Senior Penetration Tester (Mobile, API, Cloud)

Us Bank

Irving (TX)

On-site

USD 140,000 - 210,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Healthcare (medical, dental, vision)
401(k) retirement plan
Paid vacation
Life insurance

Job summary

U.S. Bank is seeking a Senior Penetration Tester to lead offensive security assessments across mobile apps, APIs, web platforms, cloud environments, and AI-enabled technologies.

You will identify vulnerabilities, demonstrate business impact, and partner with engineering teams to strengthen security posture. This onsite role requires 8+ years in information security, mobile security testing for Android and iOS, and strong knowledge of OWASP, SANS, and MASVS frameworks.

Qualifications

  • Bachelor’s degree in Engineering or Science, or equivalent work experience.
  • Eight or more years of experience in information security.
  • Two or more years of IT infrastructure management, application architecture, risk management, data architecture, middleware technology, IT operations and project management.
  • 8+ years of Information Security experience with offensive security and penetration testing.
  • 5+ years of hands-on mobile application security testing for Android and iOS.
  • Knowledge of OWASP Top 10, API Security Top 10, SANS Top 25, OWASP MASVS, and MASTG.
  • Experience with Burp Suite Pro, Postman, Insomnia, Nmap, Metasploit, Kali Linux.
  • Experience AWS, Azure, Kubernetes, containers, and cloud-native security platforms.
  • Scripting in Python, PowerShell, Bash, Ruby, Go.
  • Understanding of HTTP/S, REST APIs, OAuth, SAML, JWT, TCP/IP, DNS, firewalls, IDS/IPS, application architecture.
  • AI and ML security risks.
  • PCI-DSS, HIPAA, NIST 800-53, ISO 27001, FedRAMP.
  • Excellent communication skills with the ability to present findings to technical teams, business stakeholders, and executive leadership.

Responsibilities

  • Lead penetration testing engagements across mobile applications, APIs, web applications, cloud platforms, and supporting infrastructure.
  • Perform manual security testing and exploitation to identify vulnerabilities, validate risk, and demonstrate business impact.
  • Assess applications against OWASP Top 10, OWASP API Security Top 10, OWASP MASVS, and MASTG.
  • Evaluate security controls within AWS, Azure, containerized environments, and Kubernetes platforms.
  • Conduct threat modeling and risk assessments to prioritize testing activities and remediation efforts.
  • Develop detailed security reports including vulnerability analysis, risk ratings, attack paths, and remediation recommendations.
  • Create and enhance security testing tools, scripts, and automation to improve operational effectiveness and assessment coverage.
  • Mentor junior testers, support knowledge-sharing initiatives, and collaborate with stakeholders to strengthen enterprise security practices.

Skills

Penetration testing
Mobile security
API security
Cloud security
Burp Suite Pro
Postman
Nmap
Metasploit
Kali Linux
Python
PowerShell
Bash
Ruby
Go
HTTP/S
OAuth
SAML

Education

Bachelor's degree in Engineering or Science

Tools

AWS
Azure
Kubernetes

Job description

At U.S. Bank, we’re on a journey to do our best. Helping the customers and businesses we serve to make better and smarter financial decisions and enabling the communities we support to grow and succeed. We believe it takes all of us to bring our shared ambition to life, and each person is unique in their potential. A career with U.S. Bank gives you a wide, ever-growing range of opportunities to discover what makes you thrive at every stage of your career. Try new things, learn new skills and discover what you excel at—all from Day One.

Job Description

The Senior Penetration Tester will lead advanced offensive security assessments across mobile applications, APIs, web platforms, cloud environments, and emerging AI-enabled technologies. This role is responsible for identifying security weaknesses, validating business impact through controlled exploitation, and partnering with engineering teams to strengthen security posture across the enterprise. Experience with mobile security, API testing, cloud security, threat modeling, and regulatory compliance is critical. Relevant internal learning pathways emphasize cloud penetration testing, API security, mobile security frameworks, and offensive security tooling.

Key Responsibilities
  • Lead penetration testing engagements across mobile applications, APIs, web applications, cloud platforms, and supporting infrastructure.

  • Perform manual security testing and exploitation to identify vulnerabilities, validate risk, and demonstrate business impact.

  • Assess applications against industry standards including OWASP Top 10, OWASP API Security Top 10, OWASP MASVS, and MASTG.

  • Evaluate security controls within AWS, Azure, containerized environments, and Kubernetes platforms.

  • Conduct threat modeling and risk assessments to prioritize testing activities and remediation efforts.

  • Develop detailed security reports including vulnerability analysis, risk ratings, attack paths, and remediation recommendations.

  • Create and enhance security testing tools, scripts, and automation to improve operational effectiveness and assessment coverage.

  • Mentor junior testers, support knowledge-sharing initiatives, and collaborate with stakeholders to strengthen enterprise security practices.

Basic Qualifications
  • Bachelor’s degree in Engineering or Science, or equivalent work experience.

  • Eight or more years of experience in information security.

  • Two or more years of experience in:

    • IT infrastructure management

    • Application architecture

    • Risk management

    • Data architecture

    • Middleware technology

    • IT operations and project management

Required Skills & Experience
  • 8+ years of Information Security experience with demonstrated expertise in offensive security and penetration testing.

  • 5+ years of hands-on mobile application security testing for Android and iOS platforms.

  • Strong knowledge of OWASP Top 10, API Security Top 10, SANS Top 25, OWASP MASVS, and MASTG frameworks.

