Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Penetration Tester – Offensive Security image - Rise Careers
Job details

Senior Penetration Tester – Offensive Security - job 2 of 2

This role offers a hybrid work schedule; offering the flexibility to work remotely two days a week, while providing the opportunity for in-person collaboration at our Buffalo, NY Tech Hub.

Overview:  

Searches for application weaknesses that are exploitable, and partners with technology, cybersecurity, and risk teams to remediate any found weaknesses. Collaborates with technology teams when implementing new applications to help the team identify weaknesses before an attacker does.

Primary Responsibilities:

  • Complete penetration testing (primarily Grey & White Box testing) of web applications, Application Programming Interfaces (APIs), hardware, and mobile.
  • Define testing methods to meet the scope and goals of assigned penetration tests.
  • Gather intelligence to better understand how target works and its potential vulnerabilities.
  • Understand breach and attack simulation solutions and work with the team to validate controls effectiveness.
  • Document and formally report testing initiative findings.
  • Maintain tools and scripts used in penetration testing and red team processes.
  • Effectively educate and train Cybersecurity teams on new tactics, techniques, and procedures to ensure technology applications and services are not at risk of compromise or will leak information.
  • Collaborate across Cybersecurity and Technology teams to leverage intelligence sources, identify new threats, improve tool usage and workflow, and mature monitoring and response capabilities.
  • Identify areas of opportunities in daily tasks to advance penetration testing skills and regularly learn new tactics, techniques, procedures to assess risk and implement and validate controls as necessary.
  • Understand and adhere to the Company’s risk and regulatory standards, policies, and controls in accordance with the Company’s Risk Appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues needing escalation to management.
  • Promote an environment that supports diversity and reflects the M&T Bank brand.
  • Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
  • Complete other related duties as assigned.

Scope of Responsibilities:

  • Engages in regular interaction with middle management within Internal Audit, Compliance, Risk Management, and Technology.
  • Determines and develops approach to solutions. Work is evaluated upon completion to ensure objectives have been met. Work is accomplished with periodic check-ins for alignment and limited direction.
  • Basic knowledge of all penetration testing and red team tools.
  • Strong knowledge of networking and network protocols.
  • Intermediate working knowledge of operating systems and scripting and/or coding.

Education and Experience Required:

  • Bachelor's degree and a minimum of 3 years’ relevant work experience, or in lieu of a degree, a combined minimum of 7 years’ higher education and/or work experience.
  • Intermediate working knowledge of penetration testing and red team tools to be able to simulate attacker tactics, techniques, and procedures
  • Strong knowledge of networking and network protocols
  • Intermediate working knowledge of operating systems and scripting and/or coding

Education and Experience Preferred:

  • Bachelor’s degree in an applicable discipline such as Computer Science, Cybersecurity, or Information Technology
  • Strong understanding of information security concepts (both technical and organizational requirements)
  • Highly ethical and expected to maintain a level of professionalism at all times
  • Intermediate working knowledge in social engineering, application security (web and mobile), physical methods, lateral movement, threat analysis, internal and external network architecture and a wide array of commercial and bring-your-own (BYO) products
  • Prior experience with and demonstrable aptitude for quickly learning new technical skills
  • Experience training others to ensure they have basic knowledge of and ability to use function-specific tools and systems
  • Ability to analyze and draw conclusions based on quantitative data from multiple sources
  • Penetration testing-specific or Cybersecurity domain-related industry-recognized certification

M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $93,581.10 - $155,968.51 Annual (USD). The successful candidate’s particular combination of knowledge, skills, and experience will inform their specific compensation.

Location

Buffalo, New York, United States of America

Average salary estimate

$124774.5 / YEARLY (est.)
min
max
$93581K
$155968K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Penetration Tester – Offensive Security, MTB

Are you ready to take the next step in your career as a Senior Penetration Tester with M&T Bank? Located in Buffalo, NY, this hybrid position offers the flexibility you need to work two days remotely, while also providing ample opportunity for in-person collaboration at our vibrant Tech Hub. In this dynamic role, you will dive deep into discovering application weaknesses that could be exploited, collaborating with tech, cybersecurity, and risk teams to reinforce defenses. Your day-to-day responsibilities will include executing penetration tests, primarily using Grey & White Box methodologies on a variety of platforms, including web applications, APIs, and mobile devices. You’ll be instrumental in defining testing approaches that align perfectly with project goals while gathering vital intelligence to spot potential vulnerabilities. Apart from documenting findings and working closely with cybersecurity teams to bolster defenses, you will have the unique opportunity to educate and train your peers in the latest tactics and techniques. Your input will drive continuous improvements in processes and tools, while you share ideas that enhance overall cybersecurity posture. With your strong background in networking and systems, along with a Bachelor's degree or equivalent experience, you'll be a key player in foundational security efforts. Join M&T Bank, where we promote an environment that values diversity and supports our brand ethos while keeping security at the forefront. Explore a challenging yet rewarding career path with competitive pay ranging from $93,581.10 to $155,968.51 annually – your contributions will truly matter here!

