1

Associate Penetration Tester Jobs in California (NOW HIRING)

Senior Associate - Cyber Security

Los Angeles, CA · On-site

$107K - $139K/yr

Vulnerability and Penetration Testing Standards such as OWASP top 10, DoD or NSA * Some scripting knowledge Windows, Unix, Bash, Python, Perl or Ruby * Security policies, tools and technology ...

Vulnerability and Penetration Testing Standards such as OWASP top 10, DoD or NSA * Some scripting knowledge Windows, Unix, Bash, Python, Perl or Ruby * Security policies, tools and technology ...

Lead vendor and Business Associate security diligence, including security questionnaires, SOC 2 ... Experience working with fractional or external security resources, penetration testers, and ...

... penetration testing. * Familiarity with SSDLC and DevSecOps practices. * Knowledge of Azure ... Relevant certifications such as Azure Security Engineer Associate, CISSP, CEH, or CCSP are a plus.

Welder

Fremont, CA · On-site

$35 - $44/hr

... testing standards, including work in hard-to-reach locations. * Metallurgy & Parameter Setup ... Associate's Degree or formal certification from an accredited welding training program. * 3 to 5 ...

next page

Showing results 1-20

Associate Penetration Tester information

See California salary details

$22.2K

$118.3K

$166.3K

How much do associate penetration tester jobs pay per year?

As of Sep 1, 2026, the average yearly pay for associate penetration tester in California is $118,325.00, according to ZipRecruiter salary data. Most workers in this role earn between $94,700.00 and $139,200.00 per year, depending on experience, location, and employer.

What is an associate penetration tester?

An Associate Penetration Tester is an entry-level cybersecurity professional who helps identify security vulnerabilities in networks, applications, and systems. They conduct ethical hacking tests, analyze findings, and provide recommendations to strengthen security. Typically, they work under the guidance of senior penetration testers and use various tools and techniques to simulate cyberattacks. This role requires knowledge of networking, security fundamentals, and scripting or programming skills. It is a great starting point for a career in ethical hacking and cybersecurity.

What does an associate penetration tester do?

As an Associate Penetration Tester, your daily tasks often include researching and identifying potential security vulnerabilities, conducting controlled penetration tests on networks and applications, and documenting your findings. You will frequently collaborate with senior testers, IT teams, and clients to review results, provide feedback, and help develop remediation strategies. This role typically involves a mix of independent analysis and teamwork, offering hands-on learning opportunities and exposure to real-world cyber threats. Over time, you’ll gain valuable experience and can progress to more advanced security testing or specialized cybersecurity roles.

What skills and qualifications are needed to be an associate penetration tester?

To thrive as an Associate Penetration Tester, you need foundational knowledge in cybersecurity, network protocols, and vulnerability assessment, typically supported by a degree in computer science or a related field. Familiarity with tools like Metasploit, Nmap, Burp Suite, and industry certifications such as CEH or OSCP is advantageous. Strong analytical thinking, attention to detail, teamwork, and clear written and verbal communication skills are also important. These skills and qualities ensure that you can effectively identify and communicate security weaknesses while working with diverse technical teams.

What are the most commonly searched types of Penetration Tester jobs in California?

The most popular types of Penetration Tester jobs in California are:

What are popular job titles related to Associate Penetration Tester jobs in California?

For Associate Penetration Tester jobs in California, the most frequently searched job titles are:

What job categories do people searching Associate Penetration Tester jobs in California look for?

The top searched job categories for Associate Penetration Tester jobs in California are:

What cities in California are hiring for Associate Penetration Tester jobs?

Cities in California with the most Associate Penetration Tester job openings:

Infographic showing various Associate Penetration Tester job openings in California as of August 2026, with employment types broken down into 1% As Needed, 71% Full Time, 26% Part Time, 1% Temporary, and 1% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution, with an average salary of $118,325 per year, or $56.9 per hour.

