Chubb Ltd logo

Senior Application Penetration Tester

Chubb Ltd
  • Philadelphia, PA
    1 day ago

    Job Description

    • Plan and execute penetration tests across web, mobile (iOS & Android), API, cloud-native/containerized, and AI/LLM-integrated applications
    • Assess AI/ML and generative AI-powered features for risks such as prompt injection, insecure output handling, training data poisoning, model denial of service, and sensitive information disclosure, aligned to the OWASP Top 10 for LLM Applications and MITRE ATLAS
    • Partner with AI/ML engineering and data science teams to threat-model AI-powered features and embed security testing into MLOps and CI/CD pipelines
    • Evaluate cloud-native and containerized workloads (AWS, Azure, GCP, Docker, Kubernetes) and Infrastructure as Code for misconfigurations and weak security controls
    • Test modern API architectures (REST, GraphQL, gRPC), including OAuth2, OIDC, and JWT authentication and authorization flaws, and microservices-based applications
    • Conduct mobile application security testing and reverse engineering, including hardcoded credentials, insecure keychain storage, and anti-emulator/obfuscation bypass
    • Own the overall vulnerability remediation status of the global application portfolio, and serve as the primary point of contact for application teams on remediation matters
    • Manage application risk rating processes and ensure timely risk scoring of new and changing applications
    • Build and maintain dashboards and status reports for portfolio leads and CIOs, and follow up on overdue vulnerabilities to meet compliance timelines
    • Develop clear, actionable penetration test reports and communicate findings and remediation strategy to both technical and executive stakeholders
    • Research emerging attack techniques and tooling, and drive automation and process improvements across the testing program

    Chubb is a world leader in insurance. With operations in 54 countries, Chubb provides commercial and personal property and casualty insurance, personal accident and supplemental health insurance, reinsurance, and life insurance to a diverse group of clients. The company is distinguished by its extensive product and service offerings, broad distribution capabilities, exceptional financial strength, underwriting excellence, superior claims handling expertise and local operations globally.

    At Chubb, we are committed to equal employment opportunity and compliance with all laws and regulations pertaining to it. Our policy is to provide employment, training, compensation, promotion, and other conditions or opportunities of employment, without regard to race, color, religious creed, sex, gender, gender identity, gender expression, sexual orientation, marital status, national origin, ancestry, mental and physical disability, medical condition, genetic information, military and veteran status, age, and pregnancy or any other characteristic protected by law. Performance and qualifications are the only basis upon which we hire, assign, promote, compensate, develop and retain employees. Chubb prohibits all unlawful discrimination, harassment and retaliation against any individual who reports discrimination or harassment.

    Minimum:

    • Prior experience managing Information Security projects
    • Bachelor''s Degree in Computer Science, Engineering, or other Engineering or Technical discipline, or equivalent relevant experience
    • Minimum of 2 years'' professional experience performing web application, API endpoint, and mobile (iOS & Android) penetration testing
    • Knowledge of prioritizing remediation activities with operational teams through risk ratings of vulnerabilities and assets
    • Knowledge of industry standards regarding vulnerability management, including Common Vulnerabilities and Exposures (CVE) and Common Vulnerability Scoring System (CVSS)
    • Knowledge of technology and security topics including network security, wireless security, application security, infrastructure hardening and security baselines, and web server and database security
    • Knowledge of penetration testing principles, tools, and techniques
    • Working experience with industry frameworks (OWASP, OWASP API Security Top 10, OWASP Top 10 for Large Language Model (LLM) Applications, NIST, NIST AI Risk Management Framework, MITRE ATT&CK, etc.)
    • Comfortable working outside their comfort zone with a willingness to learn
    • Excellent verbal and written communication skills
    • Strong analytical skills
    • Strong team player with the ability to work independently
    • Strong project management skills and ability to multi-task
    • Self-motivated with strong initiative
    • Knowledge of computer networking concepts and protocols, and application security methodologies
    • Skill in performing impact/risk assessments
    • Familiarity with modern application architectures, including cloud-native (AWS, Azure, GCP), containerized (Docker, Kubernetes), microservices, and API-first (REST, GraphQL, gRPC) designs
    • Foundational understanding of AI/ML and generative AI security risks (e.g., prompt injection, model manipulation, sensitive data leakage) is a plus

    Nice To Have:

    • Strong understanding of secure SDLC, exploit/attack techniques, and core networking, application, and OS concepts, with the ability to manipulate application logic, bypass security controls, and develop exploits
    • Experience scoping and leading engagements end-to-end - from kickoff through remediation tracking - and improving testing efficiency through automation, tooling, and process improvements
    • Proficient with industry-standard tools across categories: Kali Linux, Metasploit, Nmap, Burp Suite/OWASP ZAP (web); Santoku, Genymotion, APKTool, JD-GUI (mobile); SQLMap, Semgrep, Snyk, Checkmarx/AppScan/Veracode (code); Postman/Insomnia (API); Trivy/Grype, Prowler/ScoutSuite (cloud & containers); and Garak/PyRIT (AI red-teaming)
    • Skilled in identifying OWASP Top 10 (Web & Mobile), OWASP API Security Top 10, and OWASP LLM Top 10 vulnerabilities, and developing secure coding checklists based on OWASP ASVS
    • Experience conducting full-scope assessments and penetration tests - web, mobile, API, social engineering, and server/client-side attacks - including mobile reverse engineering (hardcoded credentials, SQLi, keychain exposure, anti-emulator/obfuscation bypass)
    • Experience assessing cloud-native and containerized applications (AWS, Azure, GCP, Docker, Kubernetes), modern CI/CD pipelines and Infrastructure as Code, and modern API architectures (REST, GraphQL, gRPC) including OAuth2/OIDC/JWT flaws
    • Experience or working knowledge testing AI/ML and generative AI features for risks such as prompt injection, insecure output handling, training data poisoning, and sensitive data disclosure, aligned to the OWASP LLM Top 10 and MITRE ATLAS, plus working knowledge of securing AI agent/orchestration frameworks (LangChain, Semantic Kernel, AutoGen) and RAG vector databases
    • Skilled in code analysis, exploit development, and using attacker tools/tactics/procedures to identify, validate, and demonstrate vulnerabilities an adversary could exploit
    • Ability to analyze findings (including root cause analysis), risk-rate vulnerabilities by actual business impact, and prioritize key risk areas
    • Ability to document findings clearly, including reproduction steps, and produce comprehensive, accurate penetration test reports
    • Ability to research and recommend practical short- and long-term remediations, and communicate findings and strategy effectively to both technical and executive stakeholders
    • Experience working closely with development teams to track remediation through to production deployment, maintain vulnerability status dashboards, and follow up on overdue items to meet compliance timelines
    • Preferred certifications: OSCP, OSWE, GWAPT, GPEN, CEH, GCPN, CCSP, or equivalent AI/ML security credentials
    • Strong communicator and collaborative team player, able to adapt and reprioritize as project needs shift

    Numbers & Facts

    LocationPhiladelphia, PA
    IndustryInsurance
    Company Size500 to 999 employees
    Year Founded1792
    Websitehttps://www.chubb.com/

    About Company

    Chubb is the world’s largest publicly traded property and casualty insurance company and the largest commercial insurer in the U.S.

    With operations in 54 countries and territories, we are a major personal lines writer, as well as a leading middle market, small commercial and large industrial commercial insurer, providing a wide range of traditional and specialty coverages.

    As an underwriting company, we assess, assume and manage risk with insight and discipline. We service and pay our claims fairly and promptly. And we combine the precision of craftsmanship with deep experience to conceive, craft and deliver the very best insurance coverage and service to individuals and families and to businesses of all sizes.

    Our products and services are distributed through brokers, independent agents, exclusive agents and various forms of direct marketing.

    What we deliver:

    • Extensive product and service offerings
    • Broad distribution capabilities
    • Service excellence
    • Risk expertise
    • Underwriting discipline
    • Exceptional financial strength
    • Local operations globally

    Skills

    • Amazon Web Services (AWS)unmatched
    • Analysis Skillsunmatched
    • Androidunmatched
    • Application Programming Interface (API)unmatched
    • Applications Securityunmatched
    • Artificial Intelligence (AI)unmatched
    • Automationunmatched
    • CCSP - Cisco Certified Security Professionalunmatched
    • Claims Processingunmatched
    • Cloud Architectureunmatched
    • Cloud Computingunmatched
    • Communication Skillsunmatched
    • Computer Networksunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Continuous Deployment/Deliveryunmatched
    • Continuous Integrationunmatched
    • Data Scienceunmatched
    • Dockerunmatched
    • Emulatorsunmatched
    • Establish Prioritiesunmatched
    • GCP (Good Clinical Practices)unmatched
    • GPEN - GIAC Penetration Testerunmatched
    • GraphQLunmatched
    • Graphical User Interface (GUI)unmatched
    • IBM Rational AppScanunmatched
    • Industry Standardsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Injectionsunmatched
    • Insomniaunmatched
    • Insuranceunmatched
    • Internet Applicationunmatched
    • Internet Securityunmatched
    • Kernel Programmingunmatched
    • Linux Operating Systemunmatched
    • Machine Toolunmatched
    • Mail Servicesunmatched
    • Metasploitunmatched
    • Microservicesunmatched
    • Microsoft Windows Azureunmatched
    • Multitaskingunmatched
    • NMapunmatched
    • Network Protocolsunmatched
    • OAuthunmatched
    • Operating Systemsunmatched
    • Penetration Testingunmatched
    • Presentation/Verbal Skillsunmatched
    • Process Improvementunmatched
    • Project/Program Managementunmatched
    • REST (Representational State Transfer)unmatched
    • Reporting Dashboardsunmatched
    • Research Skillsunmatched
    • Reverse Engineeringunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Root Cause Analysisunmatched
    • Security Attacksunmatched
    • Security Infrastructureunmatched
    • Security Monitoringunmatched
    • Social Engineeringunmatched
    • Software Development Lifecycle (SDLC)unmatched
    • Software Testingunmatched
    • Status Reportsunmatched
    • Team Playerunmatched
    • Technical Strategyunmatched
    • Test Automationunmatched
    • Test Programunmatched
    • Testingunmatched
    • Threat Modelingunmatched
    • Time Managementunmatched
    • Underwritingunmatched
    • Web Serverunmatched
    • Web Testingunmatched
    • Wireless Securityunmatched
    • Writing Skillsunmatched
    • iOSunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder