1

Application Penetration Tester Jobs (NOW HIRING)

REQUIRED QUALIFICATIONS 5+ years of experience in security applications and systems Minimum of 5 years of Information Security Engineer/Consultant experience with application penetration testing.

... Device Application penetration testing. • Execute Federal and Commercial Cloud technology penetration testing. • Conduct High Value Asset Assessments. • Utilize knowledge of Red, Blue, and ...

... Application penetration testing. • Executing High Value Asset Assessments. • Utilizing various methodologies for penetration testing. • Gathering information and conducting comprehensive ...

... with application penetration testing. • Minimum of 5 years of demonstrated experience with automated penetration tools • Minimum of 5 years of demonstrated experience with manual penetration ...

... Application penetration testing. • Experience with Federal and Commercial Cloud technology penetration testing. • Experience conducting High Value Asset Assessments. • Knowledge of Red, Blue ...

... Application penetration testing. • Experience with Federal and Commercial Cloud technology penetration testing. • Experience conducting High Value Asset Assessments. • Knowledge of Red, Blue ...

... Application penetration testing. • Experience with Federal and Commercial Cloud technology penetration testing. • Experience conducting High Value Asset Assessments. • Knowledge of Red, Blue ...

next page

Showing results 1-20

Application Penetration Tester information

See salary details

$96.5K

$132.3K

$159.5K

How much do application penetration tester jobs pay per year?

As of Jul 26, 2026, the average yearly pay for application penetration tester in the United States is $132,307.00, according to ZipRecruiter salary data. Most workers in this role earn between $121,500.00 and $146,500.00 per year, depending on experience, location, and employer.

What does a typical day look like for an Application Penetration Tester?

A typical day for an Application Penetration Tester involves planning and executing tests on web and mobile applications to identify security vulnerabilities, documenting findings, and collaborating with development or security teams to discuss remediation strategies. You might spend time replicating attack scenarios, reviewing code, and researching emerging threats or new testing methodologies. Regular team meetings and client briefings are common, especially when working on larger projects or audits. The work is highly dynamic, often requiring you to juggle multiple projects and stay current with evolving security best practices.

Is a penetration tester in demand?

Yes, application penetration testers are in high demand due to increasing cybersecurity threats and the need for organizations to identify vulnerabilities. The role often requires knowledge of security tools, scripting, and certifications like OSCP or CEH, and job growth is expected to remain strong as cyberattacks become more sophisticated.

What are the key skills and qualifications needed to thrive in the Application Penetration Tester position, and why are they important?

To thrive as an Application Penetration Tester, you need strong knowledge of application security, vulnerability assessment, and web technologies, typically supported by a degree in computer science, cybersecurity, or a related field. Familiarity with common penetration testing tools such as Burp Suite, OWASP ZAP, Kali Linux, as well as certifications like OSCP or CEH, is highly beneficial. Critical thinking, keen attention to detail, and clear written and verbal communication are essential soft skills for effective reporting and collaboration. These competencies ensure thorough security assessments, actionable findings, and effective teamwork to protect digital assets.

What is an application penetration tester?

An application penetration tester is a cybersecurity professional who evaluates the security of software applications by simulating cyberattacks to identify vulnerabilities. They use tools like vulnerability scanners and perform manual testing to help organizations strengthen their defenses and ensure application security compliance.

What is an Application Penetration Tester job?

An Application Penetration Tester is a cybersecurity professional who assesses the security of applications by simulating real-world attacks. They identify vulnerabilities, exploit weaknesses, and provide recommendations to improve security. Their work involves using automated tools and manual testing techniques to uncover risks. They collaborate with developers and security teams to ensure applications are protected against threats. This role requires knowledge of coding, common exploits, and security frameworks.

How to get into a penetration testing job?

To become an application penetration tester, develop strong knowledge of networking, operating systems, and security principles. Obtain relevant certifications such as Offensive Security Certified Professional (OSCP) or Certified Ethical Hacker (CEH), and gain hands-on experience through labs, internships, or bug bounty programs. Proficiency with tools like Kali Linux, Burp Suite, and Metasploit is also valuable.

