Security Testing Specialist Sr - Sunday - Thursday 3pm - 11pm MST - Application Security
PNC
Denver, CO · Onsite · Full Time
Posted
Job description
CO Salary Range: USD 123,200.00 - 228,800.00 per year Position Overview At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all of our employees feel respected, valued and have an opportunity to contribute to the company's success. As a Security Testing Specialist Sr within PNC's Technology Security organization, you will be based in Denver, CO or Phoenix, AZ. Hours: Sunday - Thursday 3:00 PM - 11:00 PM (Denver local) Key Responsibilities • Conducts security assessments of applications, APIs, cloud environments, networks, artificial intelligence systems, and other technology platforms to identify vulnerabilities, attack paths, and security control weaknesses. • Administers and operates security testing capabilities, including DAST platforms, automated scanning infrastructure, vulnerability validation processes, and security testing automation. • Develops and integrates AI-powered security testing capabilities, including custom testing harnesses, autonomous assessment workflows, and tooling that improves the effectiveness and efficiency of security assessments. • Performs targeted penetration testing and deep-dive security assessments of critical systems, technologies, and business processes to identify complex attack chains and high-impact vulnerabilities. • Researches emerging threats, attack techniques, and security technologies to develop innovative testing methodologies and enhance vulnerability discovery capabilities. • Reviews testing results with stakeholders, determines risk ratings, and provides technical remediation guidance to reduce enterprise security risk. Preferred Qualifications • Experience performing application, cloud, network, or infrastructure penetration testing. • Experience administering enterprise vulnerability scanning or DAST platforms. • Experience with AWS, Azure, Google Cloud Platform (GCP), or cloud-native technologies. • Experience assessing AI-powered applications, large language models (LLMs), AI agents, or machine learning systems. • Experience with API security testing, authentication and authorization testing, and OWASP Top 10 vulnerabilities. • Experience with hardware, embedded systems, kiosks, ATMs, IoT, or other specialized te…