1

City Penetration Testing Jobs (NOW HIRING)

$72 - $119/hr

You will perform hands‑on security testing and peer review activities, validate vulnerabilities ... If performed in New York City, the base pay range is $85,900 - $143,300. If performed in Rochester ...

Offensive Security Engineer

Mclean, VA · On-site

$120 - $160/hr

... VA / Jersey City, NJ / Wilmington, DE Drive the security of critical banking applications and ... Plan, scope, and execute penetration testing engagements across a variety of environments ...

The City of Torrance is recruiting for a Systems Analyst - Cybersecurity to be part of the ... penetration testing, and security audits of enterprise systems, networks, and cloud environments ...

Product Software Engineer

New York, NY · On-site

$180K - $250K/yr

We're building Sybil: an AI-powered penetration testing product that finds vulnerabilities faster ... Hybrid role based in New York City. Compensation: The base salary for this full-time position ...

... and penetration testing support, provide detailed reporting, and assist with the development and execution of incident response readiness assessments to ensure the City is prepared for security ...

Offensive Security Analyst

Alpharetta, GA · On-site

$76.40 - $138.60/hr

A minimum of 4 years of experience in penetration testing, red teaming, purple teaming or offensive ... The base salary range for New York City Metro Area, Washington State and California (excluding ...

Security Engineer City : Wood-lawn, MD Duration: 9 months Required US,GC on W2 : 5+ years in ... penetration testing. 3+ years of experience analyzing malware, advanced persistent threats ...

Showing results 21-40

City Penetration Testing information

See salary details

$22.5K

$119.9K

$168.5K

How much do city penetration testing jobs pay per year?

As of Sep 5, 2026, the average yearly pay for city penetration testing in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What is the difference between City Penetration Testing vs Network Penetration Testing?

AspectCity Penetration TestingNetwork Penetration Testing
FocusAssessing security of city infrastructure, public systems, and urban networksEvaluating security of computer networks and systems
CredentialsCertifications like CEH, OSCP, relevant urban security knowledgeCertifications like CEH, OSCP, network security expertise
Work EnvironmentUrban areas, public infrastructure sites, city government agenciesCorporate offices, data centers, network environments
Industry UsageMunicipalities, urban planning, public safety agenciesIT companies, cybersecurity firms, enterprise networks

City Penetration Testing focuses on evaluating the security of urban infrastructure and city systems, while Network Penetration Testing targets computer networks and digital systems. Both roles require similar certifications but differ in their work environments and industry applications.

Is city penetration testing a good career?

City penetration testing is a specialized cybersecurity role focused on assessing the security of urban infrastructure and systems. It requires technical skills in network security, ethical hacking, and often certifications like CEH or OSCP. The field offers growth opportunities due to increasing digitalization and demand for security professionals in urban environments.
More about City Penetration Testing jobs

What cities are hiring for City Penetration Testing jobs?

Cities with the most City Penetration Testing job openings:

What states have the most City Penetration Testing jobs?

States with the most job openings for City Penetration Testing jobs include:

Infographic showing various City Penetration Testing job openings in the United States as of August 2026, with employment types broken down into 49% Full Time, 48% Part Time, and 3% Contract. Highlights an 98% Physical, 1% Hybrid, and 1% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

Security Assurance Penetration Tester

RXinsider LTD.

On-site

$72 - $119/hr

Other

Posted 14 days ago


Job description

Are you a collaborative Penetration Tester looking to work for a mission driven global organization?

About the role - This role supports the offensive security function within Elsevier's Security Engineering team. You will perform hands‑on security testing and peer review activities, validate vulnerabilities and security controls, and support the automation of security assurance processes. This is a hands‑on role for a motivated security professional eager to grow in a collaborative, fast‑paced environment.

About the team - The Security Assurance team supports the third‑party penetration testing program, security control validation, and ongoing offensive security testing activities.

Responsibilities
  • Tracking and triaging findings from third-party assessments, ensuring timely follow-up and remediation tracking.
  • Collaborating with development, platform, and product teams to communicate findings, track remediation efforts, and improve overall security posture.
  • Facilitating post-assessment reviews and lessons learned sessions with development teams to identify recurring security issues and promote secure development practices.
  • Maintaining program documentation, test records, and reporting artifacts.
  • Conducting penetration testing of web applications, APIs, cloud environments, and internal systems, escalating complex testing scenarios as needed.
  • Performing peer review of penetration testing deliverables, including test plans, findings, and final reports.
  • Participating in scoping exercises and contributing to the selection of appropriate testing methodologies.
  • Supporting security assessments of GenAI-powered applications and features, including LLM integrations, RAG pipelines, and AI agents.
  • Assisting in testing for AI-specific vulnerabilities such as prompt injection, jailbreaking, insecure output handling, model data leakage, and training data poisoning.
  • Contributing to the development of internal GenAI security testing checklists and methodologies, aligned with frameworks such as OWASP Top 10 for LLMs.
Requirements
  • Experience in information security, penetration testing, or a related field. Experience or coursework in software development, DevOps, or scripting is highly desirable.
  • At least one relevant security certification (e.g., Security+, eJPT, PNPT, CEH, or equivalent) preferred; advanced offensive security certifications such as OSCP are a plus.
  • Foundational understanding of web application architecture, networking, and operating system security.
  • Familiarity with common penetration testing tools (e.g., Burp Suite, Nmap, Metasploit, Nuclei, or equivalent).
  • Working knowledge of OWASP Top 10, common CVEs, and vulnerability scoring frameworks (CVSS).
  • Scripting ability in at least one language (Python, Bash, PowerShell, or similar); development experience is a strong plus.
  • Basic understanding of cloud environments (AWS, Azure, or GCP) and associated security considerations.
  • Exposure to SAST/DAST tools and secure code review practices is desirable.
  • Awareness of GenAI security risks (prompt injection, LLM abuse, insecure AI integrations)

Elsevier is a renowned global information analytics company that primarily focuses on providing scientific, technical, and medical (STM) research content, tools, and services. It is one of the largest publishers of academic journals and scholarly literature in the world.

Elsevier operates in various domains, including science, technology, medicine, social sciences, and more. They publish a vast number of peer‑reviewed journals covering a wide range of disciplines. These journals act as platforms for researchers and academics to share their findings and contribute to the advancement of knowledge in their respective fields.

In addition to publishing, Elsevier offers a suite of digital solutions and services to support researchers, scientists, and professionals in their work. They provide online platforms like ScienceDirect, Scopus, and Mendeley, which offer access to a vast repository of scholarly articles, research papers, and other scientific content. These platforms often serve as essential resources for software developers seeking to stay updated with the latest scientific advancements.

U.S. National Base Pay Range: $71,600 - $119,400. Geographic differentials may apply in some locations to better reflect local market rates. If performed in Colorado, the base pay range is $71,600 - $119,400. If performed in New York, the base pay range is $78,700 - $131,400. If performed in New York City, the base pay range is $85,900 - $143,300. If performed in Rochester, NY, the base pay range is $71,600 - $119,400. If performed in New Jersey, the base pay range is $84,546 - $135,054. This job is eligible for an annual incentive bonus. Application deadline is 09/17/2026.

We know your well‑being and happiness are key to a long and successful career. We are delighted to offer country specific benefits.

#J-18808-Ljbffr