Penetration Testing Engineer

Alliant Credit Union
Chicago, IL, United States
26 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience required
0 years minimum
Compensation
$76,600.0 - $119,100.0
Working hours
Regular working hours
Job source

Tech stack

Testing (Software) Application Programming Interfaces (APIs) Software System Penetration Testing Cyber Security Information Systems Python (Programming Language) Web Applications Cloud Platform System GWAPT Information Technology Static Application Security Testing Web Api
+1 more
Dynamic Application Security Testing

Job description

  • Perform penetration testing with a primary focus on web applications and web APIs across homegrown and vendor systems, support testing of cloud, mobile, and internal systems.
  • Conduct manual and automated testing, including authenticated and unauthenticated attack scenarios.
  • Identify and validate vulnerabilities, and assist in assessing risk and potential impact
  • Develop proof-of-concept exploits and document attack paths when appropriate.
  • Work with development teams to support remediation efforts by review fixes, validate resolutions, and retesting.
  • Support the analysis and prioritization of vulnerabilities based on exploitability, severity, and business impact.
  • Produce clear, actionable penetration test reports for technical and non-technical audiences.
  • Contribute to improving internal testing methodologies, tooling, and standards.
  • Stay current on emerging threats, attack techniques, and best practices relevant to modern web applications, APIs, and cloud environments.
  • Maintain and administer DAST, SAST, and SCA tools, including scan execution, troubleshooting, and validation of findings.
  • Support, troubleshoot and enhance internal security workflow applications and automation written in Python.

Requirements

Education & Years of Experience

  • Minimum - 4 Year Bachelors Degree in Computer Science, Cybersecurity, Information Systems or related
  • Minimum - 0 Years of Penetration testing, offensive security or related

In Lieu of Education

  • 4 Years of Penetration testing, offensive security or related

License/Certifications/Training

  • Preferred - Industry certifications such as OSWE, OSCP, OSCE, GPEN, GWAPT, CRTO, or related offensive security credentials

Benefits & conditions

Typical hiring range: $76,600.00 to $119,100.00 Annually. Actual compensation will be determined using factors such as experience, skills & knowledge.

Benefits: Alliant provides a benefits package including health care, vision, dental, and 401k with employer match including:

  • Annual performance bonus
  • Work from home up to 3 days a week
  • Paid parental leave
  • Employee discount programs
  • Time off including paid personal and sick days
  • 11 paid holidays
  • Education reimbursement

  • Note that eligibility and cost of benefits can vary depending on the number of regularly scheduled hours, and job status such as regular full-time, regular part-time, or temporary employment.

Adhere to and ensure compliance of all business transactions with policy and process of the Bank Secrecy Act. Ensures compliance with all applicable state and federal laws, company procedures and policies. Maintains integrity and ethics in all actions and conversations with or regarding credit union members and their accounts; complies with Privacy Act directives.

The responsibilities listed do not contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this position. Duties, responsibilities and activities may change at any time with or without notice.

Equal Opportunity Employer

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

9:56 min

Expanding browser capabilities with modern web APIs

Ire Aderinokun · JS Congress

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

7:44 min

Bootstrapping a test-driven asp.net web api

Alex Banul · LIVE

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

Videos

See all

Related articles

See all