Frequently Asked Questions (FAQs) for Senior Penetration Tester – Offensive Security Role at MTB
What responsibilities will a Senior Penetration Tester at M&T Bank have?

As a Senior Penetration Tester at M&T Bank, you'll be responsible for executing penetration tests, primarily utilizing Grey & White Box methodologies on web applications, APIs, and mobile platforms. You'll define testing methods, gather intelligence on target vulnerabilities, validate control effectiveness through breach and attack simulations, and document your findings thoroughly. Your collaboration with technology and cybersecurity teams will enhance security protocols and also include educating your colleagues on the latest trends and tactics.

Join Rise to see the full answer
What qualifications do I need to apply for the Senior Penetration Tester role at M&T Bank?

To qualify for the Senior Penetration Tester position at M&T Bank, candidates must possess a Bachelor's degree or equivalent experience combined with at least three years of relevant work in cybersecurity. Familiarity with penetration testing and red team tools is essential, as is a strong understanding of networking protocols and operating systems. Preferred qualifications include relevant certifications and a strong grasp of information security concepts.

Join Rise to see the full answer
How does the hybrid work schedule for the Senior Penetration Tester at M&T Bank function?

The hybrid work schedule for the Senior Penetration Tester at M&T Bank allows you to work remotely two days a week, offering a balance between home-based work and in-person collaboration at our Buffalo, NY Tech Hub. This flexibility aims to foster a productive work environment while still enabling team interactions crucial for collaboration and innovation in cybersecurity.

Join Rise to see the full answer
What tools and methodologies will I use as a Senior Penetration Tester at M&T Bank?

In the role of Senior Penetration Tester at M&T Bank, you will utilize various penetration testing tools and methodologies, especially Grey and White Box testing. You’ll also work with breach and attack simulation solutions to validate the effectiveness of security controls, while leveraging intelligence to stay ahead of potential threats. Familiarity with commercial and BYO products will enhance your testing capabilities.

Join Rise to see the full answer
What is the company culture like for the Senior Penetration Tester at M&T Bank?

At M&T Bank, the culture for the Senior Penetration Tester role is one that promotes diversity, collaboration, and continuous learning. Employees are encouraged to share ideas, drive innovation and stay abreast of new threats and developments in cybersecurity. The company emphasizes a professional environment where ethical standards are paramount and teamwork is encouraged to strengthen defenses against cyber threats.

Join Rise to see the full answer
Common Interview Questions for Senior Penetration Tester – Offensive Security
What experience do you have with penetration testing tools?

Discuss various penetration testing tools you've used, such as Metasploit, Burp Suite, or OWASP ZAP, detailing specific projects or scenarios where these tools were instrumental in identifying vulnerabilities. Emphasize your ability to adapt to new tools and your eagerness to learn additional systems.

Join Rise to see the full answer
How do you stay updated with the latest cybersecurity threats?

Share strategies you employ to keep yourself informed about new threats, such as following industry blogs, participating in webinars, attending conferences, or being active in professional cybersecurity communities. Communicate your proactive approach to continuous education in the fast-evolving field of cybersecurity.

Join Rise to see the full answer
Can you explain the difference between Grey Box and White Box testing?

Clearly articulate the distinctions where Grey Box testing combines both internal and external knowledge of the system, whilst White Box testing involves full access to the application’s source code and architecture. Provide examples of when you would use each approach in a testing scenario.

Join Rise to see the full answer
What steps do you take when you find a vulnerability?

Outline your process when you discover a vulnerability, which may include documenting the finding, assessing its severity, reporting it to the relevant stakeholders, and collaborating on remediation strategies. Emphasize the importance of communication and teamwork in addressing security issues.

Join Rise to see the full answer
How would you approach a penetration test for a web application?

Describe a systematic approach to assessing a web application, covering initial reconnaissance, scanning for vulnerabilities, exploiting identified weaknesses, and reporting findings. Discuss the tools and methodologies you would use throughout this process.

Join Rise to see the full answer
What is your experience with breach and attack simulations?

Share your background with breach and attack simulation tools, whether it’s conducting simulated attacks to validate defenses or interpreting results to improve security posture. Give examples of how these simulations have helped inform security decisions.

Join Rise to see the full answer
How do you document your penetration testing processes and findings?

Explain the importance of thorough documentation in cybersecurity. Describe your methods for recording your testing processes, findings, and remediation measures, ensuring that your reports are clear, actionable, and easy for technical and non-technical stakeholders to understand.

