Security Engineer III

Bank of America

Chennai District

On-site

INR 4,000,000 - 7,000,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Bank of America is seeking an Ethical Pen Testing Leader to join the Global Information Security team in India. You will conduct application security and penetration tests across internal and external web, mobile, and API services, using manual techniques and automated tools to uncover vulnerabilities.

Lead a large India-based team, communicating complex risks to engineers and managers who may not be security specialists.

Qualifications

  • Education: B.E./B.Tech/M.E./M.Tech
  • CEH certification (preferred)
  • Experience: 10+ years in application security
  • Experience in India PEN testing
  • Strong communication and leadership abilities
  • Hands-on testing across web/mobile apps and APIs (OWASP Top 10)

Responsibilities

  • Conduct application security/penetration tests on web/mobile/API apps
  • Communicate risk and remediation steps to developers and senior managers
  • Lead and coordinate Pen Testing teams in India
  • Develop and implement Pen Testing capabilities and processes

Skills

Penetration testing
Vulnerability assessment
Web security
Mobile security
Executive presence
Communication
Team leadership

Education

B.E./B.Tech/M.E./M.Tech
CEH certification

Tools

Invicti DAST Scanner
Burp Suite Pro
Checkmarx
SoapUI

Job description

Job Description:
About Us

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits. We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve. Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

Global Business Services

Global Business Services delivers Technology and Operations capabilities to Lines of Business and Staff Support Functions of Bank of America through a centrally managed, globally integrated delivery model and globally resilient operations.

Global Business Services is recognized for flawless execution, sound risk management, operational resiliency, operational excellence, and innovation.

In India, we are present in five locations and operate as BA Continuum India Private Limited (BACI), a non-banking subsidiary of Bank of America Corporation and the operating company for India operations of Global Business Services.

Process Overview

Global Information Security (GIS) is responsible for protecting bank information systems, confidential and proprietary data, and customer information. GIS develops the bank’s Information Security strategy and policy, manages the Information Security program, identifies and addresses vulnerabilities and operates global security operations center that monitor, detects and responds to cybersecurity incidents. Within GIS, the Cloud Security organization is responsible for leading a team of deeply technical cyber security engineers and architects to design and implement best in class cyber security capabilities for internal and external cloud instances in partnership with infrastructure and application technology teams. In addition, lead efforts across other Global Information Security functions to enable cyber security technology and operations in cloud environments.

Job Description

The Ethical Pen Testing Leader will join a dynamic team of world class security experts to conduct application security/penetration tests of our internal/external web, mobile, web, and web API service applications, leveraging both manual techniques as well as automated tools to uncover and report security vulnerabilities that exist.

You must be knowledgeable with business risks associated to common security vulnerabilities and to be able to effectively communicate complex technical concepts such as security vulnerabilities to application developers and/or senior managers who may have little to no experience with application security.

The must have the ability to work independently in a very large scale, enterprise setting and collaborate with peer team members. Previous experience as an application security professional with a large Financial Institution a plus.

Requirements

Education: B.E. / B. Tech/M.E. /M. Tech

Certifications, If Any: CEH

Experience Range: 10+ years

Foundational Skills
  • Web application vulnerability scanning tools (Invicti DAST Scanner, SoapUI, Burp Suite Pro, Checkmarx)

  • Conducting vulnerability assessments, code reviews and penetration tests against web/mobile application technologies, services, platforms and languages to find flaws and exploits

  • Strong Development background with hands on experience on Pen Testing

  • Experience in setting up Pen Testing capability in India

  • Experience in managing large teams

  • Executive presence. Very Good Communication & Interpersonal skills

  • Experience conducting vulnerability assessments, code reviews and penetration tests against web/mobile application technologies, services, platforms and languages to find flaws and exploits (e.g., SQL Injection, Cross-Site Scripting, Cross-Site Request Forgery, Clickjacking, Authentication/Authorization, Privilege Escalation, Business Logic Bypass, OWASP Top 10, SANS Top 25 etc.).

  • Knowledge of network and Web related protocols/technologies.

  • Ability to demonstrate manual web application testing experience.

  • Experience with web application vulnerability scanning tools (e.g. Invicti DAST Scanner, SoapUI, Burp Suite Pro, Checkmarx etc.).

  • Experience with vulnerability assessment tools and penetration testing techniques (e.g. web application proxies, packet capture analysis software, browser extensions, advanced penetration testing tools (full stack), Linux distributions, Windows OS, etc.).

  • Experience of penetration testing on mobile platforms such as iOS and Android, mobile device simulators.

  • Solid programming/debugging skills with proficiency in one or more of the following: Java, JavaScript, HTML, XML, PHP, ASP.NET, AJAX, JSON, Objective-C, and SOAP/REST web APIs.

  • Expert-level experience and very details technical knowledge in at least 3 of the following areas:

    • General information security.

    • Security engineering.

    • Application architecture.

    • Authentication and security protocols.

    • Application session management.

    • Applied cryptography.

    • Common communication protocols.

    • Mobile frameworks.

    • Single sign-on technologies.

    • Development frameworks (Angular, React, etc.).

    • Exploit automation platforms.

    • Threat modeling.

Desired Skills
  • Solid programming/debugging skills with proficiency in one or more of the following: Java, JavaScript, HTML, XML, PHP, ASP.NET, AJAX, JSON, Objective-C, and SOAP/REST web APIs

  • Experience of penetration testing on mobile platforms such as iOS and Android, mobile device simulators

Work Timings: General Shift (1:30 p.m. to 10:30 p.m.)

Job Location: Mumbai/ Chennai

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Feature Lead Technology - GBS IND
Feature Lead Technology - GBS IND

Bank of America • Hyderabad

On-site
INR 3,500,000 - 7,000,000
Feature Lead Technology - GBS IND
Feature Lead Technology - GBS IND

Bank of America • Chennai District

On-site
INR 3,000,000 - 5,200,000
Offensive Security Professional II A
Offensive Security Professional II A

Bank of America • India

On-site
INR 2,500,000 - 4,000,000
Info Security Consultant II A
Info Security Consultant II A

Bank of America • Mumbai City

On-site
INR 3,000,000 - 4,500,000
Software Engineer III - GBS IND
Software Engineer III - GBS IND

Bank of America • Mumbai

On-site
INR 2,500,000 - 4,000,000
Senior Associate - Cyber Security - VAPT
Senior Associate - Cyber Security - VAPT

BDO India • Pune District

On-site
INR 900,000 - 1,500,000
Info Security Incident Management Specialist I B
Info Security Incident Management Specialist I B

Bank of America • Maharashtra

On-site
INR 800,000 - 1,200,000
Penetration Testing Engineer / Application Security Testing Engineer
Penetration Testing Engineer / Application Security Testing Engineer

VMC Soft Technologies, Inc • Bengaluru Urban

On-site
INR 1,800,000 - 3,600,000
SENIOR ENGINEER - Penetration Testing
SENIOR ENGINEER - Penetration Testing

Happiest Minds Technologies • Bengaluru

On-site
INR 1,100,000 - 1,700,000
Manager
Manager

United States Digital Space LLC • Gurgaon

On-site
INR 900,000 - 1,500,000