Fidelity Investments

Principal, Cybersecurity Penetration Tester

Fidelity Investments  •  United States (Onsite)  •  3 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Performs security assessments of applications prior to production deployment using Static Code Analysis, dynamic testing tools, and manual techniques. Assists in establishing the strategy, policy, and standards of security for cybersecurity operations. Develop custom Python scripts to automate repetitive tasks. Defends enterprise against attacks, damage, and unauthorized access to information, data, and systems. Ensures threat and vulnerability reduction, deterrence, incident response, resiliency, and recovery policies and activities are up to date. Proactively identifies vulnerabilities in proprietary applications prior to production release and remediates identified vulnerabilities to prevent real-life cyberattacks.

Primary Responsibilities:

  • Performs advanced Web application source code auditing.
  • Analyzes codes, writes scripts, and exploits web vulnerabilities.
  • Analyzes test results, draw conclusions from results.
  • Identifies vulnerabilities by performing thorough evaluations of security vulnerabilities on Web and mobile applications.
  • Collaborates with application developers to mitigate risk and improve security posture.
  • Performs security testing on web and mobile applications to support production releases.
  • Models potential external threats by replicating the techniques and tools used by malicious attackers.
  • Prepares reports on completed assessments and present results to application owners, developers, and business unit information security teams.
  • Consults with operations and software development teams to ensure potential weaknesses are addressed.
  • Contributes to the research and development of tools to assist in the vulnerability discovery process.
  • Keeps abreast of current cybersecurity best practices and vulnerabilities.
  • Conducts peer reviews to facilitate continuous improvement across the team.

Education and Experience

Bachelor’s degree in Computer Science, Engineering, Information Technology, Information Systems, or a closely related field (or foreign education equivalent) and five (5) years of experience as a Principal, Cybersecurity Penetration Tester (or closely related occupation) performing black and white box testing to protect against cyber threats and ensure application security (web, mobile, API, and thick client).

Or, alternatively, Master’s degree in Computer Science, Engineering, Information Technology, Information Systems, or a closely related field (or foreign education equivalent) and three (3) years of experience as a Principal, Cybersecurity Penetration Tester (or closely related occupation) performing black and white box testing to protect against cyber threats and ensure application security (web, mobile, API, and thick client).

Skills and Knowledge

Candidate must also possess:

  • Demonstrated Expertise (“DE”) estimating risks on security flaws uncovered during static or dynamic analysis in line with the OWASP testing guide; conducting pen-testing on applications to uncover security vulnerabilities - Injection attacks, Server-side attacks, Privilege escalation, GraphQL batching attacks, or JWT signature manipulation attacks - using BurpSuite Professional Edition, Fiddler, Kali Linux, and SQLMap.
  • DE analyzing source code for security weaknesses, writing custom scripts, exploiting security vulnerabilities, and conducting retests to determine mitigation measures implemented by development teams, through a combination of manual analysis by using BurpSuite Professional, and automated scans using GitHub Advanced Security(GHAS) and MEND.
  • DE analyzing Common Vulnerability Exposure (CVE) on third party libraries, using Veracode SCA, MEND, Exploit-DB, and NVD databases; and coordinating actions associated with the dismissal or reopening of policy violation alerts related to security, licensing, and coding standards using GitHub Advanced Security (GHAS).
  • DE crafting custom scripts to effectively automate labor-intensive manual tasks (logging security findings, preparing weekly status reports, verifying artifact correctness) and empower the efficient allocation of resources, enhancing the overall security assessment process, using Python or Selenium.

#PE1M2

#LI-DNI

Certifications:

Category:

Information Technology

Please be advised that Fidelity’s business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.

Fidelity Investments

About Fidelity Investments

Fidelity’s mission is to strengthen the financial well-being of our customers and deliver better outcomes for the clients and businesses we serve. Fidelity’s strength comes from the scale of our diversified, market-leading financial services businesses that serve individuals, families, employers, wealth management firms, and institutions. With assets under administration of $15.0 trillion, including discretionary assets of $5.9 trillion as of March 31, 2025, we focus on meeting the unique needs of a broad and growing customer base. Privately held for 78 years, Fidelity employs more than 77,000 associates across the United States, Ireland, and India.

For our Terms and Conditions, please visit http://go.fidelity.com/LIterms

Industry
Finance & Insurance
Company Size
10,000+ employees
Headquarters
Boston, MA
Year Founded
1946
Social Media