1

Api Penetration Testing Jobs (NOW HIRING)

Be Seen First

Penetration Tester

Knoxville, TN · Remote

$120K - $145K/yr

This role requires proven hands-on capability in both network and web application/API penetration testing. You'll combine manual analysis with appropriate tooling, identify and pursue viable attack ...

Be Seen First

Penetration Tester

Knoxville, TN · Remote

$120K - $145K/yr

This role requires proven hands-on capability in both network and web application/API penetration testing. You'll combine manual analysis with appropriate tooling, identify and pursue viable attack ...

Demonstrated experience with web application and API penetration testing, including identifying and exploiting attack chains across complex application logic, authentication, and authorization flows.

Demonstrated experience with web application and API penetration testing, including identifying and exploiting attack chains across complex application logic, authentication, and authorization flows.

Demonstrated experience with web application and API penetration testing, including identifying and exploiting attack chains across complex application logic, authentication, and authorization flows.

Demonstrated experience with web application and API penetration testing, including identifying and exploiting attack chains across complex application logic, authentication, and authorization flows.

$100 - $125/hr

Web, Mobile, API, Cloud & Infrastructure | U.S.-Based About the Opportunity At TechCompass, penetration testing is about more than producing a list of vulnerabilities. Our testers simulate realistic ...

Responsibilities : • Conduct web application, API, and network penetration tests to identify and validate security vulnerabilities. • Perform grey-box and black-box testing following NIST SP 800 ...

Description Tharros is seeking a Senior Penetration Testing, Software Assurance and Vulnerability ... Experience testing cloud, application, identity, API, microservices, CI/CD, DevSecOps, Zero Trust ...

Tharros is seeking a Senior Penetration Testing, Software Assurance and Vulnerability Assessment ... Support secure cloud, hybrid, DevSecOps, application, identity, API, microservices, CI/CD, Zero ...

Penetration Tester

Leesburg, VA · On-site

$125 - $150/hr

Work closely with all members of the team to conduct penetration testing of customer networks, applications (API, web, and mobile), and/or social engineering activities to achieve the customer ...

Senior Penetration Tester

Washington, DC · On-site

$145K - $180K/yr

Expertise with API focused penetration testing. * Proficiency with penetration testing tools (Kali Linux, Binwalk, BurpSuite, Wireshark, etc) Nice To Have: * Certification focuses on Web Application ...

next page

Showing results 1-20

Api Penetration Testing information

See salary details

$11K

$109.6K

$183.5K

How much do api penetration testing jobs pay per year?

As of Sep 8, 2026, the average yearly pay for api penetration testing in the United States is $109,565.00, according to ZipRecruiter salary data. Most workers in this role earn between $80,000.00 and $143,000.00 per year, depending on experience, location, and employer.

What is API penetration testing?

API penetration testing is a security assessment process that focuses on evaluating the security of Application Programming Interfaces (APIs). Testers simulate real-world cyberattacks on APIs to identify vulnerabilities such as broken authentication, improper access controls, data exposure, and injection flaws. The goal is to uncover weaknesses before malicious actors can exploit them, ensuring that APIs are robust and secure. It typically involves both automated tools and manual testing techniques to thoroughly assess the API's security posture.

What are the key skills and qualifications needed to thrive as an API penetration tester, and why are they important?

To thrive as an API Penetration Tester, you need a deep understanding of web application security, networking protocols, and common API vulnerabilities, often supported by cybersecurity certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Postman, OWASP ZAP, and scripting languages like Python is typically required. Strong analytical thinking, attention to detail, and effective communication skills help testers identify, document, and explain vulnerabilities to stakeholders. These skills are crucial for safeguarding applications, ensuring regulatory compliance, and helping organizations mitigate security risks.

What are some common challenges faced by API penetration testers during an engagement?

API penetration testers often encounter challenges such as incomplete or outdated documentation, which can make it difficult to understand the full functionality and endpoints of an API. Additionally, handling complex authentication mechanisms or rate-limiting controls can require creative approaches to thoroughly test for vulnerabilities. Collaboration with development teams is crucial to clarify uncertainties and gain necessary access, while maintaining accurate and detailed reporting is essential for communicating findings back to stakeholders effectively.

What is the difference between Api Penetration Testing vs API Security Analyst?

AspectApi Penetration TestingAPI Security Analyst
Primary FocusIdentifying vulnerabilities in APIs through simulated attacksMonitoring, analyzing, and improving API security measures
CertificationsOSCP, CEH, GPENCISSP, GIAC Security Essentials
Work EnvironmentSecurity testing teams, cybersecurity firmsIT security departments, development teams
Industry UsageCybersecurity, software developmentEnterprise security, API management

Api Penetration Testing focuses on actively discovering vulnerabilities by simulating attacks on APIs, while API Security Analysts monitor and enhance API security protocols. Both roles require cybersecurity certifications and are vital in protecting API infrastructure, but they differ in approach: testing versus ongoing security management.

How much do Api Penetration Testers make?

Api Penetration Testers typically earn between $70,000 and $130,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in security tools and scripting can command higher salaries.

Is Api Penetration Testing a good career?

