> Markdown version of [/jobs/ext/3531270-senior-penetration-tester](https://www.wearedevelopers.com/jobs/ext/3531270-senior-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Penetration Tester - **Company:** JPMorgan Chase & Co. - **Location:** Columbus, OH, United States - **Experience:** Expert - **Salary:** $156,750.0 - $260,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Microsoft Windows, Application Programming Interfaces (APIs), Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Burp Suite, Unix, Cloud Computing, Code Review, Cyber Security, Fat Client, Mobile Application Software, Python (Programming Language), Nmap, Open Web Application Security, Reverse Engineering, Web Applications, Rust (Programming Language), Scripting, GWAPT, Metasploit - **Published:** October 1, 2026 - **Apply:** https://dejobs.org/x/x/705B59AD1AD14B239468115F4F0948CD/job/ ## About the Role * 5+ years of hands-on penetration testing experience in offensive security, with a proven track record of scoping, executing, and reporting on complex engagements. * Expertise in manual penetration testing of web, API, cloud (AWS/Azure/GCP), infrastructure, thick-client, and/or mobile applications (android/iOS), including the use of industry-standard tools (e.g., Burp Suite, Nmap, Metasploit, etc.). * Strong understanding of security assessment methodologies such as OWASP Top Ten, NIST Cybersecurity Framework, and other relevant standards. * Ability to identify and articulate systemic security issues related to threats, vulnerabilities, and risks, and provide clear, actionable recommendations for remediation. * Exceptional organizational and communication skills, including the ability to write detailed technical reports and present findings to both technical and non-technical stakeholders. * Experience conducting peer reviews of penetration test reports and mentoring junior testers. * Continuous learner who keeps up with the latest offensive security trends, tools, and techniques., * Knowledge of cybersecurity practices, operational risk management, and incident response methodologies within the US financial services sector, including relevant regulations, threats, and risks. * Proficiency in penetration testing and security concepts for both Windows and Unix-like operating systems. * Experience conducting security-focused source code reviews (e.g., Python, Java, Rust). * Experience in reverse engineering thick-client and mobile applications to identify vulnerabilities. * Relevant certifications such as OSWE, CREST (CRT, CCT), OSCP, OSCE, GXPN, GWAPT, GPEN, GMOB, or BSCP. GXPN, GWAPT, GPEN, GMOB, or BSCP ## Description This position is also open in the following locations: Tampa, FL / Atlanta, FL / Plano, TX / Columbus, OH / McLean, VA / Wilmington, DE / Jersey City, NJ / Chicago, IL / Brooklyn, NY / Houston, TX Drive the security of critical banking applications and platforms through hands-on offensive testing. As an Assessments & Exercises Vice President in the Cybersecurity and Technology Controls organization, you will play a key role in safeguarding the firm's most vital assets. Your primary responsibility will be to plan, execute, and report on penetration tests targeting high-impact applications, platforms, and services. Leveraging industry-standard methodologies and advanced techniques, you will proactively identify vulnerabilities, collaborate with application owners to understand root causes, and guide effective remediation to strengthen the firm's security posture. We are seeking candidates with a passion for offensive security, deep technical expertise in penetration testing, and a commitment to continuous learning and excellence., * Plan, scope, and execute penetration testing engagements across a variety of environments, including web applications, APIs, cloud platforms, infrastructure, thick-client, and/or mobile applications. * Collect and validate pre-requisites for each engagement, ensuring all necessary access, documentation, and approvals are in place. * Perform manual and automated testing to identify vulnerabilities, misconfigurations, and security weaknesses, leveraging industry-standard tools and custom scripts. * Document and communicate findings through comprehensive reports that include technical details, risk assessments, and actionable remediation recommendations. * Conduct peer reviews of penetration test reports to ensure accuracy, consistency, and quality of deliverables. * Collaborate with development, infrastructure, and security teams to clarify findings, support remediation efforts, and provide subject matter expertise on offensive security. * Stay current with emerging threats, vulnerabilities, and attack techniques by leveraging threat intelligence, security research, and participation in relevant industry groups. * Contribute to the continuous improvement of penetration testing methodologies, tools, and frameworks to enhance effectiveness and alignment with firm strategy and regulatory requirements. ## Related Videos - [ The attacker's footprint](https://www.wearedevelopers.com/videos/375-the-attacker-s-footprint) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Plants vs. Thieves: Automated Tests in the World of Web Security](https://www.wearedevelopers.com/videos/1282-plants-vs-thieves-automated-tests-in-the-world-of-web-security) - [The Time Paradox: Building Timezone-Safe Python/Django Applications](https://www.wearedevelopers.com/videos/1915-the-time-paradox-building-timezone-safe-python-django-applications) - [Coffee with Developers - Robby Russell](https://www.wearedevelopers.com/videos/917-coffee-with-developers-robby-russell) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Benefits of Using JMeter For Performance Testing](https://www.wearedevelopers.com/magazine/96-benefits-of-using-jmeter-for-performance-testing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)