Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Senior Penetration Tester – Offensive Security image - Rise Careers
Job details

Senior Penetration Tester – Offensive Security - job 1 of 2

This role offers a hybrid work schedule; offering the flexibility to work remotely two days a week, while providing the opportunity for in-person collaboration at our Wilmington, DE Tech Hub.

Overview:  

Searches for application weaknesses that are exploitable, and partners with technology, cybersecurity, and risk teams to remediate any found weaknesses. Collaborates with technology teams when implementing new applications to help the team identify weaknesses before an attacker does.

Primary Responsibilities:

  • Complete penetration testing (primarily Grey & White Box testing) of web applications, Application Programming Interfaces (APIs), hardware, and mobile.
  • Define testing methods to meet the scope and goals of assigned penetration tests.
  • Gather intelligence to better understand how target works and its potential vulnerabilities.
  • Understand breach and attack simulation solutions and work with the team to validate controls effectiveness.
  • Document and formally report testing initiative findings.
  • Maintain tools and scripts used in penetration testing and red team processes.
  • Effectively educate and train Cybersecurity teams on new tactics, techniques, and procedures to ensure technology applications and services are not at risk of compromise or will leak information.
  • Collaborate across Cybersecurity and Technology teams to leverage intelligence sources, identify new threats, improve tool usage and workflow, and mature monitoring and response capabilities.
  • Identify areas of opportunities in daily tasks to advance penetration testing skills and regularly learn new tactics, techniques, procedures to assess risk and implement and validate controls as necessary.
  • Understand and adhere to the Company’s risk and regulatory standards, policies, and controls in accordance with the Company’s Risk Appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues needing escalation to management.
  • Promote an environment that supports diversity and reflects the M&T Bank brand.
  • Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
  • Complete other related duties as assigned.

Scope of Responsibilities:

  • Engages in regular interaction with middle management within Internal Audit, Compliance, Risk Management, and Technology.
  • Determines and develops approach to solutions. Work is evaluated upon completion to ensure objectives have been met. Work is accomplished with periodic check-ins for alignment and limited direction.
  • Basic knowledge of all penetration testing and red team tools.
  • Strong knowledge of networking and network protocols.
  • Intermediate working knowledge of operating systems and scripting and/or coding.

Education and Experience Required:

  • Bachelor's degree and a minimum of 3 years’ relevant work experience, or in lieu of a degree, a combined minimum of 7 years’ higher education and/or work experience.
  • Intermediate working knowledge of penetration testing and red team tools to be able to simulate attacker tactics, techniques, and procedures
  • Strong knowledge of networking and network protocols
  • Intermediate working knowledge of operating systems and scripting and/or coding

Education and Experience Preferred:

  • Bachelor’s degree in an applicable discipline such as Computer Science, Cybersecurity, or Information Technology
  • Strong understanding of information security concepts (both technical and organizational requirements)
  • Highly ethical and expected to maintain a level of professionalism at all times
  • Intermediate working knowledge in social engineering, application security (web and mobile), physical methods, lateral movement, threat analysis, internal and external network architecture and a wide array of commercial and bring-your-own (BYO) products
  • Prior experience with and demonstrable aptitude for quickly learning new technical skills
  • Experience training others to ensure they have basic knowledge of and ability to use function-specific tools and systems
  • Ability to analyze and draw conclusions based on quantitative data from multiple sources
  • Penetration testing-specific or Cybersecurity domain-related industry-recognized certification

M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $102,939.06 - $171,565.10 (USD). The successful candidate’s particular combination of knowledge, skills, and experience will inform their specific compensation.

Location

Wilmington, Delaware, United States of America

Average salary estimate

$137252 / YEARLY (est.)
min
max
$102939K
$171565K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Penetration Tester – Offensive Security, MTB

