This role offers a hybrid work schedule at our Wilmington, DE Tech Hub. Overview: Searches for application weaknesses that are exploitable, and partners with technology, cybersecurity, and risk teams to remediate any found weaknesses. Collaborates with technology teams when implementing new applications to help the team identify weaknesses before an attacker does. Primary Responsibilities: Complete penetration testing (primarily Grey & White Box testing) of web applications, Application Programming Interfaces (APIs), hardware, and mobile. Define testing methods to meet the scope and goals of assigned penetration tests. Gather intelligence to better understand how target works and its potential vulnerabilities. Understand breach and attack simulation solutions and work with the team to validate controls effectiveness. Document and formally report testing initiative findings. Maintain tools and scripts used in penetration testing and red team processes. Effectively educate and train Cybersecurity teams on new tactics, techniques, and procedures to ensure technology applications and services are not at risk of compromise or will leak information. Collaborate across Cybersecurity and Technology teams to leverage intelligence sources, identify new threats, improve tool usage and workflow, and mature monitoring and response capabilities. Identify areas of opportunities in daily tasks to advance penetration testing skills and regularly learn new tactics, techniques, procedures to assess risk and implement and validate controls as necessary. Understand and adhere to the Company’s risk and regulatory standards, policies, and controls in accordance with the Company’s Risk Appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues needing escalation to management. Promote an environment that supports belonging and reflects the M&T Bank brand. Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable. Complete other related duties as assigned. Scope of Responsibilities: Engages in regular interaction with middle management within Internal Audit, Compliance, Risk Management, and Technology. Determines and develops approach to solutions. Work is evaluated upon completion to ensure objectives have been met. Work is accomplished with periodic check-ins for alignment and limited direction. Basic knowledge of all penetration testing and red team tools. Strong knowledge of networking and network protocols. Intermediate working knowledge of operating systems and scripting and/or coding. Manager Responsibilities: No supervisory responsibilities.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Number of Employees
5,001-10,000 employees