Senior Offensive Security Engineer - Pentester
Bank of America
Senior Offensive Security Engineer - Pentester
Denver, Colorado;Washington, District of Columbia; Seattle, Washington; Charlotte, North Carolina; Jacksonville, Florida; Jersey City, New Jersey; Chicago, Illinois
To proceed with your application, you must be at least 18 years of age.
Acknowledge (
Bank of America employees are required to meet all posting eligibility requirements prior to applying for any new position.
Acknowledge (
Refer a friend
To proceed with your application, you must be at least 18 years of age.
Acknowledge (
Bank of America employees are required to meet all posting eligibility requirements prior to applying for any new position.
Acknowledge (
Job Description:
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates’ physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Job Description:
Are you passionate about cybersecurity and looking to work with some of the best information security professionals in the world in challenging environments? Bank of America is hiring top talent to join our team. You bring your talent and passion, and we’ll provide you with an opportunity to shine and grow.
The Cyber Security Assurance Division is looking for a Senior Full Stack Pentester to join a team of world-class offensive security professionals. In this role, you will diligently hunt for high-risk vulnerabilities across the bank’s global technology environment. Understanding security policy and compliance is important, but in this role your focus is to identify exploitable vulnerabilities in critical systems; ones that can bring about that “nightmare scenario.”
This is a highly-technical role that requires broad technical knowledge, a deep understanding of threats, and a hacker mentality. You will lead and participate in collaborative, technical assessments that leverage a wide range of penetration testing techniques (reconnaissance, weaponization, delivery, exploitation) to identify and prove the concept of high-risk vulnerabilities across a variety of technologies. Your strong problem-solving skills, practical demonstration of technical competency, and lateral thinking will contribute to our team-first culture of collaboration and impactful findings.
This senior technical role is responsible for leading and performing assessments of the bank's technologies, applications, and cyber security controls while adapting testing methods to evolving and emerging threats. Key responsibilities include leading and performing research, understanding the bank's security policy, working with appropriate partners to complete assessments, identifying misconfigurations and vulnerabilities to achieve security impact, and reporting on the associated risk. These individuals partner closely with security partners, CIO clients, and multiple lines of business.
You will coordinate with senior leadership on development projects, share your knowledge and experience by mentoring junior engineers, and assist with monitoring and response functions, so those teams can practice and improve their capability to respond to a realistic threat actor.
Required Skills:
Minimum of 5+ years of professional offensive security experience
Must be able to critically examine an organization and system through the perspective of a threat actor and articulate risk in clear, precise terms to technical and non-technical audiences.
Must be very proficient with the common tools associated with penetration testing (Burp Suite, Metasploit, nmap, etc.).
Must have a solid understanding of voice and data networks, major operating systems, active directory, their associated peripherals, and a strong desire to learn new technologies and skill sets.
Must demonstrate knowledge of tactics, techniques, and procedures associated with malicious activity, an understanding of industry classifications and frameworks, and the ability to chain vulnerabilities in the advanced exploitation of systems.
Must be proficient in report delivery and technical documentation of vulnerabilities.
Must be able to effectively code in a programming or scripting language (Python, Java, C#, etc.)
Desirable Skills:
Certifications: OSCP, GPEN, GXPN, OSED, OSEP, OSWE, OSCE, GWAPT
Ability to work remotely if/when necessary
Previous experience working in the financial industry
Experience with hardware hacking, embedded systems analysis, and IoT hacking
This job will be open and accepting applications for a minimum of seven days from the date it was posted.
Shift:
1st shift (United States of America)
Hours Per Week:
40
Bank of America and its affiliates consider for employment and hire qualified candidates without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity, in accordance with all applicable federal, state, provincial and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our teammates.
View your "Know your Rights ( " poster.
View the LA County Fair Chance Ordinance ( .
Bank of America aims to create a workplace free from the dangers and resulting consequences of illegal and illicit drug use and alcohol abuse. Our Drug-Free Workplace and Alcohol Policy (“Policy”) establishes requirements to prevent the presence or use of illegal or illicit drugs or unauthorized alcohol on Bank of America premises and to provide a safe work environment.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. Should you be offered a role with Bank of America, your hiring manager will provide you with information on the in-office expectations associated with your role. These expectations are subject to change at any time and at the sole discretion of the Company. To the extent you have a disability or sincerely held religious belief for which you believe you need a reasonable accommodation from this requirement, you must seek an accommodation through the Bank’s required accommodation request process before your first day of work.
This communication provides information about certain Bank of America benefits. Receipt of this document does not automatically entitle you to benefits offered by Bank of America. Every effort has been made to ensure the accuracy of this communication. However, if there are discrepancies between this communication and the official plan documents, the plan documents will always govern. Bank of America retains the discretion to interpret the terms or language used in any of its communications according to the provisions contained in the plan documents. Bank of America also reserves the right to amend or terminate any benefit plan in its sole discretion at any time for any reason.
