ForgeApply
Try it free

ForgeApply · Job listing

AVP, Penetration Tester

LPL Financial

Fort Mill/Charlotte | New York | Washington DC, US$123k – $204konsite

See all 311 open roles at LPL Financial

Tailor your resume for this LPL Financial job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for LPL Financial's site. Free trial, no card required.

About this role

Where Ambition Meets Innovation

Build a career that matches all your initiative with an impressive dose of innovation. From cutting-edge resources and a collaborative environment to the freedom to make an impact and more, you’ll find the ingredients you need at LPL Financial to shape your success while helping clients pursue their financial goals.

At LPL Financial, protecting our clients, advisors, and employees is foundational to everything we do. Offensive Security is a top area of investment within Information Security, and this role offers the opportunity to directly influence the security posture of a large, complex enterprise. If you enjoy hands‑on technical work, collaborating across teams, and creatively testing the limits of modern systems, this is an exciting opportunity to help evolve LPL’s offensive security capabilities.

Job Overview As a member of the Cyber Security team, the Senior Penetration Tester, Offensive Security, is responsible for the scheduling, scoping, and execution of internal penetration testing, with a primary focus on web, mobile, cloud, API, and AI‑enabled applications.

This individual contributor role performs advanced manual penetration testing to validate the security of company resources. The position serves as the primary point of contact for assigned testing initiatives and partners closely with stakeholders across the organization to identify security weaknesses, recommend mitigation strategies, and validate remediation efforts across LPL applications and platforms.

Responsibilities • Partner with product and technology stakeholders to drive end‑to‑end penetration testing activities, including collaboration with Security Architects throughout the SDLC to identify and address security issues prior to production deployment

• Conduct tactical penetration testing assessments of web, mobile, and API applications against OWASP Top 10 threats and emerging risks, and collaborate with Application Security teams to provide actionable feedback and recommendations, including opportunities to expand automated and AI‑assisted testing capabilities

• Perform security assessments of internal and external networks, infrastructure, cloud environments, and a wide range of internally developed and commercial products

• Apply creative and analytical thinking to bypass security controls, identify vulnerabilities, and develop practical remediation guidance; stay informed on evolving tactics, techniques, and procedures (TTPs), zero‑day vulnerabilities, and mitigation strategies

• Develop or modify custom tools and scripts to support new penetration testing needs, automation, and AI‑assisted testing approaches

• Document and formally report testing scope, methodology, findings, risk ratings, remediation recommendations, and validation results in a clear and concise manner

• Present testing results to technology and business partners, clearly communicating risk, impact, and remediation guidance in an accessible and collaborative way

• Lead execution of assigned penetration testing initiatives, including status communication to leadership and coordination with stakeholders

• Oversee communication, tracking, and retesting of findings to validate successful closure of previously identified issues

• Assist with validation and triage of submissions from the company’s Vulnerability Disclosure Program and Bug Bounty programs

What are we looking for? We are seeking collaborative professionals who enjoy hands‑on technical work and take pride in delivering a high‑quality internal client experience. This role is well suited for individuals who thrive in a fast‑paced environment, enjoy solving complex security challenges, and continuously look for ways to improve processes, tooling, and outcomes.

Requirements • 8+ years of experience conducting application, API, and network‑based penetration testing engagements

• 6+ years of experience troubleshooting tools, manually identifying vulnerabilities in code, and rewriting code to remediate security issues

• 3+ years of experience leading penetration testing engagements from scoping through reporting and remediation validation

• 1+ year of experience testing AI, LLM, or Generative AI‑enabled applications

• 1+ year of experience using AI models (such as Claude or similar) to accelerate tool development or testing workflows + Advanced knowledge of security assessment tools and frameworks, such as Burp Suite, Kali Linux, Nessus, Accunetix, Metasploit, AutoSploit, Cobalt Strike, MITRE ATT&CK, MITRE ATLAS, OWASP Top 10 (including OWASP Top 10 for LLMs)

Preferences • Bachelor’s degree or equivalent experience in Information Security, Engineering, Computer Science, or a related field

• Advanced understanding of OWASP frameworks, MITRE ATT&CK and ATLAS, and secure software development lifecycle (SDLC) practices

• At least one industry‑recognized certification, such as OSCP, OSCE, OSWE, GPEN, GCIH, GWAPT, or GXPN

• Advanced proficiency in one or more programming or scripting languages, such as .NET, JavaScript, Python, Java, PowerShell, Perl, Ruby, Bash, or similar

• Advanced knowledge of Linux, macOS, and Windows operating systems, as well as AWS and Azure cloud environments and cloud‑native services (e.g., containers, Kubernetes, microservices, serverless functions)

• Experience performing reverse engineering on mobile applications, including those with obfuscation or anti‑emulation protections

• Broad knowledge of operating system security, networking and protocols, firewalls, databases, middleware, forensics, and secure coding practices

• Effective written and verbal communication skills, with the ability to collaborate with technical and non‑technical stakeholders

• Organized approach to managing multiple testing efforts and deliverables

• A natural curiosity for exploring, testing, and understanding security controls and how they can be improved

  Pay Range: $122,570.00 - $204,249.00   Actual base salary varies base

Salary insight

The midpoint of this range ($163k) is right around the median disclosed salary for New York roles listed on ForgeApply ($165k across 8,051 jobs).

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this LPL Financial role before you apply.

Tailor my resume for this job

Similar jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)