Burp Suite, Kali Linux, BugCrowd, Sonarqube * SecOps & Vulnerability: Tenable, Bitsight, OneTrust * IT & Endpoint Ecosystem: Jira, AWS, Sophos, JAMF, PDQ, BetterCloud * Certifications: CompTIA ...
Quick apply
Burp Suite, Kali Linux, BugCrowd, Sonarqube * SecOps & Vulnerability: Tenable, Bitsight, OneTrust * IT & Endpoint Ecosystem: Jira, AWS, Sophos, JAMF, PDQ, BetterCloud * Certifications: CompTIA ...
Quick apply
Burp Suite, Kali Linux, BugCrowd, Sonarqube * SecOps & Vulnerability: Tenable, Bitsight, OneTrust * IT & Endpoint Ecosystem: Jira, AWS, Sophos, JAMF, PDQ, BetterCloud * Certifications: CompTIA ...
Lehi, UT · On-site +1
Burp Suite, Kali Linux, BugCrowd, Sonarqube * SecOps & Vulnerability: Tenable, Bitsight, OneTrust * IT & Endpoint Ecosystem: Jira, AWS, Sophos, JAMF, PDQ, BetterCloud * Certifications: CompTIA ...
Lehi, UT · On-site +1
Burp Suite, Kali Linux, BugCrowd, Sonarqube * SecOps & Vulnerability: Tenable, Bitsight, OneTrust * IT & Endpoint Ecosystem: Jira, AWS, Sophos, JAMF, PDQ, BetterCloud * Certifications: CompTIA ...
Hands-on experience with tools such as Kali Linux, Metasploit, Burp Suite Pro, Cobalt Strike, Nmap, Nessus, BloodHound, Impacket, and other offensive security platforms used for enumeration ...
Hands-on experience with tools such as Kali Linux, Metasploit, Burp Suite Pro, Cobalt Strike, Nmap, Nessus, BloodHound, Impacket, and other offensive security platforms used for enumeration ...
$61.50 - $82/hr
Experience with any of the following commercial application scanning tools such as Acunetix, IBM's AppScan, Client's WebInspect, NTOSpider, Cenzic's Hailstorm, Burp Suite Professional Understanding ...
$61.50 - $82/hr
Experience with any of the following commercial application scanning tools such as Acunetix, IBM's AppScan, Client's WebInspect, NTOSpider, Cenzic's Hailstorm, Burp Suite Professional Understanding ...
Hands-on experience with tools such as Kali Linux, Metasploit, Burp Suite Pro, Cobalt Strike, Nmap, Nessus, BloodHound, Impacket, and other offensive security platforms used for enumeration ...
New
Hands-on experience with tools such as Kali Linux, Metasploit, Burp Suite Pro, Cobalt Strike, Nmap, Nessus, BloodHound, Impacket, and other offensive security platforms used for enumeration ...
New
Perform API security testing, traffic interception, and replay analysis using tools such as Burp Suite or Fiddler * Validate secure communication protocols, including TLS 1.2/1.3 and certificate ...
Perform API security testing, traffic interception, and replay analysis using tools such as Burp Suite or Fiddler * Validate secure communication protocols, including TLS 1.2/1.3 and certificate ...
Annapolis Junction, MD · On-site
$170K - $180K/yr
Burp Suite, Web Inspect, Appdetective. * Must have experience with or strong familiarity of Kali. * Must have experience with or strong familiarity of IPS/IDS solutions. * Must have a strong ...
Annapolis Junction, MD · On-site
$170K - $180K/yr
Burp Suite, Web Inspect, Appdetective. * Must have experience with or strong familiarity of Kali. * Must have experience with or strong familiarity of IPS/IDS solutions. * Must have a strong ...
Columbia, MD · On-site
$204K - $247K/yr
Experience with Burp Suite, browser developer tools, or Wireshark to monitor network communications * Service containerization and deployment with Docker/Kubernetes * Familiarity with Git/Gitlab
Columbia, MD · On-site
$204K - $247K/yr
Experience with Burp Suite, browser developer tools, or Wireshark to monitor network communications * Service containerization and deployment with Docker/Kubernetes * Familiarity with Git/Gitlab
Required : • Minimum 6 years of experience in web application security testing. • Minimum 4 years of hands-on experience with Burp Suite and OWASP ZAP. • Ability to manually identify ...
Required : • Minimum 6 years of experience in web application security testing. • Minimum 4 years of hands-on experience with Burp Suite and OWASP ZAP. • Ability to manually identify ...
$107K - $140K/yr
Use tools including Tenable Nessus, Burp Suite, and CrowdStrike to identify vulnerabilities, investigate threats, and recommend remediation. * Test web applications to identify potential exploits ...
$107K - $140K/yr
Use tools including Tenable Nessus, Burp Suite, and CrowdStrike to identify vulnerabilities, investigate threats, and recommend remediation. * Test web applications to identify potential exploits ...
Reston, VA · On-site
$150K - $185K/yr
Hands-on experience with tools such as Kali Linux, Metasploit, Burp Suite Pro, Cobalt Strike, Nmap, Nessus, BloodHound, Impacket, and other offensive security platforms used for enumeration ...
