Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Truist

Senior Penetration Tester, Mainframe and Web Application Security

Truist

. Conduct black box, grey box, and assumed breach penetration tests of enterprise z/OS environments .

Posted 10/7/2026full-timeRemote • United StatesSenior💰 $140,000 - $180,000 per yearWebsite

Tech Stack

Tools & technologies
Cyber Security

About the role

Key responsibilities & impact
  • Conduct black box, grey box, and assumed breach penetration tests of enterprise z/OS environments
  • Assess USS, RACF, ACF2, Top Secret, CICS, IMS, Db2, MQ, JCL, JES2, TSO/ISPF, TN3270, FTP, z/OS Connect, REST APIs, and NJE
  • Use manual techniques, custom scripting, and offensive tooling to enumerate users and resources, map datasets, access unprotected spool and job output, and exploit misconfigured CICS transactions and insecure interfaces
  • Evaluate exploitability and business impact and determine finding severity and risk
  • Document findings with reproduction steps, evidence, impact statements, and remediation recommendations
  • Present and defend technical findings to application teams, mainframe engineers, technology leaders, risk partners, and stakeholders
  • Perform validation and retesting to confirm remediation and risk reduction
  • Maintain testing evidence for audit, regulatory, and compliance requirements including PCI DSS and SOX
  • Partner with internal and external testing teams to improve coverage, methodologies, playbooks, tooling, automation, and repeatable processes
  • Perform peer reviews of penetration testing reports and provide technical guidance and mentorship
  • Maintain current knowledge of mainframe attack techniques, security controls, platform changes, offensive security practices, and industry threats

Requirements

What you’ll need
  • Bachelor’s degree or equivalent education, training, and work-related experience
  • Minimum of 7 years of experience in security engineering or related cybersecurity roles
  • Deep specialized knowledge in cybersecurity principles, theories, and concepts
  • Proven experience in software development lifecycle security practices
  • Deep knowledge of threat modeling, security testing, and penetration testing
  • Experience implementing and managing complex information security technologies
  • Five or more years of penetration testing, red team, offensive security, vulnerability research, or related cybersecurity experience
  • Hands-on experience assessing mainframe environments, including z/OS and RACF, ACF2, or Top Secret
  • Knowledge of mainframe architecture, identity and access management, privileged access, JCL, TSO/ISPF, CICS, Db2, network services, system configuration, and security hardening
  • Experience identifying and validating mainframe vulnerabilities, misconfigurations, excessive access, insecure interfaces, and attack paths
  • Strong technical writing and communication skills
  • Ability to independently manage multiple testing engagements and drive work to completion
  • Experience developing scripts, automation, or AI-enabled tooling
  • Experience in banking, financial services, or another highly regulated industry
  • Relevant offensive security certifications such as OSCP, OSEP, OSWE, GPEN, GXPN, or equivalent credentials
  • English language fluency required
  • Must not require employer sponsorship for work visa status or employment authorization

Benefits

Comp & perks
  • Medical insurance
  • Dental insurance
  • Vision insurance
  • Life insurance
  • Disability insurance
  • Accidental death and dismemberment coverage
  • Tax-preferred savings accounts
  • 401k plan
  • At least 10 days of vacation during the first year of employment, prorated as applicable
  • 10 sick days, prorated as applicable
  • Paid holidays
  • Defined benefit pension plan (depending on position and division)
  • Restricted stock units (depending on position and division)
  • Deferred compensation plan (depending on position and division)