1

Burp Suite Practitioner Jobs (NOW HIRING)

Application Security Engineer

Rockville, MD ยท On-site

$60 - $80/hr

GWAPT OSWE Burp Suite Certified Practitioner CISSP CSSLP Experience supporting enterprise DevSecOps transformation initiatives. Technical Environment Application Security: SAST, DAST, IAST, Secure ...

New

DataRobot empowers practitioners to deliver predictive and generative AI, and enables leaders to ... Hands-on experience with common security tools such as Semgrep, Trivy, and Burp Suite. * Strategic ...

DataRobot empowers practitioners to deliver predictive and generative AI, and enables leaders to ... Hands-on experience with common security tools such as Semgrep, Trivy, and Burp Suite. * Strategic ...

Certifications such as GWAPT, OSWE, or Burp Suite Certified Practitioner are beneficial. Education Requirements: Bachelor's degree in computer science, computer engineering, or a related field.

DataRobot empowers practitioners to deliver predictive and generative AI, and enables leaders to ... Hands-on experience with common security tools such as Semgrep, Trivy, and Burp Suite. * Strategic ...

Proficiency in penetration testing tools such as Metasploit, Burp Suite, Nmap, and custom scripting ... A minimum of 2 years as a security testing practitioner / cyber practitioner in which you have ...

Much of the work involves using Linux-based environments and tools such as Burp Suite, Metasploit ... Highly motivated senior cybersecurity practitioners who bring deep hands-on experience in ...

Posted today

... cybersecurity practitioners. We're committed to helping solve our common security problems ... Burp Suite Professional (essential - Repeater, Intruder, Scanner, Extensions, and advanced ...

This role represents the transition from emerging practitioner to confident, self-sufficient ... Nmap, Metasploit, Burp Suite, Nessus/OpenVAS, BloodHound, or equivalents. * Solid understanding of ...

This role represents the transition from emerging practitioner to confident, self-sufficient ... Nmap, Metasploit, Burp Suite, Nessus/OpenVAS, BloodHound, or equivalents. * Solid understanding of ...

This role represents the transition from emerging practitioner to confident, self-sufficient ... Nmap, Metasploit, Burp Suite, Nessus/OpenVAS, BloodHound, or equivalents. * Solid understanding of ...

next page

Showing results 1-20

Burp Suite Practitioner information

See salary details

$41.5K

$130.3K

$200K

How much do burp suite practitioner jobs pay per year?

As of Aug 5, 2026, the average yearly pay for burp suite practitioner in the United States is $130,295.00, according to ZipRecruiter salary data. Most workers in this role earn between $108,000.00 and $150,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Burp Suite Practitioner?

To thrive as a Burp Suite Practitioner, you need a solid understanding of web application security, penetration testing methodologies, and common vulnerabilities, often supported by a background in cybersecurity or computer science. Familiarity with Burp Suite's suite of tools, web protocols, and relevant certifications like OSCP or Burp Suite Certified Practitioner is typically required. Strong analytical thinking, attention to detail, and effective communication skills help practitioners identify vulnerabilities and clearly report findings. These skills are crucial to accurately assessing web application security and providing actionable recommendations to reduce organizational risk.

What is a Burp Suite Practitioner?

A Burp Suite Practitioner is a cybersecurity professional proficient in using Burp Suite, a popular tool for web application security testing. They use Burp Suite to identify vulnerabilities such as SQL injection, cross-site scripting (XSS), and other security flaws in websites and web applications. These practitioners often perform penetration testing, automate security scans, and analyze application traffic to help organizations improve their security posture. Their expertise is essential for finding and addressing weaknesses before malicious actors can exploit them.

What are some common challenges faced by Burp Suite Practitioners during web application penetration testing?

Burp Suite Practitioners often encounter challenges related to complex authentication mechanisms, encrypted traffic, and dynamic web applications that change content or structure with each visit. Navigating these obstacles requires a strong understanding of session management, the ability to configure Burp Suite's tools (like interceptors and decoders), and collaboration with development teams to gain necessary access or bypass security controls ethically. Practitioners may also face time constraints during assessments, making efficient workflow and prioritization of vulnerabilities essential for successful testing.
More about Burp Suite Practitioner jobs
What cities are hiring for Burp Suite Practitioner jobs? Cities with the most Burp Suite Practitioner job openings:
What states have the most Burp Suite Practitioner jobs? States with the most job openings for Burp Suite Practitioner jobs include:
What job categories do people searching Burp Suite Practitioner jobs look for? The top searched job categories for Burp Suite Practitioner jobs are:
Infographic showing various Burp Suite Practitioner job openings in the United States as of July 2026, with employment types broken down into 80% Full Time, and 20% Contract. Highlights an 60% In-person, 20% Hybrid, and 20% Remote job distribution, with an average salary of $130,295 per year, or $62.6 per hour.

