Zions Bancorporation logo

Cybersecurity Red Team-Penetration Tester

Zions Bancorporation

Midvale, UTHybridJobNo compensation foundTracked 3w agoSeen in employer's feed 3 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
No compensation found
Location
Midvale, UTHybrid
Work Authorization
Not specified

Requirements

Credentials this posting asks for.

Bachelor's degree

Job overview

Zions Bancorporation is hiring a Cybersecurity Red Team-Penetration Tester. Zions Bancorporation seeks a highly skilled Cybersecurity Red Team‑Penetration Tester to think like an adversary and proactively identify, exploit, and remediate complex security vulnerabilities across enterprise infrastructure, applications, and cloud environments.

Key focus areas include Emulate advanced adversaries by executing comprehensive red team operations and objective‑based testing, Conduct multidisciplinary testing across web applications, APIs, cloud environments, networks, and operating systems, and Audit and attack AI systems by designing adversarial simulations against LLMs and machine‑learning pipelines.

Important skills include Cyberattack Simulations, Manual Penetration Testing, Automated Penetration Testing, Red Team Operations, Objective-Based Testing, and Web Application Penetration Testing.

Skills & qualifications

RequiredNice to have

Skills

Cyberattack SimulationsManual Penetration TestingAutomated Penetration TestingRed Team OperationsObjective-Based TestingWeb Application Penetration TestingAPI Penetration TestingCloud Environment Penetration TestingAWSAzureKubernetesInternal Network Penetration TestingExternal Network Penetration TestingWindows Operating System Penetration TestingActive Directory Penetration TestingLinux Operating System Penetration TestingAI System AuditingAI System Attack SimulationLarge Language Model Vulnerability ExploitationMachine Learning Pipeline Vulnerability ExploitationCustom Exploit DevelopmentScriptingTool DevelopmentBypassing EDR AgentsTechnical ReportingRisk Impact PresentationCollaborationMITRE ATT&CKOWASP Top 10NISTPrompt InjectionTraining Data PoisoningModel InversionAPI-Based Data ExfiltrationCobalt StrikeBurp SuiteNessusNmapMetasploitBreach and Attack Simulation PlatformsActive Directory ExploitationKerberoastingAs-REP RoastingPass-the-HashGolden Ticket AttacksSilver Ticket AttacksDomain Delegation Flaws ExploitationPythonPowerShellBash

Qualifications

5+ Years Network Penetration Testing Experience5+ Years Application Security Testing Experience5+ Years Red Teaming ExperienceBachelor's Degree in Computer ScienceBachelor's Degree in CybersecurityBachelor's Degree in Information SecurityBachelor's Degree in Related FieldEquivalent Hands-on Industry ExperienceOSCP CertificationOSCE CertificationOSEP CertificationSANS/GIAC Certification

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
Paid Time Off
Parental Leave
401(k) Match
Tuition Assistance

Full job description

Zions Bancorporation is transforming what it means to work for a financial institution. With a commitment to technology and innovation, we have been providing our community, clients, and colleagues with the best experience possible for over 150 years. Help us transform our workforce of the future, today.

We are seeking a highly skilled and driven Cybersecurity Red Team-Penetration Tester to join our offensive security team. In this role, you will think like an adversary to proactively identify, exploit, and help remediate complex security vulnerabilities across our enterprise infrastructure, applications, and cloud environments.

Rather than just running automated scanners, you will design and execute sophisticated, real-world cyberattack simulations and manually dissect systems to identify deep-seated security flaws. As a critical partner to our Incident Response and development groups, your ultimate goal is not just to find weaknesses, but to collaboratively strengthen our overall security posture and educate internal stakeholders on emerging adversarial tactics.

Key Responsibilities

  • Emulate Advanced Adversaries: Execute comprehensive red team operations and objective-based testing to simulate real-world cyberattacks, testing both technical controls and incident response capabilities.

  • Conduct Multidisciplinary Testing: Perform manual and automated penetration testing across web applications, APIs, cloud environments (AWS/Azure/Kubernetes), internal/external networks, and operating systems (Windows, Active Directory, Linux).

  • Audit and Attack AI Systems: Design and execute adversarial simulations against Large Language Models (LLMs) and machine learning pipelines to identify enterprise vulnerabilities, verifying that deployed AI applications are resilient to manipulation and data exposure.

