Senior Penetration Tester defending fintech platform from payment fraud and cyber threats. Leading offensive security assessments to enhance fraud defenses and ensure customer trust.
Responsibilities
Lead penetration testing engagements focused on payment abuse, transaction manipulation, and business logic exploitation.
Design and execute automated attack simulations to test our defenses against: Carding and BIN attacks
Credential stuffing and account takeovers
Checkout and payment flow abuse
API-level enumeration and fraud
Build custom tooling and frameworks to mimic the behavior of real-world fraudsters and cybercriminals.
Partner with fraud engineering, product security, and risk teams to identify weak points in our controls, detection systems, and architecture.
Conduct threat modeling and red teaming exercises related to payments, authentication, and user account abuse.
Document findings in technical reports with clear risk impact, exploitability, and remediation guidance.
Mentor junior testers and contribute to a culture of security innovation and continuous improvement.
Requirements
7+ years of experience in offensive security, penetration testing, or red teaming.
Strong background in payment systems, financial fraud tactics, and transaction-level attack surfaces.
Fluency in scripting and automation (e.g., Python, JavaScript, Go, Bash) to simulate attacker workflows at scale.
Familiarity with tools like Burp Suite Pro, Selenium, Scapy, ffuf, SQLMap, Metasploit, and bot automation frameworks.
Senior Security Engineer establishing and maintaining cybersecurity measures for a financial services company. Responsible for leading security event responses, documentation of policies, and training.
Senior Corporate Security Investigator at Duke Energy conducting complex investigations in support of Ethics, HR, Legal, Nuclear, and Enterprise Security with field mobility.
AI Enterprise Security Architect focusing on AI Security architectural standards and integrating security measures into AI development lifecycle. Leading a global team in securing AI systems.
Cloud Security Engineer supporting and securing client environments across AWS and hybrid infrastructures. Collaborating with Cloud Operations to monitor, investigate, and remediate security events.
Account Cybersecurity Lead providing cybersecurity governance and oversight at Capgemini. Leading client relationships, security management systems, and risk compliance oversight.
Cybersecurity Risk Coordinator at Globo ensuring operational security across digital content. Analyzing risks and developing strategies to enhance business resilience.
Senior SAP Security Specialist managing SAP Security responsibilities and projects. Collaborating on security tools and conducting workshops in Hamburg.
Sales Account Manager for Cyber Security and Awareness role at HvS - Consulting GmbH. Providing holistic consulting on Cyber Security services and managing client relationships.
Security Engineer at PRC - Saltillo safeguarding IT infrastructure from cyber threats. Collaborating with IT teams to design and maintain security controls in a hybrid work environment.
Information Security Manager leading cyber security initiatives at NVISO, enhancing clients’ security posture and managing a team of consultants in Germany.