1

Ethical Hacking Certification Jobs (NOW HIRING)

Showing results 21-40

Ethical Hacking Certification information

See salary details

$40.5K

$122.9K

$180K

How much do ethical hacking certification jobs pay per year?

As of Sep 6, 2026, the average yearly pay for ethical hacking certification in the United States is $122,890.00, according to ZipRecruiter salary data. Most workers in this role earn between $102,000.00 and $142,000.00 per year, depending on experience, location, and employer.

What is an ethical hacking certification?

An Ethical Hacking Certification is a professional credential that validates an individual's skills and knowledge in identifying, assessing, and addressing security vulnerabilities in computer systems, networks, and applications. Ethical hackers use the same techniques as malicious hackers, but with the permission of the system owner to help improve security. This certification demonstrates to employers that you have the expertise to conduct penetration testing and follow ethical guidelines. Some of the most recognized certifications include Certified Ethical Hacker (CEH) and Offensive Security Certified Professional (OSCP). Obtaining this certification can open doors to careers in cybersecurity, penetration testing, and information security analysis.

What are the key skills and qualifications needed to thrive as an ethical hacker, and why are they important?

To thrive as an Ethical Hacker, you need a strong understanding of computer networks, operating systems, cybersecurity concepts, and typically a relevant certification such as CEH (Certified Ethical Hacker) or OSCP. Familiarity with penetration testing tools like Metasploit, Nmap, Wireshark, and vulnerability scanners is crucial. Critical thinking, problem-solving skills, and the ability to communicate complex findings clearly set top ethical hackers apart. These competencies are vital to proactively identify and address security vulnerabilities, helping organizations safeguard their digital assets.

What types of hands-on projects or assessments can I expect during an ethical hacking certification program?

During an Ethical Hacking Certification program, you can expect to work on real-world simulations such as penetration testing labs, vulnerability assessments, and network intrusion exercises. These projects are designed to enhance your practical skills in identifying and exploiting security weaknesses ethically. Many programs also include capture-the-flag (CTF) challenges and scenario-based assessments that mirror challenges faced by cybersecurity professionals in the field. This hands-on component is critical for building confidence and demonstrating your abilities to potential employers.

What is the difference between Ethical Hacking Certification vs Penetration Tester?

AspectEthical Hacking CertificationPenetration Tester
CredentialsCertifications like CEH, OSCPCertifications like OSCP, GPEN often preferred
Work EnvironmentTraining, assessments, and security auditsConducting simulated attacks on systems and networks
Industry UsageUsed by security professionals to validate skillsPerformed by security experts to identify vulnerabilities

While Ethical Hacking Certification validates knowledge and skills through exams, a Penetration Tester actively performs security assessments. Certifications prepare professionals, whereas Penetration Testers execute real-world testing to find security flaws.

How much do certified ethical hackers make?

Certified ethical hackers typically earn between $70,000 and $120,000 annually, depending on experience, location, and industry. Professionals with advanced certifications and skills in penetration testing and security tools tend to have higher salaries.

What jobs can I get with a Certified Ethical Hacker certification?

A Certified Ethical Hacker (CEH) certification qualifies individuals for roles such as penetration tester, security analyst, security consultant, and vulnerability assessor. These jobs involve identifying and fixing security weaknesses using tools like Kali Linux and Metasploit, often requiring strong knowledge of networks, systems, and cybersecurity best practices.
More about Ethical Hacking Certification jobs

What cities are hiring for Ethical Hacking Certification jobs?

Cities with the most Ethical Hacking Certification job openings:

What states have the most Ethical Hacking Certification jobs?

States with the most job openings for Ethical Hacking Certification jobs include:

What job categories do people searching Ethical Hacking Certification jobs look for?

The top searched job categories for Ethical Hacking Certification jobs are:

Infographic showing various Ethical Hacking Certification job openings in the United States as of August 2026, with employment types broken down into 2% As Needed, 73% Full Time, 18% Part Time, and 7% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution, with an average salary of $122,890 per year, or $59.1 per hour.

AI Attack Surface and Threat Exposure Management Consulting Director

Cna

Chicago, IL • On-site

Full-time

Re-posted 12 days ago


Job description

You have a clear vision of where your career can go. And we have the leadership to help you get there.At CNA, we strive to create a culture in which people know they matter and are part of something important, ensuring the abilities of all employees are used to their fullest potential.

