1

Ethical Penetration Testing Jobs (NOW HIRING)

Penetration Tester

Rensselaer, NY · On-site

$90K - $105K/yr

Experience in penetration testing or ethical hacking with a focus on Java application security. * Experience with penetration testing tools such as Burp Suite and Metasploit. * Familiarity with ...

Possess a certification in penetration testing, such as: * Licensed Penetration Tester (LPT) * Certified Expert Penetration Tester (CEPT) * Certified Ethical Hacker (CEH) * Global Information ...

Showing results 21-40

Ethical Penetration Testing information

See salary details

$22.5K

$119.9K

$168.5K

How much do ethical penetration testing jobs pay per year?

As of Sep 11, 2026, the average yearly pay for ethical penetration testing in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What is ethical penetration testing?

Ethical penetration testing, also known as ethical hacking, is the practice of simulating cyberattacks on a computer system, network, or application with the permission of its owner. The goal is to identify security vulnerabilities before malicious hackers can exploit them. Ethical penetration testers use the same tools and techniques as cybercriminals but report findings so they can be fixed, helping organizations strengthen their security. This process is a critical part of a comprehensive cybersecurity program and helps ensure compliance with industry regulations.

What are the key skills and qualifications needed to thrive as an ethical penetration tester?

To thrive as an Ethical Penetration Tester, you need strong knowledge of network security, operating systems, and common vulnerabilities, typically backed by a degree in computer science or cybersecurity and relevant certifications like CEH or OSCP. Familiarity with tools such as Metasploit, Burp Suite, and Nmap is essential for simulating and assessing security threats. Critical thinking, problem-solving, and effective communication are key soft skills for identifying risks and clearly reporting findings to technical and non-technical stakeholders. These competencies ensure that security assessments are thorough, actionable, and help organizations strengthen their defenses against real-world cyber threats.

What are some common challenges faced by ethical penetration testers during client engagements?

Ethical penetration testers often encounter challenges such as limited timeframes to conduct thorough assessments, incomplete or ambiguous scope definitions from clients, and the need to balance effective testing with minimal disruption to live systems. Communication is key—testers must clearly report findings and collaborate with IT teams to remediate vulnerabilities. Additionally, staying current with emerging threats and tools is essential to deliver valuable insights and maintain industry standards.

What is the difference between Ethical Penetration Testing vs Vulnerability Analyst?

AspectEthical Penetration TestingVulnerability Analyst
CertificationsOSCP, CEH, GPENCompTIA Security+, CISSP, CEH
Work EnvironmentSimulated attacks on systems to identify security gapsAnalyzing vulnerabilities and assessing risk levels
Industry UsageSecurity firms, IT departments, consultingSecurity teams, risk management, compliance

Ethical Penetration Testers actively simulate cyberattacks to find exploitable weaknesses, while Vulnerability Analysts focus on identifying and prioritizing security flaws through assessments. Both roles require similar certifications and often work within the same industry sectors, but their core activities differ: testing versus analysis.

More about Ethical Penetration Testing jobs

What cities are hiring for Ethical Penetration Testing jobs?

Cities with the most Ethical Penetration Testing job openings:

What states have the most Ethical Penetration Testing jobs?

States with the most job openings for Ethical Penetration Testing jobs include:

What other helpful pages are available for Ethical Penetration Testing?

Other pages related to Ethical Penetration Testing:

Infographic showing various Ethical Penetration Testing job openings in the United States as of September 2026, with employment types broken down into 1% Internship, 1% As Needed, 84% Full Time, 10% Part Time, 3% Contract, and 1% Nights. Highlights an 89% Physical, 2% Hybrid, and 9% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

Penetration Tester

Rensselaer, NY • On-site

$90K - $105K/yr

Other

Posted 24 days ago


Job description

Career Opportunities with Amatriot Group, LLC

A great place to work.

Share with friends or Subscribe!

Are you ready for new challenges and new opportunities?

Join our team!

Current job opportunities are posted here as they become available.

Subscribe to our RSS feeds to receive instant updates as new positions become available.

Location: Albany, NY
Security Clearance: None
Job Type: Full-Time

Target Salary Range*:$90,000 - $105,000

*This represents the potential salary range for this position depending on education level, years of experience and/or certifications in addition to other position specific requirements which may impact salary

Position Overview

A Penetration Tester with a focus on Java application security identifies, exploits, and supports remediation of vulnerabilities in Java applications to help guard against cyber threats.

Key ResponsibilitiesPenetration Testing and Vulnerability Assessment
  • Conduct penetration tests and vulnerability assessments for Java applications and infrastructure.
  • Identify security flaws in Java code using automated and manual methods.
  • Create and use custom exploits to test application security, simulating attacker tactics.
  • Assist in responding to security incidents related to Java vulnerabilities and current published NIST CVEs.
Secure Development and Remediation Support
  • Collaborate with development teams to understand application architecture and identify security weaknesses early.
  • Collaborate with testing teams to integrate security testing with manual and automated testing.
  • Provide guidance on secure coding and vulnerability remediation.
  • Contribute to security policies for Java development and deployment.
Reporting, Communication, and Threat Awareness
  • Clearly document and report findings, including technical details, risk assessments and recommended solutions.
  • Communicate findings and recommendations to both technical and non-technical staff.
  • Stay updated on Java security threats and best practices.
  • Apply familiarity with the MITRE ATT&CK Framework.
QualificationsEducation
  • Bachelor’s degree in Computer Science, Information Security, or a related field.
Experience
  • Minimum of 6 years of development or security experience. [Required]
  • Experience in penetration testing or ethical hacking with a focus on Java application security.
  • Experience with penetration testing tools such as Burp Suite and Metasploit.
  • Familiarity with Fortify on Demand SAST and DAST tools.
Skills
  • Strong knowledge of Java programming and Java security practices.
  • Scripting experience.
  • Proficiency in web application security principles, including OWASP.
  • Knowledge of common web vulnerabilities, including SQL injection and cross-site scripting, and exploit techniques.
  • Strong understanding of cryptography and secure communication protocols, including SSL/TLS.
  • Excellent problem-solving and analytical skills.
  • High ethical standards and confidentiality.
  • Familiarity with the MITRE ATT&CK Framework.
Preferred Qualifications
  • Certifications such as OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP, or other industry security certifications.
  • Experience with scripting languages, such as Python or Bash.
  • Experience with secure code review for Java.
  • Familiarity with cloud security testing.
  • Experience with mobile application penetration testing.
#J-18808-Ljbffr