Investment products offered through MLPF&S and insurance and annuity products offered through MLLA:
Are Not FDIC Insured Are Not Bank Guaranteed May Lose Value
Are Not Deposits Are Not Insured by Any Federal Government Agency Are not a condition to Any Banking Service or Activity
Merrill Lynch, Pierce, Fenner & Smith Incorporated (also referred to as “MLPF&S” or “Merrill”) makes available certain investment products sponsored, managed, distributed or provided by companies that are affiliates of Bank of America Corporation (“BofA Corp.”). MLPF&S is a registered broker-dealer, registered investment adviser, Member SIPC and a wholly owned subsidiary of BofA Corp. Insurance and annuity products are offered through Merrill Lynch Life Agency Inc., a licensed insurance agency and wholly owned subsidiary of Bank of America Corporation.
Trust, fiduciary and investment management services are provided by Bank of America, N.A., Member FDIC and wholly owned subsidiary of Bank of America Corporation (“BofA Corp.”).
Bank of America Private Bank is a division of Bank of America, N.A.
Banking products are provided by Bank of America, N.A. and affiliated banks, Members FDIC and wholly owned subsidiaries of Bank of America Corporation.
© 2026 Bank of America Corporation. All rights reserved.
$160k - $205k
...some of the best information security professionals in the world in... ...Assurance Division is looking for a Senior Full Stack Pentester to join a team of world-class offensive security professionals. In... ...experience by mentoring junior engineers, and assist with monitoring...SeniorFull timeWork at officeRemote workShift workDay shift- Urbane Security is looking for talented professionals in offensive and defensive security to enhance their Security Services team. The role involves extensive penetration testing, risk assessment, and developing tailored security solutions. Applicants should have strong...Senior
$117.6k - $161.7k
...Washington DC metro, Chicago, Boston, Atlanta, Nashville))We're building a new AI & Offensive Tooling capability inside our Offensive Security organization, and we're looking for a senior engineer who can both build it and use it. As Senior Offensive Security Engineer, AI-...SeniorFull timeTemporary workApprenticeshipWork at officeRemote workWork from homeHome office$160k - $205k
...the Application Development Security Framework Program within Bank... ...America’s Cyber Security Assurance Offensive Security group. The program... ...hacking activity.This senior technical role is responsible... ...(s)/ eWPT; eWPTX; eMAPT [INE Pentester Academy] Strong programming/scripting...SeniorFull timeWork at officeShift workDay shift- A cybersecurity company is seeking a Solutions Engineer to enhance engagement with clients and drive revenue through specialized knowledge of offensive security solutions. The role involves understanding competitive landscapes, assisting with customer success, and representing...SuggestedRemote jobFlexible hours
- Bank of America’s Global Information Security (GIS) team is seeking a Cyber Threat Defense AI Security Senior Engineer to drive the integration of advanced AI technologies... ..., and explainability. Collaborate with offensive security teams to develop AI‑enhanced red teaming...SeniorShift workDay shift
$128.9k - $180k
...passionate team at your back. If Braze sounds like a place where you can thrive, we can’t wait to meet you.WHAT YOU'LL DOAs a Senior Security Engineer on the Enterprise Security team, you'll protect Braze employees, their assets, and work locations using various tools and...SeniorWork at officeLocal area$130k - $145k
...BasePosted: 2026-08-20Company: Addison GroupCONFIDENTIAL SEARCH - Senior Network Security EngineerLocation: Chicago - OnsitePay: $130 - $145K Base... ...401(k)Confidential search for a Senior Network Security Engineer for a highly respected Chicago organization undergoing a...Senior$130k - $150k
How you'll make an impact: As the Senior Security Engineer, you will work as a team member on the Security team you will be ensuring Strata has the correct security measures in place and provide continuous improvement opportunities to extend our capabilities and security...SeniorWork experience placement$200k - $225k
...re looking to apply your relevant experience to a new industry, join our team as we help shape a brighter way forward. The Senior Security Engineer, AI Enablement is Security's embedded, full-time representative on JLL's Falcon team, owning the product's security...SeniorFull timeLocal areaImmediate startRemote work$92k - $120k
...Click here to access. Time Type:Full timeRemote Type:Job Family Group:Information TechnologyJob Description Summary: The Senior IT Security Engineer is responsible for planning, deploying, administering, and maintaining security platforms and technologies to protect the...SeniorFull timeWork at officeWork from homeFlexible hours2 days per week$149k - $235k
...spanning AWS, GCP, and self-managed Kubernetes, backed by self-managed data stores such as MongoDB. We're looking for a Senior Cloud Security Engineer II to join our Security Engineering function as a senior individual contributor and technical leader for cloud security...SeniorWork at officeLocal area$112k - $209k
...and your search for important and impactful work lead to the same place.The global law firm of K&L Gates LLP is seeking a Senior Security Engineer to join the firm. The Senior Security Engineer develops, automates, and enhances security capabilities for cloud, on-premises...SeniorFull timeTemporary workWork experience placementLocal areaRemote work$134k - $205k