Application Security Engineer

SDH Systems

Rockville, MD โ€ข On-site

$60 - $80/hr

Other

Posted yesterday

New


Job description

Title: Application Security Engineer

Location: Rockville, MD or McLean, VA (Hybrid โ€“ 3 days onsite with 2 days remote)

Duration: 6 Months with possible extension

Interview process:  Onsite panel

Job Summary:

The Senior Application Security Engineer is responsible for designing, implementing, and advancing application security practices across the Software Development Life Cycle (SDLC). This role partners closely with engineering, DevOps, and security teams to identify vulnerabilities, support remediation efforts, evaluate security tooling, and strengthen secure development practices.

The ideal candidate brings strong hands-on application security expertise, experience integrating security into CI/CD pipelines, and the ability to leverage modern automation and GenAI technologies to scale secure code review and vulnerability analysis capabilities.

Key Responsibilities

Perform application security assessments, manual penetration testing, and vulnerability validation using tools such as Burp Suite and other proxy/security testing tools.

Analyze and triage findings from SAST, DAST, IAST, IaC, and secrets detection tools to identify, prioritize, and support remediation of security vulnerabilities.

Partner with engineering teams to integrate security controls and testing into CI/CD pipelines in support of DevSecOps initiatives.

Conduct secure code reviews and leverage GenAI-enabled security tooling to improve scalability and efficiency of application security analysis.

Evaluate, recommend, and implement application security tools and technologies, including emerging capabilities related to automated code analysis and cloud security.

Perform AWS configuration and cloud security reviews to ensure adherence to security best practices and compliance standards.

Develop and maintain documentation related to security findings, remediation activities, risk assessments, and compliance requirements.

Contribute to the development, interpretation, and enforcement of application security policies, standards, and procedures.

Support enterprise security compliance initiatives and participate in audit and risk management activities.

Deliver security awareness training and educate developers and QA engineers on common application security risks, secure coding practices, and remediation techniques.

Stay current on emerging threats, vulnerabilities, attack techniques, and security technologies to continuously improve the organization''s security posture.

 

Required Qualifications

Bachelor''s degree in Computer Science, Computer Engineering, Cybersecurity, or a related technical field.

5+ years of experience in cybersecurity with a strong focus on application security.

Hands-on experience with SAST, DAST, IAST, and related application security testing methodologies and tools.

Strong understanding of OWASP Top 10 vulnerabilities, secure coding principles, and remediation strategies.

Experience performing manual penetration testing and application vulnerability assessments.

Proficiency in one or more programming or scripting languages such as Java, Python, or JavaScript.

Experience integrating security tooling into CI/CD pipelines using platforms such as Jenkins and GitLab.

Strong knowledge of security engineering concepts including authentication, authorization, cryptography, network security, and secure application architecture.

Experience with AWS cloud security concepts, services, and configuration reviews.

Excellent communication skills with the ability to collaborate effectively across engineering and security teams.

 

Preferred Qualifications

Background in software engineering or application development.

Familiarity with GenAI-assisted security tooling and automated code analysis solutions.

Experience with Infrastructure as Code (IaC) security scanning and secrets management tools.

Experience conducting infrastructure or application-level vulnerability testing and security auditing.

 

Industry certifications such as:

GWAPT

OSWE

Burp Suite Certified Practitioner

CISSP

CSSLP

Experience supporting enterprise DevSecOps transformation initiatives.

Technical Environment

Application Security: SAST, DAST, IAST, Secure Code Review

Cloud Platforms: AWS

CI/CD Tools: Jenkins, GitLab

Security Testing Tools: Burp Suite and related proxy/testing tools

Programming Languages: Java, Python, JavaScript

DevSecOps & Automation: Security pipeline integration, GenAI-assisted analysis