Senior Information Security Engineer - Penetration Testing
Core
Lead security incident response, conduct digital forensics, and perform penetration testing and application security assessments for banking/financial services applications.
Role type
Senior IC penetration testing engineer (offensive security)
Builds
Security test cases, automated scanning tools, exploits, and incident response playbooks
Domain
Financial services / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Penetration testing, offensive security, red teaming, OWASP Top 10, SANS Top 25, vulnerability analysis, risk assessment, incident response, cloud security, secure SDLC, networking (TCP/IP, DNS, ICMP)
Preferred skills
OSCP, CPT, CISSP, Python, PowerShell, Burp Suite, HCL AppScan, Invicti, WebInspect, GitHub, DAST
Technologies
Burp Suite, HCL AppScan, Invicti, WebInspect, Python, PowerShell, GitHub
Responsibilities
Lead or participate in computer security incident response activities; Conduct technical investigation of security related incidents and post incident digital forensics; Perform penetration testing and application security assessments across web, mobile, thick client, and API/web services; Conduct automated scans using tools like HCL AppScan, Invicti, or WebInspect; Perform manual testing using tools such as Burp Suite to identify and exploit vulnerabilities; Build tools, scripts, or exploits to support automation and testing efficiency; Design, document, test, maintain, and provide issue resolution recommendations for moderately complex security solutions.
Seniority
Senior, hands-on IC