Senior Penetration Tester - Web Application

Remote Full-time
About the position This role offers a hybrid work schedule at our Buffalo, NY Tech Hub. Overview: Searches for application weaknesses that are exploitable, and partners with technology, cybersecurity, and risk teams to remediate any found weaknesses. Collaborates with technology teams when implementing new applications to help the team identify weaknesses before an attacker does. Responsibilities • Complete penetration testing (primarily Grey & White Box testing) of web applications, Application Programming Interfaces (APIs), network, hardware, and mobile. • Define testing methods to meet the scope and goals of assigned penetration tests. • Gather intelligence to better understand how target works and its potential vulnerabilities. • Understand breach and attack simulation solutions and work with the team to validate controls effectiveness. • Document and formally report testing initiative findings. • Maintain tools and scripts used in penetration testing and red team processes. • Effectively educate and train Cybersecurity teams on new tactics, techniques, and procedures to ensure technology applications and services are not at risk of compromise or will leak information. • Collaborate across Cybersecurity and Technology teams to leverage intelligence sources, identify new threats, improve tool usage and workflow, and mature monitoring and response capabilities. • Identify areas of opportunities in daily tasks to advance penetration testing skills and regularly learn new tactics, techniques, procedures to assess risk and implement and validate controls as necessary. • Understand and adhere to the Company's risk and regulatory standards, policies, and controls in accordance with the Company's Risk Appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues needing escalation to management. • Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable. • Complete other related duties as assigned. Requirements • Bachelor's degree and a minimum of 3 years' relevant work experience, or in lieu of a degree, a combined minimum of 7 years' higher education and/or work experience. • Intermediate working knowledge of penetration testing and red team tools to be able to simulate attacker tactics, techniques, and procedures • Strong knowledge of networking and network protocols • Intermediate working knowledge of operating systems and scripting and/or coding Nice-to-haves • Bachelor's degree in an applicable discipline such as Computer Science, Cybersecurity, or Information Technology • Strong understanding of information security concepts (both technical and organizational requirements) • Understanding and working knowledge of the OWASP Top 10 and other Security Testing Frameworks. • Highly ethical and expected to maintain a level of professionalism at all times • Intermediate working knowledge in social engineering, application security (web and mobile), physical methods, lateral movement, threat analysis, internal and external network architecture and a wide array of commercial and bring-your-own (BYO) products • Prior experience with and demonstrable aptitude for quickly learning new technical skills • Experience training others to ensure they have basic knowledge of and ability to use function-specific tools and systems • Ability to analyze and draw conclusions based on quantitative data from multiple sources • Penetration testing-specific or Cybersecurity domain-related industry-recognized certification Apply tot his job
Apply Now

Similar Opportunities

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote Full-time

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote Full-time

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote Full-time

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote Full-time

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote Full-time

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote Full-time

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote Full-time

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote Full-time

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote Full-time

USPS Office Helper

Remote Full-time

Pharmacy Order Entry Technician- Full Time- Onsite

Remote Full-time

Experienced Remote Work Professional - Entry-Level Work from Home Opportunities with Comprehensive Training and Support

Remote Full-time

Experienced Data Entry and Customer Service Representative – Detail-Oriented Administrative Professional for arenaflex

Remote Full-time

Remote Concrete Megastructures Estimator

Remote Full-time

Channel Development Manager Alpine

Remote Full-time

Experienced Remote Data Entry Specialist – Global Financial Services Leader at blithequark

Remote Full-time

Epidemiologist III- Preventive Medicine and Biostatistics

Remote Full-time

Remote Data Entry Job at Disney

Remote Full-time

Compliance Sr. Analyst- Supply Chain Master Data Compliance

Remote Full-time

Medical Record/Data Entry Clerk/Project Support

Remote Full-time
← Back to Home