AVP, Penetration Tester

LPL Financial

New York (NY)

On-site

USD 122,570 - 204,249

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401K matching
Health benefits
Employee stock options
Paid time off
Volunteer time off

Job summary

LPL Financial is seeking a Senior Penetration Tester to join their Cyber Security team in New York. This role involves conducting thorough penetration testing of applications and networks to identify and mitigate security vulnerabilities.

With a strong emphasis on collaboration, you'll partner with various stakeholders to enhance the security posture of LPL's applications, utilizing advanced testing techniques and tools. Comprehensive benefits and a competitive salary range of $122,570.00 - $204,249.00 are offered as part of the LPL Total Rewards package.

Qualifications

  • 8+ years of experience in application, API, and network penetration testing.
  • 6+ years of experience troubleshooting tools and identifying vulnerabilities.
  • 3+ years leading penetration testing engagements from scoping to reporting.
  • 1+ year of experience testing AI-enabled applications.

Responsibilities

  • Conduct penetration testing assessments for web, mobile, and API applications.
  • Collaborate with Security Architects to address security issues.
  • Document and report testing findings and remediation recommendations.
  • Validate and communicate closure of identified vulnerabilities.

Skills

Penetration testing
Application security
Vulnerability assessment
Scripting languages
Collaboration

Education

Bachelor’s degree in Information Security or related field

Tools

Burp Suite
Kali Linux
Metasploit
Nessus

Job description

Job Overview

As a member of the Cyber Security team, the Senior Penetration Tester, Offensive Security, is responsible for the scheduling, scoping, and execution of internal penetration testing, with a primary focus on web, mobile, cloud, API, and AI‑enabled applications.

This individual contributor role performs advanced manual penetration testing to validate the security of company resources. The position serves as the primary point of contact for assigned testing initiatives and partners closely with stakeholders across the organization to identify security weaknesses, recommend mitigation strategies, and validate remediation efforts across LPL applications and platforms.

Responsibilities
  • Partner with product and technology stakeholders to drive end‑to‑end penetration testing activities, including collaboration with Security Architects throughout the SDLC to identify and address security issues prior to production deployment.
  • Conduct tactical penetration testing assessments of web, mobile, and API applications against OWASP Top 10 threats and emerging risks, and collaborate with Application Security teams to provide actionable feedback and recommendations, including opportunities to expand automated and AI‑assisted testing capabilities.
  • Perform security assessments of internal and external networks, infrastructure, cloud environments, and a wide range of internally developed and commercial products.
  • Apply creative and analytical thinking to bypass security controls, identify vulnerabilities, and develop practical remediation guidance; stay informed on evolving tactics, techniques, and procedures (TTPs), zero‑day vulnerabilities, and mitigation strategies.
  • Develop or modify custom tools and scripts to support new penetration testing needs, automation, and AI‑assisted testing approaches.
  • Document and formally report testing scope, methodology, findings, risk ratings, remediation recommendations, and validation results in a clear and concise manner.
  • Present testing results to technology and business partners, clearly communicating risk, impact, and remediation guidance in an accessible and collaborative way.
  • Lead execution of assigned penetration testing initiatives, including status communication to leadership and coordination with stakeholders.
  • Oversee communication, tracking, and retesting of findings to validate successful closure of previously identified issues.
  • Assist with validation and triage of submissions from the company’s Vulnerability Disclosure Program and Bug Bounty programs.
Requirements
  • 8+ years of experience conducting application, API, and network‑based penetration testing engagements.
  • 6+ years of experience troubleshooting tools, manually identifying vulnerabilities in code, and rewriting code to remediate security issues.
  • 3+ years of experience leading penetration testing engagements from scoping through reporting and remediation validation.
  • 1+ year of experience testing AI, LLM, or Generative AI‑enabled applications.
  • 1+ year of experience using AI models (such as Claude or similar) to accelerate tool development or testing workflows.
  • Advanced knowledge of security assessment tools and frameworks, such as Burp Suite, Kali Linux, Nessus, Accunetix, Metasploit, AutoSploit, Cobalt Strike, MITRE ATT&CK, MITRE ATLAS, OWASP Top 10 (including OWASP Top 10 for LLMs).
Preferred Qualifications
  • Bachelor’s degree or equivalent experience in Information Security, Engineering, Computer Science, or a related field.
  • Advanced understanding of OWASP frameworks, MITRE ATT&CK and ATLAS, and secure software development lifecycle (SDLC) practices.
  • At least one industry‑recognized certification, such as OSCP, OSCE, OSWE, GPEN, GCIH, GWAPT, or GXPN.
  • Advanced proficiency in one or more programming or scripting languages, such as .NET, JavaScript, Python, Java, PowerShell, Perl, Ruby, Bash, or similar.
  • Advanced knowledge of Linux, macOS, and Windows operating systems, as well as AWS and Azure cloud environments and cloud‑native services (e.g., containers, Kubernetes, microservices, serverless functions).
  • Experience performing reverse engineering on mobile applications, including those with obfuscation or anti‑emulation protections.
  • Broad knowledge of operating system security, networking and protocols, firewalls, databases, middleware, forensics, and secure coding practices.
  • Effective written and verbal communication skills, with the ability to collaborate with technical and non‑technical stakeholders.
  • Organized approach to managing multiple testing efforts and deliverables.
  • A natural curiosity for exploring, testing, and understanding security controls and how they can be improved.
Pay Range and Benefits