Join Rise to see the full answer
What are some common vulnerabilities you find in applications?

Detail common vulnerabilities such as SQL injection, cross-site scripting (XSS), and security misconfigurations. Provide examples or scenarios where you've identified and resolved these issues in past roles, demonstrating your practical experience.

Join Rise to see the full answer
How do you prioritize your tasks during a penetration test?

Discuss how you assess the scope of a penetration test, identify the highest-risk assets, and manage your time effectively to address critical vulnerabilities first. Reflect on the importance of strategic planning in ensuring a thorough assessment.

Join Rise to see the full answer
What ethical considerations do you take into account as a penetration tester?

Highlight the importance of ethics in penetration testing, such as ensuring you have proper authorization, maintaining confidentiality of sensitive information, and responsibly disclosing vulnerabilities. Discuss your commitment to adhering to professional standards and regulations.

Join Rise to see the full answer
Similar Jobs

M&T Bank aims to hire a detail-oriented Business & Commercial Collections Specialist I to manage a portfolio of delinquent loans and mitigate financial loss.

Become a key player in M&T Bank’s Enterprise Risk Management department as an Enterprise Risk Advisor specializing in Risk Policy Governance.

Photo of the Rise User
Posted 10 days ago

Ventra Health is looking for a Senior Billing Systems Analyst to provide innovative solutions for complex revenue management challenges in healthcare.

Posted 12 days ago

Join D-ploy as an IT Support Specialist and contribute to innovative IT solutions in the pharma industry.

Photo of the Rise User
Posted 11 days ago

As a Salesforce Administrator at Employment Hero, you'll play a key role in optimizing their Salesforce platform within a dynamic remote environment.

Photo of the Rise User
ManTech Hybrid US, Prince George's County, MD; Maryland, Laurel, MD
Posted 20 hours ago

As a Systems Administrator at ManTech, you'll play a critical role in upgrading and maintaining our Cisco networks to support national defense efforts.

Photo of the Rise User
Posted 8 days ago

Peraton, a leader in national security solutions, is looking for a Configuration Management expert to enhance efficiency in IT service operations.

Photo of the Rise User
Aretum Hybrid No location specified
Posted 7 days ago

ARETUM is looking for an experienced Cyber Liaison Officer to enhance cyber defense strategies for government contracting.

Photo of the Rise User
Posted 2 days ago

Join AbbVie as a Network Engineer to drive digital transformation in healthcare technology solutions.

Posted 8 days ago

We are looking for an experienced Workplace Engineer to provide second-level support and streamline technology solutions to enhance workplace efficiency.

MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
HQ LOCATION
No info
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 8, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
56 people applied to Cyber Crime Analyst at TEKsystems
Photo of the Rise User
Someone from OH, Columbus just viewed Community Outreach Canvasser $24/Hr at Confidential
Photo of the Rise User
Someone from OH, Cincinnati just viewed Email Marketing Coordinator at Creative Circle
Photo of the Rise User
Someone from OH, Columbus just viewed UX Researcher, Amazon Autos at Amazon
Photo of the Rise User
Someone from OH, Cincinnati just viewed AI training and enablement at Writer
Photo of the Rise User
Someone from OH, Cincinnati just viewed Data Analyst (Contact Center-Hybrid) at Dow Jones
S
16 people applied to SOC Intern at SHEIN
Photo of the Rise User
Someone from OH, Delaware just viewed Practice Group Manager at LifeStance Health
Photo of the Rise User
Someone from OH, Youngstown just viewed Event Services Human Resources Coordinator at Allied Universal
Photo of the Rise User
Someone from OH, Columbus just viewed IP Network Engineering Intern - Summer 2025 at Bandwidth
Photo of the Rise User
Someone from OH, Cleveland just viewed Director, Education Programs & Partnerships at Encoura
Photo of the Rise User
Someone from OH, Cleveland just viewed Operations Associate (Part-Time) - Pinecrest at Alo Yoga
Photo of the Rise User
Someone from OH, Dayton just viewed Medical Receptionist at LifeStance Health
Photo of the Rise User
Someone from OH, Coldwater just viewed Engineering Design Checker Jobs at Lockheed Martin
Photo of the Rise User
Someone from OH, Loveland just viewed SEO Admin & Business Support at Outliant
Photo of the Rise User
Someone from OH, Columbus just viewed Casting: Cedar Lake - Pilot Episode at Backstage
Photo of the Rise User
Someone from OH, Mount Orab just viewed Software Development Manager at Assured Guaranty
H
Someone from OH, Mansfield just viewed Medical Appointment Setter (Remote LatAm) at HireHawk