Citizens Bank logo
Principal Penetration Tester
full-timeUnited States$150k - $170k

Summary

Location

United States

Salary

$150k - $170k

Type

full-time

Explore Jobs

About this role

Locations: This role will require an on-site hybrid work schedule in one of our primary organizational hubs including: Johnston, RI - Pittsburgh, PA - Phoenix, AZ - Westwood or Medford, MA - Plano, TX - Iselin, NJ - Franklin, TN

Position Overview

At our organization, we are committed to innovation and excellence. As part of our team, you’ll have the opportunity to shape a rewarding career filled with impactful challenges. The Principal Penetration Tester will play a critical role in building and shaping our newly formed penetration testing team, bringing deep technical expertise and a collaborative mindset to establish a world-class program. This role focuses on hands-on penetration testing across diverse environments, including cloud (AWS, Azure, GCP), applications, networks, and endpoints, while contributing to the strategic development of the team’s methodologies, tools, and processes.

This position requires exceptional technical aptitude, a passion for identifying and exploiting vulnerabilities, and the ability to work closely with cross-functional teams to enhance the organization’s security posture. The Principal Penetration Tester will deliver detailed findings and actionable recommendations, maintaining clear communication with technical teams, leadership, and compliance stakeholders.

Key Responsibilities

Penetration Testing Execution:

  • Conduct advanced penetration tests across cloud environments (AWS, Azure, GCP), web and mobile applications, APIs, networks, and endpoints to identify vulnerabilities and misconfigurations.
  • Develop and execute custom exploits, scripts, and attack scenarios to simulate real-world threats.

Team Building and Development:

  • Collaborate with leadership to build and shape the new penetration testing team, defining methodologies, workflows, and standards.
  • Mentor junior testers, fostering a culture of technical excellence, curiosity, and continuous learning.

Technical Expertise:

  • Maintain and enhance a penetration testing toolkit, including custom tools, scripts (Go, Python, Bash), and industry-standard platforms (e.g., Burp Suite, Nmap).
  • Stay current with emerging vulnerabilities, exploits, and attack techniques to ensure cutting-edge testing practices.

Reporting and Collaboration:

  • Produce detailed, high-quality reports with clear findings, risk assessments, and remediation recommendations for technical and non-technical audiences.
  • Partner with application development, infrastructure, and security operations teams to prioritize and address vulnerabilities.
  • Contribute to metrics and KPIs to demonstrate the impact of the penetration testing program.

Process Improvement:

  • Establish repeatable, scalable testing processes aligned with frameworks like OWASP, NIST, PTES, and CVSS.
  • Drive automation initiatives to enhance the efficiency and coverage of penetration testing activities.

Required Experience and Skills

  • 10+ years of cybersecurity experience, with at least 6 years focused on penetration testing across diverse environments.
  • Proven expertise in testing cloud platforms (AWS, Azure, GCP), web/mobile applications, APIs, and network infrastructure.
  • Advanced technical skills in scripting (Python, Bash, PowerShell) and hands-on use of tools like Burp Suite, Metasploit, Nmap, and Nessus.
  • Experience contributing to or building a penetration testing program, including defining methodologies and workflows.
  • Strong understanding of vulnerability management processes and frameworks (e.g., OWASP, NIST, CVSS, CWE).
  • Excellent documentation skills, with the ability to produce clear, actionable reports for technical and executive audiences.
  • Superior communication skills to collaborate with cross-functional teams and present findings to stakeholders.
  • Demonstrated ability to mentor and guide junior team members.
  • Familiarity with secure development practices and DevSecOps principles is a plus.

Education and Certifications

  • A bachelor’s degree in Computer Science, Cybersecurity, or a related field.
  • Preferred Certifications: OSCP, OSCE, OSEP, GPEN, GWAPT, CEH, or equivalent.

Pay Transparency

The salary range for this position is $150,000-$170,000 per year plus an opportunity to earn an annual discretionary bonus. Actual pay is based on various factors including but not limited to the work location, and relevant skills and experience.  

We offer competitive pay, comprehensive medical, dental and vision coverage, retirement benefits, maternity/paternity leave, flexible work arrangements, education reimbursement, wellness programs and more. Note, Citizens’ paid time off policy exceeds the mandatory, paid sick or paid time-away policy of very local and state jurisdiction in the United States. For an overview of our benefits, visit https://jobs.citizensbank.com/benefits.

#LI-Citizens1


Equal Employment Opportunity

Citizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague’s or a dependent’s reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws. At Citizens, we are committed to fostering an inclusive culture that enables all colleagues to bring their best selves to work every day and everyone is expected to be treated with respect and professionalism. Employment decisions are based solely on merit, qualifications, performance and capability.

Equal Employment and Opportunity Employer

Job Applicant Data Privacy Policy

Background Check

Any offer of employment is conditioned upon the candidate successfully passing a background check, which may include initial credit, motor vehicle record, public record, prior employment verification, and criminal background checks. Results of the background check are individually reviewed based upon legal requirements imposed by our regulators and with consideration of the nature and gravity of the background history and the job offered. Any offer of employment will include further information.


Other facts

Tech stack
Penetration Testing,Cloud Security,Vulnerability Management,Scripting,Technical Documentation,Communication Skills,Team Building,Mentoring,Automation,Cybersecurity,Risk Assessment,Reporting,DevSecOps,Methodologies,Tools,Frameworks

About Citizens Bank

At Citizens Bank, we recognize that the journey to accomplishment is no longer linear and that individuals are made of all they have done and all they are going to do. As one of the oldest and largest financial services firms in the United States with a history dating back to 1828, we’re committed to providing solutions and expertise that support our customers, clients, colleagues, and communities in what’s next on their own unique journey.

Whether you’re considering banking with us or looking to work with us, you’ll find a customer-centric culture and a supportive, collaborative workforce at Citizens Bank.

You’re made ready and so are we. #MadeReady

Team size: 10,001+ employees
LinkedIn: Visit
Industry: Banking

What you'll do

  • The Principal Penetration Tester will conduct advanced penetration tests across various environments to identify vulnerabilities and misconfigurations. They will also mentor junior testers and contribute to the development of the penetration testing team's methodologies and processes.

Ready to join Citizens Bank?

Take the next step in your career journey

Frequently Asked Questions

What does Citizens Bank pay for a Principal Penetration Tester?

Citizens Bank offers a competitive compensation package for the Principal Penetration Tester role. The salary range is USD 150k - 170k per year. Apply through Clera to learn more about the full compensation details.

What does a Principal Penetration Tester do at Citizens Bank?

As a Principal Penetration Tester at Citizens Bank, you will: the Principal Penetration Tester will conduct advanced penetration tests across various environments to identify vulnerabilities and misconfigurations. They will also mentor junior testers and contribute to the development of the penetration testing team's methodologies and processes..

Why join Citizens Bank as a Principal Penetration Tester?

Citizens Bank is a leading Banking company. The Principal Penetration Tester role offers competitive compensation.

Is the Principal Penetration Tester position at Citizens Bank remote?

The Principal Penetration Tester position at Citizens Bank is based in United States, United States. Contact the company through Clera for specific work arrangement details.

How do I apply for the Principal Penetration Tester position at Citizens Bank?

You can apply for the Principal Penetration Tester position at Citizens Bank directly through Clera. Click the "Apply Now" button above to start your application. Clera's AI-powered platform will help match your profile with this opportunity and guide you through the application process. You can also learn more about Citizens Bank on their website.