About this role
Execute timely, thorough, time-bound penetration testing across MUFG application and infrastructure assets to identify exploitable vulnerabilities. Produce clear reporting with severity, reproducible steps, and mitigation recommendations while mentoring junior team members.
Key Responsibilities
- Execute black/grey/white-box penetration testing of applications and infrastructure assets
- Mentor and train junior team members and peers
- Prepare clear, concise vulnerability reports with severity and remediation
- Perform vulnerability research across MUFG assets
- Utilize industry-standard penetration-testing methodologies and security frameworks
Technical Overview
Performs black/grey/white-box penetration testing across network infrastructure, Active Directory, endpoints, operating systems (Windows and Unix/Linux/AIX), databases, and cloud/container environments (AWS, Azure, Oracle, Kubernetes). Uses industry methodologies and security frameworks including OWASP and the MITRE ATT&CK framework, with hands-on tools such as Burp Suite, Metasploit, Nessus, and Kali Linux.
Ideal Candidate
The ideal candidate is a senior penetration tester with 5+ years of application and infrastructure penetration testing experience across black-box, grey-box, and white-box approaches. They have strong expertise with OWASP and the MITRE ATT&CK framework, hands-on tool experience (e.g., Burp Suite, Metasploit, Nessus, Kali Linux), and can produce clear, severity-ranked reports with reproducible steps and remediation guidance. They also mentor junior testers and have experience spanning Active Directory, Windows/Unix/Linux/AIX, databases, and cloud/container technologies.
Must-Have Skills
black/grey/white-box penetration testing5+ years of experience in application and infrastructure penetration testingOWASPMITRE ATT&CK frameworkpenetration testing methodologies and security conceptsoperational experience penetration testingBurp SuiteMetasploitKali LinuxNessusExcellent communication and report-writing skills
Nice-to-Have Skills
JavaC#CC++Assemblypost exploitationexploitation developmentbinary reverse engineeringscripting languages such as Pythonscripting languages such as PowerShellscripting languages such as Bashscripting languages such as Rubyincluding experience using automated tools and manual testing techniquesPowerShell EmpireAutoSploitGhidraIDAProOllyDbgFiddler
Tools & Platforms
Burp SuiteMetasploitCobalt StrikeKali LinuxNessusPowerShell EmpireAutoSploitGhidraIDAProOllyDbgFiddlerAmazon Web ServicesAWSAzureOracleKubernetes
Required Skills
penetration testingblack/grey/white-box penetration testingOWASPMITRE ATT&CK frameworkActive Directorynetwork infrastructureroutersswitchesfirewallsIDSIPSAVWindowsUnix/Linux/AIXMySQLSQLDB2AWSAzureOracleKubernetesBurp SuiteMetasploitCobalt StrikeKali LinuxNessusPowerShell EmpireAutoSploitGhidraIDAProOllyDbgFiddler
Hard Skills
penetration testingblack-box penetration testinggrey-box penetration testingwhite-box penetration testingnetwork infrastructureroutersswitchessecurity products and servicesfirewallsIDSIPSAVActive Directoryserversservicesdesktopsmobile devicesWindowsUnix/Linux/AIXdatabasesMySQLSQLDB2Amazon Web ServicesAWSAzureOracleKubernetesOWASPMITRE ATT&CK frameworkprogramming languagesJavaC#CC++Assemblypost exploitationexploitation developmentbinary reverse engineeringBurp SuiteMetasploitCobalt StrikeKali LinuxNessusPowerShell EmpireAutoSploitGhidraIDAProOllyDbgFiddlerPythonPowerShellBashRubyseverity calculationsteps to reproducemitigation/remediation recommendationsautomated toolsmanual testing techniques
Soft Skills
mentoringtraining junior team memberscollaborationexcellent communicationreport-writing skillsclear and concise reportingleadership
Keywords for Your Resume
Senior Penetration TesterVice Presidentpenetration testingblack-box penetration testinggrey-box penetration testingwhite-box penetration testingapplication and infrastructure penetration testingOWASPMITRE ATT&CK frameworkActive DirectoryNetwork infrastructureRoutersswitchesfirewallsIDSIPSAVWindowsUnix/Linux/AIXMySQLSQLDB2Amazon Web ServicesAzureOracleKubernetesBurp SuiteMetasploitNessusKali LinuxCobalt StrikePowerShell Empire
Deal Breakers
Bachelor's degree in computer science or related field; or applicable specialized training; or equivalent work experience, 5+ years of experience in application and infrastructure penetration testing, Must demonstrate penetration testing aligned to OWASP and the MITRE ATT&CK framework
Get matched to jobs like this
Luna finds roles that fit your skills and career goals — no endless scrolling required.
Create a Free Profile