Key Responsibilities • Conduct external network and web application penetration testing and vulnerability assessments per NIST SP 800-115 methodology. • Attempt to obtain ePHI, PII, financial ...
Key Responsibilities • Conduct external network and web application penetration testing and vulnerability assessments per NIST SP 800-115 methodology. • Attempt to obtain ePHI, PII, financial ...
Lead Penetration Tester
Washington, DC · On-site
$110 - $150K/hr
Lead Penetration Tester Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (project ... Web application security assessments (approximately 3-4 applications per year) * Test plan and ...
Quick apply
Lead Penetration Tester
Washington, DC · On-site
$110 - $150K/hr
Lead Penetration Tester Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (project ... Web application security assessments (approximately 3-4 applications per year) * Test plan and ...
GIAC Web Application Penetration Tester (GWAPT) * GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) * GIAC Assessing and Auditing Wireless Networks (GAWN) Blue Teaming Certifications:
GIAC Web Application Penetration Tester (GWAPT) * GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) * GIAC Assessing and Auditing Wireless Networks (GAWN) Blue Teaming Certifications:
Lead Penetration Tester
Kansas City, MO · On-site
$110 - $150K/hr
Lead Penetration Tester Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (project ... Web application security assessments (approximately 3-4 applications per year) * Test plan and ...
Quick apply
Lead Penetration Tester
Kansas City, MO · On-site
$110 - $150K/hr
Lead Penetration Tester Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (project ... Web application security assessments (approximately 3-4 applications per year) * Test plan and ...
Lead Penetration Tester
Fort Collins, CO · On-site
$110 - $150K/hr
Lead Penetration Tester Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (project ... Web application security assessments (approximately 3-4 applications per year) * Test plan and ...
Quick apply
Lead Penetration Tester
Fort Collins, CO · On-site
$110 - $150K/hr
Lead Penetration Tester Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (project ... Web application security assessments (approximately 3-4 applications per year) * Test plan and ...
Experience with offensive toolkits used for network and application penetration testing * Strong communication skills, both verbal and written * Knowledge of z/OS fundamentals including, but not ...
Quick apply
Experience with offensive toolkits used for network and application penetration testing * Strong communication skills, both verbal and written * Knowledge of z/OS fundamentals including, but not ...
Senior Penetration Tester
Washington, DC · On-site
$145K - $180K/yr
Assess and test the security of internal networks and underlying application infrastructure. * Conduct penetration testing and vulnerability assessments on Azure cloud infrastructure and applications
Quick apply
Senior Penetration Tester
Washington, DC · On-site
$145K - $180K/yr
Assess and test the security of internal networks and underlying application infrastructure. * Conduct penetration testing and vulnerability assessments on Azure cloud infrastructure and applications
Penetration Testers - Senior (Lead)
Washington, DC · On-site
$139K - $169K/yr
GIAC Web Application Penetration Tester (GWAPT) * GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) * Certified Penetration Testing Engineer (CPTE) * Certified Red Team Professional ...
Penetration Testers - Senior (Lead)
Washington, DC · On-site
$139K - $169K/yr
GIAC Web Application Penetration Tester (GWAPT) * GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) * Certified Penetration Testing Engineer (CPTE) * Certified Red Team Professional ...
Experience with offensive toolkits used for network and application penetration testing * Strong communication skills, both verbal and written * Knowledge of z/OS fundamentals including, but not ...
Experience with offensive toolkits used for network and application penetration testing * Strong communication skills, both verbal and written * Knowledge of z/OS fundamentals including, but not ...
GIAC Web Application Penetration Tester (GWAPT) * GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) * Certified Penetration Testing Engineer (CPTE) * Certified Red Team Professional ...
GIAC Web Application Penetration Tester (GWAPT) * GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) * Certified Penetration Testing Engineer (CPTE) * Certified Red Team Professional ...
Penetration Testers - Senior (Lead)
Washington, DC · On-site
$150 - $190/hr
The Senior Lead Penetration Tester will serve as the primary technical lead for all penetration ... Conduct web application penetration testing in accordance with industry frameworks and standards ...
Penetration Testers - Senior (Lead)
Washington, DC · On-site
$150 - $190/hr
The Senior Lead Penetration Tester will serve as the primary technical lead for all penetration ... Conduct web application penetration testing in accordance with industry frameworks and standards ...
GIAC Web Application Penetration Tester (GWAPT) * GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) * Certified Penetration Testing Engineer (CPTE) * Certified Red Team Professional ...
GIAC Web Application Penetration Tester (GWAPT) * GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) * Certified Penetration Testing Engineer (CPTE) * Certified Red Team Professional ...
Penetration Tester
Reston, VA · On-site
Knowledge of mobile application penetration testing * Experience with cloud security assessments (e.g., AWS, Azure) * Expertise in reverse engineering and malware analysis * Understanding of advanced ...
Penetration Tester
Reston, VA · On-site
Knowledge of mobile application penetration testing * Experience with cloud security assessments (e.g., AWS, Azure) * Expertise in reverse engineering and malware analysis * Understanding of advanced ...
Penetration Tester
Chantilly, VA · On-site
Knowledge of mobile application penetration testing * Experience with cloud security assessments (e.g., AWS, Azure) * Expertise in reverse engineering and malware analysis * Understanding of advanced ...
Penetration Tester
Chantilly, VA · On-site
Knowledge of mobile application penetration testing * Experience with cloud security assessments (e.g., AWS, Azure) * Expertise in reverse engineering and malware analysis * Understanding of advanced ...
Penetration Tester
Tysons, VA · On-site
Knowledge of mobile application penetration testing * Experience with cloud security assessments (e.g., AWS, Azure) * Expertise in reverse engineering and malware analysis * Understanding of advanced ...
Penetration Tester
Tysons, VA · On-site
Knowledge of mobile application penetration testing * Experience with cloud security assessments (e.g., AWS, Azure) * Expertise in reverse engineering and malware analysis * Understanding of advanced ...
Penetration Tester II
Chandler, AZ · On-site
$60K - $180K/yr
Experience with Mobile Device Application penetration testing. * Experience with Federal and Commercial Cloud technology penetration testing. * Experience conducting High Value Asset Assessments.
Penetration Tester II
Chandler, AZ · On-site
$60K - $180K/yr
Experience with Mobile Device Application penetration testing. * Experience with Federal and Commercial Cloud technology penetration testing. * Experience conducting High Value Asset Assessments.
Penetration Tester
San Antonio, TX · On-site
Knowledge of mobile application penetration testing * Experience with cloud security assessments (e.g., AWS, Azure) * Expertise in reverse engineering and malware analysis * Understanding of advanced ...
Penetration Tester
San Antonio, TX · On-site
Knowledge of mobile application penetration testing * Experience with cloud security assessments (e.g., AWS, Azure) * Expertise in reverse engineering and malware analysis * Understanding of advanced ...
Penetration Tester
Honolulu, HI · On-site
Knowledge of mobile application penetration testing * Experience with cloud security assessments (e.g., AWS, Azure) * Expertise in reverse engineering and malware analysis * Understanding of advanced ...
Penetration Tester
Honolulu, HI · On-site
Knowledge of mobile application penetration testing * Experience with cloud security assessments (e.g., AWS, Azure) * Expertise in reverse engineering and malware analysis * Understanding of advanced ...
Penetration Tester
Aurora, CO · On-site
Knowledge of mobile application penetration testing * Experience with cloud security assessments (e.g., AWS, Azure) * Expertise in reverse engineering and malware analysis * Understanding of advanced ...
Penetration Tester
Aurora, CO · On-site
Knowledge of mobile application penetration testing * Experience with cloud security assessments (e.g., AWS, Azure) * Expertise in reverse engineering and malware analysis * Understanding of advanced ...
NetSPI ® is an award-winning pioneer of Penetration Testing as a Service (PTaaS) with its AI-powered platform supported by more than 350 in-house cybersecurity experts. Specializing in 50+ pentest ...
Quick apply
NetSPI ® is an award-winning pioneer of Penetration Testing as a Service (PTaaS) with its AI-powered platform supported by more than 350 in-house cybersecurity experts. Specializing in 50+ pentest ...
Application Penetration Tester information
See salary details
$96.5K - $102.2K
4% of jobs
$102.2K - $108K
8% of jobs
$108K - $113.7K
4% of jobs
$113.7K - $119.4K
2% of jobs
$121.8K is the 25th percentile. Wages below this are outliers.
$119.4K - $125.1K
16% of jobs
$125.1K - $130.9K
15% of jobs
The median wage is $131.2K / yr.
$130.9K - $136.6K
11% of jobs
$136.6K - $142.3K
10% of jobs
$145.3K is the 75th percentile. Wages above this are outliers.
$142.3K - $148K
10% of jobs
$148K - $153.8K
11% of jobs
$153.8K - $159.5K
10% of jobs
$96.5K
$132.3K
$159.5K
How much do application penetration tester jobs pay per year?
What does an application penetration tester do?
A typical day for an Application Penetration Tester involves planning and executing tests on web and mobile applications to identify security vulnerabilities, documenting findings, and collaborating with development or security teams to discuss remediation strategies. You might spend time replicating attack scenarios, reviewing code, and researching emerging threats or new testing methodologies. Regular team meetings and client briefings are common, especially when working on larger projects or audits. The work is highly dynamic, often requiring you to juggle multiple projects and stay current with evolving security best practices.
What are the key skills and qualifications needed to thrive as an application penetration tester?
To thrive as an Application Penetration Tester, you need strong knowledge of application security, vulnerability assessment, and web technologies, typically supported by a degree in computer science, cybersecurity, or a related field. Familiarity with common penetration testing tools such as Burp Suite, OWASP ZAP, Kali Linux, as well as certifications like OSCP or CEH, is highly beneficial. Critical thinking, keen attention to detail, and clear written and verbal communication are essential soft skills for effective reporting and collaboration. These competencies ensure thorough security assessments, actionable findings, and effective teamwork to protect digital assets.
What is an application penetration tester?
An Application Penetration Tester is a cybersecurity professional who assesses the security of applications by simulating real-world attacks. They identify vulnerabilities, exploit weaknesses, and provide recommendations to improve security. Their work involves using automated tools and manual testing techniques to uncover risks. They collaborate with developers and security teams to ensure applications are protected against threats. This role requires knowledge of coding, common exploits, and security frameworks.

Contractor
Posted 10 days ago
Job description
Contract
Description
Position Summary
Performs blind and intelligent penetration testing against internet-facing assets - web applications, firewalls, remote access (VPN/RDP), and internet postings - for all 47 County departments, attempting to obtain confidential/sensitive data using real-world threat intelligence-based techniques while evading detection.
Key Responsibilities
• Conduct external network and web application penetration testing and vulnerability assessments per NIST SP 800-115 methodology.
• Attempt to obtain ePHI, PII, financial data, and privileged communications from external sources without causing service disruption.
• Document all findings with risk ratings, evidence, and remediation recommendations for the Assessment report.
• Attempt to avoid detection and evade department response efforts during testing windows, as scoped.
Requirements
Required Qualifications
• 4+ years of hands-on external network / web application penetration testing experience.
• Proficiency with industry-standard tools (Burp Suite, Nmap, Metasploit, or equivalent).
• Strong understanding of OWASP Top 10 and common network attack vectors.
Preferred Qualifications
• OSCP, GPEN, GWAPT, or CEH certification.
• Experience testing government or healthcare-sector environments.
Travel
Fully remote; must remain within the continental United States.
About Xtreme Solutions
Sourced by ZipRecruiter
Industry
It services
Company size
51 - 200 Employees
Headquarters location
Atlanta, GA, US
Year founded
2002