{"id":1694833,"url":"https://alion.io/job/interactive-brokers-security-engineer-ii","title":"Security Engineer II","company":{"id":58627,"name":"Interactive Brokers","domain":"interactivebrokers.com","url":"https://alion.io/company/interactive-brokers","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Dayforce","truth_index":{"grade":"A","score":95,"open_postings":51,"ghost_share":0,"stale_share":0,"repost_share":0,"time_to_fill_p50_days":110,"computed_at":"2026-10-10T05:45:15Z"}},"role":"Security","role_family":"Security","seniority":"middle","employment_type":null,"work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Mumbai, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":15500,"max_usd":37000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":613},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Red Teaming","optional":false},{"name":"Active Directory","optional":true},{"name":"Burp Suite","optional":true},{"name":"C#","optional":true},{"name":"Cobalt Strike","optional":true},{"name":"CWE","optional":true},{"name":"Go","optional":true},{"name":"ISO 27001","optional":true},{"name":"JavaScript","optional":true},{"name":"LDAP","optional":true},{"name":"Metasploit","optional":true},{"name":"Node JS","optional":true},{"name":"OWASP Top 10","optional":true},{"name":"PCI DSS","optional":true},{"name":"PHP","optional":true},{"name":"Postman","optional":true},{"name":"Python","optional":true},{"name":"Sliver","optional":true},{"name":"SOC 2","optional":true},{"name":"SQL","optional":true},{"name":"TypeScript","optional":true}],"status":"live","first_seen_at":"2026-06-23T00:30:00Z","employer_posted_date":"2026-10-02","last_verified_at":"2026-10-11T18:54:12Z","board_verified":true,"closed_at":null,"days_open":110,"trust":{"level":"ok","repost_count":0,"flags":[],"days_open":110},"description":"About the Role \nWe are looking for a Senior Penetration Tester who combines strong offensive testing skills with deep application security and secure code review expertise. This role is for someone who doesn't just test applications from the outside — you can read and reason about source code like a developer, trace vulnerable logic from input to sink, and then convert those code-level findings into real, working security test cases and exploits that prove impact end-to-end. You'll own full-cycle assessments: black-box testing, white-box/source-assisted review, and validation — tying it all together into a coherent risk narrative for engineering and leadership, with an attacker's mindset applied throughout. Exposure to broader red team operations is a plus and will allow you to extend application-layer footholds into wider adversary simulation scenarios. \nKey Responsibilities \nApplication Penetration Testing (Black-box & White-box) \nPlan, scope, and execute end-to-end penetration tests on web applications, APIs, and mobile apps using both black-box and source-assisted (white-box) methodologies. \nPerform full attack-surface mapping, auth flows, session management, API contracts, business logic, access control boundaries - before diving into exploitation. \nChain vulnerabilities together to demonstrate real business impact (e.g., IDOR + broken auth → account takeover; SSRF → internal pivot → sensitive data exposure). \nValidate and retest fixes; ensure remediations actually close the exploited path, not just the symptom. \nManual Secure Code Review \nConduct manual, in-depth secure code reviews across languages such as Java, Python, JavaScript/TypeScript (Node.js), Go, C#, and PHP — going beyond automated scanner output. \nTrace data flow from source (user input, external API, file upload, etc.) to sink (DB query, deserialization, template engine, OS command, file system, etc.) to confirm real exploitability and eliminate false positives. \nIdentify vulnerability classes including injection attacks (SQL, NoSQL, Command, LDAP, XXE), insecure deserialization, authentication and session flaws, IDOR and broken access control, SSRF, race conditions, cryptographic misuse, and business logic flaws. \nTurning Code Findings into Working Security Tests \nFor every significant code-review finding, build a corresponding proof-of-concept, exploit script, or test case that demonstrates exploitability in a running environment — not just a theoretical writeup. \nDevelop custom scripts/tools (Python, Go, Bash) to weaponize and automate exploitation of identified code patterns across the codebase (e.g., identifying a vulnerable pattern, then scripting mass validation across multiple endpoints/services). \nTranslate secure code review findings into repeatable regression security tests that can be reused across engagements and retesting cycles to catch reintroduction of the same bug class. \nBridge the gap between \"this line of code looks dangerous\" and \"here's the request/script/payload that proves it,\" making findings actionable and unambiguous for developers. \nOffensive Tooling & Automation \nGo beyond automated scan output — treat static/dynamic analysis as a recon and target-prioritization step, then manually validate and weaponize findings into working exploits, the way an attacker would triage a leaked or decompiled codebase. \nBuild and maintain a personal/team exploit and payload library mapped to recurring vulnerability patterns — reusable proof-of-concepts, request templates, and scripts that turn a static finding into a live, demonstrable attack within minutes, speeding up engagement turnaround. \nChain application-layer findings into deeper exploitation paths — e.g., using a discovered IDOR or auth flaw to escalate privileges within the app, or an SSRF/file-read bug to pivot into other exposed application components or internal services reachable from the app. \nContinuously stress-test your own exploit library and detection logic against the live application — attempt to bypass existing input validation, WAF rules, and app-layer guardrails to ensure findings reflect genuine adversary capability, not just tool coverage. \nExtending Findings into Red Team Scenarios (Good to Have) \nUse application-layer footholds (e.g., an SSRF, exposed internal endpoint, or leaked credential from source code) as an entry point into broader adversary simulation — pivoting from app compromise toward internal network or Active Directory attack paths where in scope. \nApply working knowledge of C2 concepts (beaconing, traffic patterns, evasion) to understand how an application-layer compromise could realistically be leveraged for persistence or lateral movement in a full red team engagement. \nBring an adversary-emulation mindset to engagements — thinking beyond \"is this exploitable\" to \"how would a real threat actor chain this into a larger compromise.\" \nReporting & Communication \nAuthor clear, detailed technical reports that connect the dots: vulnerable code snippet → proof-of-concept/exploit → business impact → remediation guidance. \nMap findings to OWASP Top 10, SANS Top 25, and CWE, with risk ratings and clear reproduction steps. \nPresent findings to both engineering teams (code-level detail) and leadership (business risk, executive summary). \nSupport developers during remediation — reviewing patches and confirming the fix addresses root cause, not just the trigger. \nMentorship & Program Development \nMentor junior pentesters/AppSec engineers on manual code review techniques and exploit development. \nHelp mature the internal AppSec/pentest methodology — playbooks, custom tooling, and code-review checklists tailored to the tech stacks in use. \nStay current with new vulnerability classes, framework-specific CVEs, and emerging exploitation techniques; incorporate them into review checklists and test cases. \nRequired Qualifications \n5+ years in penetration testing / offensive security, with strong demonstrable experience in application security testing and manual secure code review (not just automated scanning). \nProven ability to read and understand source code fluently in at least one major backend language (Java, Python, C#, Go, or JavaScript/TypeScript), enough to trace logic, understand data flow, and spot subtle flaws. \nTrack record of converting static findings (from code review) into working dynamic proof-of-concepts — able to go from \"vulnerable line of code\" to an actual exploit/request/script that proves it. \nStrong scripting/programming skills (Python, Go, Bash, or similar) for building custom test scripts, automation, and exploit tooling. \nSolid understanding of web/API architecture and common vulnerability classes (OWASP Top 10, SANS Top 25, CWE). \nHands-on experience with web/API application testing toolchains (e.g., Burp Suite Pro, Postman) and static/dynamic code analysis approaches. \nStrong report writing and communication skills, able to explain code-level vulnerabilities to both developers and non-technical stakeholders. \nPreferred Qualifications \nCertifications such as OSWE, OSCP, GWAPT, CRTE, or equivalent — OSWE especially valued given the code-review/exploit-dev focus. \nPrior red team experience — comfort with Active Directory attack paths, lateral movement, privilege escalation, and C2 frameworks (e.g., Cobalt Strike, Sliver, Metasploit) is a strong plus. \nExperience with mobile application security testing (iOS/Android) including static analysis of app binaries/source. \nKnowledge of compliance frameworks (PCI-DSS, ISO 27001, SOC 2) as they relate to application security testing. \nActive participation in bug bounty programs with a strong track record of validated findings is a plus. \nSpeaking engagements at security/bug bounty conferences (e.g., DEF CON, Black Hat, Nullcon, c0c0n, BSides) or publishing security research/write-ups is a strong plus. \nCompany Benefits & Perks: \nCompetitive salary package.\nPerformance based annual bonus (cash and stocks).\nHybrid working model (3 days office/week).\nGroup Medical & Life Insurance.\nModern offices with free amenities & fully stocked cafeterias.\nMonthly food card & company paid snacks.\nHardship/shift allowance with company provided pickup & drop facility*\nAttractive employee referral bonus.\nFrequent company sponsored team building events and outings.\n* Depending upon the shifts.\n**The benefits package is subject to change at the management's discretion.","description_format":"text","description_chars":8431,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Cafeteria","Hybrid work","Life insurance"],"hiring_locations":[{"name":"India","iso":"IN","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Financial Services"],"lifecycle":[{"event":"open","at":"2026-10-02T11:57:18Z"}],"visa":[],"liveness":{"score":42,"band":"fade","label":"Fading","p_open":1,"p_active":0.703,"p_room":0.6,"age_days":109,"expected_fill_days":110,"reasons":["conf:1","velocity","win:late","crowd:brand"],"computed_at":"2026-10-10T05:45:15Z"},"pay":null,"html_url":"https://alion.io/job/interactive-brokers-security-engineer-ii","json_url":"https://alion.io/job/interactive-brokers-security-engineer-ii.json","meta":{"generated_at":"2026-10-11T20:08:46Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler_verified","counted_by":"address","units_charged":1,"used_today":7677,"day_limit":null,"remaining_today":null,"minute_limit":300,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":58627},"rest":"https://alion.io/mcp/rest/get_company?id=58627"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Finteractive-brokers-security-engineer-ii"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Finteractive-brokers-security-engineer-ii"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Finteractive-brokers-security-engineer-ii"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/interactive-brokers-security-engineer-ii\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Finteractive-brokers-security-engineer-ii"}]}