Senior Mobile Penetration Tester
Company: U.S. Bank
Location: Saint Paul
Posted on: April 5, 2026
|
|
|
Job Description:
At U.S. Bank, we’re on a journey to do our best. Helping the
customers and businesses we serve to make better and smarter
financial decisions and enabling the communities we support to grow
and succeed. We believe it takes all of us to bring our shared
ambition to life, and each person is unique in their potential. A
career with U.S. Bank gives you a wide, ever-growing range of
opportunities to discover what makes you thrive at every stage of
your career. Try new things, learn new skills and discover what you
excel at—all from Day One. Job Description U.S. Bank is seeking a
Senior Mobile Penetration Tester (Mobile, API, Cloud) with
demonstrated competence and experience to support the success of
our information security program. In this role, you will assess the
security of mobile, API, and web applications as well as
information systems by identifying vulnerabilities, performing
exploitations, and recommending mitigation strategies to strengthen
resilience against cyber threats. Responsibilities Lead dynamic
penetration testing against mobile, API, and web applications and
information systems. Identify vulnerabilities and use manual
exploitation techniques to demonstrate business impact. Deliver
clear, actionable reports outlining findings, vulnerability
scoring, and remediation guidance for both technical and
non?technical audiences. Continuously enhance testing methodologies
by researching emerging threats, tools, and techniques. Support
team initiatives such as process optimization, tool/script
development, and knowledge sharing. Basic Qualifications Bachelor’s
degree in Engineering or Science, or equivalent work experience.
Eight or more years of experience in information security. Two or
more years of experience in: IT infrastructure management
Application architecture Risk management Data architecture
Middleware technology IT operations and project management Required
Skills/Experience Mobile Application Security 5 years of hands?on
experience with Android and iOS testing methodologies. Familiarity
with platform?specific risks, OWASP MASVS, and MASTG. Web & API
Penetration Testing Deep understanding of OWASP Top 10, API
Security Top 10, and SANS Top 25 vulnerabilities. Manual Testing &
Exploitation Advanced proficiency with Burp Suite Pro,
Postman/Insomnia, and custom scripts. Skilled in identifying
business logic flaws, access control issues, and chaining exploits.
Cloud & Platform Fluency Experience testing in AWS, Azure,
containerized environments, and Kubernetes. Familiarity with
cloud?native tools such as AWS Inspector, Azure Defender, and
ScoutSuite. Technical Proficiency Strong scripting skills (Python,
PowerShell, Bash, Ruby, Go). Solid understanding of HTTP/S, OAuth,
SAML, JWT, TCP/IP, DNS, firewalls, and IDS/IPS. Tooling &
Automation Experience developing custom tools and scripts to
automate testing workflows. Familiarity with tools such as Nmap,
Metasploit, and Kali Linux. Threat Modeling & Risk Assessment
Ability to conduct threat modeling and risk assessments to
prioritize testing and communicate business impact. Regulatory &
Compliance Knowledge of PCI?DSS, HIPAA, NIST 800?53, ISO 27001, and
FedRAMP. Communication & Documentation Excellent written and verbal
communication skills. Experienced in articulating findings to
technical and non?technical audiences, including executives.
Leadership & Mentorship Proven ability to lead engagements, manage
stakeholder expectations, and mentor junior testers. Preferred
Skills/Experience Source code review. ServiceNow Application
Vulnerability Response. Knowledge of change control and security
architecture Certifications (Preferred) GMOB, GWAPT, OSWE, OSCP,
GPEN, GXPN, or equivalent. This role requires working from a U.S.
Bank location three (3) or more days per week. If there’s anything
we can do to accommodate a disability during any portion of the
application or hiring process, please refer to our disability
accommodations for applicants . Benefits: Our approach to benefits
and total rewards considers our team members’ whole selves and what
may be needed to thrive in and outside work. That's why our
benefits are designed to help you and your family boost your
health, protect your financial security and give you peace of mind.
Our benefits include the following: Healthcare (medical, dental,
vision) Basic term and optional term life insurance Short-term and
long-term disability Pregnancy disability and parental leave 401(k)
and employer-funded retirement plan Paid vacation (from two to five
weeks depending on salary grade and tenure) Up to 11 paid holiday
opportunities Adoption assistance Sick and Safe Leave accruals of
one hour for every 30 worked, up to 80 hours per calendar year
unless otherwise provided by law Review our full benefits available
by employment status here . U.S. Bank is an equal opportunity
employer. We consider all qualified applicants without regard to
race, religion, color, sex, national origin, age, sexual
orientation, gender identity, disability or veteran status, and
other factors protected under applicable law. E-Verify U.S. Bank
participates in the U.S. Department of Homeland Security E-Verify
program in all facilities located in the United States and certain
U.S. territories. The E-Verify program is an Internet-based
employment eligibility verification system operated by the U.S.
Citizenship and Immigration Services. Learn more about the E-Verify
program . The salary range reflects figures based on the primary
location, which is listed first. The actual range for the role may
differ based on the location of the role. In addition to salary,
U.S. Bank offers a comprehensive benefits package, including
incentive and recognition programs, equity stock purchase 401(k)
contribution and pension (all benefits are subject to eligibility
requirements). Pay Range: $119,765.00 - $140,900.00 U.S. Bank will
consider qualified applicants with arrest or conviction records for
employment. U.S. Bank conducts background checks consistent with
applicable local laws, including the Los Angeles County Fair Chance
Ordinance and the California Fair Chance Act as well as the San
Francisco Fair Chance Ordinance. U.S. Bank is subject to, and
conducts background checks consistent with the requirements of
Section 19 of the Federal Deposit Insurance Act (FDIA). In
addition, certain positions may also be subject to the requirements
of FINRA, NMLS registration, Reg Z, Reg G, OFAC, the NFA, the FCPA,
the Bank Secrecy Act, the SAFE Act, and/or federal guidelines
applicable to an agreement, such as those related to ethics,
safety, or operational procedures. Applicants must be able to
comply with U.S. Bank policies and procedures including the Code of
Ethics and Business Conduct and related workplace conduct and
safety policies. Posting may be closed earlier due to high volume
of applicants.
Keywords: U.S. Bank, St. Paul , Senior Mobile Penetration Tester, IT / Software / Systems , Saint Paul, Minnesota