> Markdown version of [/jobs/ext/3021101-senior-penetration-tester-mobile-api-cloud](https://www.wearedevelopers.com/jobs/ext/3021101-senior-penetration-tester-mobile-api-cloud). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Penetration Tester (Mobile, API, Cloud) - **Company:** U.S. Bank, National Association - **Location:** Irving, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Apple IOS, Applications Architecture, Business Logic, Software System Penetration Testing, Microsoft Azure, Bash Shell, Burp Suite, Cloud Computing, Cloud Computing Security, Cyber Security, Data Architecture, Information Leak Prevention, Domain Name System (DNS), Middleware, Information Technology Operations, Intrusion Detection Systems, Mobile Application Software, Python (Programming Language), Kali Linux, Nmap, OAuth, Open Web Application Security, PCI Data Security Standards, Windows PowerShell, Ruby, JSON Web Token, Security Assertion Markup Language (SAML), Mobile Security, TCP/IP, Web Applications, Web Platforms, Cloud Platform System, Postman, Software Security, Firewalls (Computer Science), Containerization, Kubernetes, Metasploit, Restful APIs, Api Management, Vulnerability Analysis - **Published:** September 21, 2026 - **Apply:** https://usbank.wd1.myworkdayjobs.com/US_Bank_Careers/job/Irving-TX/Senior-Penetration-Tester--Mobile--API--Cloud-_2026-0028584 ## About the Role * Bachelor's degree in Engineering or Science, or equivalent work experience. * Eight or more years of experience in information security. * Two or more years of experience in: + IT infrastructure management + Application architecture + Risk management + Data architecture + Middleware technology + IT operations and project management, * 8+ years of Information Security experience with demonstrated expertise in offensive security and penetration testing. * 5+ years of hands-on mobile application security testing for Android and iOS platforms. * Strong knowledge of OWASP Top 10, API Security Top 10, SANS Top 25, OWASP MASVS, and MASTG frameworks. * Advanced experience conducting manual penetration testing, exploit chaining, business logic testing, and access control assessments. * Expert proficiency with Burp Suite Pro, Postman, Insomnia, Nmap, Metasploit, Kali Linux, and related security testing tools. * Experience assessing security within AWS, Azure, Kubernetes, containers, and cloud-native security platforms. * Strong scripting and automation skills using Python, PowerShell, Bash, Ruby, or Go. * Deep understanding of HTTP/S, REST APIs, OAuth, SAML, JWT, TCP/IP, DNS, firewalls, IDS/IPS, and application architecture. * Knowledge of AI and Machine Learning security risks, including prompt injection, insecure model access, API abuse, and data leakage concerns. * Familiarity with PCI-DSS, HIPAA, NIST 800-53, ISO 27001, FedRAMP, and other security compliance frameworks. * Excellent communication skills with the ability to present findings to technical teams, business stakeholders, and executive leadership. ## Description The Senior Penetration Tester will lead advanced offensive security assessments across mobile applications, APIs, web platforms, cloud environments, and emerging AI-enabled technologies. This role is responsible for identifying security weaknesses, validating business impact through controlled exploitation, and partnering with engineering teams to strengthen security posture across the enterprise. Experience with mobile security, API testing, cloud security, threat modeling, and regulatory compliance is critical. Relevant internal learning pathways emphasize cloud penetration testing, API security, mobile security frameworks, and offensive security tooling., * Lead penetration testing engagements across mobile applications, APIs, web applications, cloud platforms, and supporting infrastructure. * Perform manual security testing and exploitation to identify vulnerabilities, validate risk, and demonstrate business impact. * Assess applications against industry standards including OWASP Top 10, OWASP API Security Top 10, OWASP MASVS, and MASTG. * Evaluate security controls within AWS, Azure, containerized environments, and Kubernetes platforms. * Conduct threat modeling and risk assessments to prioritize testing activities and remediation efforts. * Develop detailed security reports including vulnerability analysis, risk ratings, attack paths, and remediation recommendations. * Create and enhance security testing tools, scripts, and automation to improve operational effectiveness and assessment coverage. * Mentor junior testers, support knowledge-sharing initiatives, and collaborate with stakeholders to strengthen enterprise security practices. ## Related Videos - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [11 Best Practices For PHP Security](https://www.wearedevelopers.com/magazine/90-11-best-practices-for-php-security) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)