Reston, VA · On-site
$150K - $185K/yr
Hands-on experience with tools such as Kali Linux, Metasploit, Burp Suite Pro, Cobalt Strike, Nmap, Nessus, BloodHound, Impacket, and other offensive security platforms used for enumeration ...
Familiarity with penetration testing toolsets (Burp Suite, NessQualys, Kali Linux, Metasploit, Cobalt Strike) at a level sufficient to interpret vendor outputs. * Bachelor's degree in Computer ...
Familiarity with penetration testing toolsets (Burp Suite, NessQualys, Kali Linux, Metasploit, Cobalt Strike) at a level sufficient to interpret vendor outputs. * Bachelor's degree in Computer ...
$60.25 - $80.25/hr
... OWASP ZAP, Burp Suite, commercial scanners). • Knowledge of common web application vulnerabilities (e.g., OWASP Top 10). • Proficiency in one or more programming languages. • Relevant ...
$60.25 - $80.25/hr
... OWASP ZAP, Burp Suite, commercial scanners). • Knowledge of common web application vulnerabilities (e.g., OWASP Top 10). • Proficiency in one or more programming languages. • Relevant ...
Deploy and manage security testing tools for SAST, DAST, and SCA analysis (e.g., Semgrep, Trivy, Burp Suite). * Threat Modeling: Review technical designs for new features, performing threat models to ...
Deploy and manage security testing tools for SAST, DAST, and SCA analysis (e.g., Semgrep, Trivy, Burp Suite). * Threat Modeling: Review technical designs for new features, performing threat models to ...
Cherry Hills Village, CO · On-site
$58.50 - $78/hr
... Burp Suite Professional • Understanding of Web Services technologies such as XML, SOAP, and AJAX • Understanding of various web application frameworks such as ASP.NET, J2EE, Zend • Web Server ...
Cherry Hills Village, CO · On-site
$58.50 - $78/hr
... Burp Suite Professional • Understanding of Web Services technologies such as XML, SOAP, and AJAX • Understanding of various web application frameworks such as ASP.NET, J2EE, Zend • Web Server ...
$90K - $150K/yr
Minimum three (3) years of experience with testing tools, including NESSUS, METASPLOIT, CANVAS, NMAP, Burp Suite, and Kismet * Minimum three (3) years of experience with network vulnerability ...
$90K - $150K/yr
Minimum three (3) years of experience with testing tools, including NESSUS, METASPLOIT, CANVAS, NMAP, Burp Suite, and Kismet * Minimum three (3) years of experience with network vulnerability ...
Deploy and manage security testing tools for SAST, DAST, and SCA analysis (e.g., Semgrep, Trivy, Burp Suite). * Threat Modeling: Review technical designs for new features, performing threat models to ...
Deploy and manage security testing tools for SAST, DAST, and SCA analysis (e.g., Semgrep, Trivy, Burp Suite). * Threat Modeling: Review technical designs for new features, performing threat models to ...
Deploy and manage security testing tools for SAST, DAST, and SCA analysis (e.g., Semgrep, Trivy, Burp Suite). * Threat Modeling: Review technical designs for new features, performing threat models to ...
Deploy and manage security testing tools for SAST, DAST, and SCA analysis (e.g., Semgrep, Trivy, Burp Suite). * Threat Modeling: Review technical designs for new features, performing threat models to ...
... Burp Suite, Netsparker, etc.). Regards Rajeev Gaddam West Advanced Technologies, Inc E: rajeev.g@wati.com D: 916 318 7021 Serving government agencies for 22 Years www.wati.com
Quick apply
... Burp Suite, Netsparker, etc.). Regards Rajeev Gaddam West Advanced Technologies, Inc E: rajeev.g@wati.com D: 916 318 7021 Serving government agencies for 22 Years www.wati.com
Deploy and manage security testing tools for SAST, DAST, and SCA analysis (e.g., Semgrep, Trivy, Burp Suite). * Threat Modeling: Review technical designs for new features, performing threat models to ...
Deploy and manage security testing tools for SAST, DAST, and SCA analysis (e.g., Semgrep, Trivy, Burp Suite). * Threat Modeling: Review technical designs for new features, performing threat models to ...
$96.5K - $102.2K
4% of jobs
$102.2K - $108K
8% of jobs
$108K - $113.7K
4% of jobs
$113.7K - $119.4K
2% of jobs
$121.8K is the 25th percentile. Wages below this are outliers.
$119.4K - $125.1K
16% of jobs
$125.1K - $130.9K
15% of jobs
The median wage is $131.2K / yr.
$130.9K - $136.6K
11% of jobs
$136.6K - $142.3K
10% of jobs
$145.3K is the 75th percentile. Wages above this are outliers.