Api Penetration Testing is a specialized cybersecurity role focused on identifying vulnerabilities in APIs, often requiring knowledge of security tools, scripting, and protocols. It is a growing field with high demand for skilled professionals, offering opportunities for advancement and specialization in cybersecurity. Certifications like OSCP or CEH can enhance career prospects in this area.
Infographic showing various Api Penetration Testing job openings in the United States as of September 2026, with employment types broken down into 33% Full Time, 33% Part Time, and 34% Contract. Highlights an 33% In-person, 34% Hybrid, and 33% Remote job distribution, with an average salary of $109,565 per year, or $52.7 per hour.

Penetration Tester

Zelvin Security LLC

Knoxville, TN • Remote

$120K - $145K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 25 days ago

Be Seen First

After you apply to this job, you can share why you’re interested to jump to the top of the candidate list.


Job description

Zelvin Security is seeking an experienced Penetration Tester to join our Ethical Hacking Team and conduct hands-on ethical hacking engagements across networks, web applications, APIs, cloud platforms, and hybrid environments.

This role requires proven hands-on capability in both network and web application/API penetration testing. You’ll combine manual analysis with appropriate tooling, identify and pursue viable attack paths, validate exploitability, demonstrate real-world impact, and turn technical evidence into a clear, compelling narrative that helps clients understand their risk and take meaningful action.

At Zelvin, penetration testing is not about generating a list of vulnerabilities. Our testers think like attackers, follow the evidence, challenge assumptions, and determine which weaknesses create meaningful risk. They then help clients understand what matters, why it matters, and what they can do about it.

We are looking for someone who wants their work to make a meaningful impact serving clients, contributing to our team, their own professional growth, and the broader offensive security community.

Skills & Qualifications

· Minimum of three years of professional penetration testing or offensive security experience.

· Demonstrated hands-on experience conducting both network and web application/API penetration testing.

· Strong knowledge of Active Directory and Windows enterprise environments, including authentication, privilege escalation, lateral movement, and common attack paths.

· Working knowledge of cloud and hybrid environments, including identity, networking, permissions, and exposed services.

· Strong understanding of networking, operating systems, web technologies, authentication, exploitation techniques, and offensive security methodologies.

· Ability to analyze attack paths, adapt testing approaches, troubleshoot unsuccessful techniques, and distinguish demonstrated risk from assumptions or theoretical exposure.

· Strong critical-thinking, technical-curiosity, attention-to-detail, and problem-solving skills.

· Excellent written and verbal communication skills, including the ability to translate technical evidence and security risk for technical and non-technical audiences.

· Demonstrated professionalism, integrity, accountability, and sound judgment.

· Ability to work independently while collaborating effectively, sharing knowledge, respecting different perspectives, and contributing to team success.

· Bachelor’s degree in information security, computer science, a related field, or equivalent professional experience.

Professional Requirements:

At least one recognized hands-on offensive security certification such as OSCP, OSWE, or an equivalent. Other certifications such as CPTS, BSCP, GPEN, GWAPT, or equivalents will be considered.

Strong desire to make a meaningful impact through client service, team contribution, continued professional growth, and active engagement with the broader offensive security community. Uphold professional and technical standards, especially when doing so is challenging.

Responsibilities

As a Penetration Tester:

· Conduct all aspects of hands-on, manual and tool-assisted penetration testing of internal and external networks, web applications, APIs, cloud platforms, and hybrid environments.

· Identify, investigate, validate, safely exploit, and document vulnerabilities and attack paths to demonstrate actual security risk and real-world impact.

· Turn technical evidence into clear, defensible findings and practical remediation guidance that helps clients understand their risk and take meaningful action.

· Take ownership of assigned engagements through completion, while producing technically accurate, well-supported deliverables that uphold Zelvin’s quality standards.

As a Teammate:

· Participate in peer reviews and give and receive constructive feedback that improves the quality and accuracy of our work.

· Develop or adapt scripts, tools, payloads, and exploitation techniques when existing approaches are insufficient

· Research emerging technologies, vulnerabilities, and attack techniques, and contribute improvements to Zelvin’s methodologies, tools, and technical capabilities to support continuous innovation.


· Combine technical excellence with curiosity, professional judgment, and accountability. Communicate concerns, share in finding solutions to barriers, and act with integrity.

Technical excellence has its greatest impact when it strengthens our clients, improves our work, and develops the people around us.

What We Offer

· Remote work environment

· Unlimited paid time off (Policy Guided)

· Continuing education and professional development opportunities

· Competitive base salary and performance-based bonus

· Medical, dental, and vision insurance

· 401(k) with company match

· Opportunities to contribute directly to Zelvin’s testing methodologies, tools, processes, and technical capabilities

· Process improvement is guided by the team and everyone’s suggestions are considered


Position Details

This is a full-time remote position with less than 5% of required travel annually.

Zelvin Security is an equal opportunity employer. Employment is contingent upon successful completion of applicable background screening, drug screening, and E-Verify requirements. This position is not eligible for visa sponsorship. Applicants must have permanent authorization to work in the U. S. at the time of hire.

Base salary is determined by experience, technical capability, certifications, and overall qualifications. Performance bonuses are awarded according to defined company standards.

Company Description

Zelvin Security is a cybersecurity firm specializing in Ethical Hacking. We work with businesses and organizations to help them secure applications, networks, architecture and other sensitive assets to reduce cybersecurity risks. Our experienced Ethical Hacking testers perform penetration tests: application, mobile, cloud, network testing and other red and purple team exercises. We are a privately owned business with strong values and a team environment.