Jobs

Penetration Tester


Job details
  • Visa
  • London
  • 1 week ago

Job Description

Cybersecurity is at the beating heart of our business. Our diligence and expertise is what makes us undisputed leader in electronic payments.  We’ve made it our priority to create exemplary security operations and incident response teams, poised to defend us against any potential cyber threats.  We’re looking for those of you who are inherently driven and fascinated by the art and science of cyber defence. We’ll equip you with the very best tools and tech so that you can deliver top notch results. 

 

Continuous self-development underpins job fulfilment at Visa. If you have a burning desire for self-development, working with us will expose you to challenges and opportunities to hone your skills. We’ll provide the right environment and a plethora of top notch professionals to learn with and from.

 

Essential Functions:

  • The objective of Visa’s Penetration Testing program is to pro-actively identify weaknesses and shortcomings in Visa’s security posture and recommend necessary controls and procedures to protect Visa adversarial threats. With this mission in mind, our pentest experts are pro-actively involved in engagements that simulate adversarial threats & attacks in a timely manner.

  • The Security Specialist will be a key contributor for performing internal and external ethical hacks of Visa applications and systems. Pentest team members also help with design, development and recommendation of security solutions to protect Visa proprietary/confidential data and systems.

  • Conducting high risk and sensitive ethical hacks of internally and externally hosted applications according to scope defined by the pen test team.

  • Subject matter expertise in web, mobile or network penetration testing with track record of end to end testing of complex systems

  • Co-ordinate and execute system/network level pen tests and ethical hacking exercises.

  • Pro-actively research and Identify network and system vulnerabilities and provide recommended counter measures or controls to reduce risk to acceptable and manageable level.

  • Reviews results of network and application ethical hacks in order to determine severity of findings and to ensure proper remediation is applied.

  • Provide accurate and timely reporting of findings and proposed remediation and mitigations.

  • Technical support could include but not limited to the following: (1) Audit support & remediation, (2) Process Improvement, (3) Analysis & Reporting, (4) Cross Divisional Functional education, training and awareness, (5) function/Methodology/Strategy advancement.

  • Provide technical support to senior management in identifying and streamlining new/existing protocols and tools used by the penetration testing team.

  • Develop and automate scripts, tools and resources needed to advance ethical hacking capabilities around new and emerging technologies like mobile, cloud and embedded systems.

This is a hybrid position. Expectation of days in office will be confirmed by your hiring manager.


Qualifications

Basic Qualifications:
•2+ years of relevant work experience and a Bachelors degree, OR 5+ years of relevant work experience

Preferred Qualifications:
•3 or more years of work experience with a Bachelor’s Degree or more than 2 years of work experience with an Advanced Degree (e.g. Masters, MBA, JD, MD)
•The candidate will ideally hold one or more of the following - CREST Certified Tester – Infrastructure or Application or other equivalent certifications.
•Good knowledge on performing pen test assessments on containers and cloud environments (Azure, AWS, GCP).
•Exposure to mainframe penetration testing would be an added advantage.
•Strong understanding of cryptographic concepts and applied cryptography (SSL, AES etc.).
•Proficiency in one or more scripting language. E.g. Perl, Python, Shell Scripting etc.
•Proficiency in one or more high level programming languages like Java, C, C++, Ruby etc.
•Understanding of OWASP Top 10 and SANS Top 25 web application and network vulnerabilities.
•Expertise and experience in web/API application and network penetration testing.
•Knowledge of exploit development, vulnerability research/reporting or writing system modules in C & C++, a major advantage and added bonus.
•Detailed understanding of OSI and TCP stack with emphasis on computer architecture and networking protocols.
•Knowledge of web application technologies and layer 7 protocols like HTTP, DHCP, DNS, FTP etc.
•Good understanding of networking concepts around Ethernet, switched LAN and WAN environment.
•Good understanding of protecting AI and LLMs through tailored penetration testing methodologies and practices.
•Prior knowledge or academic familiarity with reverse engineering, malware analysis, security research and forensic tools will be an added advantage.



Additional Information

Visa is an EEO Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status. Visa will also consider for employment qualified applicants with criminal histories in a manner consistent with EEOC guidelines and applicable local law.

Sign up for our newsletter

The latest news, articles, and resources, sent to your inbox weekly.

Similar Jobs

Penetration Tester

Starling is the UK’s first and leading digital bank on a mission to fix banking! We built a new kind of bank because we knew technology had the power to help people save, spend and manage their money in a new and transformative way. Read more aboutOur Storyhere.We’re a fully...

Starling Bank London

Penetration Tester

Job DescriptionCybersecurity is at the beating heart of our business. Our diligence and expertise is what makes us undisputed leader in electronic payments.  We’ve made it our priority to create exemplary security operations and incident response teams, poised to defend us against any potential cyber threats.  We’re looking for those...

Visa London

Lead Cyber Assessor

A Scottish-based Cyber Security Consultancy are looking for a Lead Cyber Assessor (or Penetration Tester) to join their remote team as they enter a really exciting period of growth - Fully Remote working from within the UK available.They've been operating for a couple of years now and are already starting...

Cathcart Technology Edinburgh

Security Consultant

The Opportunity:Our Technical Security Consultant team in the UK and Spain is growing - we are looking to speak with innovative technical Security Consultants/Penetration Testers.Key Accountabilities:As a Security Consultant, you will be involved with on-site client visits and remote engagements, in order to complete penetration security testing engagements and mitigate...

NCC Group Montpellier

Freelance Cybersecurity Trainers

We empower organisations and nations to counter digital threats. Our internationally acclaimed team of digital threat experts and thought leaders work at the cutting-edge of threat detection, continually scanning the horizon for next-generation risks. We use technology to support deep human insight, enabling us to build long-range resilience for clients.We...

Protection Group International Oxford

Security Engineer

We are looking for a Security Engineer. You’ll be directly responsible for safeguarding Ometria’s digital assets by actively managing risks to maintain a secure and resilient environment. You will work closely with our Product and Engineering teams to ensure that security and privacy best practices are followed whilst finding solutions...

Ometria