated to rebuilding consumer trust in how personal data is used.Our vision is to create an internet that serves the needs of its users, first and foremostwith indiv...[internal_linking.show_more]

 • [job_card.promoted]

Senior Paid Search Strategist

Sia/Ready Set RocketNew York, NY, United States
[job_card.full_time]

About Sia Experience - Creative.Sia Experience is the full-service creative agency.In the SiaX-Creative business line, we combine creative, CX, marketing, and deep AI expertise with industry leadin...[internal_linking.show_more]

 • [job_card.promoted]

Senior Technical RecruiterPeople & PlacesSan Francisco, CA

RipplingNew York, NY, United States
[job_card.full_time]

We're looking for a talented Technical Recruiter who loves building exceptional Engineering teams.If you thrive in fast-paced environments, know how to spot truly great engineers, and enjoy partner...[internal_linking.show_more]

 • [job_card.promoted]

Staff EVM Protocol Engineer — Core Blockchain

P2PNew York, NY, United States
[job_card.full_time]

A leading blockchain technology firm is seeking a Staff Engineer to join their Platform Engineering Group in New York.This role involves maintaining and advancing EVM-compatible chains, with respon...[internal_linking.show_more]

 • [job_card.promoted]

Senior Technical Recruiter

HarveyNew York, NY, United States
[job_card.full_time]

At Harvey, we're transforming how legal and professional services operate not incrementally, but end-to-end.By combining frontier agentic AI, an enterprise-grade platform, and deep domain expertise...[internal_linking.show_more]

 • [job_card.promoted]

Hiring for Mobile QA Engineer in Englewood, NJ

Wise Equation Solutions Inc.Englewood, NJ, United States
[job_card.temporary]
[filters_job_card.quick_apply]

MsoNoSpacing">Position: Mobile QA Engineer Location: Englewood, NJ Duration: 12+ Months contract Appium OR Mobile Testing Ex.Must have Minimum Requirements:<...[internal_linking.show_more]

Senior Technical Recruiter

TalentfulNew York, NY, United States
[job_card.full_time]

Talentful is shaping the future of how high-growth companies build world-class teams.We partner with some of the fastest-scaling technology businesses to turn talent into a durable competitive adva...[internal_linking.show_more]

 • [job_card.promoted]

Senior Media Buyer, Programmatic & Native

Gen DigitalNew York, NY, United States
[job_card.full_time]

Senior Media Buyer, Programmatic & Native.Gen is a global company dedicated to powering Digital Freedom through its trusted consumer brands including Norton, Avast, LifeLock, MoneyLion and more.Our...[internal_linking.show_more]

 • [job_card.promoted]

Senior Technical Recruiter

PeregrineNew York, NY, United States
[job_card.full_time]

Peregrine helps public safety organizations, state and local and governments, federal agencies, and private-sector institutions address society's challenges with unprecedented speed and accuracy.Ou...[internal_linking.show_more]

 • [job_card.promoted]

Senior Recruiter

PermitFlowNew York, NY, United States
[job_card.full_time]

PermitFlow is redefining how America builds.We're an applied AI company serving the nation's builders, tackling one of the largest information challenges in the economy: understanding what can be b...[internal_linking.show_more]

 • [job_card.promoted]

Bilingual QA Manager

Manufacturing FoodsHawthorne, NJ, United States
[job_card.full_time]

Bilingual Quality Assurance Manager.Join a Family-Owned Legacy of Quality Italian Sausage.At Premio Foods, we've been crafting the finest Italian sausages for nearly seven decades with a deep commi...[internal_linking.show_more]

 • [job_card.promoted]

Senior Full-stack (React Native/Java) Engineer - Health Care

Truelogic SoftwareNew York, NY, United States
[job_card.full_time]

At Truelogic we are a leading provider of nearshore staff augmentation services headquartered in New York.For over two decades, we’ve been delivering top-tier technology solutions to companies of a...[internal_linking.show_more]

 • [job_card.promoted]

Senior Strategist, Paid Search

Socium MediaNew York, NY, United States
[job_card.full_time]

Senior Strategist, Paid Search.Want to join an agency where your hard work will be recognized? An agency where you'll have abundant opportunities to learn and grow while significantly impacting you...[internal_linking.show_more]

 • [job_card.promoted]

Senior Technical Recruiter - Engineering

MercuryNew York, NY, United States
[job_card.full_time]

Senior Technical Recruiter - Engineering.Mercury is revolutionizing finance for startups by building a complete, user-friendly banking stack.This requires scaling exceptional engineering teams, so ...[internal_linking.show_more]