This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Wells Fargo is seeking a Senior Application Pen Tester to identify, validate, and exploit security vulnerabilities through hands-on, manual testing across a broad range of application technologies (browser-based/web, APIs, mobile, mainframe, and thick client). Successful candidates will have demonstrable, real-world manual penetration testing experience and be comfortable going beyond automated scanner output to reproduce, validate, and investigate findings. Success in this role means delivering high-confidence, reproducible vulnerabilities with clear evidence and practical remediation guidance, and partnering with application teams to drive timely fixes.
Job Responsibility:
Conduct application penetration testing across browser-based/web applications, APIs, and mobile applications (and where applicable mainframe and thick client applications) using primarily manual techniques supplemented by automated tools
include authentication/authorization testing and business-logic abuse cases where applicable
Configure and tune automated tools to support testing, improve coverage, and accelerate discovery (as a complement to manual testing)
Perform deep defect analysis by reproducing, validating, and safely demonstrating impact (including chained attack paths when applicable)
triage and disposition false positives from automated tooling
Produce clear, reproducible technical reports with evidence (steps to reproduce, impacted components/endpoints, and risk/impact) and practical remediation guidance
Collaborate with application and security teams to ensure shared understanding of defects, prioritization, and remediation paths
support defect walkthroughs and follow-up questions as needed
Support continuous improvement of testing methodologies and processes leveraging industry standards and best practices
Collaborate with other members of the team to share knowledge and complete peer reviews of reports
Communicate findings and risk clearly to technical and non-technical stakeholders
support readouts, status updates, and remediation Q&A
Demonstrate proficiency in using AI assisted development and analysis tools (e.g., GitHub Copilot and approved code centric agents)
Leverage AI to accelerate system design, coding, testing, analysis, and troubleshooting
Apply strong technical judgment when validating and integrating AI assisted outputs into solutions
Understand and account for model limitations, security risks, and operational considerations
Apply AI responsibly in development and production environments
Ensure AI usage aligns with security, compliance, privacy, and ethical standards
Requirements:
4+ years of Cyber Security Research experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
2+ years of hands-on application penetration testing experience (manual testing required), beyond reviewing/validating automated scanner results
2+ years of Dynamic Application Security Testing (DAST) experience, including tool configuration/tuning and manual verification of findings
Nice to have:
Advanced experience with testing tools such as Burp Suite, Invicti, WebInspect, and Fiddler (and applying them to web, API, mobile, and thick client testing as applicable)
Advanced knowledge of application security and common vulnerabilities (OWASP Top 10)
Experience with scripting and automation (e.g., Python, Shell)
Knowledge of security best practices and compliance standards (e.g., PCI DSS, GDPR)
Excellent communication skills and the ability to collaborate effectively with cross-functional teams
Strong problem-solving and analytical skills
Demonstrated knowledge of AI/ML-enabled applications and common security risks (for example, prompt injection, sensitive data exposure, and insecure integrations)
Security certifications such as OSCP, BSCP, GWAPT, GPEN, GXPN or equivalent are a plus