This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
U.S. Bank is seeking a Senior Mobile Penetration Tester (Mobile, API, Cloud) with demonstrated competence and experience to support the success of our information security program. In this role, you will assess the security of mobile, API, and web applications as well as information systems by identifying vulnerabilities, performing exploitations, and recommending mitigation strategies to strengthen resilience against cyber threats.
Job Responsibility:
Lead dynamic penetration testing against mobile, API, and web applications and information systems
Identify vulnerabilities and use manual exploitation techniques to demonstrate business impact
Deliver clear, actionable reports outlining findings, vulnerability scoring, and remediation guidance for both technical and non‑technical audiences
Continuously enhance testing methodologies by researching emerging threats, tools, and techniques
Support team initiatives such as process optimization, tool/script development, and knowledge sharing
Requirements:
Bachelor’s degree in Engineering or Science, or equivalent work experience
Eight or more years of experience in information security
Two or more years of experience in: IT infrastructure management
Application architecture
Risk management
Data architecture
Middleware technology
IT operations and project management
5+ years of hands‑on experience with Android and iOS testing methodologies
Familiarity with platform‑specific risks, OWASP MASVS, and MASTG
Deep understanding of OWASP Top 10, API Security Top 10, and SANS Top 25 vulnerabilities
Advanced proficiency with Burp Suite Pro, Postman/Insomnia, and custom scripts
Skilled in identifying business logic flaws, access control issues, and chaining exploits
Experience testing in AWS, Azure, containerized environments, and Kubernetes
Familiarity with cloud‑native tools such as AWS Inspector, Azure Defender, and ScoutSuite