Penetration Testing Engineer

Alliant Credit Union

Chicago (IL)

On-site

USD 77,000 - 119,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Annual performance bonus
Work from home up to 3 days a week
Paid parental leave
Employee discount programs
Time off including paid personal and s
11 paid holidays

Job summary

Alliant Credit Union in Chicago offers a hybrid role focused on planning, executing, and reporting on penetration testing for web applications and APIs across homegrown and vendor systems.

You will perform hands-on offensive security testing, develop PoCs, and work with software engineering and security teams to remediate findings, while staying current on threats and best practices relevant to cloud environments.

Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or related field.
  • Penetration testing/offensive security experience preferred.
  • Industry certifications or equivalent in offensive security are a plus.

Responsibilities

  • Plan, execute, and report on web app and API penetration testing across homegrown and vendor systems.
  • Perform manual and automated testing including authenticated scenarios.
  • Identify and validate vulnerabilities; drive remediation and retesting.
  • Develop PoCs and document attack paths when appropriate.
  • Create clear reports for technical and non-technical audiences.
  • Maintain and administer DAST, SAST, and SCA tools.
  • Stay current on threats and best practices relevant to cloud environments.

Skills

Penetration testing
Offensive security
Python scripting

Education

Bachelor's degree in Computer Science / Cybersecurity / Information Systems or related

Tools

DAST tools
SAST tools
SCA tools

Job description

In this hybrid role based at our Chicago headquarters, you will plan, execute, and report on penetration testing for web applications and web APIs across both internally developed and vendor SaaS solutions. Perform hands‑on offensive security testing to identify, validate, and drive remediation of vulnerabilities in modern application and API architectures. Support targeted testing of related infrastructure, cloud services, and internal systems. Work with software engineering, application security, and cyber threat mitigation teams to strengthen the organization’s overall security posture.

  • Perform penetration testing with a primary focus on web applications and web APIs across homegrown and vendor systems, support testing of cloud, mobile, and internal systems.
  • Conduct manual and automated testing, including authenticated and unauthenticated attack scenarios.
  • Identify and validate vulnerabilities, and assist in assessing risk and potential impact
  • Develop proof‑of‑concept exploits and document attack paths when appropriate.
  • Work with development teams to support remediation efforts by review fixes, validate resolutions, and retesting.
  • Support the analysis and prioritization of vulnerabilities based on exploitability, severity, and business impact.
  • Produce clear, actionable penetration test reports for technical and non‑technical audiences.
  • Contribute to improving internal testing methodologies, tooling, and standards.
  • Stay current on emerging threats, attack techniques, and best practices relevant to modern web applications, APIs, and cloud environments.
  • Maintain and administer DAST, SAST, and SCA tools, including scan execution, troubleshooting, and validation of findings.
  • Support, troubleshoot and enhance internal security workflow applications and automation written in Python.

Education &Years of Experience

  • Minimum - 4 Year Bachelors Degree in Computer Science, Cybersecurity, Information Systems or related
  • Minimum - 0 Years of Penetration testing, offensive security or related

In Lieu of Education

  • 4 Years ofPenetration testing, offensive security or related

License/Certifications/Training

  • Preferred - Industry certifications such as OSWE, OSCP, OSCE, GPEN, GWAPT, CRTO, or related offensive security credentials

Typical hiring range: $76,600.00 to $119,100.00 Annually. Actual compensation will be determined using factors such as experience, skills & knowledge.

Benefits: Alliant provides a benefits package including health care, vision, dental, and 401k with employer match including:

  • Annual performance bonus
  • Work from home up to 3 days a week
  • Paid parental leave
  • Employee discount programs
  • Time off including paid personal and sick days
  • 11 paid holidays

*Note that eligibility and cost of benefits can vary depending on the number of regularly scheduled hours, and job status such as regular full-time, regular part-time, or temporary employment.

Adhere to and ensure compliance of all business transactions with policy and process of the Bank Secrecy Act. Ensures compliance with all applicable state and federal laws, company procedures and policies. Maintains integrity and ethics in all actions and conversations with or regarding credit union members and their accounts; complies with Privacy Act directives.

The responsibilities listed do not contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this position. Duties, responsibilities and activities may change at any time with or without notice.

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Offensive Security Engineer
Offensive Security Engineer

J.P. Morgan • New York (NY)

On-site
USD 130,000 - 180,000
Comprehensive health care coverage
Retirement savings plan
Tuition reimbursement
+1
Offensive Security Engineer
Offensive Security Engineer

TwinThread • McLean (VA)

On-site
USD 120,000 - 160,000
Health care coverage
Retirement savings plan
Tuition reimbursement
Senior Penetration Tester
Senior Penetration Tester

JPMorgan Chase & Co. • New York (NY)

On-site
USD 180,000 - 280,000
Penetration Testing Manager (Sr. Manager InfoSec) - Remote
Penetration Testing Manager (Sr. Manager InfoSec) - Remote

First Citizens Bank • Bedford

Remote
USD 155,000 - 190,000
Senior Security Engineer - Penetration Tester
Senior Security Engineer - Penetration Tester

Habitat For Humanity Of Durham • Raleigh (NC)

On-site
USD 120,000 - 170,000
Medical, dental, vision
401k plan
Vacation and holidays
Senior Security Engineer - Penetration Tester
Senior Security Engineer - Penetration Tester

Truist • Charlotte (NC)

On-site
USD 120,000 - 170,000
Medical insurance
Dental insurance
Vision insurance
+6
Senior Security Engineer - Penetration Tester
Senior Security Engineer - Penetration Tester

Truist • Raleigh (NC)

On-site
USD 120,000 - 170,000
Medical Insurance
Dental Insurance
Vision Insurance
+6
Application Security Analyst
Application Security Analyst

Consumers Credit Union • Lake Forest (IL)

Hybrid
USD 67,000 - 109,000
401(k) savings plan
Medical, dental, and vision insurance
Paid time off
Senior IT Penetration Tester
Senior IT Penetration Tester

BDO USA • United States

On-site
USD 120,000 - 160,000
Senior IT Penetration Tester
Senior IT Penetration Tester

BDO USA, LLP • Oak Brook (IL)

On-site
USD 120,000 - 160,000