Manual Ethical Hacker
Core
Performing manual application security assessments and offensive security testing to identify vulnerabilities and misconfigurations in the bank's technologies and applications.
Role type
Intermediate manual ethical hacker (application security)
Builds
Security assessments and simulations for the bank's applications and cyber security controls
Domain
Cybersecurity, Application Security, Offensive Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Manual pentesting, Application security testing, SQL injection (manual), XSS (manual), Manual code review, SAST tool usage, Vulnerability assessment, Penetration testing techniques, Scripting/coding, Protocol knowledge (TCP/IP, HTTP)
Preferred skills
Binary analysis, Mobile application analysis, Frida, Advanced exploit automation
Technologies
IBM AppScan, Burp Suite, SQL Map, UNIX/LINUX
Responsibilities
Perform assigned analysis of internal and external threats, Incorporate threat actor TTPs into testing, Assess security effectiveness of technology systems, Develop PoCs for vulnerabilities, Produce detailed technical reports and notifications, Mentor junior assessors
Seniority
Intermediate, hands-on IC