  • Advanced experience conducting manual penetration testing, exploit chaining, business logic testing, and access control assessments.

  • Expert proficiency with Burp Suite Pro, Postman, Insomnia, Nmap, Metasploit, Kali Linux, and related security testing tools.

  • Experience assessing security within AWS, Azure, Kubernetes, containers, and cloud-native security platforms.

  • Strong scripting and automation skills using Python, PowerShell, Bash, Ruby, or Go.

  • Deep understanding of HTTP/S, REST APIs, OAuth, SAML, JWT, TCP/IP, DNS, firewalls, IDS/IPS, and application architecture.

  • Knowledge of AI and Machine Learning security risks, including prompt injection, insecure model access, API abuse, and data leakage concerns.

  • Familiarity with PCI-DSS, HIPAA, NIST 800-53, ISO 27001, FedRAMP, and other security compliance frameworks.

  • Excellent communication skills with the ability to present findings to technical teams, business stakeholders, and executive leadership.

Location expectations
This role requires working from a U.S. Bank location three (3) or more days per week.

If there’s anything we can do to accommodate a disability during any portion of the application or hiring process, please refer to our disability accommodations for applicants.

Benefits:

Our approach to benefits and total rewards considers our team members’ whole selves and what may be needed to thrive in and outside work. That's why our benefits are designed to help you and your family boost your health, protect your financial security and give you peace of mind. Our benefits include the following:

  • Healthcare (medical, dental, vision)

  • Basic term and optional term life insurance

  • Short-term and long-term disability

  • Pregnancy disability and parental leave

  • 401(k) and employer-funded retirement plan

  • Paid vacation (from two to five weeks depending on salary grade and tenure)

  • Up to 11 paid holiday opportunities

  • Adoption assistance

  • Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law

Review our full benefits available by employment status here.

U.S. Bank is an equal opportunity employer. We consider all qualified applicants without regard to race, religion, color, sex, national origin, age, sexual orientation, gender identity, disability or veteran status, and other factors protected under applicable law.

E-Verify

U.S. Bank participates in the U.S. Department of Homeland Security E-Verify program in all facilities located in the United States and certain U.S. territories. Learn more about the E-Verify program.

U.S. Bank will consider qualified applicants with arrest or conviction records for employment. U.S. Bank conducts background checks consistent with applicable local laws, including the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act as well as the San Francisco Fair Chance Ordinance. U.S. Bank is subject to, and conducts background checks consistent with the requirements of Section 19 of the Federal Deposit Insurance Act (FDIA). In addition, certain positions may also be subject to the requirements of FINRA, NMLS registration, Reg Z, Reg G, OFAC, the NFA, the FCPA, the Bank Secrecy Act, the SAFE Act, and/or federal guidelines applicable to an agreement, such as those related to ethics, safety, or operational procedures.

Applicants must be able to comply with U.S. Bank policies and procedures including the Code of Ethics and Business Conduct and related workplace conduct and safety policies.

Posting may be closed earlier due to high volume of applicants.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Information Security Consultant - API Security & Governance
Lead Information Security Consultant - API Security & Governance

Usbank • Irving (TX)

On-site
USD 127,000 - 149,000
Healthcare
Life insurance
Disability insurance
+6
Lead Information Security Consultant - API Security & Governance
Lead Information Security Consultant - API Security & Governance

Usbank • Hopkins (MN)

Hybrid
USD 127,000 - 149,000
Healthcare (medical, dental, vision)
Life insurance
Paid vacation
Senior Cloud Security Infrastructure Engineer
Senior Cloud Security Infrastructure Engineer

Us Bank • Minneapolis (MN)

On-site
USD 120,000 - 141,000
Healthcare
401(k)
Paid vacation
+5
Senior Software Engineer - 3 (Full Stack)
Senior Software Engineer - 3 (Full Stack)

U.S. Bank • Irving (TX)

On-site
USD 110,000 - 150,000
Healthcare (medical, dental, vision)
401(k) and employer-funded retirement
Paid vacation and holidays
+1
Sr. Software Engineer– API & Developer Platform
Sr. Software Engineer– API & Developer Platform

U.S. Bank • Atlanta (GA)

On-site
USD 140,000 - 180,000
Healthcare (medical, dental, vision)
Life insurance
Disability insurance
+6
Sr. Software Engineer– API & Developer Platform
Sr. Software Engineer– API & Developer Platform

U.S. Bank • Chicago (IL)

On-site
USD 140,000 - 190,000
Healthcare
Retirement plan
Paid vacation
Senior Info Security Engineer
Senior Info Security Engineer

Us Bank • Minneapolis (MN)

On-site
USD 119,765 - 140,900
Healthcare (medical, dental, vision)
401(k) and employer-funded retirement plan
Paid vacation
+2
Senior Software Engineer
Senior Software Engineer

Us Bank • Irving (TX)

On-site
USD 120,000 - 141,000
Healthcare (medical, dental, vision)
401(k) and employer-funded retirement
Paid vacation and holidays
+2
Senior Systems Engineer (Network Security Engineer)
Senior Systems Engineer (Network Security Engineer)

Us Bank • Saint Paul (MN)

On-site
USD 105,000 - 124,000
Lead Software Engineer (Contact Center Modernization, AWS & AI)
Lead Software Engineer (Contact Center Modernization, AWS & AI)

Usbank • Hopkins (MN)

On-site
USD 133,000 - 157,000