1

Contractual Application Penetration Tester Jobs (NOW HIRING)

next page

Showing results 1-20

Contractual Application Penetration Tester information

See salary details

$96.5K

$132.3K

$159.5K

How much do contractual application penetration tester jobs pay per year?

As of Aug 25, 2026, the average yearly pay for contractual application penetration tester in the United States is $132,307.00, according to ZipRecruiter salary data. Most workers in this role earn between $121,500.00 and $146,500.00 per year, depending on experience, location, and employer.

What is the difference between Contractual Application Penetration Tester vs Security Analyst?

AspectContractual Application Penetration TesterSecurity Analyst
CertificationsOSCP, CEH, GPENCISSP, Security+
Work EnvironmentProject-based, client sites, consulting firmsIn-house, corporate security teams
Industry UsageCybersecurity consulting, freelance, contractingOrganizations' security departments
Primary FocusIdentifying vulnerabilities through penetration testingMonitoring, incident response, security policies

While both roles focus on cybersecurity, a Contractual Application Penetration Tester specializes in testing applications for vulnerabilities on a contractual basis, often working with multiple clients. In contrast, a Security Analyst typically works within an organization to monitor and improve overall security posture. The roles differ mainly in scope, environment, and daily responsibilities, but both require relevant certifications and a strong understanding of cybersecurity principles.

What cities are hiring for Contractual Application Penetration Tester jobs?

Cities with the most Contractual Application Penetration Tester job openings:

What are the most commonly searched types of Application Penetration Tester jobs?

The most popular types of Application Penetration Tester jobs are:

What states have the most Contractual Application Penetration Tester jobs?

States with the most job openings for Contractual Application Penetration Tester jobs include:

Senior Specialist, MAST Application Penetration Tester

San Francisco, CA • On-site

Full-time

Re-posted 25 days ago


Job description

Job Summary:
KPMG is currently seeking a Senior Specialist, MAST Application Penetration Tester to join our Managed Services practice. The role involves conducting manual application penetration testing and executing threat modeling while demonstrating application testing experience.
Responsibilities:
• Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications
• Perform objective based on abstract penetration testing engagements
• Execute threat modeling, evaluate application business logic, and perform application architecture reviews
• Demonstrate application testing experience in real time via demos to both internal and external audiences
• Function independently in penetration testing engagements, with minimal oversight and guidance
• Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
Qualifications:
Required:
• Minimum three years of recent experience in application penetration testing of Application Programming Interface (API's), web applications, or mobile applications
• Bachelor's degree from an accredited college/university or equivalent industry experience
• Ability to communicate reporting results with technical and non-technical audiences and lead remediation conversations
• Experience with burp suite pro, and other app testing tools such as Netsparker and Checkmarx
• Ability to travel as required
• Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa)
Preferred:
• One or more major ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert (OSWE), Offensive Security Web Assessor (OSWA)
Company:
KPMG is one of the world’s leading professional services firms and the fastest growing Big Four accounting firm in the United States. Founded in 2010, the company is headquartered in New York, USA, with a team of 10001+ employees. The company is currently Late Stage.