Application Security enhances the ability of the development organization to consistently deliver ... The role will lead a critical application penetration testing program for the bank. It will oversee ...
Application Security enhances the ability of the development organization to consistently deliver ... The role will lead a critical application penetration testing program for the bank. It will oversee ...
Penetration Tester For AI/ML Systems 7+ years of experience in penetration testing with a focus on ... Expertise in cloud-native security testing (AWS preferred, with services like EC2, S3, and ...
Penetration Tester For AI/ML Systems 7+ years of experience in penetration testing with a focus on ... Expertise in cloud-native security testing (AWS preferred, with services like EC2, S3, and ...
Conduct application, network, and wireless penetration testing in accordance with approved methodologies and rules of engagement. Identify security flaws in computing platforms, applications, and ...
Conduct application, network, and wireless penetration testing in accordance with approved methodologies and rules of engagement. Identify security flaws in computing platforms, applications, and ...
Penetration Tester
San Antonio, TX · On-site
Conduct application, network, and wireless penetration testing in accordance with approved methodologies and rules of engagement. Identify security flaws in computing platforms, applications, and ...
Penetration Tester
San Antonio, TX · On-site
Conduct application, network, and wireless penetration testing in accordance with approved methodologies and rules of engagement. Identify security flaws in computing platforms, applications, and ...
Penetration Tester
Scottsdale, AZ · On-site
Conduct application, network, and wireless penetration testing in accordance with approved methodologies and rules of engagement. Identify security flaws in computing platforms, applications, and ...
Penetration Tester
Scottsdale, AZ · On-site
Conduct application, network, and wireless penetration testing in accordance with approved methodologies and rules of engagement. Identify security flaws in computing platforms, applications, and ...
Conduct application, network, and wireless penetration testing in accordance with approved methodologies and rules of engagement. Identify security flaws in computing platforms, applications, and ...
Conduct application, network, and wireless penetration testing in accordance with approved methodologies and rules of engagement. Identify security flaws in computing platforms, applications, and ...
Conduct application, network, and wireless penetration testing in accordance with approved methodologies and rules of engagement. Identify security flaws in computing platforms, applications, and ...
Conduct application, network, and wireless penetration testing in accordance with approved methodologies and rules of engagement. Identify security flaws in computing platforms, applications, and ...
Conduct application, network, and wireless penetration testing in accordance with approved methodologies and rules of engagement. Identify security flaws in computing platforms, applications, and ...
Conduct application, network, and wireless penetration testing in accordance with approved methodologies and rules of engagement. Identify security flaws in computing platforms, applications, and ...
Conduct application, network, and wireless penetration testing in accordance with approved methodologies and rules of engagement. Identify security flaws in computing platforms, applications, and ...
Conduct application, network, and wireless penetration testing in accordance with approved methodologies and rules of engagement. Identify security flaws in computing platforms, applications, and ...
Conduct application, network, and wireless penetration testing in accordance with approved methodologies and rules of engagement. Identify security flaws in computing platforms, applications, and ...
Conduct application, network, and wireless penetration testing in accordance with approved methodologies and rules of engagement. Identify security flaws in computing platforms, applications, and ...
Penetration Tester
Charlotte, NC · On-site
REQUIRED QUALIFICATIONS 5+ years of experience in security applications and systems Minimum of 5 years of Information Security Engineer/Consultant experience with application penetration testing.
Penetration Tester
Charlotte, NC · On-site
REQUIRED QUALIFICATIONS 5+ years of experience in security applications and systems Minimum of 5 years of Information Security Engineer/Consultant experience with application penetration testing.
Penetration Testing Lead
Leesburg, VA · On-site
The Penetration Testing Lead will analyze vulnerabilities, identify gaps in IT security policies and configurations, and deliver actionable recommendations to reduce organizational cyber risk. This ...
Penetration Testing Lead
Leesburg, VA · On-site
The Penetration Testing Lead will analyze vulnerabilities, identify gaps in IT security policies and configurations, and deliver actionable recommendations to reduce organizational cyber risk. This ...
Web Application Penetration Testing Ampcus Inc. is a certified global provider of a broad range of ... The ideal candidate will have a deep understanding of web application security, vulnerability ...
Web Application Penetration Testing Ampcus Inc. is a certified global provider of a broad range of ... The ideal candidate will have a deep understanding of web application security, vulnerability ...
Penetration Tester
Charlotte, NC · On-site
Qualifications • Minimum of 5 years of Information Security Engineer/Consultant experience with application penetration testing. • Minimum of 5 years of demonstrated experience with automated ...