Pay Range: $122,570.00 - $204,249.00

Actual base salary varies based on factors, including but not limited to, relevant skill, prior experience, education, base salary of internal peers, demonstrated performance, and geographic location. LPL Total Rewards package is highly competitive, designed to support your success at work, at home, and at play – 401K matching, health benefits, employee stock options, paid time off, volunteer time off, and more.

Legal Statements

Principals only. EOE.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AVP, Penetration Tester
AVP, Penetration Tester

LPL Financial LLC • Charlotte (TX), Fort Mill (SC)

On-site
USD 122,000 - 205,000
401K matching
Health benefits
Employee stock options
+2
AVP Penetration Testing & AI Security Leader
AVP Penetration Testing & AI Security Leader

LPL Financial • New York (NY)

On-site
USD 122,000 - 205,000
401K matching
Health benefits
Employee stock options
+2
Senior Penetration Tester, AI & App Security
Senior Penetration Tester, AI & App Security

LPL Financial LLC • Charlotte (TX), Fort Mill (SC)

On-site
USD 122,000 - 205,000
401K matching
Health benefits
Employee stock options
+2
Senior IT Penetration Tester
Senior IT Penetration Tester

BDO USA, LLP • Oak Brook (IL)

On-site
USD 120,000 - 160,000
Senior IT Penetration Tester
Senior IT Penetration Tester

BDO USA, Llp • Northern (KY)

Hybrid
USD 120,000 - 160,000
Sr. Application Security Engineer
Sr. Application Security Engineer

LPL Financial • New York (NY)

On-site
USD 101,000 - 168,000
Sr. Application Security Engineer
Sr. Application Security Engineer

LPL Financial • Austin (TX)

On-site
USD 101,000 - 168,000
Penetration Tester, AVP
Penetration Tester, AVP

2755 Barclays Services Corpor • Hanover Township (NJ)

On-site
USD 125,000 - 170,000
Medical, dental, and vision coverage
401(k) plan
Comprehensive life insurance
+1
Senior Penetration Testing Engineer
Senior Penetration Testing Engineer

Alliant Credit Union • Illinois

Hybrid
USD 92,000 - 145,000
Health insurance
Vision & dental
401k with employer match
+2
Sr. Application Security Engineer
Sr. Application Security Engineer

LPL Financial • Tempe (AZ)

On-site
USD 101,000 - 168,000
401K matching
Health benefits
Employee stock options
+2