KPMG is currently seeking a Senior Specialist, MAST Application Penetration Tester to join our Managed Services practice. The role involves conducting manual application penetration testing and ...
KPMG is currently seeking a Senior Specialist, MAST Application Penetration Tester to join our Managed Services practice. The role involves conducting manual application penetration testing and ...
They are currently seeking a Senior Specialist, MAST Application Penetration Tester to conduct manual penetration testing and evaluate application security within their Managed Services practice.
They are currently seeking a Senior Specialist, MAST Application Penetration Tester to conduct manual penetration testing and evaluate application security within their Managed Services practice.
They are seeking a Senior Specialist, MAST Application Penetration Tester to conduct penetration testing and evaluate application security while fostering a collaborative team environment.
They are seeking a Senior Specialist, MAST Application Penetration Tester to conduct penetration testing and evaluate application security while fostering a collaborative team environment.
They are seeking a Senior Specialist, MAST Application Penetration Tester to conduct manual penetration testing and execute threat modeling while working independently in various engagements.
They are seeking a Senior Specialist, MAST Application Penetration Tester to conduct manual penetration testing and execute threat modeling while working independently in various engagements.
They are currently seeking a Senior Specialist, MAST Application Penetration Tester to perform manual penetration testing and threat modeling, while working independently and demonstrating ...
They are currently seeking a Senior Specialist, MAST Application Penetration Tester to perform manual penetration testing and threat modeling, while working independently and demonstrating ...
They are currently seeking a Senior Specialist, MAST Application Penetration Tester to conduct manual penetration testing and evaluate application security across various platforms. Responsibilities ...
They are currently seeking a Senior Specialist, MAST Application Penetration Tester to conduct manual penetration testing and evaluate application security across various platforms. Responsibilities ...
Jnr. Penetration Tester - Cloud, Mobile & Web Application
California, MO · On-site
$80 - $132/hr
Cloud, Mobile and Web Application Penetration Tester in Orange County, CA. This is an onsite position (hybrid is possible) for US Citizens and Green Card holders. If you need visa sponsorship now or ...
Jnr. Penetration Tester - Cloud, Mobile & Web Application
California, MO · On-site
$80 - $132/hr
Cloud, Mobile and Web Application Penetration Tester in Orange County, CA. This is an onsite position (hybrid is possible) for US Citizens and Green Card holders. If you need visa sponsorship now or ...
Senior Specialist, MAST Application Penetration Tester
Atlanta, GA · On-site
$95K - $208K/yr
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Senior Specialist, MAST Application Penetration Tester
Atlanta, GA · On-site
$95K - $208K/yr
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
GIAC Penetration Tester (GPEN) * Offensive Security Web Expert (OSWE) * eLearnSecurity Web Application Penetration Tester (eWPT) * Certified Red Team Operator (CRTO) * Other relevant offensive ...
GIAC Penetration Tester (GPEN) * Offensive Security Web Expert (OSWE) * eLearnSecurity Web Application Penetration Tester (eWPT) * Certified Red Team Operator (CRTO) * Other relevant offensive ...
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Minimum of 2 years' professional experience performing web application, API endpoint, and mobile (iOS & Android) penetration testing * Knowledge of prioritizing remediation activities with ...
Minimum of 2 years' professional experience performing web application, API endpoint, and mobile (iOS & Android) penetration testing * Knowledge of prioritizing remediation activities with ...
$90 - $130/hr
* Plan and execute penetration tests across web, mobile (iOS & Android), API, cloud-native ... Conduct mobile application security testing and reverse engineering, including hardcoded ...
$90 - $130/hr
* Plan and execute penetration tests across web, mobile (iOS & Android), API, cloud-native ... Conduct mobile application security testing and reverse engineering, including hardcoded ...
Penetration Tester
Charlotte, NC · On-site
... with application penetration testing. • Minimum of 5 years of demonstrated experience with automated penetration tools • Minimum of 5 years of demonstrated experience with manual penetration ...
Penetration Tester
Charlotte, NC · On-site
... with application penetration testing. • Minimum of 5 years of demonstrated experience with automated penetration tools • Minimum of 5 years of demonstrated experience with manual penetration ...
Penetration Tester
Charlotte, NC · On-site
REQUIRED QUALIFICATIONS 5+ years of experience in security applications and systems Minimum of 5 years of Information Security Engineer/Consultant experience with application penetration testing.
Penetration Tester
Charlotte, NC · On-site
REQUIRED QUALIFICATIONS 5+ years of experience in security applications and systems Minimum of 5 years of Information Security Engineer/Consultant experience with application penetration testing.
Minimum of 2 years' professional experience performing web application, API endpoint, and mobile (iOS & Android) penetration testing * Knowledge of prioritizing remediation activities with ...
Minimum of 2 years' professional experience performing web application, API endpoint, and mobile (iOS & Android) penetration testing * Knowledge of prioritizing remediation activities with ...
Penetration tester
Dallas, TX · On-site
... Web Application/Web Services penetration testing • network Penetration Testing • Mobile Application Penetration Testing • Thick Client Penetration Testing • Knows scripting language. • ...
Penetration tester
Dallas, TX · On-site
... Web Application/Web Services penetration testing • network Penetration Testing • Mobile Application Penetration Testing • Thick Client Penetration Testing • Knows scripting language. • ...
Minimum of 2-3 years of work experience in application penetration testing * Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite, Metasploit, Nessus)
Minimum of 2-3 years of work experience in application penetration testing * Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite, Metasploit, Nessus)
Minimum of 2-3 years of work experience in application penetration testing * Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite, Metasploit, Nessus)
Quick apply
Minimum of 2-3 years of work experience in application penetration testing * Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite, Metasploit, Nessus)
Penetration Tester
Hillsboro, OR · On-site
... penetration testing or application security background * Strong understanding of a variety of ... Application development, networking, systems administration, and information security practices.
Penetration Tester
Hillsboro, OR · On-site
... penetration testing or application security background * Strong understanding of a variety of ... Application development, networking, systems administration, and information security practices.
Application Penetration Tester information
See salary details
$96.5K - $102.2K
4% of jobs
$102.2K - $108K
8% of jobs
$108K - $113.7K
4% of jobs
$113.7K - $119.4K
2% of jobs
$121.8K is the 25th percentile. Wages below this are outliers.
$119.4K - $125.1K
16% of jobs
$125.1K - $130.9K
15% of jobs
The median wage is $131.2K / yr.
$130.9K - $136.6K
11% of jobs
$136.6K - $142.3K
10% of jobs
$145.3K is the 75th percentile. Wages above this are outliers.
$142.3K - $148K
10% of jobs
$148K - $153.8K
11% of jobs
$153.8K - $159.5K
10% of jobs
$96.5K
$132.3K
$159.5K
How much do application penetration tester jobs pay per year?
What is an application penetration tester?
An Application Penetration Tester is a cybersecurity professional who assesses the security of applications by simulating real-world attacks. They identify vulnerabilities, exploit weaknesses, and provide recommendations to improve security. Their work involves using automated tools and manual testing techniques to uncover risks. They collaborate with developers and security teams to ensure applications are protected against threats. This role requires knowledge of coding, common exploits, and security frameworks.
What does an application penetration tester do?
A typical day for an Application Penetration Tester involves planning and executing tests on web and mobile applications to identify security vulnerabilities, documenting findings, and collaborating with development or security teams to discuss remediation strategies. You might spend time replicating attack scenarios, reviewing code, and researching emerging threats or new testing methodologies. Regular team meetings and client briefings are common, especially when working on larger projects or audits. The work is highly dynamic, often requiring you to juggle multiple projects and stay current with evolving security best practices.
What are the key skills and qualifications needed to thrive as an application penetration tester?
To thrive as an Application Penetration Tester, you need strong knowledge of application security, vulnerability assessment, and web technologies, typically supported by a degree in computer science, cybersecurity, or a related field. Familiarity with common penetration testing tools such as Burp Suite, OWASP ZAP, Kali Linux, as well as certifications like OSCP or CEH, is highly beneficial. Critical thinking, keen attention to detail, and clear written and verbal communication are essential soft skills for effective reporting and collaboration. These competencies ensure thorough security assessments, actionable findings, and effective teamwork to protect digital assets.
What cities are hiring for Application Penetration Tester jobs?
Cities with the most Application Penetration Tester job openings:
What are the most commonly searched types of Application Penetration Tester jobs?
The most popular types of Application Penetration Tester jobs are:
What states have the most Application Penetration Tester jobs?
States with the most job openings for Application Penetration Tester jobs include:
What job categories do people searching Application Penetration Tester jobs look for?
The top searched job categories for Application Penetration Tester jobs are:
- International Penetration Tester
- Freelance Web App Penetration Testing
- Remote Network Penetration Testing
- Part Time Oscp
- Physical Penetration Testing
- Penetration Tester Ethical Hacker
- Overnight International Penetration Tester
- Ethical Penetration Testing
- Full Time Cybersecurity Penetration Tester
- Freelance Penetration Tester Ethical Hacker
What are popular job titles related to Application Penetration Tester jobs?
For Application Penetration Tester jobs, the most frequently searched job titles are:

Full-time
Re-posted 6 days ago
Job description
KPMG is currently seeking a Senior Specialist, MAST Application Penetration Tester to join our Managed Services practice. The role involves conducting manual application penetration testing and executing threat modeling while ensuring high professional standards in a collaborative environment.
Responsibilities:
• Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications
• Perform objective based on abstract penetration testing engagements
• Execute threat modeling, evaluate application business logic, and perform application architecture reviews
• Demonstrate application testing experience in real time via demos to both internal and external audiences
• Function independently in penetration testing engagements, with minimal oversight and guidance
• Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
Qualifications:
Required:
• Minimum three years of recent experience in application penetration testing of Application Programming Interface (API's), web applications, or mobile applications
• Bachelor's degree from an accredited college/university or equivalent industry experience
• Ability to communicate reporting results with technical and non-technical audiences and lead remediation conversations
• Experience with burp suite pro, and other app testing tools such as Netsparker and Checkmarx
• Ability to travel as required
• Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa)
Preferred:
• One or more major ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert (OSWE), Offensive Security Web Assessor (OSWA)
Company:
KPMG is one of the world’s leading professional services firms and the fastest growing Big Four accounting firm in the United States. Founded in 2010, the company is headquartered in New York, USA, with a team of 10001+ employees. The company is currently Late Stage.