Offensive Security Professional II A

Bank of America

India

On-site

INR 2,500,000 - 4,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Bank of America is seeking an experienced GIS Penetration Tester to perform security testing of web, mobile, and API services in a large enterprise environment in India. You will use manual techniques and automated tools to uncover vulnerabilities and report them to engineering teams.

The role requires strong communication, ability to work independently, and familiarity with banking risks. Prior experience at a large financial institution is a plus.

Qualifications

  • 10+ years of experience in penetration testing and application security.
  • Experience performing source code reviews for web, mobile, and API services.
  • Proficiency with security testing tools and reporting vulnerabilities clearly.

Responsibilities

  • Conduct comprehensive manual penetration testing across web, mobile, and API services.
  • Review source code to identify security flaws and suggest remediations.
  • Communicate findings to developers and management with actionable guidance.

Skills

Penetration testing
Code reviews
Security tools
Communication skills
Networking protocols
Programming skills
Mobile security
Cryptography

Education

B.E./B.Tech
M.E./M.Tech

Tools

Invicti
Burp Suite Pro
Checkmarx
Kali Linux
Metasploit

Job description

Job Description

This role is for the GIS Penetration Testing team to conduct penetration tests and source code reviews of our internal and external web, mobile, and web API service applications, leveraging both manual techniques and automated tools to uncover and report security vulnerabilities that exist. Candidates must be knowledgeable about business risks associated with common security vulnerabilities and be able to effectively communicate complex technical concepts such as security vulnerabilities to application developers and/or senior managers who may have little to no experience with application security. The role requires working independently in a very large‑scale, enterprise setting while collaborating with peer team members. Experience as an application security professional with a large financial institution is an plus.

Requirements

Education: B.E. / B. Tech / M.E. / M. Tech

Certifications: GWAPT, CEH, OSCP, SANS

Experience Range: 10+ years

Foundational Skills
  • Strong hands‑on experience in conducting comprehensive manual penetration tests and source code reviews against web, API, mobile applications, services, platforms, systems, and networks to identify security vulnerabilities.
  • Solid experience in using various security tools such as Invicti, SoapUI, Burp Suite Pro, Checkmarx, Kali Linux, Metasploit, etc.
  • Very good communication and interpersonal skills.
  • Knowledge of network and web related protocols/technologies.
  • Experience with latest penetration testing techniques (e.g., web application proxies, packet capture analysis software, browser extensions, advanced penetration testing tools, Linux distributions, Windows OS, etc.).
  • Experience of penetration testing on mobile platforms such as iOS, Android, and mobile device simulators.
  • Solid programming/debugging skills with proficiency in one or more of the following: Java, JavaScript, HTML, XML, PHP, ASP.NET, AJAX, JSON, Python, Perl, Shell script, Objective‑C, and SOAP/REST web APIs.
  • Expert‑level experience and knowledge in the following areas:
    • Authentication and security protocols.
    • Application session management.
    • Applied cryptography.
    • Common communication protocols.
    • Mobile frameworks.
    • Single sign‑on technologies.
    • Development frameworks (Angular, React, etc.).
    • Exploit automation platforms.
  • Knowledge of a Structured Query Language.
  • Developer experience or coding background (nice‑to‑have).
Desired Skills
  • Experience of penetration testing and source code reviews on web, API and mobile platforms.
  • Solid programming/debugging skills with proficiency in one or more of the following: Java, JavaScript, HTML, XML, PHP, ASP.NET, AJAX, JSON, Objective‑C, and SOAP/REST web APIs.

Work Timings: 11:00 AM to 8:00 PM

Job Location: Mumbai, Hyderabad, Chennai

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Offensive Security Professional II A
Offensive Security Professional II A

Bank of America • Chennai District

On-site
INR 5,000,000 - 7,000,000
Hiring For Penetration Tester - Mumbai
Hiring For Penetration Tester - Mumbai

Saint Gobain • Mumbai, Navi Mumbai

On-site
INR 4,000,000 - 8,000,000
Application Security Consultant
Application Security Consultant

Securityboat • Mumbai

On-site
INR 1,200,000 - 2,000,000
Flexible engagements
Competitive compensation
Collaborative cybersecurity team
+1
Senior Security Analyst
Senior Security Analyst

Uplers • Bengaluru

On-site
INR 700,000 - 1,200,000
Penetration Testing Engineer / Application Security Testing Engineer
Penetration Testing Engineer / Application Security Testing Engineer

VMC Soft Technologies, Inc • Bengaluru Urban

On-site
INR 1,800,000 - 3,600,000
Security Consultant II (Web Application Penetration Tester)
Security Consultant II (Web Application Penetration Tester)

NetSPI Inc. • Pune District

On-site
INR 1,500,000 - 2,000,000
Application Security Engineer
Application Security Engineer

Byline Learning Solutions • Pune District

On-site
INR 1,200,000 - 1,800,000
Offensive Security Engineer
Offensive Security Engineer

Systems Plus • Pune District

On-site
INR 1,800,000 - 2,800,000
Senior Security Engineer
Senior Security Engineer

Crossbow Cybersecurity • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Competitive salary and benefits
Medical Insurance – Self & family
Parental Support – Maternity Leave
+3
Penetration Tester Architect ( VAPT, Android , IOS ) - Naukri.com
Penetration Tester Architect ( VAPT, Android , IOS ) - Naukri.com

Info Edge • Greater Noida, Dadri

On-site
INR 900,000 - 1,200,000