Be Part Of A High-Performing Team:
Join a leading global financial institution known for its strong commitment to security, innovation, and operational excellence. The organization operates in a highly regulated environment, prioritizing robust cybersecurity practices to protect critical systems and data. Teams are collaborative and fast-paced, working closely across application development, infrastructure, and security functions to proactively identify and mitigate risks. This role sits within a dedicated information security group focused on strengthening application defenses and enhancing overall cyber resilience.
What's In Store For You:
- Engagement: W2 only (no C2C/1099)
- Hybrid work model with a balance of onsite collaboration and remote flexibility
- Opportunity to work on enterprise-level security initiatives and high-impact applications
- Exposure to cross-functional teams including development, security, and external vendors
- Hands-on experience managing full lifecycle penetration testing programs
How You Will Make An Impact:
- Manage end-to-end application penetration testing activities across multiple systems
- Coordinate with external security vendors and internal development teams to plan and execute testing
- Review, validate, and communicate vulnerabilities identified during penetration tests
- Drive remediation efforts by partnering with application teams and tracking issue resolution
- Conduct retesting of remediated vulnerabilities to ensure security gaps are fully addressed
- Provide expert guidance to developers and leadership on secure coding practices and risk mitigation
Are you an experienced application security professional ready to make an impact?
- 5–7 years of experience in application security, penetration testing, or related cybersecurity roles
- Strong knowledge of application penetration testing methodologies and processes
- Deep familiarity with OWASP Top 10 vulnerabilities and secure coding principles
- Experience coordinating with third-party security testing vendors
- Ability to interpret technical findings and communicate risk clearly to both technical and non-technical stakeholders
- Strong collaboration and stakeholder management skills
- Experience working in regulated environments (financial services preferred)
- Relevant certifications (e.g., CEH, OSCP, GWAPT) are a plus