Senior Application Penetration Tester

Chubb Ltd.

Philadelphia, Northern (Philadelphia County, KY)

Hybrid

USD 120,000 - 180,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Chubb Ltd. seeks a seasoned penetration tester to plan and execute security assessments across web, mobile, API, cloud-native, and AI-enabled applications.

You will collaborate with AI/ML teams to threat-model features, embed testing into CI/CD, and drive remediation through risk scoring and executive reporting. The role covers modern authentication, containerized workloads, and proactive vulnerability management in a global portfolio, requiring strong communication with technical and executive

Responsibilities

  • Plan and execute penetration tests across web, mobile (iOS & Android), API, cloud-native/containerized, and AI/LLM-integrated applications
  • Assess AI/ML and generative AI-powered features for risks such as prompt injection, insecure output handling, training data poisoning, model denial of service, and sensitive information disclosure, aligned to OWASP Top 10 for LLM Applications and MITRE ATLAS
  • Partner with AI/ML engineering and data science teams to threat-model AI-powered features and embed security testing into MLOps and CI/CD pipelines
  • Evaluate cloud-native and containerized workloads (AWS, Azure, GCP, Docker, Kubernetes) and Infrastructure as Code for misconfigurations and weak security controls
  • Test modern API architectures (REST, GraphQL, gRPC), including OAuth2, OIDC, and JWT authentication and authorization flaws, and microservices-based applications
  • Conduct mobile application security testing and reverse engineering, including hardcoded credentials, insecure keychain storage, and anti-emulator/obfuscation bypass
  • Own the overall vulnerability remediation status of the global application portfolio, and serve as the primary point of contact for application teams on remediation matters
  • Manage application risk rating processes and ensure timely risk scoring of new and changing applications
  • Build and maintain dashboards and status reports for portfolio leads and CIOs, and follow up on overdue vulnerabilities to meet compliance timelines
  • Develop clear, actionable penetration test reports and communicate findings and remediation strategy to both technical and executive stakeholders
  • Research emerging attack techniques and tooling, and drive automation and process improvements across the testing program

Job description

  • Plan and execute penetration tests across web, mobile (iOS & Android), API, cloud-native/containerized, and AI/LLM-integrated applications
  • Assess AI/ML and generative AI-powered features for risks such as prompt injection, insecure output handling, training data poisoning, model denial of service, and sensitive information disclosure, aligned to the OWASP Top 10 for LLM Applications and MITRE ATLAS
  • Partner with AI/ML engineering and data science teams to threat-model AI-powered features and embed security testing into MLOps and CI/CD pipelines
  • Evaluate cloud-native and containerized workloads (AWS, Azure, GCP, Docker, Kubernetes) and Infrastructure as Code for misconfigurations and weak security controls
  • Test modern API architectures (REST, GraphQL, gRPC), including OAuth2, OIDC, and JWT authentication and authorization flaws, and microservices-based applications
  • Conduct mobile application security testing and reverse engineering, including hardcoded credentials, insecure keychain storage, and anti-emulator/obfuscation bypass
  • Own the overall vulnerability remediation status of the global application portfolio, and serve as the primary point of contact for application teams on remediation matters
  • Manage application risk rating processes and ensure timely risk scoring of new and changing applications
  • Build and maintain dashboards and status reports for portfolio leads and CIOs, and follow up on overdue vulnerabilities to meet compliance timelines
  • Develop clear, actionable penetration test reports and communicate findings and remediation strategy to both technical and executive stakeholders
  • Research emerging attack techniques and tooling, and drive automation and process improvements across the testing program
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Penetration Tester
Senior Application Penetration Tester

Chubb Life Fund • Philadelphia, Northern (KY)

Hybrid
USD 90,000 - 130,000
Penetration Testing Engineer – VP
Penetration Testing Engineer – VP

Jobtailor • Massachusetts

On-site
USD 120,000 - 160,000
Senior Penetration Testing Engineer: AI/LLM Security Lead
Senior Penetration Testing Engineer: AI/LLM Security Lead

Jobtailor • Massachusetts

On-site
USD 120,000 - 160,000
Penetration Tester
Penetration Tester

GTN Technical Staffing • United States

On-site
USD 120,000 - 180,000
Senior Application Security & Penetration Tester
Senior Application Security & Penetration Tester

Chubb Life Fund • Philadelphia, Northern (KY)

Hybrid
USD 90,000 - 130,000
Application Security Engineer
Application Security Engineer

BridgeView • New York (NY)

On-site
USD 120,000 - 160,000
Senior Penetration Tester
Senior Penetration Tester

JPMorgan Chase & Co. • New York (NY)

On-site
USD 180,000 - 280,000
Security Engineer
Security Engineer

Jobtailor • Denver (CO)

On-site
USD 140,000 - 180,000
Cyber Security Web Application Research Engineer
Cyber Security Web Application Research Engineer

Jobtailor • Arizona

Hybrid
USD 90,000 - 130,000
Application & AI Security Engineer
Application & AI Security Engineer

Hydrogen Group • United States

On-site
USD 140,000 - 190,000