1

Ethical Penetration Testing Jobs in Merced, CA (NOW HIRING)

Ethical Penetration Testing information

See Merced, CA salary details

$23.8K

$126.6K

$177.9K

How much do ethical penetration testing jobs pay per year?

As of Sep 1, 2026, the average yearly pay for ethical penetration testing in Merced, CA is $126,612.00, according to ZipRecruiter salary data. Most workers in this role earn between $101,400.00 and $148,900.00 per year, depending on experience, location, and employer.

What is ethical penetration testing?

Ethical penetration testing, also known as ethical hacking, is the practice of simulating cyberattacks on a computer system, network, or application with the permission of its owner. The goal is to identify security vulnerabilities before malicious hackers can exploit them. Ethical penetration testers use the same tools and techniques as cybercriminals but report findings so they can be fixed, helping organizations strengthen their security. This process is a critical part of a comprehensive cybersecurity program and helps ensure compliance with industry regulations.

What are the key skills and qualifications needed to thrive as an ethical penetration tester?

To thrive as an Ethical Penetration Tester, you need strong knowledge of network security, operating systems, and common vulnerabilities, typically backed by a degree in computer science or cybersecurity and relevant certifications like CEH or OSCP. Familiarity with tools such as Metasploit, Burp Suite, and Nmap is essential for simulating and assessing security threats. Critical thinking, problem-solving, and effective communication are key soft skills for identifying risks and clearly reporting findings to technical and non-technical stakeholders. These competencies ensure that security assessments are thorough, actionable, and help organizations strengthen their defenses against real-world cyber threats.

What are some common challenges faced by ethical penetration testers during client engagements?

Ethical penetration testers often encounter challenges such as limited timeframes to conduct thorough assessments, incomplete or ambiguous scope definitions from clients, and the need to balance effective testing with minimal disruption to live systems. Communication is key—testers must clearly report findings and collaborate with IT teams to remediate vulnerabilities. Additionally, staying current with emerging threats and tools is essential to deliver valuable insights and maintain industry standards.

What is the difference between Ethical Penetration Testing vs Vulnerability Analyst?

AspectEthical Penetration TestingVulnerability Analyst
CertificationsOSCP, CEH, GPENCompTIA Security+, CISSP, CEH
Work EnvironmentSimulated attacks on systems to identify security gapsAnalyzing vulnerabilities and assessing risk levels
Industry UsageSecurity firms, IT departments, consultingSecurity teams, risk management, compliance

Ethical Penetration Testers actively simulate cyberattacks to find exploitable weaknesses, while Vulnerability Analysts focus on identifying and prioritizing security flaws through assessments. Both roles require similar certifications and often work within the same industry sectors, but their core activities differ: testing versus analysis.

What are popular job titles related to Ethical Penetration Testing jobs in Merced, CA?

For Ethical Penetration Testing jobs in Merced, CA, the most frequently searched job titles are:

What cities near Merced, CA are hiring for Ethical Penetration Testing jobs?

Cities near Merced, CA with the most Ethical Penetration Testing job openings:

Spring & Summer 2027 Intern - Security & GRC

Workiva

Merced, CA • On-site

$40/hr

Other

Retirement

Posted 4 days ago


Workiva rating

9.9

Company rating: 9.9 out of 10

Based on 7 frontline employees who took The Breakroom Quiz

1st of 247 rated software companies


Job description

The Security Intern is an integral part of the Information Security team at Workiva. You will help solve security issues, develop tools to assist with security threats, and assist with vulnerability testing of web applications. This role may involve making recommendations on security controls and collaborating with internal stakeholders.

What You'll Do

  • Provide Incident Response support when an actionable incident is confirmed
  • Document, investigate, and report on information security issues and emerging trends
  • Manage and configure tools and devices to expand our security monitoring infrastructure
  • Develop tools to assist with security and compliance tasks
  • Assist with continual vulnerability testing of web applications to identify weaknesses
  • Research and identify potential security controls to fix active vulnerabilities
  • Collaborate with other teams to create remediation strategies and timelines for vulnerabilities
  • Develop queries and visualizations to assist with security and compliance tasks
  • Help solve security issues identified in the production application
  • Provide analysis and trending of security log data from a large number of various security devices
  • Collaborate with other teams to gather information regarding security problems, issues, and ideas

What You'll Need

Minimum Qualifications

  • Currently enrolled in a degree-seeking program, preferably in Computer Engineering, Computer Science, Management Information Systems, or a similar degree

Preferred Qualifications

  • Strong ethical and discretionary ability to handle sensitive information and data
  • Strong communication and networking skills (written, verbal, listening)
  • Basic competency in one or more programming languages (Python, Java, SQL, Go, and/or Dart)
  • Familiarity with vulnerability scanning tools and/or penetration testing techniques
  • Familiarity with Amazon Web Services (AWS) and/or Google App Engine (GAE)
  • Working knowledge of Linux/Unix operating systems
  • If Security Engineering focused: Ability to analyze problems and devise creative solutions within business constraints; good understanding of HTTP and common web application vulnerabilities
  • If Security Operations focused: Self-motivation and initiative skills to search for and resolve security issues; initiative and social skills to network with technical individuals to gather information on projects

Travel Requirements & Working Conditions

  • Minimal travel
  • Reliable internet access for any period of time working remotely and not in a Workiva office

Location: This internship is primarily a remote opportunity. However, if you are located near one of our office hubs, you are welcome to work in a hybrid capacity and utilize our office spaces. Check out our article on Workplace Flexibility to learn more.

When can you expect to hear back?

We are committed to attending all career fairs and recruitment events before closing our positions. That means, this position might be open without updates for a few weeks to give us time to connect with all potential candidates before wrapping up the recruitment season. Check out our tentative timeline below to see when you can expect to hear from us!

Postings close: September 27, 2026

Engineering postings close: October 2, 2026

Interviews: Early to mid October

Offers: Late October

2027 Start Dates:

This position has opportunities to start in the Spring or Summer. Please see our start dates below and let us know your availability in your application.

  • Spring 2027 Internships: Monday, January 4, 2027 (15-20 hours per week max)
  • Summer 2027 Internships: Monday, May 17, 2027 (40/hours per week max)

How You’ll Be Rewarded

Salary range in the US: $40.00 - $40.00 401(k) participation and match Paid sick leave A unique opportunity to further your learning experience through additional internship seasons

Why Join Workiva

Workiva is the platform designed to bring confidence, control, and a competitive edge to the world’s most complex organizations. Our AI-powered platform unifies finance, risk, and sustainability on a single, secure foundation-ensuring data is trusted, traceable, and ready to act on. With an unbroken path from source to output, leaders gain confidence in their numbers, visibility into current and emerging risks, and the ability to move with speed and precision in a constantly changing world.

At Workiva, you’ll bring technology to market that executives, boards, and regulators depend on. The work you do here helps organizations navigate uncertainty, maintain trust, and make decisions that stand up to scrutiny. If you’re energized by meaningful challenges, inspired by collaborative teams, and motivated to help organizations turn uncertainty into advantage, we’d love to meet you.

Employment decisions are made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other protected characteristic.

Workiva is committed to working with and providing reasonable accommodations to applicants with disabilities. To request assistance with the application process, please email earlycareer@workiva.com.

Workiva employees are required to undergo comprehensive security and privacy training tailored to their roles, ensuring adherence to company policies and regulatory standards.

Workiva supports employees in working where they work best - either from an office or remotely from any location within their country of employment.


What Workiva employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom