Full-Time

Lead Web Application Penetration Tester

Confirmed live in the last 24 hours

M&T Bank

M&T Bank

10,001+ employees

Full-service banking for individuals and businesses

Compensation Overview

$110.6k - $184.4k/yr

Senior

Buffalo, NY, USA

Hybrid work schedule; remote work two days a week.

Category
Cybersecurity
IT & Security
Required Skills
Operating Systems
Risk Management
Requirements
  • Bachelor's degree and a minimum of 5 years’ relevant work experience, or in lieu of a degree, a combined minimum of 9 years’ higher education and/or work experience.
  • Prior experience penetration testing and red team tools to be able to simulate attacker tactics, techniques, and procedures.
  • Advanced knowledge of networking and network protocols
  • Intermediate working knowledge of operating systems and scripting and/or coding.
Responsibilities
  • Complete penetration testing or red team/adversarial exploitation exercises of web applications, Application Programming Interfaces (APIs), hardware, and mobile.
  • Perform reconnaissance, social engineering, initial access, and post-exploitation activities across internal and external environments.
  • Develop and deploy custom payloads, exploits, and tools for use during engagements, including client-side, server-side, and lateral movement scenarios.
  • Contribute to purple team exercises by sharing red team findings and collaborating with detection engineering and incident response teams to improve defensive capabilities.
  • Document detailed findings, attack paths, and security gaps with clear recommendations for mitigation and risk reduction.
  • Stay current on emerging TTPs, CVEs, and adversary tradecraft, especially in the context of web and cloud exploitation techniques.
  • Define testing methods to meet the scope and goals of assigned penetration tests.
  • Understand breach and attack simulation solutions and work with the team to validate controls effectiveness.
  • Effectively educate and train Cybersecurity teams on new tactics, techniques, and procedures to ensure technology applications and services are not at risk of compromise or will leak information.
  • Collaborate across Cybersecurity and Technology teams to leverage intelligence sources, identify new threats, improve tool usage and workflow, and mature monitoring and response capabilities.
  • Identify areas of opportunities in daily tasks to advance penetration testing skills and regularly learn new tactics, techniques, procedures to assess risk and implement and validate controls as necessary.
  • Understand and adhere to the Company’s risk and regulatory standards, policies, and controls in accordance with the Company’s Risk Appetite. Design, implement, maintain, and enhance internal controls to mitigate risk on an ongoing basis. Identify risk-related issues needing escalation to management.
  • Promote an environment that supports diversity and reflects the M&T Bank brand.
  • Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
  • Complete other related duties as assigned.
Desired Qualifications
  • Bachelor’s degree in an applicable discipline such as Computer Science, Cybersecurity, or Information Technology
  • Extensive understanding of information security concepts (both technical and organizational requirements)
  • Highly ethical and expected to maintain a level of professionalism at all times
  • Intermediate working knowledge in social engineering, application security (web and mobile), physical methods, lateral movement, threat analysis, internal and external network architecture, and a wide array of commercial and bring-your-own (BYO) products.
  • Excellent ability to strategically learn new technical skills, and apply broadly across systems, tools, and processes
  • Experience training penetration tester to ensure they have intermediate knowledge of penetration testing and red team concepts, tools, and ability to simulate attacker tactics, techniques, and procedures
  • Strong ability to analyze and draw reliable conclusions based on large volumes of quantitative data from diverse sources
  • Penetration testing-specific or Cybersecurity domain-related industry-recognized certification

M&T Bank provides a variety of banking services to individuals, small businesses, and larger enterprises. Its offerings include mortgage assistance programs, personal and business checking accounts, and mobile banking solutions. The bank primarily serves clients in the Northeastern and Mid-Atlantic regions of the United States, emphasizing community engagement and a customer-focused approach. M&T Bank's business model is based on traditional banking services such as loans, deposits, and investment products, generating revenue through interest income, fees, and service charges. A key aspect that sets M&T Bank apart from its competitors is its commitment to community involvement, which includes providing employees with volunteer time and supporting local organizations. The recent merger with United Bank, N.A. has further expanded its services and market presence.

