Network Penetration Testing Specialist
- Hiring from
- Ireland
- Work type
- Hybrid
- Posted
Show job descriptionHide job description
SMBC Group is a top-tier global financial group. Headquartered in Tokyo and with a 400-year history, SMBC Group offers a diverse range of financial services, including banking, leasing, securities, credit cards, and consumer finance. The Group has more than 130 offices and 80,000 employees worldwide in nearly 40 countries. Sumitomo Mitsui Financial Group, Inc. (SMFG) is the holding company of SMBC Group, which is one of the three largest banking groups in Japan. SMFG’s shares trade on the Tokyo, Nagoya, and New York (NYSE: SMFG) stock exchanges.
In the Americas, SMBC Group has a presence in the US, Canada, Ireland, Mexico, Brazil, Chile, Colombia, and Peru. Backed by the capital strength of SMBC Group and the value of its relationships in Asia, the Group offers a range of commercial and investment banking services to its corporate, institutional, and municipal clients. It connects a diverse client base to local markets and the organization’s extensive global network. The Group’s operating companies in the Americas include Sumitomo Mitsui Banking Corp. (SMBC), SMBC Nikko Securities America, Inc., SMBC Capital Markets, Inc., SMBC MANUBANK, JRI America, Inc., SMBC Leasing and Finance, Inc., Banco Sumitomo Mitsui Brasileiro S.A., and Sumitomo Mitsui Finance and Leasing Co., Ltd.
This is a hybrid role, requiring the successful candidate to attend our Tralee office weeky.
Role Description
SMBC Group is seeking an experienced Network Penetration Testing Specialist to join our Cyber Security team in Tralee. This role is ideal for a security professional with a strong background in network penetration testing, vulnerability assessment and exposure management who is passionate about improving the security posture of a global financial institution.
You will be responsible for ensuring that internal and external networks across the organisation are tested against evolving threats and security requirements. Working closely with infrastructure, security engineering, architecture and vulnerability management teams, you will identify risks, validate remediation efforts and provide expert guidance to stakeholders across the business. The role requires strong technical expertise combined with the ability to clearly communicate findings and recommendations to both technical and non-technical audiences.
This role will report to the Executive Director, Application Security Manager.
Role Objectives: Delivery
- Perform network penetration testing activities across internal and external infrastructure.
- Validate vulnerabilities through manual testing and technical security assessments.
- Identify, document and communicate security findings to relevant stakeholders.
- Work closely with technology owners to explain vulnerabilities, attack paths and remediation recommendations.
- Partner with Network and Security Architecture teams on network security best practices, threat modelling and risk reduction initiatives.
- Collaborate with Vulnerability Management teams to ensure findings are tracked, remediated and validated in line with agreed SLAs.
- Prepare and present network security metrics and management reports to senior stakeholders.
- Assess the overall state of network security and identify opportunities for continuous improvement.
- Provide expert guidance on network security risks, attack vectors and mitigation strategies.
- Support the development and maintenance of penetration testing methodologies, processes and standards.
- Create and maintain detailed technical and operational documentation.
- Act as a subject matter expert for network penetration testing and exposure management activities.
- Occasionally support weekend or out-of-hours testing activities based on project and business requirements.
Qualifications and Skills
Essential
- 7+ years of experience in Penetration Testing, Ethical Hacking or Cyber Security.
- Strong experience conducting network penetration testing and vulnerability assessments.
- Expertise with industry-standard penetration testing tools and methodologies.
- Experience managing vulnerability remediation programmes and working with technology teams to address security findings.
- Strong understanding of common network threats, attack techniques and mitigation strategies.
- Knowledge of OWASP Top 10, CWE and security testing best practices.
- Experience working with security champions, infrastructure teams and application development teams.
- Strong analytical, problem-solving and investigative skills.
- Excellent written, verbal and stakeholder management skills.
- Experience producing and presenting security reports to senior management.
- Experience using Jira and Confluence.
- Strong attention to detail with the ability to create detailed technical documentation and processes.
- Industry-recognised penetration testing certification such as OSCP, GPEN, CREST or equivalent.
Desirable
- Experience within financial services or other highly regulated environments.
- Experience with Exposure Management or Vulnerability Management programmes.
- Knowledge of threat modelling methodologies and frameworks.
- Experience with developer security awareness or security champion programmes.
- Bug bounty participation or bug bounty programme experience.
- Experience assessing hybrid and cloud-based environments.
Additional Requirements
SMBC’s employees participate in a hybrid workforce model that provides employees with an opportunity to work from home, as well as, from an SMBC office. SMBC requires that employees live within a reasonable commuting distance of their office location. Prospective candidates will learn more about their specific hybrid work schedule during their interview process.
SMBC provides reasonable accommodations during candidacy for applicants with disabilities consistent with applicable federal, state, and local law. If you need a reasonable accommodation during the application process, please let us know at accommodations@smbcgroup.com.