Join M&T Bank as a Senior Penetration Tester in Wilmington, DE, where you will have the opportunity to work in a hybrid schedule, enjoying the flexibility of remote work while engaging in collaborations at our state-of-the-art Tech Hub. In this vital role, you will search for exploitable application weaknesses alongside our technology, cybersecurity, and risk teams. Your expertise will help the organization prevent attacks by working closely with technology teams on new applications to identify vulnerabilities early on. You will conduct thorough penetration tests, focusing on Grey and White Box testing of web applications, APIs, hardware, and mobile platforms. Your responsibilities will also include defining testing methods, gathering intelligence on targets, and understanding breach and attack simulations to gauge the effectiveness of current controls. Documentation is key, as you will formally report your findings and continuously maintain the tools and scripts used in your testing processes. As an educator, you will empower the Cybersecurity teams by sharing insights on the latest tactics and techniques, fostering an environment that values diversity and aligns with M&T Bank’s core values. Moreover, your role will extend to collaborating with various teams within Cybersecurity and Technology to amplify our threat intelligence capabilities. Your strong ethical foundation and professionalism will help elevate our internal controls and operational standards. Embrace this opportunity to amplify your skills while making a difference at a leading financial institution.

Frequently Asked Questions (FAQs) for Senior Penetration Tester – Offensive Security Role at MTB
What are the responsibilities of a Senior Penetration Tester at M&T Bank?

As a Senior Penetration Tester at M&T Bank, your main responsibilities include performing penetration testing, specifically Grey and White Box tests, on web applications, APIs, mobile devices, and hardware. You will gather intelligence on targets, document findings, and educate Cybersecurity teams about emerging threats. Collaborating with technology teams to identify vulnerabilities before security breaches occur is also a key part of the job. You’ll maintain testing tools, create reports on vulnerabilities, and ensure compliance with the company's risk standards.

Join Rise to see the full answer
What qualifications do I need to be a Senior Penetration Tester at M&T Bank?

To qualify for the Senior Penetration Tester position at M&T Bank, candidates must possess a Bachelor's degree along with at least three years of relevant experience, or a combination of seven years of education and work experience. Important skills include knowledge of penetration testing and red team tools, networking protocols, and some scripting or coding experience. Industry-recognized certifications in cybersecurity or penetration testing are preferred and reflect your expertise.

Join Rise to see the full answer
What is the work environment like for a Senior Penetration Tester at M&T Bank?

The work environment for a Senior Penetration Tester at M&T Bank is dynamic and collaborative. You’ll enjoy a hybrid schedule that allows you to work remotely for two days a week while taking advantage of in-person collaboration at the Wilmington, DE Tech Hub. The culture emphasizes innovation, continual learning, and cross-team collaboration to tackle cybersecurity challenges head-on in a supportive setting.

Join Rise to see the full answer
How does M&T Bank support ongoing training for its Senior Penetration Testers?

M&T Bank places a strong emphasis on continuous learning and professional development for its Senior Penetration Testers. Employees are encouraged to advance their skills in cybersecurity by attending training sessions and obtaining industry-recognized certifications. Additionally, the collaborative environment facilitates knowledge sharing, where team members can educate one another on new techniques and tools, ensuring that everyone is up-to-date in the rapidly evolving field of cybersecurity.

Join Rise to see the full answer
What compensation can I expect as a Senior Penetration Tester at M&T Bank?

As a Senior Penetration Tester at M&T Bank, the compensation ranges from $102,939 to $171,565, reflecting the candidate’s unique combination of skills and experience. The company is dedicated to providing fair and competitive pay, with the possibility of additional benefits based on the qualifications of the successful candidate.

Join Rise to see the full answer
Common Interview Questions for Senior Penetration Tester – Offensive Security
Can you describe your experience with penetration testing methodologies?

When preparing to answer this question, highlight your familiarity with various methodologies including Grey Box and White Box testing. Discuss specific projects where you applied these techniques, emphasizing the tools used and the outcomes that demonstrated your proficiency. Be sure to mention the importance of tailored approaches based on the unique context of each application.

Join Rise to see the full answer
How do you approach identifying vulnerabilities in web applications?

To effectively address this question, outline your systematic approach starting with reconnaissance to gather as much information about the target as possible. Discuss the use of automated tools combined with manual testing to ensure comprehensive coverage. Mention common vulnerabilities you prioritize and how you validate findings for report generation.

Join Rise to see the full answer
What tools do you commonly use for penetration testing?

When asked about tools, provide a list of common penetration testing tools you've utilized, such as Burp Suite, OWASP ZAP, Metasploit, and Wireshark. Discuss your experience with each tool, explaining their use cases and particular strengths in different testing scenarios. This shows your practical knowledge and adaptability to different contexts.

Join Rise to see the full answer
How do you stay updated on the latest security threats and techniques?

