
Senior Penetration Tester, Mainframe and Web Application Security
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in North Carolina, +1 more state.
• Execute penetration tests, including black box, grey box, and assumed breach assessments for enterprise z/OS environments.
• Evaluate USS, RACF, ACF2, Top Secret, CICS, IMS, Db2, MQ, JCL, JES2, TSO/ISPF, TN3270, FTP, z/OS Connect, REST APIs, and NJE.
• Utilize manual methods, custom scripts, and offensive tools to identify users and resources, map datasets, access unsecured spool and job outputs, and exploit poorly configured CICS transactions and insecure interfaces.
• Assess exploitability and business implications, determining the severity and risk of findings.
• Document findings with steps for reproduction, evidence, impact statements, and recommendations for remediation.
• Present and defend technical findings to application teams, mainframe engineers, technology leaders, risk partners, and stakeholders.
• Conduct validation and retesting to ensure remediation and risk mitigation.
• Preserve testing evidence for audit, regulatory, and compliance purposes, including PCI DSS and SOX.
• Collaborate with internal and external testing teams to enhance coverage, methodologies, playbooks, tooling, automation, and repeatable processes.
• Perform peer reviews of penetration testing reports while offering technical guidance and mentorship.
• Stay updated on mainframe attack techniques, security controls, platform changes, offensive security practices, and industry threats.
• Bachelor's degree or equivalent education, training, and work-related experience.
• At least 7 years of experience in security engineering or related cybersecurity roles.
• In-depth specialized knowledge of cybersecurity principles, theories, and concepts.
• Demonstrated experience in security practices throughout the software development lifecycle.
• Extensive understanding of threat modeling, security testing, and penetration testing.
• Experience in implementing and managing complex information security technologies.
• Five or more years of experience in penetration testing, red team operations, offensive security, vulnerability research, or related cybersecurity fields.
• Practical experience evaluating mainframe environments, including z/OS and RACF, ACF2, or Top Secret.
• Familiarity with mainframe architecture, identity and access management, privileged access, JCL, TSO/ISPF, CICS, Db2, network services, system configuration, and security hardening.
• Proven ability to identify and validate mainframe vulnerabilities, misconfigurations, excessive access, insecure interfaces, and attack paths.
• Strong technical writing and communication skills.
• Capacity to independently manage multiple testing engagements and ensure work is completed.
• Experience in developing scripts, automation, or AI-enabled tools.
• Background in banking, financial services, or another highly regulated sector.
• Relevant offensive security certifications such as OSCP, OSEP, OSWE, GPEN, GXPN, or equivalent credentials.
• Fluency in the English language is required.
• Must not require employer sponsorship for work visa status or employment authorization.
• Medical insurance.
• Dental insurance.
• Vision insurance.
• Life insurance.
• Disability insurance.
• Accidental death and dismemberment coverage.
• Tax-preferred savings accounts.
• 401k plan.
• At least 10 days of vacation during the first year of employment, prorated as applicable.
• 10 sick days, prorated as applicable.
• Paid holidays.
• Defined benefit pension plan (depending on position and division).
• Restricted stock units (depending on position and division).
• Deferred compensation plan (depending on position and division).
Capco
CI&T
TrueML
Allocate
Get handpicked remote jobs straight to your inbox weekly.