2

Entry Level Web App Penetration Testing Jobs (NOW HIRING)

Conducting penetration testing of web applications, APIs, cloud environments, and internal systems, escalating complex testing scenarios as needed. * Performing peer review of penetration testing ...

The Penetration Tester is responsible for working as part of the Assessment Team to conduct and ... Conduct security audits, network penetration tests, and web application, API and cloud assessments.

In this role, you will be responsible for the execution of comprehensive security testing across a ... Execute internal, external, wireless, and web application pen tests * Execute social engineering ...

In this role, you will be responsible for the execution of comprehensive security testing across a ... Execute internal, external, wireless, and web application pen tests * Execute social engineering ...

The Penetration Tester is responsible for working as part of the Assessment Team to conduct and ... Conduct security audits, network penetration tests, and web application, API and cloud assessments.

Cloud Penetration Tester

Ashburn, VA ยท On-site

$87K - $157K/yr

Conduct penetration testing activities aligned withCBPand industry best practices ... Pen Testing and Vulnerability Assessment,with specificemphasis on web applicationand enterprise ...

Cloud Penetration Tester

Ashburn, VA ยท On-site

$87K - $157K/yr

Conduct penetration testing activities aligned with CBP and industry best practices. * Perform internal and external web application, network, and infrastructure pentest assessments using commercial ...

The Penetration Tester is responsible for working as part of the Assessment Team to conduct and ... Conduct security audits, network penetration tests, and web application, API and cloud assessments.

Understand common Web Application vulnerabilities like SQLi, XSS, CSRF, and HTTP Flooding. * Experience with penetration testing tools such as Metasploit, Burp Suite, Nmap, etc. * Fundamentals of ...

Understand common Web Application vulnerabilities like SQLi, XSS, CSRF, and HTTP Flooding. * Experience with penetration testing tools such as Metasploit, Burp Suite, Nmap, etc. * Fundamentals of ...

next page

Showing results 1-20

Entry Level Web App Penetration Testing information

See salary details

$11

$59

$86

How much do entry level web app penetration testing jobs pay per hour?

As of Jul 22, 2026, the average hourly pay for entry level web app penetration testing in the United States is $59.01, according to ZipRecruiter salary data. Most workers in this role earn between $51.20 and $66.83 per hour, depending on experience, location, and employer.

What is the difference between Entry Level Web App Penetration Testing vs Web Developer?

AspectEntry Level Web App Penetration TestingWeb Developer
CertificationsCompTIA Security+, CEH (optional)None required, but coding certifications help
Work EnvironmentSecurity teams, testing labs, client sitesDevelopment teams, office or remote
Primary FocusIdentifying security vulnerabilities in web appsBuilding and maintaining websites and applications
Tools & SkillsPenetration testing tools, scripting, security protocolsProgramming languages, frameworks, UI/UX design

Entry Level Web App Penetration Testing focuses on assessing web app security, while Web Developers create and maintain web applications. Both roles require technical skills, but penetration testers emphasize security testing and vulnerability identification, whereas developers focus on coding and user experience.

More about Entry Level Web App Penetration Testing jobs
What cities are hiring for Entry Level Web App Penetration Testing jobs? Cities with the most Entry Level Web App Penetration Testing job openings:
What are the most commonly searched types of Web App Penetration Testing jobs? The most popular types of Web App Penetration Testing jobs are:
Infographic showing various Entry Level Web App Penetration Testing job openings in the United States as of July 2026, with employment types broken down into 100% Full Time. Highlights an 67% In-person, and 33% Remote job distribution, with an average salary of $122,736 per year, or $59 per hour.
Security Assurance Penetration Tester

Security Assurance Penetration Tester

RELX

Philadelphia, PA โ€ข On-site, Remote

$85K - $143K/yr

Full-time

Posted 12 days ago


Job description

Are you a collaborative Penetration Tester looking to work for a mission driven global organization?