  • Develop Custom Exploits: Design, write, and modify custom scripts and tools to bypass modern endpoint detection and response (EDR) agents and navigate restrictive environments.

  • Deliver Clear Reporting: Translate complex technical findings into detailed, actionable remediation reports and present risk impact clearly to both technical developers and non-technical stakeholders.

  • Collaborate for Remediation: Partner closely with Cyber Threat Intelligence, Incident Response, Detection Engineering and development groups to provide post-assessment debriefs, validate remediation efforts, and continuously strengthen the overall security posture.

Qualifications:

  • Adversarial Frameworks: Deep practical knowledge of industry frameworks and standards, primarily the MITRE ATT&CK matrix, OWASP Top 10, and NIST.

  • AI & LLM Vulnerability Exploitation: Practical understanding of the OWASP Top 10 for LLMs and hands-on experience executing attacks such as prompt injection (direct and indirect), training data poisoning, model inversion, and API-based data exfiltration.

  • Commercial & Custom Tooling: Proficient hands-on experience with offensive security suites, including C2 frameworks (e.g., Cobalt Strike), proxy utilities (Burp Suite), scanners (Nessus, Nmap), exploitation platforms (Metasploit) and breach and attack simulation platforms (BAS).

  • Active Directory Domain Dominance: Proven experience exploiting AD environments, including Kerberoasting, AS-REP roasting, pass-the-hash, golden/silver ticket attacks, and domain delegation flaws.

  • Scripting & Automation: Strong programming capability in languages such as Python, PowerShell, Bash, or Go to automate tasks and build custom tooling.

  • Cloud Security: Experience identifying misconfigurations and exploiting cloud-native infrastructure within AWS, Microsoft Azure, or containerized environments (Kubernetes/Docker).

  • Professional Experience: 5+ years of dedicated professional experience focusing on network penetration testing, application security testing, or red teaming.

  • Educational Background: Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or a related field (or equivalent hands-on industry experience).

  • Industry Certifications (Highly Valued):

  • OSCP (Offensive Security Certified Professional) or OSCE / OSEP

  • SANS/GIAC certifications (e.g., GPEN, GXPN, GWAPT)

  • HTB Certified Penetration Testing Specialist (CPTS)

Work Location:

This position has a hybrid work from home schedule with a minimum of three days per week in the office at the new Zions Technology Center in Midvale, UT

The Zions Technology Center is a 400,000-square-foot technology campus in Midvale, Utah. Located on the former Sharon Steel Mill superfund site, the sustainably built campus is the company’s primary technology and operations center. This modern and environmentally friendly technology center enables Zions to compete for the best technology talent in the state while providing team members with an exceptional work environment with features such as:

  • Electric vehicle charging stations and close proximity to Historic Gardner Village UTA TRAX station.

  • At least 75% of the building is powered by on-site renewable solar energy.

  • Access to outdoor recreation, parks, trails, shareable bikes and locker rooms.

  • Large modern cafe with a healthy and diverse menu.

  • Healthy indoor environment with ample natural light and fresh air.

  • LEED-certified sustainable building that features include the use of low VOC-emitting construction materials.

Benefits:

  • Medical, Dental and Vision Insurance - START DAY ONE!

  • Life and Disability Insurance, Paid Parental Leave and Adoption Assistance

  • Health Savings (HSA), Flexible Spending (FSA), and dependent care accounts

  • Paid Training, Paid Time Off (PTO) and 11 Paid Federal Holidays

  • 401(k) plan with company match, Profit Sharing, competitive compensation in line with work experience

  • Mental health benefits including coaching and therapy sessions

  • Tuition Reimbursement for qualifying employees

  • Employee Ambassador preferred banking products

Req ID: 071100

Equal Opportunity Employer

It is the policy of this corporation to provide equal employment and advancement opportunities to all employees and applicants for employment, without regard to race, color, religion, age (40 and over), sex, pregnancy, gender, disability, national origin, ethnic background, citizenship, veteran status, sexual orientation, gender identity and expression or any other characteristic protected by applicable law. This policy is established and administered in accordance with all applicable federal, state, and local laws.

If you are an individual with disabilities who needs accommodation, or you are having difficulty using our website to apply for employment, please contact us at (801) 844-7628, Mon.-Fri. between 9 a.m. - 5 p.m. MST.

Click here to view applicable Federal, State and/or local employment law posters.

You've read the whole posting — now see how you match it.

Cybersecurity Red Team-Penetration Tester | Olive Jobs