> Markdown version of [/jobs/ext/1453427-senior-adaptive-threat-replication-engineer-web-mobile](https://www.wearedevelopers.com/jobs/ext/1453427-senior-adaptive-threat-replication-engineer-web-mobile). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Adaptive Threat Replication Engineer - Web/Mobile - **Company:** Hispanic Technology Executive Council - **Location:** Chicago, IL, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** ASP.NET, HTML, Java (Programming Language), JavaScript (Programming Language), PHP (Programming Language), Application Programming Interfaces (APIs), Ajax (Programming Language), Android Software Development, Apple IOS, Business Logic, Software System Penetration Testing, User Authentication, Burp Suite, Code Review, Cyber Security, Cross-Site Request Forgery, Software Debugging, Mobile Application Software, JSON, Open Web Application Security, Simple Object Access Protocol (SOAP), Mobile Security, SoapUI, SQL Injection, Web Applications, Extensible Markup Language (XML), GWAPT, Metasploit, Cross Site Scripting, Checkmarx, Objective C++, Restful APIs, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** July 26, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/75260348/1 ## About the Role * Must be able to critically examine an organization and application through the perspective of a threat actor and articulate risk in clear, precise terms to technical and non-technical audience. * Must be proficient with the common tools associated with red teaming, penetration testing, and vulnerability assessments (Metasploit, Burp Suite, Cobalt Strike, Kali, etc.). * Must be very proficient with web application vulnerability scanning tools (e.g. Invicti DAST Scanner, SoapUI, Burp Suite Pro, Checkmarx etc.). * Experience conducting manual and automated vulnerability assessments, code reviews and penetration tests against web/mobile application technologies, services, platforms and languages to identify flaws and exploits (e.g., SQL Injection, Cross-Site Scripting, Cross-Site Request Forgery, Clickjacking, Authentication/Authorization, Privilege Escalation, Business Logic Bypass, OWASP Top 10, SANS Top 25 etc.). * Experience pentesting mobile platforms such as iOS and Android, mobile device simulators. * Solid programming/debugging skills with proficiency in one or more of the following: Java, JavaScript, HTML, XML, PHP, ASP.NET, AJAX, JSON, Objective-C, and SOAP/REST web APIs. Desirable Skills: * Certifications: OSCP, GPEN, GXPN, OSCE, GWAPT, GMOB * Previous experience working in the financial industry, * Typically has 5-10 years of experience in technology and offensive security assessments Are you passionate about cyber security and looking to work with some of the best information security professionals in the world and in challenging environments? Bank of America is hiring top talent to join our team. You bring your talent and passion and we'll provide you with an opportunity to shine and grow. Enterprise Role Overview - Leads the analysis, implementation, execution and improvement of proactive security controls to prevent external threat actors from infiltrating company information or systems. Conducts research and provides leadership updates regarding advanced attempts/efforts to compromise security protocols. Maintains or reviews security systems and assesses security policies that control access to systems. Provides status updates and recommendations to the leadership team regarding the impact of theft, destruction, alteration or denial of access to information. Follows standard practices and procedures in analyzing situations or data. Typically has 5-10 years of relevant experience and will act as an individual contributor. ## Description The Cyber Security Assurance Division is looking for a Senior Ethical Hacker, specializing in application and mobile security assessments. The individual will join a team of world-class offensive security professionals diligently hunting for vulnerabilities across the bank's global technology environment. This is a senior technical role that requires a deep understanding of web application technology and a solid understanding of threats and threat TTPs. In addition to performing application assessments, as a senior member of the team you will coordinate with senior leadership on development projects, share your knowledge and experience by mentoring junior engineers, and assist the monitoring and response functions. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [The Resilience of the World Wide Web](https://www.wearedevelopers.com/videos/1281-the-resilience-of-the-world-wide-web) - [Getting under the skin: The Social Engineering techniques](https://www.wearedevelopers.com/videos/38-getting-under-the-skin-the-social-engineering-techniques) - [Introducing JSON Structure](https://www.wearedevelopers.com/videos/100219-introducing-json-structure) - [NoLoJS - Avoiding JavaScript Cruft with HTML and CSS - Aaron T. Grogg](https://www.wearedevelopers.com/videos/1806-nolojs-avoiding-javascript-cruft-with-html-and-css-aaron-t-grogg) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)