Penetration Tester
Charlotte, NC · On-site
Qualifications • Minimum of 5 years of Information Security Engineer/Consultant experience with application penetration testing. • Minimum of 5 years of demonstrated experience with automated ...
The Penetration Testing Lead will analyze vulnerabilities, identify gaps in IT security policies and configurations, and deliver actionable recommendations to reduce organizational cyber risk. This ...
The Penetration Testing Lead will analyze vulnerabilities, identify gaps in IT security policies and configurations, and deliver actionable recommendations to reduce organizational cyber risk. This ...
Security Analyst Tool Name: Client Webinspect and HCL Appscan preferred - any other tools is OK as well Minimum 7 years of experience Work with enterprise programs on penetration testing and online ...
Security Analyst Tool Name: Client Webinspect and HCL Appscan preferred - any other tools is OK as well Minimum 7 years of experience Work with enterprise programs on penetration testing and online ...
... senior testing leadership, validating the security posture of mission-critical network ... penetration testing activities to identify exploitable vulnerabilities, insecure configurations ...
New
... senior testing leadership, validating the security posture of mission-critical network ... penetration testing activities to identify exploitable vulnerabilities, insecure configurations ...
New
Preferred : • Prior experience in cybersecurity or penetration testing environments. • Exposure to vulnerability management or security operations. Company : Universal Music Group is a music ...
Preferred : • Prior experience in cybersecurity or penetration testing environments. • Exposure to vulnerability management or security operations. Company : Universal Music Group is a music ...
Under general supervision, perform penetration testing of applications, systems, and network enclaves to identify security weaknesses and vulnerabilities. Assess enterprise systems using offensive ...
Under general supervision, perform penetration testing of applications, systems, and network enclaves to identify security weaknesses and vulnerabilities. Assess enterprise systems using offensive ...
Penetration Tester III
Washington, DC · On-site
Required : • Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience) • Minimum 5 years of hands-on penetration testing experience; 7 years ...
Penetration Tester III
Washington, DC · On-site
Required : • Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience) • Minimum 5 years of hands-on penetration testing experience; 7 years ...
Security Penetration Testing information
See salary details
$61.5K - $74.6K
0% of jobs
$74.6K - $87.7K
2% of jobs
$87.7K - $100.8K
3% of jobs
$100.8K - $113.9K
6% of jobs
$113.9K - $127K
5% of jobs
$127K - $140K
4% of jobs
$141.4K is the 25th percentile. Wages below this are outliers.
$140K - $153.1K
39% of jobs
$161.2K is the 75th percentile. Wages above this are outliers.
$153.1K - $166.2K
24% of jobs
$166.2K - $179.3K
2% of jobs
$179.3K - $192.4K
0% of jobs
$192.4K - $205.5K
14% of jobs
$61.5K
$152.8K
$205.5K
How much do security penetration testing jobs pay per year?
What is a security penetration tester?
What are the key skills and qualifications needed to thrive as a Security Penetration Tester, and why are they important?
What is security penetration testing?
What is the difference between Security Penetration Testing vs Security Analyst?
| Aspect | Security Penetration Testing | Security Analyst |
|---|---|---|
| Certifications | OSCP, CEH, GPEN | CISSP, Security+ |
| Work Environment | Project-based, technical testing | Monitoring, incident response |
| Primary Focus | Identifying vulnerabilities through simulated attacks | Monitoring security systems and analyzing threats |
| Employer & Industry Usage | Cybersecurity firms, IT departments | Corporate, government, finance sectors |
While both roles focus on cybersecurity, Security Penetration Testing involves actively probing systems for vulnerabilities through simulated attacks, whereas Security Analysts monitor and analyze security threats to protect organizational assets. Both roles require relevant certifications and are essential for comprehensive cybersecurity defense.
Can you make $500,000 a year in cyber security?
What jobs can I get with a security+ certification?
Can I make $200 a year in cyber security?
What are some common challenges Security Penetration Testers face when conducting assessments in large organizations?
- Penetration Tester Ethical Hacker Redlens Infosec
- Web Penetration Testing
- Physical Penetration Tester
- Penetration Testing Engineer
- Home Based Penetration Tester Red Team
- Ethical Penetration Testing
- Full Time Cybersecurity Penetration Tester
- Penetration Testers
- Freelance Network Penetration Testing
- Overnight International Penetration Tester

Full-time
Posted 3 days ago
Wells Fargo rating
7.8
Based on 686 frontline employees who took The Breakroom Quiz
66th of 141 rated banks
Job description
About this role:
Wells Fargo is seeking an Information Security Senior Manager for our Application Security Team. Application Security enhances the ability of the development organization to consistently deliver highly functional applications that are secure and resilient against attack. We develop policies, processes, controls, and tools to proactively embed security into Wells Fargo-developed applications.