Company Size

10,001+

Company Stage

IPO

Headquarters

Buffalo, New York

Founded

1993

Simplify Jobs

Simplify's Take

What believers are saying

  • M&T Bank's strong earnings support its $4 billion stock repurchase program.
  • The bank's expansion into new markets enhances growth opportunities.
  • M&T's focus on digital banking aligns with industry trends for improved customer experience.

What critics are saying

  • Integration challenges from the United Bank merger may affect operational efficiency.
  • Increased competition from fintechs could erode M&T's market share.
  • Rising interest rates may increase loan default rates, impacting profitability.

What makes M&T Bank unique

  • M&T Bank emphasizes community engagement and customer-centric banking experiences.
  • The bank offers a wide range of traditional and digital banking solutions.
  • M&T's recent merger with United Bank expands its market reach and service offerings.

Help us improve and share your feedback! Did you find this helpful?

Benefits

401(k) Company Match

401(k) Retirement Plan

Flexible Work Hours

Hybrid Work Options

Paid Vacation

Paid Holidays

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

Health Savings Account/Flexible Spending Account

Company News

PR Newswire
Apr 14th, 2025
Mt Bank Corporation (Nyse:Mtb) Announces First Quarter 2025 Results

BUFFALO, N.Y., April 14, 2025 /PRNewswire/ -- MT Bank Corporation ("MT" or "the Company") reports quarterly net income of $584 million or $3.32 of diluted earnings per common share

PR Newswire
Apr 8th, 2025
Mazzotta Rentals, Inc. Secures $160 Million Credit Facility to Accelerate Growth and Continue Fleet Expansion

/PRNewswire/ -- Mazzotta Rentals, Inc. (MRI), a leading provider of rental equipment solutions serving CT, MA, NY, RI, VT, NH, and ME in the construction,...

PR Newswire
Feb 16th, 2025
Wilmington Trust Names Dave Diluigi Head Of U.S. Markets

Also Named to Wilmington's Senior Leadership TeamWILMINGTON, Del., Feb. 13, 2025 /PRNewswire/ -- Wilmington Trust announced today that Dave DiLuigi has been named the new Head of U.S. Markets for the firm's Wealth division, effective February 17.In this new role, DiLuigi will be responsible for helping set the strategic direction for Wilmington Trust's Wealth business and managing the firm's mission to provide comprehensive wealth management advice to its clients looking to fulfill their financial goals and aspirations

PR Newswire
Jan 22nd, 2025
Mt Bank Corporation Announces Common Stock Repurchase Program

BUFFALO, N.Y., Jan. 22, 2025 /PRNewswire/ -- M&T Bank Corporation ("M&T") (NYSE:MTB) announced that its Board of Directors authorized a share repurchase program to repurchase up to $4.0 billion of M&T common stock, $0.50 par value per share, on the open market or in privately negotiated transactions. The authorization replaces, and terminates effective January 22, 2025, the prior $3.0 billion share repurchase program authorized by the Board of Directors in July 2022.Daryl Bible, M&T's Chief Financial Officer, noted: "The Board's decision underscores our dedication to managing shareholders' capital responsibly, in line with our established practices. Our primary focus in capital allocation is to support our customers and the communities we serve while continuing to invest in our businesses. Our strong earnings and solid capital position allow us to meet these essential goals and return surplus capital to our investors."The exact number of shares, timing for such repurchases, and the price and terms at and on which such repurchases are to be made will be at the discretion of M&T and subject to all applicable regulatory limitations.About M&T BankM&T is a financial holding company headquartered in Buffalo, New York. M&T's principal banking subsidiary, M&T Bank, provides banking products and services with a branch and ATM network spanning the eastern U.S

Reporter
Dec 19th, 2024
M&T Bank Completes $1.5 Billion Senior Notes Offering

On December 17, 2024, M&T Bank Corporation successfully closed a public offering, raising a total of $1.5 billion through the issuance of senior notes. The offering included $500,000,000 aggregate principal amount of 4.833% Fixed Rate/Floating Rate Senior Medium-Term Notes, Series A due January 16, 2029 (2029 Notes) and $1,000,000,000 aggregate principal amount of 5.385% Fixed […]