About the role - This role supports the offensive security function within Elsevier's Security Engineering team. You will perform hands-on security testing and peer review activities, validate vulnerabilities and security controls, and support the automation of security assurance processes. This is a hands-on role for a motivated security professional eager to grow in a collaborative, fast-paced environment.

About the team - The Security Assurance team supports the third-party penetration testing program, security control validation, and ongoing offensive security testing activities.

Responsibilities

  • Tracking and triaging findings from third-party assessments, ensuring timely follow-up and remediation tracking.
  • Collaborating with development, platform, and product teams to communicate findings, track remediation efforts, and improve overall security posture.
  • Facilitating post-assessment reviews and lessons learned sessions with development teams to identify recurring security issues and promote secure development practices.
  • Maintaining program documentation, test records, and reporting artifacts.
  • Conducting penetration testing of web applications, APIs, cloud environments, and internal systems, escalating complex testing scenarios as needed.
  • Performing peer review of penetration testing deliverables, including test plans, findings, and final reports.
  • Participating in scoping exercises and contributing to the selection of appropriate testing methodologies.
  • Supporting security assessments of GenAI-powered applications and features, including LLM integrations, RAG pipelines, and AI agents.
  • Assisting in testing for AI-specific vulnerabilities such as prompt injection, jailbreaking, insecure output handling, model data leakage, and training data poisoning.
  • Contributing to the development of internal GenAI security testing checklists and methodologies, aligned with frameworks such as OWASP Top 10 for LLMs.

Requirements

  • Experience in information security, penetration testing, or a related field. Experience or coursework in software development, DevOps, or scripting is highly desirable.
  • At least one relevant security certification (e.g., Security+, eJPT, PNPT, CEH, or equivalent) preferred; advanced offensive security certifications such as OSCP are a plus.
  • Foundational understanding of web application architecture, networking, and operating system security.
  • Familiarity with common penetration testing tools (e.g., Burp Suite, Nmap, Metasploit, Nuclei, or equivalent).
  • Working knowledge of OWASP Top 10, common CVEs, and vulnerability scoring frameworks (CVSS).
  • Scripting ability in at least one language (Python, Bash, PowerShell, or similar); development experience is a strong plus.
  • Basic understanding of cloud environments (AWS, Azure, or GCP) and associated security considerations.
  • Exposure to SAST/DAST tools and secure code review practices is desirable.
  • Awareness of GenAI security risks (prompt injection, LLM abuse, insecure AI integrations)

Elsevier is a renowned global information analytics company that primarily focuses on providing scientific, technical, and medical (STM) research content, tools, and services. It is one of the largest publishers of academic journals and scholarly literature in the world.

Elsevier operates in various domains, including science, technology, medicine, social sciences, and more. They publish a vast number of peer-reviewed journals covering a wide range of disciplines. These journals act as platforms for researchers and academics to share their findings and contribute to the advancement of knowledge in their respective fields.

In addition to publishing, Elsevier offers a suite of digital solutions and services to support researchers, scientists, and professionals in their work. They provide online platforms like ScienceDirect, Scopus, and Mendeley, which offer access to a vast repository of scholarly articles, research papers, and other scientific content. These platforms often serve as essential resources for software developers seeking to stay updated with the latest scientific advancements.

U.S. National Base Pay Range: $71,600 - $119,400. Geographic differentials may apply in some locations to better reflect local market rates. If performed in Colorado, the base pay range is $71,600 - $119,400.If performed in New York, the base pay range is $78,700 - $131,400.If performed in New York City, the base pay range is $85,900 - $143,300.If performed in Rochester, NY, the base pay range is $71,600 - $119,400.If performed in New Jersey, the base pay range is $84,546 - $135,054. This job is eligible for an annual incentive bonus. Application deadline is 09/17/2026.

We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click here to access benefits specific to your location.

We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Formor please contact 1-855-833-5120.

Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams here.

Please read our Candidate Privacy Policy.

We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.

USA Job Seekers:

EEO Know Your Rights.