Senior Penetration Tester (Mobile, API, Cloud)

US Bank

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Irving, TX
Posted
4 days ago
Freshness
Confirmed live yesterday
Closes
Oct 15, 2026

Market check

Salary context

How this pay compares to similar roles

Similar $174k
$124k most similar roles pay here $215k

This listing doesn't post a salary. Most similar roles pay $145,925–$202,800.

Based on 240 similar postings.

Employer

About US Bank

U.S. Bank (U.S. Bancorp) is the fifth-largest bank in the United States, providing retail banking, corporate and commercial banking, wealth management, and payment services to millions of customers. Industry: Banking & Financial Services

US Bank currently has 35 open roles on FindRole.

Listed pay typically runs $111,605–$131,300 across 31 roles with salary data.

Most-posted roles

View all roles at US Bank

At a glance

TL;DR · Senior Penetration Tester (Mobile, API, Cloud)

Senior Penetration Tester (Mobile, API, Cloud) leads advanced offensive security assessments across mobile applications, APIs, web platforms, cloud environments, and emerging AI-enabled technologies. The role involves performing manual security testing and exploitation to identify vulnerabilities, validate business impact, and partner with engineering teams to strengthen enterprise security posture. Key responsibilities include conducting threat modeling, creating detailed risk reports, and developing automation scripts to improve assessment coverage. Candidates must possess expertise in OWASP Top 10, API Security Top 10, MASVS, and MASTG frameworks while evaluating controls within AWS, Azure, Kubernetes, and containerized environments. Required tools and languages include Burp Suite Pro, Postman, Nmap, Metasploit, Kali Linux, Python, PowerShell, Bash, Ruby, and Go. The role addresses security risks in mobile platforms for Android and iOS, as well as AI-related concerns like prompt injection and data leakage.

What you'll do

  • Lead penetration testing engagements across mobile applications, APIs, web platforms, and cloud environments.
  • Perform manual security testing and exploitation to identify vulnerabilities and validate business impact.
  • Assess infrastructure against industry standards including OWASP Top 10, API Security Top 10, and MASVS.
  • Evaluate security controls within AWS, Azure, containerized environments, and Kubernetes platforms.
  • Conduct threat modeling and risk assessments to prioritize testing activities and remediation efforts.
  • Develop detailed security reports featuring vulnerability analysis, risk ratings, and actionable remediation recommendations.
  • Create and enhance security testing tools, scripts, and automation to improve assessment coverage.
  • Mentor junior testers and lead knowledge-sharing initiatives to strengthen enterprise security practices.

What we're looking for

  • Bachelor's degree in Engineering or Science, or equivalent work experience.
  • Eight or more years of experience in information security with expertise in offensive security and penetration testing.
  • Two or more years of experience in IT infrastructure management, application architecture, risk management, data architecture, middleware technology, IT operations, and project management.
  • Five or more years of hands-on mobile application security testing for Android and iOS platforms.
  • Expert proficiency with Burp Suite Pro, Postman, Insomnia, Nmap, Metasploit, Kali Linux, and other security tools.
  • Strong scripting and automation skills using Python, PowerShell, Bash, Ruby, or Go.
  • Experience assessing security within AWS, Azure, Kubernetes, containers, and cloud-native platforms.
  • Knowledge of AI and Machine Learning security risks, including prompt injection and insecure model access.

More like this

Similar roles

Senior Penetration Tester

CoStar Group

Arlington, VA 88 days ago $115,000–$203,000
Penetration Testing Python PowerShell C# Java JavaScript Go AWS Kubernetes CI/CD Active Directory Burp Suite OWASP ZAP Nmap Bloodhound Metasploit Cobalt Strike Sliver Mythic MITRE ATT&CK Secure Code Review
6+ yrs exp

Lead Penetration Test Engineer

S&P Global

Boston, MA +11 15 days ago $135,000–$200,000
Penetration Testing Vulnerability Management DAST SAST SCA CI/CD Burp Suite Nessus Metasploit Nmap OWASP Top 10 MITRE ATT&CK Python Go Bash PowerShell JavaScript AWS Azure GCP Java
8+ yrs exp Hybrid

AVP Penetration Tester

LPL Financial

Austin, TX +1 8 days ago $128,647–$214,343
LLM GenAI API Penetration Testing OWASP Top 10 Burp Suite Promptfoo HexStrike Claude Garak Pyrit Kali Linux Nessus Metasploit Cobalt Strike Python JavaScript Java PowerShell Bash C# Golang .NET AWS Azure Kubernetes SDLC
Hybrid

Expert Penetration Tester

IBM

40 days ago
Penetration Testing NMap Nessus Metasploit BurpSuite Nikto Tcpdump LLMs Unix Windows TCP/IP VLANs Firewalls Intrusion Detection Intrusion Prevention SQL Databases Containers C C++ Java C#

Red Team Penetration Tester

Booz Allen Hamilton

Dahlgren, VA 16 days ago $86,800–$198,000
Penetration Testing Red Team Operations Kali Metasploit NMAP Cobalt Strike Wireshark tcp dump Java PHP SQL No SQL HTML Linux Windows Reverse Engineering C2 WSUS
5+ yrs exp

Red Team Penetration Tester

Booz Allen Hamilton

Virginia Beach, VA 16 days ago $86,800–$198,000
Penetration Testing Kali Metasploit NMAP Cobalt Strike Wireshark tcp dump Java PHP SQL NoSQL HTML Linux Windows Reverse Engineering C2 WSUS
5+ yrs exp