In your answer, emphasize your commitment to continuous learning. Mention specific sources you follow, such as cybersecurity blogs, forums, and conferences. Highlight any certifications you’re pursuing to enhance your knowledge and discuss how applying this knowledge has helped in practical scenarios.

Join Rise to see the full answer
Can you explain your experience with collaboration in cross-functional teams?

Share specific examples where collaboration was essential for identifying and mitigating vulnerabilities. Discuss how you communicated findings and fostered relationships with technology and cybersecurity teams. Emphasize the benefits of a coordinated approach in improving security measures and developing comprehensive strategies.

Join Rise to see the full answer
What challenges have you faced during penetration testing, and how did you overcome them?

Discuss particular challenges, such as time constraints or resistance from teams. Share how you navigated these challenges by leveraging communication skills, adjusting your testing approach, and prioritizing efforts to deliver valuable insights. Focus on the positive outcome that resulted from overcoming the challenges.

Join Rise to see the full answer
Describe a time when your findings led to a significant security improvement.

Provide a narrative about a specific instance where your penetration testing led to tangible security enhancements. Detail the vulnerability you discovered, how you reported it, and the subsequent changes implemented by the organization. This reflects your impact on improving the organization's security posture.

Join Rise to see the full answer
How do you ensure that your testing complies with legal and ethical standards?

In your response, emphasize your understanding of the ethical implications of penetration testing and your commitment to obtaining the necessary permissions before undertaking any testing. Discuss how you adhere to legal guidelines and internal policies throughout the testing process to maintain integrity and professionalism.

Join Rise to see the full answer
What role do you believe penetration testing plays in overall cybersecurity strategy?

To answer this question, articulate the critical importance of penetration testing in identifying risks before they can be exploited, thus informing the organization's overall security posture. Highlight how penetration testing integrates with proactive security measures and overall risk management strategies to safeguard assets.

Join Rise to see the full answer
How would you educate non-technical stakeholders on cybersecurity risks?

When answering this question, emphasize your ability to translate technical concepts into accessible language for non-technical stakeholders. Discuss your approach, such as using analogies or visual aids, and tailor your messages to address the concerns of different audiences. Highlight past experiences where you successfully communicated risk assessments to leadership or other non-technical groups.

Join Rise to see the full answer
Similar Jobs
MTB Hybrid Pikesville, MD
Posted 7 days ago

Become a key member of M&T Bank as a Teller, where you'll elevate the customer experience with your transactional and customer service skills.

Posted 7 days ago

Join M&T Bank's Mortgage Division as a Mid-Level HR Business Partner and drive strategic HR initiatives within a collaborative environment.

Photo of the Rise User

We are looking for an experienced Network Administrator at Towson University to oversee the management and operation of our campus data network.

Photo of the Rise User
Posted 3 days ago

Join NexThreat as a SOC Project Manager and lead the charge in cybersecurity while enjoying a supportive and innovative workplace.

Photo of the Rise User

Join Spektrum to take part in NATO's modernization of IT services by supporting cloud service management in a fully remote role.

Photo of the Rise User
Posted 7 hours ago

Aetos Systems is looking for a Cybersecurity Threat Analyst to enhance our security systems and contribute to team excellence.

Photo of the Rise User
Posted 3 days ago

Join Four Seasons as a Director of IT and play a pivotal role in delivering exceptional technology support to a luxury hotel.

Photo of the Rise User

Shawmut is on the lookout for a Director to steer its data and application strategy, influencing IT and business directions.

Join the Society of St. Vincent de Paul as the Chief Information Officer to spearhead technology initiatives supporting 90,000 volunteers across the U.S.

Photo of the Rise User

Join ARK Systems, Inc. as an IT/Electronics Systems Technical Rep, where you will be responsible for the installation and troubleshooting of sophisticated electronic systems.

Photo of the Rise User
Inclusive & Diverse
Diversity of Opinions
Work/Life Harmony
Dare to be Different
Reward & Recognition
Empathetic
Take Risks
Growth & Learning
Transparent & Candid
Mission Driven
Passion for Exploration
Feedback Forward
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Learning & Development
Paid Time-Off
Maternity Leave
Social Gatherings
Photo of the Rise User
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development
Photo of the Rise User
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
HQ LOCATION
No info
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 20, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!