Senior Penetration Tester, Mainframe and Web Application Security

Job not on LinkedIn

🔥 0 minutes ago

🌲 North Carolina, Virginia – Remote

infoinfo

💵 $140k - $180k / year

⏰ Full Time

🟠 Senior

🔧 QA Engineer (Quality Assurance)

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Truist

Truist

10,000+ employees

Founded 2019

🏦 Banking

💸 Finance

🤝 B2B

Banking • Finance • B2B

Truist is a financial institution that offers a wide range of banking services, focusing on branch banking, commercial banking, corporate and institutional banking, and mortgage and consumer lending. The company emphasizes a culture of care, diversity, and inclusion, striving to make a positive impact in clients' lives and the community. Truist provides various career opportunities and values employee growth, offering comprehensive benefits and resources for well-being. With a commitment to diversity and workplace equity, Truist has received numerous accolades for its employment practices, including recognition for diversity and inclusion efforts.

📋 Description

• Conduct black box, grey box, and assumed breach penetration tests of enterprise z/OS environments • Assess USS, RACF, ACF2, Top Secret, CICS, IMS, Db2, MQ, JCL, JES2, TSO/ISPF, TN3270, FTP, z/OS Connect, REST APIs, and NJE • Use manual techniques, custom scripting, and offensive tooling to enumerate users and resources, map datasets, access unprotected spool and job output, and exploit misconfigured CICS transactions and insecure interfaces • Evaluate exploitability and business impact and determine finding severity and risk • Document findings with reproduction steps, evidence, impact statements, and remediation recommendations • Present and defend technical findings to application teams, mainframe engineers, technology leaders, risk partners, and stakeholders • Perform validation and retesting to confirm remediation and risk reduction • Maintain testing evidence for audit, regulatory, and compliance requirements including PCI DSS and SOX • Partner with internal and external testing teams to improve coverage, methodologies, playbooks, tooling, automation, and repeatable processes • Perform peer reviews of penetration testing reports and provide technical guidance and mentorship • Maintain current knowledge of mainframe attack techniques, security controls, platform changes, offensive security practices, and industry threats

🎯 Requirements

• Bachelor’s degree or equivalent education, training, and work-related experience • Minimum of 7 years of experience in security engineering or related cybersecurity roles • Deep specialized knowledge in cybersecurity principles, theories, and concepts • Proven experience in software development lifecycle security practices • Deep knowledge of threat modeling, security testing, and penetration testing • Experience implementing and managing complex information security technologies • Five or more years of penetration testing, red team, offensive security, vulnerability research, or related cybersecurity experience • Hands-on experience assessing mainframe environments, including z/OS and RACF, ACF2, or Top Secret • Knowledge of mainframe architecture, identity and access management, privileged access, JCL, TSO/ISPF, CICS, Db2, network services, system configuration, and security hardening • Experience identifying and validating mainframe vulnerabilities, misconfigurations, excessive access, insecure interfaces, and attack paths • Strong technical writing and communication skills • Ability to independently manage multiple testing engagements and drive work to completion • Experience developing scripts, automation, or AI-enabled tooling • Experience in banking, financial services, or another highly regulated industry • Relevant offensive security certifications such as OSCP, OSEP, OSWE, GPEN, GXPN, or equivalent credentials • English language fluency required • Must not require employer sponsorship for work visa status or employment authorization

🏖️ Benefits

• Medical insurance • Dental insurance • Vision insurance • Life insurance • Disability insurance • Accidental death and dismemberment coverage • Tax-preferred savings accounts • 401k plan • At least 10 days of vacation during the first year of employment, prorated as applicable • 10 sick days, prorated as applicable • Paid holidays • Defined benefit pension plan (depending on position and division) • Restricted stock units (depending on position and division) • Deferred compensation plan (depending on position and division)

Apply Now

Similar Jobs

🔥 2 hours ago

NeuraFlash

201 - 500

💼 Consulting

🏭 Manufacturing

📣 Marketing

QA Consultant owning testing strategy and delivery for NeuraFlash-Accenture’s Salesforce, AWS Connect, and AI implementations. Leading functional, integration, UAT, performance, and go-live quality activities.

🔥 2 hours ago

L3Harris Technologies

10,000+ employees

🏭 Manufacturing

💼 Consulting

📦 Logistics

Senior Supplier Quality Engineer qualifying suppliers and strengthening manufacturing quality for L3Harris aerospace and defense programs. Supporting missile production expansion through risk management, process control, and supplier development.

🔥 2 hours ago

Securiti AI

501 - 1000

🔒 Cybersecurity

🤖 Artificial Intelligence

📋 Compliance

Senior Quality Assurance Representative auditing United Airlines aircraft maintenance and technical operations. Conducting regulatory investigations, risk assessments, and corrective-action oversight with 50% travel.

🇺🇸 United States – Remote

💵 $90k - $117.2k / year

💰 Venture Round - Securiti on 2023-03

⏰ Full Time

🟠 Senior

🔧 QA Engineer (Quality Assurance)

🔥 3 hours ago

Baptist Health

10,000+ employees

🏥 Healthcare

🤝 Non-profit

HIM QA Lead supporting Baptist Health’s hospitals and outpatient services. Ensuring health information quality, software workflows, regulatory compliance, and staff education.

🔥 19 hours ago

AAA

5001 - 10000

🚘 Automotive

🛡️ Insurance

📦 Logistics

QA Manager governing testing strategy, automation, and release readiness for AAA’s insurance and financial services platforms. Leading QA consultants and quality delivery across applications.