Will pentesters be replaced by AI?

Application penetration testers perform manual and automated security assessments to identify vulnerabilities, and while AI tools can assist in detecting certain issues, they cannot fully replace the critical thinking, creativity, and contextual understanding that human pentesters provide. AI may augment the testing process but is unlikely to eliminate the need for skilled professionals in the foreseeable future.
More about Application Penetration Tester jobs
What cities are hiring for Application Penetration Tester jobs? Cities with the most Application Penetration Tester job openings:
What are the most commonly searched types of Application Penetration Tester jobs? The most popular types of Application Penetration Tester jobs are:
What states have the most Application Penetration Tester jobs? States with the most job openings for Application Penetration Tester jobs include:
What are popular job titles related to Application Penetration Tester jobs? For Application Penetration Tester jobs, the most frequently searched job titles are:
Infographic showing various Application Penetration Tester job openings in the United States as of July 2026, with employment types broken down into 77% Full Time, 17% Part Time, 1% Temporary, and 5% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $132,307 per year, or $63.6 per hour.
Application Penetration Tester

Application Penetration Tester

Booz Allen Hamilton

Chantilly, VA • On-site

$62K - $141K/yr

Full-time

Medical, Life, Retirement, PTO

Posted 5 days ago


Booz Allen Hamilton rating

8.8

Company rating: 8.8 out of 10

Based on 48 frontline employees who took The Breakroom Quiz

13th of 73 rated business consultants


Job description

Application Penetration Tester

The Opportunity:

Work with a wide variety of clients, including Fortune 100 companies, to validate security controls and incident response through offensive security operations, including application penetration testing. Perform web application security testing, network penetration testing, and cloud penetration testing. Develop comprehensive and accurate reports, and presentations for both technical and executive audiences. Conduct security testing lifecycles in Windows and *nix environments. Communicate findings and strategy to client stakeholders, including technical staff, executive leadership, and legal counsel. Perform innovative research and promote an environment of innovation and knowledge sharing. Apply security testing and penetration testing techniques and mindset to a wide range of projects, become part of a team of security enthusiasts that perform cutting-edge research, and promote an environment of innovation and knowledge sharing. Due to the nature of work performed within this facility, U.S. citizenship is required.

You Have:

  • 1+ years of experience conducting application penetration testing
  • Experience with scripting or coding in Python, Go, or Bash
  • Experience working in a Windows environment and with Active Directory attack path enumeration
  • Experience with C2 frameworks, including Cobalt Strike, Mythic, or Havoc
  • Knowledge of network vulnerability assessments, web application security testing, network penetration testing, or red teaming
  • HS diploma or GED

Nice If You Have:

  • Experience working in a commercial environment, and with Burp Suite Professional
  • Experience deploying infrastructure in cloud environments
  • Bachelor's degree in CS or a related field
  • BSCP, OSWA, OSWE, OSCP, CRTO, GPEN, GXPN, OSCE, or GWAPT Certification

Compensation

At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.

Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $62,000.00 to $141,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date.

Identity Statement

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Candidate AI Usage Policy

AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided.

Work Model
Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.

  • Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.

  • Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.

  • Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.


What Booz Allen Hamilton employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Booz Allen Hamilton logo

About Booz Allen Hamilton

Sourced by ZipRecruiter

Booz Allen Hamilton is a leading provider of management and technology consulting services to the US government in defense, intelligence, and civil markets. Headquartered in McLean, Virginia, the firm also serves major corporations, institutions, and not-for-profit organizations. Founded in 1914 by Edwin G. Booz, the company has a long-standing tradition of helping clients achieve success by delivering a wide range of consulting services that include strategic planning, human capital and learning, communication, systems development, and others. The company's mission is to empower people to change the world, and it has a reputation for maintaining the highest standards of integrity and-excellence.

Industry

It services

Company size

10,000+ Employees

Headquarters location

McLean, VA, US

Year founded

1914