Senior Penetration Tester (Web/API/Thick-Clients) - Assessments & Exercises Vice President
- Design and execute testing and simulations - such as penetration tests, technical controls assessments, cyber exercises, or resiliency simulations, and contribute to the development and refinement of assessment methodologies, tools, and frameworks to ensure alignment with the firm's strategy and compliance with regulatory requirements
- Evaluate controls for effectiveness and impact on operational risk, as well as opportunities to automate control evaluation
- Collaborate closely with cross-functional teams to develop comprehensive assessment reports - including detailed findings, risk assessments, and remediation recommendations - making data-driven decisions that encourage continuous improvement
- Utilize threat intelligence and security research to stay informed about emerging threats, vulnerabilities, industry best practices, and regulations. Apply this knowledge to enhance the firm's assessment strategy and risk management. Engage with peers and industry groups that share threat intelligence analytics
- 5+ years of experience in cybersecurity or resiliency, with demonstrated exceptional organizational skills to plan, design, and coordinate the development of offensive security testing, assessments, or simulation exercises
- Significant experience conducting manual penetration tests against a wide variety of applications and technologies with a focus on web, API, and thick-clients
- Proficiency in software development and debugging
- Understanding of local data storage, encryption, and application security
- Knowledge of US financial services sector cybersecurity or resiliency organization practices, operations risk management processes, principles, regulations, threats, risks, and incident response methodologies
- Ability to identify systemic security or resiliency issues as they relate to threats, vulnerabilities, or risks, with a focus on recommendations for enhancements or remediation, and proficiency in multiple security assessment methodologies (e.g., Open Worldwide Application Security Project (OWASP) Top Ten, National Institute of Standards and Technology (NIST) Cybersecurity Framework), offensive testing tools, or resiliency testing equivalents
- Excellent communication, collaboration, and report writing skills, with the ability to influence and engage stakeholders across various functions and levels
- Proficiency in security concepts for both Windows and Unix-like Operating Systems
- Experience in source code review and/or building software with multiple programming languages (i.e. Python, Java, Rust, etc.)
- Experience in reverse engineering standalone, thick client and mobile applications
- Experience with hardware hacking tools and techniques
- Ability to analyze binary firmware images and reverse engineer code
- Certifications like OSWE, CREST (CRT, CCT), OSCP, OSCE, GXPN, GWAPT, GPEN, BSCP
JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans Base Pay/Salary
Jersey City,NJ $152,000.00 - $260,000.00 / year; Brooklyn,NY $152,000.00 - $260,000.00 / year; Washington,DC $152,000.00 - $260,000.00 / year; Chicago,IL $133,000.00 - $225,000.00 / year
Recommended Jobs
District Operations Supervisor
Job Description Job Description Job Description The District Operations Supervisor is responsible for identifying, prospecting and securing business opportunities to support new revenue grow…
Customer Support Rep
I'm a recruiter (headhunter). This service is free to you (the candidate). One of the companies that I recruit for is looking for a: Customer Support Rep $18 per hour to $22 per hour Hybrid…
Oracle SCM Costing/MFG Functional Consultant - Manager Save for Later Remove job
At PwC, our people in business application consulting specialise in consulting services for a variety of business applications, helping clients optimise operational efficiency. These individuals an…
Senior Research Safety Manager
Position Summary Join the University of Dayton Research Institute (UDRI), a top-tier Catholic research university where innovation meets purpose! UDRI is seeking a dynamic Senior Research Safety M…
Caseworker Intern - [Akron, OH] (Unpaid, Fall 2025 & Spring 2026)
Job Details Description Responsibilities: Assist in the development, modification, and monitoring of individual client programming. Act as a liaison with referral sources to support client…
Charity Event Assistant - Entry Level
Are you passionate about making a difference and eager to gain hands-on experience in nonprofit events and fundraising ? Join our dynamic outreach team as a Charity Events Assistant and play…
SIEM Content Developer
Ready to Code the Signals That Stop the Threats? Join a mission where every line of code you write strengthens national defense. Diligent Consulting Inc. is seeking a SIEM Developer who lives at …
Journeyman Plumber
Job Description Job Description Description: Accurate is looking for a licensed Journeyman Plumber to assist with commercial plumbing projects. In this role, you will perform preventative main…
Associate, Manufacturing - Operations
Abeona is looking for a Manufacturing Operations Associate to join our team in Cleveland, OH. The successful candidate will be responsible for Manufacturing initiatives supporting multiple product pip…
Technical Sales Representative
Job Description Job Description OUR OFFER When you come to work at the Protech Group you’ll become part of a dynamic and rapidly expanding business. Everyone has a part to play in our success …