Enable job alerts via email!

Lead Web Application Penetration Tester

M&T Bank Corporation

Buffalo (NY)

Hybrid

USD 110,000 - 185,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a Lead Web Application Penetration Tester to enhance their cybersecurity posture. This role involves conducting thorough penetration tests, collaborating with technology and cybersecurity teams, and educating staff on security practices. The successful candidate will leverage their expertise in identifying vulnerabilities and implementing effective mitigation strategies. With a hybrid work model, this position offers flexibility while working within a dynamic team environment. If you are passionate about cybersecurity and eager to make a significant impact, this opportunity is perfect for you.

Qualifications

  • 5+ years of experience in penetration testing and red team tools.
  • Strong knowledge of networking protocols and scripting.

Responsibilities

  • Conduct penetration tests on web applications and APIs.
  • Document findings and provide recommendations for risk reduction.

Skills

Penetration Testing
Red Team Tools
Networking Knowledge
Scripting/Coding
Social Engineering
Threat Analysis

Education

Bachelor's Degree
9 years of relevant experience

Tools

Penetration Testing Tools
Networking Tools

Job description

Lead Web Application Penetration Tester page is loaded

Lead Web Application Penetration Tester

Apply remote type Hybrid Position locations Buffalo, NY time type Full time posted on Posted 2 Days Ago job requisition id R74630

This role offers a hybrid work schedule; offering the flexibility to work remotely two days a week, while providing the opportunity for in-person collaboration at our Buffalo, NY Tech Hub.

Overview:

Searches for application and system weaknesses that are exploitable, and partners with technology, cybersecurity, and risk teams to remediate any found weaknesses. Partners with technology leaders to train engineering and infrastructure teams to develop new applications and systems securely to ensure weaknesses are removed prior to implementation or software deployment.

Primary Responsibilities:
  • Complete penetration testing or red team/adversarial exploitation exercises of web applications, Application Programming Interfaces (APIs), hardware, and mobile.
  • Perform reconnaissance, social engineering, initial access, and post-exploitation activities across internal and external environments.
  • Develop and deploy custom payloads, exploits, and tools for use during engagements, including client-side, server-side, and lateral movement scenarios.
  • Contribute to purple team exercises by sharing red team findings and collaborating with detection engineering and incident response teams to improve defensive capabilities.
  • Document detailed findings, attack paths, and security gaps with clear recommendations for mitigation and risk reduction.
  • Stay current on emerging TTPs, CVEs, and adversary tradecraft, especially in the context of web and cloud exploitation techniques.
  • Define testing methods to meet the scope and goals of assigned penetration tests.
  • Understand breach and attack simulation solutions and work with the team to validate controls effectiveness.
  • Effectively educate and train Cybersecurity teams on new tactics, techniques, and procedures to ensure technology applications and services are not at risk of compromise or will leak information.
  • Collaborate across Cybersecurity and Technology teams to leverage intelligence sources, identify new threats, improve tool usage and workflow, and mature monitoring and response capabilities.
  • Identify areas of opportunities in daily tasks to advance penetration testing skills and regularly learn new tactics, techniques, procedures to assess risk and implement and validate controls as necessary.
  • Understand and adhere to the Company’s risk and regulatory standards, policies, and controls in accordance with the Company’s Risk Appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues needing escalation to management.
  • Promote an environment that supports diversity and reflects the M&T Bank brand.
  • Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
  • Complete other related duties as assigned.
Scope of Responsibilities:
  • Engages in regular interaction with senior management and associated staff within Internal Audit, Compliance, Risk Management, and Technology.
  • Exercises judgement in selecting methods, techniques, and evaluation criteria in obtaining results. Exerts significant latitude in determining objective of assignment. Work is accomplished with limited direction.
  • Intermediate working knowledge of penetration testing and red team tools.
  • Advanced knowledge of networking and network protocols.
  • Intermediate working knowledge of operating systems and scripting and/or coding.
  • The position provides guidance and mentoring to less experienced team members.
Education and Experience Required:
  • Bachelor's degree and a minimum of 5 years’ relevant work experience, or in lieu of a degree, a combined minimum of 9 years’ higher education and/or work experience.
  • Prior experience penetration testing and red team tools to be able to simulate attacker tactics, techniques, and procedures.
  • Advanced knowledge of networking and network protocols.
  • Intermediate working knowledge of operating systems and scripting and/or coding.
Education and Experience Preferred:
  • Bachelor’s degree in an applicable discipline such as Computer Science, Cybersecurity, or Information Technology.
  • Extensive understanding of information security concepts (both technical and organizational requirements).
  • Highly ethical and expected to maintain a level of professionalism at all times.
  • Intermediate working knowledge in social engineering, application security (web and mobile), physical methods, lateral movement, threat analysis, internal and external network architecture, and a wide array of commercial and bring-your-own (BYO) products.
  • Excellent ability to strategically learn new technical skills, and apply broadly across systems, tools, and processes.
  • Experience training penetration testers to ensure they have intermediate knowledge of penetration testing and red team concepts, tools, and ability to simulate attacker tactics, techniques, and procedures.
  • Strong ability to analyze and draw reliable conclusions based on large volumes of quantitative data from diverse sources.
  • Penetration testing-specific or Cybersecurity domain-related industry-recognized certification.

M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $110,635.01 - $184,391.68 (USD). The successful candidate’s particular combination of knowledge, skills, and experience will inform their specific compensation.

Location

Buffalo, New York, United States of America

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Web Application Penetration Tester – Technical Lead (In Office or Remote)

Talentify.io

Remote

USD 150,000 - 224,000

4 days ago
Be an early applicant

Web Application Penetration Tester – Technical Lead (In Office or Remote)

Freddie Mac

Virginia

Remote

USD 150,000 - 224,000

30+ days ago

Web Application Penetration Tester – Technical Lead (Hybrid or Remote Work)

Freddie Mac

McLean

Remote

USD 150,000 - 224,000

30+ days ago

Lead Penetration Tester

Lensa

Atlanta

Remote

USD 157,000 - 196,000

30+ days ago

Red Team Penetration Tester - Technical Lead (Hybrid or Remote Work Schedule)

Freddie Mac

McLean

Remote

USD 150,000 - 200,000

30+ days ago

Lead Cloud Penetration Tester

Maveris

Minneapolis

On-site

USD 80,000 - 120,000

30+ days ago