Posted on: 22/07/2026
Job Details :
Roles & Responsibilities :
- Plan, scope, and execute advanced penetration tests across web applications, internal networks, Active Directory environments, and cloud infrastructure, delivering actionable findings within agreed timelines.
- Perform in-depth Active Directory security assessments, identifying misconfigurations, trust relationship abuses, and privilege escalation paths that expose the organization to insider and external threats.
- Design and implement Test Automation scripts and security testing frameworks to reduce manual effort and ensure repeatable, consistent vulnerability identification across application deployments.
- Continuously monitor web applications and security controls for emerging threats, zero-day vulnerabilities, and misconfigurations, recommending timely mitigations to engineering and DevSecOps teams.
- Leverage RAG-based AI tools and large language model integrations to enhance threat intelligence gathering, automate vulnerability correlation, and accelerate security research workflows.
- Produce high-quality technical and executive-level penetration test reports through strong Content Writing capabilities, clearly articulating risk severity, business impact, and step-by-step remediation guidance.
- Collaborate with development, infrastructure, and compliance teams to validate security fixes, retest patched vulnerabilities, and ensure security standards are met before production deployments.
- Serve as a subject matter expert and technical mentor to junior penetration testers, conducting knowledge transfer sessions, developing internal security playbooks, and contributing to the organization's overall security posture improvement.
Job Description Summary :
- The Staff Penetration Tester is responsible for leading complex penetration testing and offensive security operations across enterprise infrastructure, applications, and cloud platforms.
- The Penetration Tester applies advanced threat modeling, exploitation techniques and tool expertise to uncover systemic weaknesses and evaluate organizational resilience.
- The role provides strategic guidance to technical and business stakeholders, drives remediation effectiveness, and contributes to red team simulations that test detection and response maturity.
- Success requires deep technical expertise, independent decision making, and the ability to communicate complex attack paths and risks clearly across teams to strengthen Bread Financials' security posture.
Minimum Qualifications :
- Bachelor's Degree in Information Technology or Information Security or related field of study.
- At Least one (1) of the following : GPEN, GCPN, GWAPT, ECSA, OSCP, LPT Master, GRTP, or CRTE.
- 8+ years of experience in Information Security in reconnaissance, data exploitation, Web Application Testing (WAT), Active Directory (AD), scripting, automation, report writing and red teaming.
Preferred Qualifications :
- Master's Degree in Information Security or related field of study or equivalent, relevant work experience.
- 8+ years of Penetration Testing experience.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1656751