1

Contractual Application Penetration Tester Jobs (NOW HIRING)

Senior Penetration Tester

Washington, DC · On-site

$145K - $180K/yr

Assess and test the security of internal networks and underlying application infrastructure. * Conduct penetration testing and vulnerability assessments on Azure cloud infrastructure and applications

Citizenship) Preferred : • Familiarity with social engineering techniques • Knowledge of mobile application penetration testing • Experience with cloud security assessments (e.g., AWS, Azure ...

Citizenship) Preferred : • Familiarity with social engineering techniques • Knowledge of mobile application penetration testing • Experience with cloud security assessments (e.g., AWS, Azure ...

Penetration Tester

Rensselaer, NY · On-site

$90 - $105/hr

Create and use custom exploits to test application security, simulating attacker tactics. * Assist ... Experience in penetration testing or ethical hacking with a focus on Java application security.

... mobile application penetration testing • Experience with cloud security assessments (e.g., AWS, Azure) • Expertise in reverse engineering and malware analysis • Understanding of advanced ...

... mobile application penetration testing • Experience with cloud security assessments (e.g., AWS, Azure) • Expertise in reverse engineering and malware analysis • Understanding of advanced ...

Citizenship Preferred : • Familiarity with social engineering techniques • Knowledge of mobile application penetration testing • Experience with cloud security assessments (e.g., AWS, Azure ...

$90 - $105/hr

Create and use custom exploits to test application security, simulating attacker tactics. * Assist ... Experience in penetration testing or ethical hacking with a focus on Java application security.

... mobile application penetration testing • Experience with cloud security assessments (e.g., AWS, Azure) • Expertise in reverse engineering and malware analysis • Understanding of advanced ...

... mobile application penetration testing • Experience with cloud security assessments (e.g., AWS, Azure) • Expertise in reverse engineering and malware analysis • Understanding of advanced ...

... mobile application penetration testing • Experience with cloud security assessments (e.g., AWS, Azure) • Expertise in reverse engineering and malware analysis • Understanding of advanced ...

... mobile application penetration testing • Experience with cloud security assessments (e.g., AWS, Azure) • Expertise in reverse engineering and malware analysis • Understanding of advanced ...

We are seeking a skilled Penetration Tester with a focus on Java application security is sought to identify, exploit, and fix vulnerabilities in Java applications to guard against cyber threats. Key ...

Showing results 41-60

Contractual Application Penetration Tester information

See salary details

$96.5K

$132.3K

$159.5K

How much do contractual application penetration tester jobs pay per year?

As of Sep 4, 2026, the average yearly pay for contractual application penetration tester in the United States is $132,307.00, according to ZipRecruiter salary data. Most workers in this role earn between $121,500.00 and $146,500.00 per year, depending on experience, location, and employer.

What is the difference between Contractual Application Penetration Tester vs Security Analyst?

AspectContractual Application Penetration TesterSecurity Analyst
CertificationsOSCP, CEH, GPENCISSP, Security+
Work EnvironmentProject-based, client sites, consulting firmsIn-house, corporate security teams
Industry UsageCybersecurity consulting, freelance, contractingOrganizations' security departments
Primary FocusIdentifying vulnerabilities through penetration testingMonitoring, incident response, security policies

While both roles focus on cybersecurity, a Contractual Application Penetration Tester specializes in testing applications for vulnerabilities on a contractual basis, often working with multiple clients. In contrast, a Security Analyst typically works within an organization to monitor and improve overall security posture. The roles differ mainly in scope, environment, and daily responsibilities, but both require relevant certifications and a strong understanding of cybersecurity principles.

What cities are hiring for Contractual Application Penetration Tester jobs?

Cities with the most Contractual Application Penetration Tester job openings:

What are the most commonly searched types of Application Penetration Tester jobs?

The most popular types of Application Penetration Tester jobs are:

What states have the most Contractual Application Penetration Tester jobs?

States with the most job openings for Contractual Application Penetration Tester jobs include:

Penetration Tester

Amatriot Group, LLC

Rensselaer, NY

$90K - $105K/yr

Full-time

Re-posted yesterday


Job description

Location: Albany, NY
Security Clearance: None
Job Type: Full-Time

Target Salary Range*: $90,000 - $105,000

*This represents the potential salary range for this position depending on education level, years of experience and/or certifications in addition to other position specific requirements which may impact salary


Position Overview

A Penetration Tester with a focus on Java application security identifies, exploits, and supports remediation of vulnerabilities in Java applications to help guard against cyber threats.


Key ResponsibilitiesPenetration Testing and Vulnerability Assessment
  • Conduct penetration tests and vulnerability assessments for Java applications and infrastructure.
  • Identify security flaws in Java code using automated and manual methods.
  • Create and use custom exploits to test application security, simulating attacker tactics.
  • Manipulate URLs, query parameters, and application browser data to identify penetration avenues.
  • Validate and assess browser tokens, cache manipulation, and production versus non-production architecture.
  • Assist in responding to security incidents related to Java vulnerabilities and current published NIST CVEs.
Secure Development and Remediation Support
  • Collaborate with development teams to understand application architecture and identify security weaknesses early.
  • Collaborate with testing teams to integrate security testing with manual and automated testing.
  • Provide guidance on secure coding and vulnerability remediation.
  • Help improve secure development lifecycle processes.
  • Contribute to security policies for Java development and deployment.
Reporting, Communication, and Threat Awareness
  • Clearly document and report findings, including technical details, risk assessments, and recommended solutions.
  • Communicate findings and recommendations to both technical and non-technical staff.
  • Stay updated on Java security threats and best practices.
  • Apply familiarity with the MITRE ATT&CK Framework.

QualificationsEducation
  • Bachelor’s degree in Computer Science, Information Security, or a related field.
Experience
  • Minimum of 6 years of development or security experience. [Required]
  • Experience in penetration testing or ethical hacking with a focus on Java application security.
  • Experience with penetration testing tools such as Burp Suite and Metasploit.
  • Familiarity with Fortify on Demand SAST and DAST tools.
Skills
  • Strong knowledge of Java programming and Java security practices.
  • Scripting experience.
  • Proficiency in web application security principles, including OWASP.
  • Knowledge of common web vulnerabilities, including SQL injection and cross-site scripting, and exploit techniques.
  • Strong understanding of cryptography and secure communication protocols, including SSL/TLS.
  • Excellent problem-solving and analytical skills.
  • Strong communication skills.
  • High ethical standards and confidentiality.
  • Familiarity with the MITRE ATT&CK Framework.

Preferred Qualifications
  • Certifications such as OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP, or other industry security certifications.
  • Experience with scripting languages, such as Python or Bash.
  • Experience with secure code review for Java.
  • Familiarity with cloud security testing.
  • Experience with mobile application penetration testing.
  • Knowledge of regulations such as HIPAA.
  • Experience with API testing.

#LI-BM1