Schellman created our Penetration Tester role with the goal of giving talented technical IT ... There is no typical day for our Pen Test team. Our clients rely on us to find and exploit a myriad ...
Schellman created our Penetration Tester role with the goal of giving talented technical IT ... There is no typical day for our Pen Test team. Our clients rely on us to find and exploit a myriad ...
Penetration Tester with Splunk
Fort George G Meade, MD · On-site
$141K - $236K/yr
Ability to plan, develop and execute information assurance evaluation tests and document test ... Contract Wage Determination, relevant work experience, skills and competencies that align to the ...
Penetration Tester with Splunk
Fort George G Meade, MD · On-site
$141K - $236K/yr
Ability to plan, develop and execute information assurance evaluation tests and document test ... Contract Wage Determination, relevant work experience, skills and competencies that align to the ...
Penetration Tester with Security Clearance
Fort George G Meade, MD · On-site
$86K - $198K/yr
You Have: * 3+ years of experience with MITRE ATT&CK, test planning and security control assessment ... as well as contract-specific affordability and organizational requirements. The projected ...
Penetration Tester with Security Clearance
Fort George G Meade, MD · On-site
$86K - $198K/yr
You Have: * 3+ years of experience with MITRE ATT&CK, test planning and security control assessment ... as well as contract-specific affordability and organizational requirements. The projected ...
Penetration Tester with Splunk
Fort George G Meade, MD · On-site
$141K - $236K/yr
Ability to plan, develop and execute information assurance evaluation tests and document test ... Contract Wage Determination, relevant work experience, skills and competencies that align to the ...
Penetration Tester with Splunk
Fort George G Meade, MD · On-site
$141K - $236K/yr
Ability to plan, develop and execute information assurance evaluation tests and document test ... Contract Wage Determination, relevant work experience, skills and competencies that align to the ...
Information Security Analyst
San Antonio, TX · On-site
Monitor penetration test findings, coordinate evidence collection and retesting, and manage ... Hourly employees on a Service Contract Act project are eligible for paid sick leave. Note: Pay is ...
Information Security Analyst
San Antonio, TX · On-site
Monitor penetration test findings, coordinate evidence collection and retesting, and manage ... Hourly employees on a Service Contract Act project are eligible for paid sick leave. Note: Pay is ...
Job Summary - Information Security Platform Engineer (Contractor) - 6-month remote contract ... audit, penetration test, and vulnerability assessment preparation and response - Produce clear ...
Quick apply
Job Summary - Information Security Platform Engineer (Contractor) - 6-month remote contract ... audit, penetration test, and vulnerability assessment preparation and response - Produce clear ...
This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal ...
This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal ...
This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal ...
This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal ...
This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal ...
This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal ...
This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal ...
This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal ...
This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal ...
This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal ...
This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal ...
This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal ...
This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal ...
This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal ...
This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal ...
This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal ...
This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal ...
This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal ...
This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal ...
This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal ...
This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal ...
This opportunity is suited to people who test systems for a living or have done so: penetration testers, red team operators, and serious bug bounty hunters, whether from consultancies, internal ...
Contract to Hire * Review Projects and their technical design documents for Information security ... Review Vulnerability Assessment and Penetration Test scan results and recommend the risks to be ...
Quick apply
Contract to Hire * Review Projects and their technical design documents for Information security ... Review Vulnerability Assessment and Penetration Test scan results and recommend the risks to be ...
... diligence, contract controls, continuous monitoring, reassessment, and secure offboarding ... Experience reviewing assurance artifacts (SOC 2 Type II, ISO certifications, penetration test ...
... diligence, contract controls, continuous monitoring, reassessment, and secure offboarding ... Experience reviewing assurance artifacts (SOC 2 Type II, ISO certifications, penetration test ...
... diligence, contract controls, continuous monitoring, reassessment, and secure offboarding ... Experience reviewing assurance artifacts (SOC 2 Type II, ISO certifications, penetration test ...
... diligence, contract controls, continuous monitoring, reassessment, and secure offboarding ... Experience reviewing assurance artifacts (SOC 2 Type II, ISO certifications, penetration test ...
Contract Penetration Test information
See salary details
$22.5K - $35.8K
0% of jobs
$35.8K - $49K
0% of jobs
$49K - $62.3K
2% of jobs
$62.3K - $75.6K
3% of jobs
$75.6K - $88.9K
1% of jobs
$101.1K is the 25th percentile. Wages below this are outliers.
$88.9K - $102.1K
20% of jobs
$102.1K - $115.4K
14% of jobs
The median wage is $120.4K / yr.
$115.4K - $128.7K
26% of jobs
$138.1K is the 75th percentile. Wages above this are outliers.
$128.7K - $142K
13% of jobs
$142K - $155.2K
13% of jobs
$155.2K - $168.5K
9% of jobs
$22.5K
$119.9K
$168.5K
How much do contract penetration test jobs pay per year?
What is the difference between Contract Penetration Test vs Vulnerability Analyst?
| Aspect | Contract Penetration Test | Vulnerability Analyst |
|---|---|---|
| Certifications | OSCP, CEH, GPEN | OSCP, CISSP, CEH |
| Work Environment | Project-based, on-site or remote | Continuous monitoring, office or remote |
| Industry Usage | Cybersecurity firms, consulting | In-house security teams, IT departments |
Contract Penetration Testers focus on simulating attacks to identify security weaknesses during specific projects, often working with external clients. Vulnerability Analysts continuously monitor and analyze security vulnerabilities within an organization’s systems. While both roles require similar certifications and work in cybersecurity, their focus and work style differ significantly.
What cities are hiring for Contract Penetration Test jobs?
Cities with the most Contract Penetration Test job openings:
What are the most commonly searched types of Penetration Test jobs?
