Penetration Testing Engineer

Alliant Credit UnionChicago, IL
$76,600 - $119,100Hybrid

About The Position

In this hybrid role based at our Chicago headquarters, you will plan, execute, and report on penetration testing for web applications and web APIs across both internally developed and vendor SaaS solutions. Perform hands‑on offensive security testing to identify, validate, and drive remediation of vulnerabilities in modern application and API architectures. Support targeted testing of related infrastructure, cloud services, and internal systems. Work with software engineering, application security, and cyber threat mitigation teams to strengthen the organization’s overall security posture.

Requirements

  • Minimum - 4 Year Bachelors Degree in Computer Science, Cybersecurity, Information Systems or related
  • Minimum - 0 Years of Penetration testing, offensive security or related
  • 4 Years of Penetration testing, offensive security or related (In Lieu of Education)

Nice To Haves

  • Industry certifications such as OSWE, OSCP, OSCE, GPEN, GWAPT, CRTO, or related offensive security credentials

Responsibilities

  • Perform penetration testing with a primary focus on web applications and web APIs across homegrown and vendor systems, support testing of cloud, mobile, and internal systems.
  • Conduct manual and automated testing, including authenticated and unauthenticated attack scenarios.
  • Identify and validate vulnerabilities, and assist in assessing risk and potential impact.
  • Develop proof‑of‑concept exploits and document attack paths when appropriate.
  • Work with development teams to support remediation efforts by review fixes, validate resolutions, and retesting.
  • Support the analysis and prioritization of vulnerabilities based on exploitability, severity, and business impact.
  • Produce clear, actionable penetration test reports for technical and non‑technical audiences.
  • Contribute to improving internal testing methodologies, tooling, and standards.
  • Stay current on emerging threats, attack techniques, and best practices relevant to modern web applications, APIs, and cloud environments.
  • Maintain and administer DAST, SAST, and SCA tools, including scan execution, troubleshooting, and validation of findings.
  • Support, troubleshoot and enhance internal security workflow applications and automation written in Python.

Benefits

  • health care
  • vision
  • dental
  • 401k with employer match
  • Annual performance bonus
  • Work from home up to 3 days a week
  • Paid parental leave
  • Employee discount programs
  • Time off including paid personal and sick days
  • 11 paid holidays
  • Education reimbursement
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service