$142.3K - $148K
10% of jobs
$148K - $153.8K
11% of jobs
$153.8K - $159.5K
10% of jobs
$96.5K
$132.3K
$159.5K
To thrive as a Burp Suite specialist or penetration tester, you need a solid understanding of web application security, programming, and vulnerability assessment techniques, often supported by a degree in information security or a related field. Familiarity with the Burp Suite platform, as well as knowledge of other tools like OWASP ZAP and industry certifications such as OSCP or CEH, is highly valued. Strong analytical thinking, attention to detail, and effective communication skills help professionals excel in this role. These skills are essential for accurately identifying security flaws, clearly reporting findings to technical and non-technical stakeholders, and helping organizations protect their web applications.
A Burp Suite job typically involves using Burp Suite, a popular web security testing tool, to identify vulnerabilities in web applications. Professionals in this role, such as penetration testers or security analysts, use Burp Suite to perform tasks like intercepting and modifying web traffic, scanning for common security issues, and testing for vulnerabilities like SQL injection and XSS. These roles require knowledge of web security principles, HTTP protocols, and penetration testing methodologies.
Professionals working in Burp Suite-focused roles are typically responsible for conducting web application security assessments, identifying vulnerabilities such as SQL injection and cross-site scripting, and creating detailed reports of their findings. They may also collaborate closely with development and security teams to recommend remediations and validate fixes. The role often involves staying up-to-date with the latest security threats and Burp Suite features, participating in internal security reviews, and sometimes training or mentoring others in secure coding practices. This position offers a dynamic and challenging environment, making it ideal for those who enjoy continuous learning and direct impact on improving system security.
Cities with the most Burp Suite job openings:
The most popular types of Burp Suite jobs are:
States with the most job openings for Burp Suite jobs include:
The top searched job categories for Burp Suite jobs are:

As a Security Engineer, you will play a critical role in safeguarding our organization's digital assets, infrastructure, and application ecosystem. This is a mid-level, autonomous role (not entry-level) where you will bridge the gap between IT operations, software development, and risk management.
You won't just be reviewing logs, settings, and configs; you will be actively replicating vulnerabilities, collaborating with developers on secure architecture, managing our bug bounty program, and keeping our security tool stack running smoothly.
Vulnerability & Application Security Management: Own the vulnerability management program end-to-end: oversee continuous vulnerability scanning (Tenable) and software composition analysis/code dependencies (Sonarqube), drive remediation across teams, and replicate and validate discovered vulnerabilities using tools like Burp Suite and Kali Linux.
Crowdsourced Security & Threat Intel: Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight).
Secure Development Collaboration: Act as the security voice in developer architecture meetings. Partner with engineering teams to review code dependencies, threat-model new features, and ensure secure coding practices.
Risk & Change Management: Own and conduct system impact analyses for proposed changes, represent security on the Change Control Board (CCB), and lead threat modeling sessions for new systems, features, and infrastructure changes.
Incident Management & Operations: Triage and document security incidents within OneTrust and Jira. Collaborate with DevOps to ensure security tools are properly deployed across AWS environments and endpoint configurations.
Endpoint & Tool Oversight: Maintain a "read-only/audit" oversight of our endpoint detection, MDM, and email security tools (Sophos, JAMF, BetterCloud) to ensure compliance and active alerting.
Security Awareness & Culture: Administer the security awareness learning modules (RF Academy) and lead internal initiatives to keep security top-of-mind for all employees.
Citizenship: All candidates must be a US citizen.
Experience: 3–5 years of dedicated experience in a technical cybersecurity role (e.g., Security Engineer, AppSec Engineer, or Senior Security Analyst, etc.).
Application Security: Strong familiarity with the OWASP Top 10, web application security testing, and reviewing secure code dependencies (SCA).
Vulnerability Assessment: Proven experience running enterprise vulnerability scanners, interpreting results, and driving remediation across cross-functional teams.
Cloud & Infrastructure: Foundational knowledge of cloud environments (specifically AWS) and securing cloud-native applications.
Communication: Excellent collaboration skills. You must be able to sit down with software developers, understand their sprint goals, and help them fix security bugs without breaking their workflow.
Direct experience with our specific stack is a massive plus:
AppSec/PenTesting: Burp Suite, Kali Linux, BugCrowd, Sonarqube
SecOps & Vulnerability: Tenable, Bitsight, OneTrust
IT & Endpoint Ecosystem: Jira, AWS, Sophos, JAMF, PDQ, BetterCloud
Certifications: CompTIA Security+, CEH, GIAC, or progress toward a CISSP, or other relevant certifications
Automation: Basic scripting skills (Python, PowerShell, or Bash) to automate repetitive security tasks or log analysis.
Security Frameworks: Experience with maintaining compliance with PCI-DSS, ISO 27001, and SOC 2 frameworks.
Artificial Intelligence: Experience utilizing AI to improve productivity and efficiency, as well as experience reviewing AI tools, integrations, and features.
Proactive Remediation: Decreased time-to-remediation for vulnerabilities identified by Tenable and BugCrowd.
Seamless Dev Integration: Active, constructive participation in developer sprint/architecture cycles, resulting in fewer security defects reaching production.
Incident Readiness: Efficient tracking, documentation, and resolution of incidents within OneTrust
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Sourced by ZipRecruiter
Software development
11 - 50 Employees
Lehi, UT, US
2013