The most popular types of Penetration Test jobs are:
What states have the most Contract Penetration Test jobs?
States with the most job openings for Contract Penetration Test jobs include:
What job categories do people searching Contract Penetration Test jobs look for?
The top searched job categories for Contract Penetration Test jobs are:

Job description
JOB SUMMARY
Senior associates are primarily responsible for hands-on project execution. Experienced senior associates have, or are working towards, specialization in one or more service lines and are assigned to projects accordingly. Senior associates are assigned to a specific service delivery principal that is responsible for supervising the associate's career development. Additionally, senior associate's daily activities are closely supervised by the management teams of their assigned projects. Senior associates may supervise associates and/or senior associates when serving as a member of a project management team.
Schellman created our Penetration Tester role with the goal of giving talented technical IT professionals, who have at least 2 years of security experience and hands-on security certifications (e.g. OSCP), a structured plan to elevate their expertise. This is a rare opportunity to transition to a focused penetration testing position to build on your offensive skillset while working on engagements with our team, whose unrivaled knowledge and experience will provide guidance and mentorship throughout. What do we ask from you? Unwavering commitment to learn as much as possible to be a contributing member of the team, and to always be up for a new challenge.
There is no typical day for our Pen Test team. Our clients rely on us to find and exploit a myriad of vulnerabilities across their on premise and cloud-based networks and applications. The benefit of being exposed to so many different situations is that you are constantly building your knowledge base and skillset while keeping up with the latest technologies. Our team is remote yet extremely collaborative and works together to utilize their different backgrounds and experience to solve these problems.
Want to learn more about what it takes to solve penetration testing problems at scale with Schellman?
Check out this blog: 6 Problems Penetration Testers Face (& How Schellman Is Solving Them)
Essential Functions:
- Complying with Schellman's code of ethics and professional conduct, methodologies, policies, and procedures
- Adhering to the professional and regulatory standards relevant to assigned service line specialization(s)
- Promoting Schellman's company culture and exemplifying Schellman's values
- Establishing high quality relationships and rapport with client personnel
- Managing client expectations to ensure expectations are exceeded
- Completing assigned duties in a timely manner and with a high attention to detail
- Collaborating with fellow project team members in a productive and timely manner throughout the life cycle of each project
- Adhering to project schedules and keeping fellow project team members apprised of the progress of assigned tasks
- Escalating issues internally in a proper and timely manner
- Using discretion and decorum in the timing, form, and content of all client communications
- Booking travel reservations in a timely manner and in accordance with Schellman's travel and expense policies and procedures
- Performing the essential functions of other service delivery positions when qualified and called upon to do so
- Attending project kick-off and closing meetings
- Executing assigned testing procedures, performing detailed analysis, reaching conclusions, documenting results in accordance with company standards, and suggesting ideas for improvements, where applicable
- Drafting project deliverables
- Serving as a contact for clients' basic questions regarding an engagement
- Participating in recruiting and candidate interview activities
- Training project team members
- Acclimating newer team members to Schellman
- Contributing to Schellman's practice development efforts
- Developing an expert knowledge of professional and regulatory standards relevant to assigned service line specialization(s)
- Contributing to Schellman's thought leadership (e.g., articles, webinars, public speaking, etc.)
Knowledge, Skills, and Abilities:
- Working knowledge of Schellman's services, methodology, and relevant professional standards
- Requisite knowledge of applicable technology and security domains
- High level of attention to detail and quality of work product
- Client service oriented
- Excellent time management, organizational, and verbal and written communication skills
- Ability to work on-site or remotely as a valuable contributor to a collaborative team
- Capable of simultaneously managing assigned tasks for multiple projects
- Proficient using Microsoft Word, Excel, and PowerPoint, as well as Schellman's service delivery applications
- Full understanding and application of ethics, independence and Schellman's values
Education, Work Experience and Certifications
- Bachelor's degree in technology, computer science or other relevant subject area, or equivalent years of experience directly related to the duties and responsibilities specified
- 3+ years' experience in hands on penetration testing
- 1+ year experience in web application penetration testing
- Ability to work well independently, within a team and with clients
- Completion of one or more of the following certifications:
- Offensive Security Certified Professional (OSCP) (Required)
- Certified Red Team Operator (CRTO) (Preferred)
- Burp Suite Certified Practitioner (Preferred)
- Demonstrated enthusiasm for Information Security (e.g. GitHub repo, blogs, presentations, conference talks, local security association member, participated in free skill-building / hacking challenges - SANS Holiday Hack, HackerOne CTF, HackTheBox, etc.)
- Competency in common operating systems (e.g. Windows, macOS, Linux)
- An understanding of cloud computing models, technologies, and concepts
- Proficiency with at least two scripting languages (e.g. Python, Bash, JavaScript, PowerShell)
Our ideal candidate has:
- Knowledge of PCI and FedRAMP programs
- A passion for identifying and exploiting vulnerabilities
- Demonstrated entrepreneurial abilities, client focus, industry savvy, and the ability to work independently or as part of a collaborative team
- Self-driven in a remote working environment, motivation to continuously improve your skillset
Schellman is an equal opportunity employer (EOE) and strongly supports diversity in the workplace; therefore, providing equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law. Schellman uses E-Verify in our hiring process.
At Schellman, we strive to provide a flexible and balanced environment and therefore offer the opportunity to work remotely, unless otherwise stated in the job requirements. Connecting, collaborating and continuous education are also highly valued and therefore we require some travel annually, which can include in-person training, team meet-ups, and strategy meetings. Service Delivery team members will also be required to travel based on business and client needs.
About Schellman
Sourced by ZipRecruiter
Industry
Professional, scientific, and technical services
Company size
501 - 1,000 Employees
Headquarters location
Tampa, FL, US
Year founded
2002