Cyber Security Application Penetration Testing Engineer

Wells Fargo

Confirmed live today High trust
Hybrid

Quick summary

Work type
Hybrid
Location
San Francisco, CACharlotte, NCChandler, AZIrving, TX
Salary
$87,000–$168,000 / yr
Employment
Full-time
Posted
2 days ago
Freshness
Confirmed live today
Closes
Oct 10, 2026

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $173k
This role $128k
$73k most similar roles pay here $218k

This role pays less than 87% of similar roles. Most pay $142,400–$203,750 — the shaded band above. At the midpoint, this role pays about $128k versus about $173k for comparable roles.

Based on 240 similar postings.

Employer

About Wells Fargo

Wells Fargo & Company is one of the largest banks in the United States, providing banking, investment, mortgage, and consumer and commercial finance products and services nationwide. Industry: Banking & Financial Services

Wells Fargo currently has 34 open roles on FindRole.

Listed pay typically runs $119,000–$224,000 across 17 roles with salary data.

Most-posted roles

View all roles at Wells Fargo

At a glance

TL;DR · Cyber Security Application Penetration Testing Engineer

The Cyber Security Application Penetration Testing Engineer joins the Technology Cybersecurity department to perform penetration testing on web applications, mobile applications, and APIs. This role involves identifying security defects through manual testing and automated tools, analyzing scan results to triage false positives, and generating detailed technical reports for remediation. The engineer will collaborate with development and security teams to improve testing methodologies while ensuring all processes align with industry standards. Key technologies include DAST tools such as Invicti, Appscan, Webinspect, Fiddler, and Burp Suite, alongside scripting in Python or Shell. A core component of the role involves leveraging AI-enhanced scanners and tools to accelerate defect identification while managing model limitations and security risks. The position focuses on identifying vulnerabilities like those in the OWASP Top 10 within a complex technical environment.

What you'll do

  • Perform manual and automated penetration testing on web applications, mobile applications, and APIs.
  • Configure and manage automated security tools to identify vulnerabilities and defects.
  • Analyze scan results to triage findings and eliminate false positives.
  • Generate detailed technical reports documenting identified security flaws for stakeholders.
  • Advise development and security teams on remediation paths for discovered vulnerabilities.
  • Integrate AI-enhanced scanners and tools to accelerate defect identification and validation.
  • Ensure all AI-assisted outputs align with security, compliance, and ethical standards.
  • Improve testing methodologies and processes based on industry standards and best practices.

What we're looking for

  • 2+ years of Cyber Security Research experience or equivalent through work, training, military service, or education.
  • 2+ years of Web application penetration testing.
  • 2+ years of Dynamic Application Security Testing (DAST).
  • Proficiency in using AI enhanced security scanners and tools to accelerate defect identification and validation.
  • Advanced experience with DAST tools such as Invicti, Appscan, Webinspect, Fiddler, or Burp Suite (preferred).
  • Advanced knowledge of application security and common vulnerabilities like OWASP Top 10 (preferred).
  • Experience with scripting and automation using Python or Shell (preferred).
  • Security certifications such as OSCP, BSCP, GWAPT, GPEN, GXPN, or equivalent (preferred).

More like this

Similar roles

Application Security Engineer

Booz Allen Hamilton

Washington, DC 5 days ago $62,000–$141,000
SAST DAST IAST Burp Suite Veracode OWASP Top 10 Java Python .NET C# Linux UNIX Eclipse JDeveloper NIST 800-53 FIPS FedRAMP CVSS CWE
6+ yrs exp

Senior Application Security Testing Engineer

3M

Remote (Austin, TX) 80 days ago $164,612–$201,193
Application Security SAST DAST SCA Threat Modeling CI/CD GitHub Azure DevOps OWASP Top 10 Secure Coding Source Code Analysis Penetration Testing
3+ yrs exp Remote

Senior Penetration Tester (Mobile, API, Cloud)

US Bank

Irving, TX 11 days ago
Penetration Testing OWASP Top 10 API Security Mobile Security AWS Azure Kubernetes Burp Suite Pro Postman Nmap Metasploit Kali Linux Python PowerShell Bash Ruby Go REST APIs OAuth SAML JWT PCI-DSS NIST 800-53
8+ yrs exp

Cyber Test Engineer

Booz Allen Hamilton

Rome, NY 17 days ago
NIST 800-53 Kali Linux Wireshark Burp Suite Metasploit Python Ruby Bash Linux Networking Virtualization Penetration Testing Security+ Tripwire

Application Security Engineer

Opendoor

Miami, FL 106 days ago
Go Python TypeScript Ruby Terraform AWS GCP Azure Kubernetes Apollo GraphQL GitHub Advanced Security CodeQL Semgrep HackerOne Burp Suite Cloudflare WAF Claude OpenAI Threat Modeling
5+ yrs exp Hybrid