First Citizens Bank logo

Penetration Testing Manager (Sr. Manager InfoSec) - Remote

First Citizens Bank Raleigh, North Carolina, United States

remotefull-time

Salary: $155,000 - $190,000 / year

Posted Sep 12, 2026Apply by Oct 12, 2026

**Role & seniority: ** AppSec Pentest Manager; leads a penetration testing team within First Citizens Bank’s AppSec Testing Program. Senior leadership with program/people management responsibilities.

**Stack/tools: **

  • Penetration testing methodologies/standards: OWASP Top 10, PETS (Penetration Testing Execution Standard), CREST methodologies

  • Tooling/vendor procurement (unspecified)

  • Data/metrics reporting (multiple sources)

  • Mentions: agentic pentesting (experience preferred)

  • Top 3 responsibilities:

    • Penetration testing strategy & cadence aligned to AppSec/Vulnerability Mgmt/SDLC and risk appetite; drive improvement projects

    • Program management: create/sustain schedules across multiple teams; identify and remediate schedule slippage; handle urgent changes

    • Leadership + technical execution: manage team performance/training; provide pentesting SME guidance; oversee reporting, remediation guidance, and exception/risk alignment (BISOs/GRC/IT)

  • Must-have skills:

    • Deep expertise in pentesting process/standards (OWASP Top 10, PETS, CREST)

    • Strong program management and cross-team coordination

    • People management: performance management, training/development plans

    • Technical leadership and risk communication to varied audiences, including C-level

    • Ability to analyze reporting metrics and identify trends

  • Nice-to-haves:

    • Industry certs rel

Full Description

Overview

The AppSec Pentest Manager leads a team of highly qualified penetration testers in First Citizens Bank’s AppSec Testing Program. This leader is a strategic partner with application development teams and IT teams. In this role the Pentest Manager must be able to demonstrate deep knowledge of penetration testing processes such as the OWASP Top 10, Penetration Testing Execution Standard (PETS), and CREST Pentesting Methodologies. This role will lead the penetration testing team in identifying, classifying, and reporting complex vulnerabilities against First Citizens Bank’s custom applications.

Remote eligible.

Responsibilities & Qualifications

Duties & Responsibilities

Penetration Testing Strategy – Expert level of skill in strategy development that integrates into the overall AppSec and Vulnerability Management Strategy, SDLC, and First Citizens Bank’s Risk Appetite. This role should be able to expertly establish a regular penetration testing cadence that aligns with First Citizens Bank’s Cyber Security Standards. This role will also identify areas of improvement for the penetration testing team and drive the improvement projects to completion. Program Management – Ability to establish a penetration testing schedule and cadence with multiple inputs and coordination between multiple teams. Expert ability to identify schedule slippages early and remediate them to ensure applications follow First Citizens Bank standards. Ability to rapidly switch gears if an urgent need arises. Managerial Functions - Establishes and monitors expectations to achieve company and department goals. Manages the performance, training, and evaluation of assigned staff. Creates development plans for assigned staff to ensure their skillsets remain at the highest level. Responsible for vendor management and procurement of tools and services. Penetration Testing Subject Matter Expert – Provide expert technical advice to internal team members on penetration testing methodology. Provide expert technical advice to internal clients on the overall impact of penetration testing findings and recommendations for remediation. Partner with Application teams to drive the closure of penetration testing findings. Partner with application teams, BISOs, GRC, and IT Teams to ensure exceptions are properly documented and in line with First Citizens Bank’s risk appetite. Reporting – Regularly report metrics. Expert ability to analyze data from various sources to answer important business questions and identify trends or issues from the data. Communication – Ability to communicate risk to a variety of audiences, deftly changing style and level of detail accordingly. Expert ability to discuss significance of data to C-Level executives and above. Communication to direct supervisor, clearly and concisely articulating risks and issues.

Minimum Required Education And Experience

Bachelor's Degree and 8 years' experience OR High School Diploma or GED/Equivalent and 12 years' experience in Information security or technology

Preferred Area Of Experience

At least one on industry standard certification related to penetration testing and/or cybersecurity leadership (CISSP, CISM, GPEN, GWAPT, OSCP, OSWA) Experience with agentic pentesting

Additional Information

This job posting is expected to remain active for 30 days from the initial posting date listed above. If it is necessary to extend this deadline, the posting will remain active as appropriate. Job postings may come down early due to business need or a high volume of applicants.

The base pay for this position is generally between $155,000 and $190,000. Actual starting base pay will be determined based on skills, experience, location, and other non-discriminatory factors permitted by law. For some roles, total compensation may also include variable incentives, bonuses, benefits, and/or other awards as outlined in the offer of employment.

Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at https://jobs.firstcitizens.com/benefits.

Penetration TestingVulnerability ManagementOWASP Top 10Program ManagementVendor ManagementRisk ManagementSDLCTechnical ReportingStakeholder CommunicationTeam LeadershipAgentic PentestingSecurity Strategymulti-location

Cookies & analytics consent

We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.

Read how we use data in our Privacy Policy and Terms of Service.