1

Contract Penetration Test Jobs (NOW HIRING)

Contract Penetration Tester At Bishop Fox, securityisn'tjust a job-it'sour passion. As leaders in ... tests * Deep understanding of application security fundamentals, OWASP Top 10, common ...

Contract Penetration Tester At Bishop Fox, security isn't just a job-it's our passion. As leaders ... tests * Deep understanding of application security fundamentals, OWASP Top 10, common ...

Senior Penetration Tester

Leesburg, VA · On-site

$140K - $160K/yr

... awarded contract. The ideal candidate will have experience working in a network security ... Conduct penetration tests with the knowledge and written authorization of the system owner and only ...

They are seeking a Penetration Tester II to support a government contract and conduct various types of penetration tests, including Red Team engagements and IoT device testing. Responsibilities : • ...

They are seeking a Penetration Tester II to work on-site in support of a government contract ... Required : • Bachelor's degree. • At least three (3) years of pen test experience. • ...

... contracts, requiring an active Secret clearance. Responsibilities : • At least three (3) years of pen test experience. • Experience with continuous penetration testing methodologies. • ...

... contracts, requiring an active Secret clearance. Responsibilities : • At least three (3) years of pen test experience. • Experience with continuous penetration testing methodologies. • ...

Designs and conducts penetration tests, exploring more complex vulnerability analysis including ... This position is dependent on a contract seat being awarded. About LV8D Solutions LV8D Solutions is ...

Designs and conducts penetration tests, exploring more complex vulnerability analysis including ... This position is dependent on a contract seat being awarded. About LV8D Solutions LV8D Solutions is ...

Some contracts give 2 years experience credit for a Master's Degree. We will work with you to find the right fit. POSITION RESPONSIBILITIES * Conduct vulnerability assessments and penetration tests

Some contracts give 2 years experience credit for a Master's Degree. We will work with you to find the right fit. POSITION RESPONSIBILITIES * Conduct vulnerability assessments and penetration tests

next page

Showing results 1-20

Contract Penetration Test information

See salary details

$22.5K

$119.9K

$168.5K

How much do contract penetration test jobs pay per year?

As of Jul 26, 2026, the average yearly pay for contract penetration test in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What is the difference between Contract Penetration Test vs Vulnerability Analyst?

AspectContract Penetration TestVulnerability Analyst
CertificationsOSCP, CEH, GPENOSCP, CISSP, CEH
Work EnvironmentProject-based, on-site or remoteContinuous monitoring, office or remote
Industry UsageCybersecurity firms, consultingIn-house security teams, IT departments

Contract Penetration Testers focus on simulating attacks to identify security weaknesses during specific projects, often working with external clients. Vulnerability Analysts continuously monitor and analyze security vulnerabilities within an organization’s systems. While both roles require similar certifications and work in cybersecurity, their focus and work style differ significantly.

More about Contract Penetration Test jobs
What cities are hiring for Contract Penetration Test jobs? Cities with the most Contract Penetration Test job openings:
What are the most commonly searched types of Penetration Test jobs? The most popular types of Penetration Test jobs are:
What states have the most Contract Penetration Test jobs? States with the most job openings for Contract Penetration Test jobs include:
Infographic showing various Contract Penetration Test job openings in the United States as of July 2026, with employment types broken down into 57% Full Time, 22% Part Time, 1% Temporary, and 20% Contract. Highlights an 79% Physical, 2% Hybrid, and 19% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.
Penetration Tester - Contract

Other

Posted 20 days ago


Job description

Contract Penetration Tester 

At Bishop Fox, securityisn'tjust a job-it'sour passion. As leaders in continuous offensive security and penetration testing, we deliver world-class customer experiences. Trusted by over a quarter of the Fortune 100, half of the Fortune 10, and top global media companies, we help safeguard digital landscapes. Our Cosmos platform, honored as Best Emerging Technology by SC Media, exemplifies our commitment to innovation. 

Joining Bishop Fox means collaborating with a curious and dedicated team.You'lltackle complex challenges for some of the world's most recognized organizations, securing their networks against real-world threats. Withnearly 20years of industrycontributions-including 16 open-source tools and 50 security advisories published in the past fiveyears-we'recommitted to making the digital world safer. 

We'relooking for talented, experienced professional hackers to help us secure some of the world's most complex software and sophisticated technologies.You'llbe working alongside our US andinternationally-basedteams supporting clients across multiple industries.   

Responsibilities 

Bishop Fox is looking for experienced contract penetration testers with a primary focus in web application security and strong secondary expertise in cloud, mobile, source code, network, or AI/LLM security. 

You'll work on a range of projects, from short-term assessments to longer-term program engagements with well-established clients. In this role, you'll identify vulnerabilities, validate risk, develop creative solutions, and clearly communicate findings and remediation guidance to both technical and executive stakeholders. As a trusted advisor, you'll help clients understand risk and make informed security decisions. 

Experience 

  • 5+ years of experience planning, conducting, and managing web application penetration tests
  • Deep understanding of application security fundamentals, OWASP Top 10, common vulnerabilities, and secure development best practices
  • Experience assessing vulnerabilities and developing exploits across diverse targets
  • Strong understanding of system and network security, authentication protocols, security protocols, and applied cryptography
  • Ability to communicate complex technical findings clearly and provide practical remediation guidance to technical and executive audiences 

Preferred Experience 

Deep experience in at least one of the following: 

  • Cloud Security - Experience assessing AWS cloud environments, including technologies such as IAM, EC2, VPC, EBS, S3, CloudWatch, and Lambda. 
  • Mobile Application Security - Experience testing iOS and/or Android applications, including mobile application architecture, API communication, data storage, authentication flows, and common mobile security vulnerabilities. 
  • Source Assisted Application Assessments: Experience evaluating applications across multiple layers, including source code, APIs, infrastructure, and integrations. Strong proficiency in Golang is highly preferred, along with familiarity in languages such as Python, Ruby, PowerShell, Java, and JavaScript. 
  • Network Security - Experience with network and system exploitation, including modern tactics, techniques, and procedures such as C2 frameworks, EDR bypass, privilege escalation, password cracking, and lateral movement. 
  • AI/LLM Security - Experience assessing non-deterministic security controls. 

Employment Sponsorship

This engagement is for independent contractors (1099) and is not eligible for any form of employment sponsorship. Applicants must be legally authorized to work in the United States without requiring visa sponsorship now or in the future. Applicants must be located in the United States.

All new hires must pass a background check as a condition of employment. 

Bishop Fox is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law.