In this hybrid role based at our Chicago headquarters, you will plan, execute, and report on penetration testing for web applications and web APIs across both internally developed and vendor SaaS solutions. Perform hands‑on offensive security testing to identify, validate, and drive remediation of vulnerabilities in modern application and API architectures. Support targeted testing of related infrastructure, cloud services, and internal systems. Work with software engineering, application security, and cyber threat mitigation teams to strengthen the organization’s overall security posture. Essential Responsibilities Perform penetration testing with a primary focus on web applications and web APIs across homegrown and vendor systems, support testing of cloud, mobile, and internal systems. Conduct manual and automated testing, including authenticated and unauthenticated attack scenarios. Identify and validate vulnerabilities, and assist in assessing risk and potential impact Develop proof‑of‑concept exploits and document attack paths when appropriate. Work with development teams to support remediation efforts by review fixes, validate resolutions, and retesting. Support the analysis and prioritization of vulnerabilities based on exploitability, severity, and business impact. Produce clear, actionable penetration test reports for technical and non‑technical audiences. Contribute to improving internal testing methodologies, tooling, and standards. Stay current on emerging threats, attack techniques, and best practices relevant to modern web applications, APIs, and cloud environments. Maintain and administer DAST, SAST, and SCA tools, including scan execution, troubleshooting, and validation of findings. Support, troubleshoot and enhance internal security workflow applications and automation written in Python. Education & Years of Experience Minimum - 4 Year Bachelors Degree in Computer Science, Cybersecurity, Information Systems or related Minimum - 0 Years of Penetration testing, offensive security or related In Lieu of Education 4 Years of Penetration testing, offensive security or related License/Certifications/Training Preferred - Industry certifications such as OSWE, OSCP, OSCE, GPEN, GWAPT, CRTO, or related offensive security credentials Compensation & Benefits: Typical hiring range: $76,600.00 to $119,100.00 Annually. Actual compensation will be determined using factors such as experience, skills & knowledge. Benefits: Alliant provides a benefits package including health care, vision, dental, and 401k with employer match including: Annual performance bonus Work from home up to 3 days a week Paid parental leave Employee discount programs Time off including paid personal and sick days 11 paid holidays Education reimbursement *Note that eligibility and cost of benefits can vary depending on the number of regularly scheduled hours, and job status such as regular full-time, regular part-time, or temporary employment. Adhere to and ensure compliance of all business transactions with policy and process of the Bank Secrecy Act. Ensures compliance with all applicable state and federal laws, company procedures and policies. Maintains integrity and ethics in all actions and conversations with or regarding credit union members and their accounts; complies with Privacy Act directives. The responsibilities listed do not contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this position. Duties, responsibilities and activities may change at any time with or without notice.
Solutions Engineer, Penetration Testing
Prescient Security
Mechanical Engineer, Dynamometer and Actuator Testing Infrastructure
OpenAI
Product Testing Engineer
Velux
Staff Software Engineer – Testing Tools and Frameworks
Geico
IT Testing Engineer II
Conduent
Application Engineer - Aerospace & Industrial Testing
DEWESoft, LLC