1

Ethical And Penetration Testing Jobs (NOW HIRING)

Experience in Penetration Testing/Ethical Hacking with a focus on Java application security. * Strong knowledge of Java programming and its security practices as well as scripting experience.

Possess a certification in penetration testing, such as: * Licensed Penetration Tester (LPT) * Certified Expert Penetration Tester (CEPT) * Certified Ethical Hacker (CEH) * Global Information ...

Penetration Tester

Washington, DC · On-site

$117K - $199K/yr

This role combines hands-on testing with leadership, mentoring, and collaboration across ... CEH (Certified Ethical Hacker) * CISSP (Certified Information Systems Security Professional ...

Be Seen First

Penetration Tester

Knoxville, TN · Remote

$120K - $145K/yr

At Zelvin, penetration testing is not about generating a list of vulnerabilities. Our testers think like attackers, follow the evidence, challenge assumptions, and determine which weaknesses create ...

New

WV · On-site

REQUIREMENTS: * 8+ years of experience in penetration testing, application security, or ethical hacking security roles. * Experience documenting test plans, test procedures, and detailed security ...

Showing results 21-40

Ethical And Penetration Testing information

See salary details

$22.5K

$119.9K

$168.5K

How much do ethical and penetration testing jobs pay per year?

As of Aug 15, 2026, the average yearly pay for ethical and penetration testing in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

Is ethical and penetration testing a good career?

Ethical and penetration testing is a growing field within cybersecurity, offering opportunities for professionals to identify vulnerabilities and improve security systems. It typically requires skills in networking, scripting, and security tools, along with certifications like CEH or OSCP. The career can be rewarding with high demand, competitive salaries, and continuous learning opportunities.

What is the difference between Ethical And Penetration Testing vs Vulnerability Assessment?

AspectEthical And Penetration TestingVulnerability Assessment
CertificationsOSCP, CEH, GPENOSCP, CEH, CISSP
Work EnvironmentSimulated attacks on systems to find security gapsIdentify and prioritize vulnerabilities without exploiting
PurposeTest security defenses through active exploitationIdentify vulnerabilities for remediation

Ethical and Penetration Testing involves actively exploiting security weaknesses to evaluate defenses, requiring certifications like OSCP or CEH. Vulnerability Assessment focuses on identifying vulnerabilities without exploitation, helping organizations prioritize fixes. Both are essential but serve different security testing purposes.

More about Ethical And Penetration Testing jobs

What cities are hiring for Ethical And Penetration Testing jobs?

Cities with the most Ethical And Penetration Testing job openings:

What states have the most Ethical And Penetration Testing jobs?

States with the most job openings for Ethical And Penetration Testing jobs include:

What job categories do people searching Ethical And Penetration Testing jobs look for?

The top searched job categories for Ethical And Penetration Testing jobs are:

Infographic showing various Ethical And Penetration Testing job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 85% Full Time, 9% Part Time, 4% Contract, and 1% Nights. Highlights an 89% Physical, 2% Hybrid, and 9% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

Penetration Tester

Donato Technologies, Inc

Albany, NY • On-site

$60/hr

Contractor

Re-posted 2 days ago


Job description

We are seeking a skilled Penetration Tester with a focus on Java application security is sought to identify, exploit, and fix vulnerabilities in Java applications to guard against cyber threats. 

Key Responsibilities
  • Conduct penetration tests and vulnerability assessments for Java applications and infrastructure.
  • Identify security flaws in Java code using automated and manual methods.
  • Create and use custom exploits to test application security, simulating attacker tactics.
  • Collaborate with Development teams to understand application architecture and find security weaknesses early.
  • Collaborate with Testing teams to integrate with manual and automation testing.
  • Provide guidance on secure coding and how to fix vulnerabilities.
  • Stay updated on Java security threats and best practices.
  • Help improve secure development processes (SDLC).
  • Assist in responding to security incidents related to Java vulnerabilities, current published NIST CVE.
  • Clearly document and report findings, including technical details, risk assessment, and recommended solutions.
  • Communicate findings and recommendations to both technical and non-technical staff.
  • Contribute to security policies for Java development and deployment.
  • Manipulate URLs, query parameters and Application browser data to look for penetration avenues. Validate and asses’ browser tokens and cache manipulation and Production vs. none prod architecture.
  • Familiar with MITRE ATT&CK Framework.
Required Qualifications
  • Bachelor’s degree in a related software field with 6+ years in a Dev Sec role.
  • Core Java coding experience.
  • Previous job background as an engineer and Dev Sec position on a large scale public enterprise scale application.
  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • Minimum of 6 years of Development/Security experience
  • Experience in Penetration Testing/Ethical Hacking with a focus on Java application security.
  • Strong knowledge of Java programming and its security practices as well as scripting experience.
  • Proficiency in web application security principles (e.g., OWASP).
  • Knowledge of common web vulnerabilities (e.g., SQL injection, XSS) and exploit techniques.
  • Experience with penetration testing tools like Burp Suite, Metasploit.
  • Familiarity with Fortify on Demand SAST and DAST tools.
  • Strong understanding of cryptography and secure communication protocols (e.g., SSL/TLS).
  • Excellent problem-solving and analytical skills.
  • Strong communication skills.
  • High ethical standards and confidentiality.
Desired Qualifications
  • Certifications such as OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP or other industry security certifications.
  • Experience with scripting languages (e.g., Python, Bash).
  • Experience with secure code review for Java.
  • Familiarity with cloud security testing.
  • Experience with mobile application penetration testing.
  • Knowledge of regulations like HIPAA. 
  • Experience with API testing

Donato Technologies Inc. is a trusted IT staffing, consulting, and software development partner headquartered in Dallas, Texas. We support clients across industries by understanding their unique business needs and delivering tailored technology and workforce solutions. Our focus is on connecting the right talent with the right opportunity-ensuring clients receive dependable, skilled professionals and candidates receive meaningful career growth and support. We work closely with small to mid-sized organizations to provide flexible, high-quality services that drive performance, innovation, and long-term success.