Visa’s Technology Organization is a community of problem solvers and innovators reshaping the future of commerce. We operate the world’s most sophisticated processing networks capable of handling more than 65k secure transactions a second across 80M merchants, 15k Financial Institutions, and billions of everyday people. While working with us you’ll get to work on complex distributed systems and solve massive scale problems centered on new payment flows, business and data solutions, cyber security, and B2C platforms.
Cybersecurity is at the beating heart of our business. Our diligence and expertise are what makes us an undisputed leader in electronic payments. We’ve made it our priority to create exemplary security operations and incident response teams, poised to defend us against any potential cyber threats.
We’re looking for those of you who are inherently driven and fascinated by the art and science of cyber defense. We’ll equip you with the very best tools and tech so that you can deliver top notch results.
- The objective of Visa’s Penetration Testing program is pro-actively identifying weaknesses and shortcomings in Visa’s security posture and recommending necessary controls and procedures to protect Visa adversarial threats. With this mission in mind, our Pentesting experts are pro-actively involved in engagements that simulate adversarial threats & attacks in a timely manner.
- The Security Specialist will be a key contributor for performing internal and external ethical hacks of Visa applications and systems. Pentesting team members will also help with design, development, and recommendation of security solutions to protect Visa proprietary/confidential data and systems.
- Conducting high risk and sensitive ethical hacks of internally and externally hosted applications according to scope defined by the Pentesting team.
- Subject matter expertise in web, mobile or network penetration testing with track record of end-to-end testing of complex systems.
- Coordinate and execute system/network level Pentesting and ethical hacking exercises.
- Proactively research and Identify network and system vulnerabilities and provide recommended counter measures or controls to reduce risk to an acceptable and manageable level.
- Reviews results of network and application ethical hacks to determine severity of findings and to ensure proper remediation is applied.
- Provide accurate and timely reporting of findings and proposed remediation and mitigations.
- Technical support could include but not limited to the following: (1) Audit support & remediation, (2) Process Improvement, (3) Analysis & Reporting, (4) Cross Divisional Functional education, training, and awareness, (5) function/Methodology/Strategy advancement.
- Provide technical support to senior management in identifying and streamlining new/existing protocols and tools used by the penetration testing team.
- Develop and automate scripts, tools and resources needed to advance ethical hacking capabilities around new and emerging technologies like mobile, cloud and embedded systems.
· 6+ years of work experience with a University Degree.
· 3+ years of penetration testing experience.
· Strong understanding of cryptographic concepts and applied cryptography (SSL, AES etc.)
· Proficiency in one or more scripting languages like Perl, Python, Shell Scripting etc.
· Proficiency in one or more high level programming languages like Java, C, C++, Ruby etc.
· Understanding of OWASP Top 10 and SANS Top 25 web application and network vulnerabilities.
· Expertise and experience in web/mobile application and network penetration testing
· Prior experience with Red teaming.
· Knowledge of exploit development, vulnerability research/reporting or writing system modules in C & C++.
· Detailed understanding of OSI and TCP stack with emphasis on computer architecture and networking protocols.
· Exposure to mainframe penetration testing would be an added advantage.
· Knowledge of web application technologies and layer 7 protocols like HTTP, DHCP, DNS, FTP etc.
· Good understanding of networking concepts around Ethernet, switched LAN and WAN environment.
· Prior knowledge or academic familiarity with reverse engineering, malware analysis, security research and forensic tools.
Visa is an EEO Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status. Visa will also consider for employment qualified applicants with criminal histories in a manner consistent with EEOC guidelines and applicable local law.