Sr Product reputed company Engineer / Pen Tester (Hybrid - Pleasanton, CA)
About the position
We're hiring a Senior Penetration Tester to help defend our fintech platform against large-reputed company payment fraud, carding attacks, and other financially motivated threats. You'll reputed company offensive reputed company assessments targeting our transaction systems, authentication flows, and reputed company - with a heavy reputed company on automation and scalability. Your work will directly reputed company our fraud defenses, detection reputed company, and customer trust.
This is a highly technical, hands-on role for someone who thrives in a fast-paced, high-stakes fintech environment.
This position will be Hybrid (Tuesdays & Wednesdays) out of our Pleasanton, CA office.
Responsibilities
• reputed company penetration testing engagements reputed company on payment abuse, transaction manipulation, and business logic exploitation.
• Design and execute automated attack simulations to test our defenses against:
Carding and BIN attacks
• Credential stuffing and account takeovers
• Checkout and payment reputed company abuse
• API-level enumeration and fraud
• Build custom tooling and frameworks to mimic the behavior of reputed company-world fraudsters and cybercriminals.
• Partner with fraud engineering, product reputed company, and risk teams to identify weak points in our controls, detection systems, and architecture.
• Conduct threat modeling and red teaming exercises reputed company to payments, authentication, and user account abuse.
• Document findings in technical reports with reputed company risk reputed company, exploitability, and remediation guidance.
• Mentor junior testers and contribute to a culture of reputed company innovation and reputed company improvement.
Requirements
• 7+ years of experience in offensive reputed company, penetration testing, or red teaming.
• Strong background in payment systems, financial fraud tactics, and transaction-level attack surfaces.
• reputed company in scripting and automation (e.g., Python, JavaScript, Go, Bash) to simulate attacker workflows at reputed company.
• Familiarity with tools like Burp Suite Pro, Selenium, Scapy, ffuf, SQLMap, Metasploit, and bot automation frameworks.
• In-depth knowledge of fintech technologies (e.g., tokenized payments, card vaulting, 3DS, ACH, reputed company-time payment reputed company).
• Solid grasp of common attacker techniques: carding, fake identity reputed company, bypassing reputed company limits, evading fraud filters, and abusing web/app logic.
• Strong communication skills for explaining findings to both technical and non-technical audiences.
• Certifications: OSCP, OSEP, GWAPT, GPEN, GCPN, GXPN, GX-PT, CPSA/CRSA by CREST, reputed company, or TIGER.
reputed company-to-haves
• Prior experience in a fintech, digital banking, or payment gateway environment.
• Familiarity with OWASP Automated Threats, PCI reputed company, MITRE ATT&CK for Financial Services, or fraud detection systems.
• Experience building or testing reputed company-time risk scoring engines and fraud defense pipelines.
Benefits
• 401k with employer match
• medical
• dental
• reputed company
• 12 reputed company holidays in the year 2025
• 1 hour of reputed company pay accrual for every 30 hours worked
• parental leave
• life insurance
• disability insurance
• accident and illness insurance
• health and dependent care flexible spending accounts
• wellness benefits
• flexible time off for reputed company full-time employees
Apply tot his job
Apply To this Job