Senior Associate - Cyber Security

CNM LLP

Los Angeles, CA • On-site

$107K - $139K/yr

Full-time

Re-posted 3 days ago


Job description

Company Description
CNM LLP is a specialized boutique consulting firm looking for a Cyber Security Senior Consultant. We represent Fortune 500 and newly public high growth entities in rapidly changing environments in the Los Angeles and Orange County markets. You will work with the largest entertainment and public companies to review information system and network security which requires a thorough understanding of information security frameworks, ERP and cloud-based applications, and information system auditing and vulnerability assessment techniques. As a result, you will have the opportunity to grow your career in a collaborative environment that is a playground for highly skilled, self-motivated professionals. You will partner with advisory services project teams to assess and improve our client's IT environments, procedures, and controls related to their regulatory compliance and strategic objectives.
Job Description
If you're interested, here is the challenge for your first year with CNM LLP.
  • Demonstrates a thorough understanding of:
    • IT security risk assessment frameworks, including implementation experience
    • IT Security industry and regulatory requirements including participating in audits, or remediation activities for requirements such as PCI-DSS, Sarbanes-Oxley Act (SOX), Health Insurance Portability and Accountability Act (HIPAA) and Meaningful Use, SSAE-16 SOC 2 etc.
    • IT governance and security related frameworks, such as COBIT, NIST 800-53, ISO27000 and current cyber security trends
    • Conducting IT security technical and functional assessments, including drafting observations and recommendations, and assisting with remediation activities
    • Performing wireless, internal and external network, and web application vulnerability and penetration testing and the ability to document technical observations and recommendations
    • Vulnerability and Penetration Testing Standards such as OWASP top 10, DoD or NSA
    • Some scripting knowledge Windows, Unix, Bash, Python, Perl or Ruby
    • Security policies, tools and technology including Identity and Access Management, Data Loss Prevention (DLP), SIEM solutions, Firewall, Web Proxy, Anti-Virus, and Application Whitelisting solutions
  • Conduct technical security vulnerability and penetrations testing assessments on our client's web applications, wireless, internal and external networks and providing actionable and risk prioritized observations and recommendations
  • Complete the assigned IT security and application controls on 1-3 project teams, within the given budget with minimal supervision by:
  • Creating system narratives, identifying key controls, and concluding on design and operating effectiveness of key controls.
  • Demonstrating clear and concise writing, and verbal skills to communicate complex issues in simple terms to clients and team members.
  • Producing quality deliverables evidenced through minimal review time and review notes.
  • Actively improving technical and project management skills through on the job feedback, performance evaluations, mentoring and firm-sponsored formal training programs including monthly CPE and Subject Matter Expert (SME) training.
  • Responding to client needs and balancing the competing priorities with minimal client disruptions, while maintaining project progress.

Upon successfully demonstrating the skill set listed above you will have the opportunity to earn a promotion to Manager. As a Manager you will be responsible for:
  • Building internal teams through participation in our mentoring program and interviewing.
  • Managing one to several individual project teams, project scheduling, reviewing of workpapers, and being the primary point of contact between the CNM team and the client.

Qualifications
Qualifications:
  • Bachelor's degree is required in a related field; information systems or computer science preferred
  • Minimum 3+ years of relevant work experience in incident response, vulnerability assessments, penetration testing, ethical hacking, security architecture design, including supervisory experience, is required;
  • 2+ years of hands-on application and web application security experience
  • Certification(s) Preferred: CPTC, CPTE, GPEN, CEH, CISSP, CISM or CISA
  • Must have a willingness to learn and support IT internal audit, SSAE16 - SOC 1 Type II and Sarbanes-Oxley projects
  • Strong experience in performing application penetration testing, as well as using techniques and tools such as Cenzic, Wireshark, Kali Linuz, NMAP, Burp Suite, etc.
  • Must be able to articulate complex and technical information to a technical and non-technical audience
  • Ability to understand IT risks and implications to the business, identify weaknesses and recommend solutions
  • Self-directed, with the ability to thrive in a fast-paced and collaborative environment
  • Flexible, team player and deadline oriented
  • Flexibility to travel to clients within the greater Los Angeles Area

Are you ready for the challenge? If so please apply here.
You may also visit our company website www.cnmllp.com/careers.
Location: Our office is in located in Woodland Hills, but the location of our work is based on client locations primarily throughout the greater Los Angeles area.
CNM LLP is an Equal Opportunity Employer
Additional Information
All your information will be kept confidential according to EEO guidelines.