EngineerJobs.io
← Back to all jobs

Job Description

Senior Offensive Security Engineer, Pentester role based onsite in Denver, CO within Bank of America’s Cyber Security Assurance Division. The position leads high-risk vulnerability assessments across the bank's global technology environment, mentors engineers, and collaborates with senior leadership to strengthen security posture.

Role Overview

This role focuses on directing and executing advanced offensive security activities to identify and mitigate critical vulnerabilities. The successful candidate will combine hands-on testing with strategic leadership, guiding security initiatives across diverse technologies and teams while maintaining strong communication with executive stakeholders.

Responsibilities

  • Direct and conduct assessments of Bank of America technologies, applications, and security controls, adapting testing methods to evolving threats.
  • Lead and participate in collaborative technical assessments employing a broad set of penetration testing techniques to uncover and demonstrate high-risk vulnerabilities across multiple technologies.
  • Identify misconfigurations and vulnerabilities, assess security impact, and report associated risk to stakeholders.
  • Coordinate with senior leadership on development projects and partner with appropriate stakeholders to complete assessments.
  • Mentor junior engineers and support monitoring and response functions to enhance threat-hunting capabilities across teams.
  • Collaborate closely with security peers, CIO clients, and multiple lines of business to align security activities with organizational goals.
  • Continuously hunt for high-risk vulnerabilities within the bank’s global technology environment.

Requirements

  • Minimum of five or more years of professional offensive security experience.
  • Ability to evaluate an organization and its systems from a threat actor perspective and communicate risk clearly to both technical and non-technical audiences.
  • High proficiency with standard penetration testing tools such as Burp Suite, Metasploit, and nmap.
  • Solid understanding of voice and data networks, major operating systems, active directory, associated peripherals, and a strong drive to learn new technologies.
  • Knowledge of attacker tactics, techniques, and procedures, relevant industry classifications and frameworks, and the capability to chain vulnerabilities for advanced exploitation.
  • Proficiency in reporting and technical documentation of vulnerabilities.
  • Ability to code or script in at least one programming or scripting language such as Python, Java, or C#.

Technologies

  • Burp Suite
  • Metasploit
  • nmap
  • Python
  • Java
  • C#

Desirable Skills

  • Certifications: OSCP, GPEN, GXPN, OSED, OSEP, OSWE, OSCE, GWAPT
  • Ability to work remotely if and when necessary
  • Previous experience in the financial services industry
  • Experience with hardware hacking, embedded systems analysis, and IoT hacking

Compensation and Work Arrangements

Salary: USD 160,000 to 205,000 per year.

Location: Denver, CO, onsite.

Shift: 1st shift (United States of America).

Hours per week: 40.

Similar Jobs