The Consulting Director, Attack Surface Management defines strategy, adoption, and governance of automation, AI, and agentic AI across application security, vulnerability management, ethical hacking, and attack surface management programs. Oversees evaluation and deployment of AI-centric security solutions while establishing audit-defensible standards, processes, and secure AI development practices. Drives enterprise-scale identification, analysis, and remediation of external attack surface risk through advanced automation, analytics, and AI-enabled capabilities. Partners with senior leadership and cross-functional teams to prioritize risk, improve operational efficiency, and deliver measurable security outcomes. Provides expert guidance, metrics, and reporting to ensure effective risk management, regulatory alignment, and continuous program maturity.

JOB DESCRIPTION:

Essential Duties & Responsibilities

Performs a combination of duties in accordance with departmental guidelines:

  • Aid in defining and implementing strategy for applying automation, AI, and agentic AI to application security, vulnerability management, ethical hacking, and attack surface management use cases.
  • Evaluate, deploy, manage, and govern best-in-class new and existing AI-centric solutions, services, and capabilities relevant to the application security, ethical hacking, and vulnerability management domains.
  • Identify, prioritize, and drive high-value outcomes where automation and AI can improve operational effectiveness, speed, scale, and efficiency.
  • Develop and contribute to audit-defensible governance, standards, processes, procedures, methodologies, practices, playbooks, etc. for secure AI adoption and use across application security, vulnerability management, and ethical hacking domains.
  • Lead identification and risk analysis of the external attack surface through development and continuous improvement of automation to drive effective risk exposure response across the business.
  • Create secure AI, including agentic, development practices by establishing and continuously improving reusable skills, prompts, workflows, and guardrails for AI-based tools such that AI generated code adheres to secure coding expectations, including proper input validation, authentication, authorization, secrets handling, logging, error handling, dependency use, and secure design.
  • Drive the use of AI to improve threat modeling, code review, and application security testing; vulnerability analysis, prioritization, and remediation; penetration testing and red teaming; and attack surface discovery, risk analysis, and remediation.
  • Partner with peer domain leaders and practitioners to understand, align, integrate, collaborate, etc. on AI initiatives that realize value to Cyber Defense, Global Enterprise Security, and the business at large.
  • Provides proactive, frequent and consistent communication to key IT and business stakeholders on applicable measures, metrics, KRIs, KPIs, threats, risks, etc. Ensures application security, vulnerability management, ethical hacking outputs, and other attack surface management activities result in proper action, risk management, etc.

May perform additional duties as assigned.

Reporting Relationship

Typically reports to Director or above.

Skills, Knowledge & Abilities

  • In depth understanding of Vulnerability Management, Application Security, Cloud Security, Ethical Hacking, Threat Management, and Security Remediation programs and operations.
  • Strong working knowledge of AI/ML, GenAI, LLM, and agentic AI security concepts, common attack/defense techniques, and use to solve application security, vulnerability management, and ethical hacking domain problems.
  • Demonstrated experience developing and maturing service, tooling, and process automation.
  • Demonstrated experience in software development and/or scripting.
  • Strong understanding of security vulnerabilities and threats and industry standard methodologies of risk managing exposures effectively.
  • Superior analytical and problem-solving skills and the ability to effectively communicate highly technical information to all audiences.
  • Proven ability to interact effectively with senior business leadership to effectively address vulnerabilities and threats in a priority manner.
  • Working knowledge of regulations (e.g., SOX, privacy, etc.) and internal controls as they apply to IT. Routinely stays up to date on current best practices / trends to identify, document, and drive resolution of security exposures through independent and collaborative industry research.
  • Proven ability to influence change and drive the adoption of automation, AI, and agentic AI to applicable domain programs and teams.
  • Ability to work extremely well under pressure while maintaining a professional image and approach.

Education & Experience

  • Bachelor's Degree required or equivalent work experience. Master's Degree in Computer Science or technical field preferred.
  • Typically, a minimum of ten years of information security or related work experience in one or more of the following: application security, vulnerability management or exposure management, ethical hacking, penetration testing, attack surface management, security engineering, or security architecture.
  • Relevant certifications preferred.

#LI-Hybrid

#LI-DM1

In certain jurisdictions, CNA is legally required to include a reasonable estimate of the compensation for this role. In District of Columbia, California, Colorado, Connecticut, Illinois, Maryland, Massachusetts, New York and Washington, the national base pay range for this job level is $97,000 to $189,000 annually.Salary determinations are based on various factors, including but not limited to, relevant work experience, skills, certifications and location. CNA offers a comprehensive and competitive benefits package to help our employees - and their family members - achieve their physical, financial, emotional and social wellbeing goals. For a detailed look at CNA's benefits, please visitcnabenefits.com.


CNAutilizesAI-enabled technology during the recruiting process. For more information, please visitourcareers page.


CNA is committed to providing reasonable accommodations to qualified individuals with disabilities in the recruitment process. To request an accommodation, please contactleaveadministration@cna.com