The role will lead a critical application penetration testing program for the bank. It will oversee teams responsible for securing our applications and reducing the risk of data breach. The leadership role requires strong information security and offensive security foundational knowledge. The ideal candidate for this position will have demonstrated experiences leading a team, influencing, and collaborating with all levels of leadership.
In this role, you will:
- Manage and develop a geographically dispersed team of highly specialized individual contributors as they perform application penetration test assessments against a wide variety of technology systems and critical third parties
- Evolve offensive capabilities in line with threats, cyber threat intelligence and the technology strategy. Maintain an advanced awareness of current and evolving cyber threat tactics and techniques
- Make decisions and resolve issues regarding changes to information security policy, standards, and procedures as needed for systems, applications, and tools
- Set guidelines for compliance and risk management requirements for supported area and work with other stakeholders to implement key risk initiatives
- Oversee resource allocations to ensure commitments align with strategic objectives
- Advise more experienced leadership or executive management on issues with high, critical impact on the company
- Represent the organization to regulators, industry groups and governmental agencies
- Manage, hire, and develop specialized application security penetration testers across platforms.
- Develop and guide a culture of talent development to meet business objectives and strategy
- Maintain relationship with 3rd party vendors and escalate any issues.
- Managing and developing Application penetration testing assessment structure for AI and ML initiatives enterprise wide
- Demonstrate foundational AI literacy by effectively using approved AI tools to support everyday work
- Apply AI tools for activities such as research, summarization, drafting, analysis, and decision support
- Exercise sound judgment when interpreting and using AI generated outputs
- Understand basic AI limitations and appropriate use cases within daily workflows
- Adhere to data privacy, security, and data handling standards when using AI tools
- Use AI ethically and responsibly, in alignment with company policies and guidelines
Required Qualifications, US:
- 7+ years of Information Security Analysis experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
- 3+ years of management or leadership experience
- 3+ years of Penetration Testing Leadership experience
- 1+ years of application security experience
Desired Qualifications:
- 3 + years of hands-on penetration testing experience
- 2 + years of CI/CD integration experience
- Experience assessing AI and ML systems
- CISSP, CISM, GWAPT, GPEN, GXPN, GMOB, BSCP, or OSCP
- Knowledge and understanding of information security practices and policies, including information security frameworks, standards and best practices
Job Expectations
Ability to travel up to 10% of the time.
Ability to work a hybrid schedule - 3 days per week on-site/in office and 2 days per week remote
This position is not eligible for Visa sponsorship
Locations:
- 1525 W WT Harris Blvd., Charlotte, NC
- 401 Las Colinas Blvd. W, Irving, TX
Posting End Date:
23 Jun 2026*Job posting may come down early due to volume of applicants.
We Value Equal Opportunity
Wells Fargo is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other legally protected characteristic.
Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit's risk appetite and all risk and compliance program requirements.
Candidates applying to job openings posted in Canada: Applications for employment are encouraged from all qualified candidates, including women, persons with disabilities, aboriginal peoples and visible minorities. Accommodation for applicants with disabilities is available upon request in connection with the recruitment process.
Applicants with Disabilities
To request a medical accommodation during the application or interview process, visitDisability Inclusion at Wells Fargo.
Drug and Alcohol Policy
Wells Fargo maintains a drug free workplace. Please see our Drug and Alcohol Policy to learn more.
Wells Fargo Recruitment and Hiring Requirements:
a. Third-Party recordings are prohibited unless authorized by Wells Fargo.
b. Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process.
What Wells Fargo employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Wells Fargo
Sourced by ZipRecruiter
Wells Fargo & Company (NYSE: WFC) is a leading financial services company that has approximately $1.9 trillion in assets, proudly serves one in three U.S. households and more than 10% of small businesses in the U.S., and is a leading middle market banking provider in the U.S. We provide a diversified set of banking, investment and mortgage products and services, as well as consumer and commercial finance, through our four reportable operating segments: Consumer Banking and Lending, Commercial Banking, Corporate and Investment Banking, and Wealth & Investment Management. Wells Fargo ranked No. 41 on Fortune's 2022 rankings of America's largest corporations. In the communities we serve, the company focuses its social impact on building a sustainable, inclusive future for all by supporting housing affordability, small business growth, financial health and a low-carbon economy.
Industry
Finance and insurance
Company size
10,000+ Employees
Headquarters location
San Francisco, CA, US
Year founded
1852