...grow, stretch, and do work that truly matters, Gong is the place to do the best work of your career.We’re looking for a Senior Corporate Security Engineer to help secure the systems, identities, devices, and collaboration platforms that power how Gong employees work every...SeniorRemote workWork from homeFlexible hours$140k - $160k
...Leading Financial Service Client is looking to hire a strong Security Engineer who can lead Red team exercises against a hybrid environment... ...Windows and Linux system hardening concepts and techniques. Seniority level Mid-Senior level Employment type Full-time Job...SeniorFull time- ...Senior Security Engineer Chicago Overview The Senior Security Engineer works in Optiv's 24x7x365 Security Operations Center as a member of the Managed Security Services team. The Senior Security Engineer uses technical knowledge on a number of security technologies...Senior
- ...resume submitted outside of an active job posting will not be considered for employment.What You'll Do:Join our dynamic Security Engineering team as a Senior Associate and make a significant impact on our organization's cybersecurity posture. In this role, you'll manage...SeniorFull timeRemote work2 days per week
- ...Security Operations - Senior Security Engineer Reporting to the Team Lead, Security Operations Engineering, the Security Operations – Senior Security Engineer will be part of a team of highly specialized engineers dedicated to solving complex, security specific challenges...SeniorVisa sponsorship
$174.8k - $236.5k
...platform. Powered by patented Attack Signal Intelligence, it empowers security teams to rapidly prioritize, investigate and respond to the... ..., visit Position Overview As a Security Engineer (Pre-Sales) at Vectra.ai, you will blend deep technical expertise...SeniorWorldwide$112k - $130k
...Senior Security EngineerRemote - United StatesJR013945 At Ensono, our Purpose is to be a relentless ally, disrupting the status quo and... ..., PASSION Role Summary The Senior Information Security Engineer is responsible for designing, implementing, and maintaining enterprise...SeniorFull timeTemporary workRemote workWork from homeFlexible hours$131k - $169k
...Senior Security Engineer Seeking a development & cloud focused Senior Security Engineer to join our expanding security team. The ideal candidate will have passion for AppSec, Cloud and AI. They will be a skilled communicator and relationship builder capable of promoting...SeniorWork at officeWork from homeFlexible hoursDay shift$110k - $135k
...Information Security Manager At HUB International, we are a team of entrepreneurs. We believe in protecting and supporting the aspirations... ...aspects of information security operations, response, and engineering. This position will contribute to a team focusing on the...SeniorImmediate start- A leading technology firm is seeking a Remote Sr. Microsoft Security Consultant for a contract position lasting 6-8 months. This role requires strong technical expertise in integrating Microsoft Security tools, deep knowledge of Microsoft security technologies like Entra...SeniorRemote jobContract work
- ...workflow automation with Moveworks’ Reasoning Engine and natural language capabilities, we... ...RoleDo you care deeply about secure access at scale? Making sure the right people... ...security is an enabler, not a blocker. As a Senior Identity & Access Management Engineer, you...SeniorWork at officeRemote workFlexible hours
- Chicago, Illinois100% RemoteFull Time$140k - $160kA consulting company is looking to bring on a hands on a Senior Application Security Engineer to work with clients on new development. You'll perform code reviews, conduct SAST/DAST/SCA scans, identify vulnerabilities in...SeniorFull time
$105.4k - $207.8k
Position Summary Cisco Network Security Engineer/ Senior Consultant, Strategy, Growth, and TransformationDeloitte’s Cyber business is passionate about making an impact with lasting change. Delivering our industry leading services requires fresh thinking and a creative...SeniorWork experience placementLocal areaVisa sponsorship- SAGE Integration is looking for a Senior Systems Engineer in Chicago to develop solutions and support our sales & operations teams. The ideal candidate will have over 10 years in security technologies, excellent problem-solving skills, and knowledge of AutoCAD and IP surveillance...Senior
- Crowe seeks an Offensive Security Senior Consultant to help organizations navigate an evolving threat landscape and regulatory environment by delivering high-value cybersecurity and risk solutions. You will work with Crowe's Cybersecurity team on advanced engagements across...Senior
- Crowe Advisory LLC in Chicago seeks a cybersecurity consultant to lead and support offensive security engagements, including network, web app, and wireless testing, plus social engineering and red/purple team exercises. You will evaluate IT controls, present findings to...Senior
- ...providing critical information about the right treatments for the right patients, at the right time.Tempus is seeking a Senior Application Security Engineer with deep expertise in penetration testing to lead efforts in identifying and remediating vulnerabilities across web...SeniorFull time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Offensive Security Engineer - Pentester. Be the first to apply!
- security engineering manager Chicago, IL
- application security engineer Chicago, IL
- sr information security engineer Chicago, IL
- sr security engineer Chicago, IL
- entry level security engineer Chicago, IL
- senior application security engineer Chicago, IL
- principal security engineer Chicago, IL
- physical security engineer Chicago, IL
- lead security engineer Chicago, IL
- security engineer Chicago, IL

