2

Full Time Cybersecurity Penetration Tester Jobs (NOW HIRING)

The Cybersecurity Penetration Tester is a hands-on technical role responsible for conducting simulated attacks on systems and networks to identify vulnerabilities and weaknesses that could be ...

... Penetration Tester responsible for supporting authorized penetration testing and security ... cybersecurity requirements. Responsibilities : • Supports execution of authorized penetration ...

They are seeking a Penetration Tester I to perform proactive cybersecurity penetration attacks on digital systems, document actions in detail, and create reports on security breaches.

Holds or is working toward penetration testing and offensive security certifications appropriate ... cybersecurity certifications. Required Education: BS/BA degree Required Experience: 5 years ...

Assists with planning, scoping, and execution of penetration tests in coordination with Government stakeholders and senior cybersecurity personnel. Conducts technical testing activities, including ...

Possess extensive knowledge of cybersecurity frameworks, industry standards, and advanced security ... UNAVAILABLEEmployment Type: FULL_TIME

Penetration Tester

Herndon, VA · On-site

$131K - $237K/yr

We are looking for a cyber security professional to conduct penetration testing and ethical hacking, to target, assess, and exploit risk and vulnerabilities of information systems. This candidate is ...

Penetration Tester

Chantilly, VA · On-site

$150K - $195K/yr

Possess extensive knowledge of cybersecurity frameworks, industry standards, and advanced security ... TS/SCI with Poly Level 2 Penetration Tester: Education: Bachelor's Degree or Higher, AND Pen Tester ...

Possess extensive knowledge of cybersecurity frameworks, industry standards, and advanced security ... UNAVAILABLEEmployment Type: FULL_TIME

Penetration Tester

Washington, DC · On-site

$130K - $145K/yr

Performing a Cybersecurity evaluation of the product under test to identify vulnerabilities that would negatively impact the Confidentiality, Integrity, or Availability of system data or ...

next page

Showing results 1-20

Full Time Cybersecurity Penetration Tester information

See salary details

$22.5K

$119.9K

$168.5K

How much do full time cybersecurity penetration tester jobs pay per year?

As of Jul 26, 2026, the average yearly pay for full time cybersecurity penetration tester in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What is the difference between Full Time Cybersecurity Penetration Tester vs Cybersecurity Analyst?

AspectFull Time Cybersecurity Penetration TesterCybersecurity Analyst
CertificationsOSCP, CEH, GPENCISSP, Security+
Work EnvironmentConducts simulated attacks, penetration testing labsMonitors security systems, analyzes threats
Employer & Industry UsageSecurity firms, IT departments, consultingCorporate, government, financial sectors
Search & Comparison IntentUnderstanding penetration testing rolesUnderstanding security monitoring roles

The main difference is that a Full Time Cybersecurity Penetration Tester focuses on actively testing systems for vulnerabilities through simulated attacks, requiring certifications like OSCP or CEH. In contrast, a Cybersecurity Analyst primarily monitors security alerts, analyzes threats, and maintains security infrastructure. Both roles are vital in cybersecurity but serve different functions within an organization.

More about Full Time Cybersecurity Penetration Tester jobs
What cities are hiring for Full Time Cybersecurity Penetration Tester jobs? Cities with the most Full Time Cybersecurity Penetration Tester job openings:
What are the most commonly searched types of Cybersecurity Penetration Tester jobs? The most popular types of Cybersecurity Penetration Tester jobs are:
Infographic showing various Full Time Cybersecurity Penetration Tester job openings in the United States as of July 2026, with employment types broken down into 3% Locum Tenens, 89% Full Time, 5% Part Time, and 3% Contract. Highlights an 82% Physical, 6% Hybrid, and 12% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.
Principal, Cybersecurity Penetration Tester

Principal, Cybersecurity Penetration Tester

Fidelity Investments

Durham, NC

Full-time

Posted 9 days ago


Fidelity Investments rating

8.8

Company rating: 8.8 out of 10

Based on 269 frontline employees who took The Breakroom Quiz

9th of 150 rated financial services


Job description

Job Description:

Position Description:

Performs security assessments of applications prior to production deployment using Static Code Analysis, dynamic testing tools, and manual techniques. Assists in establishing the strategy, policy, and standards of security for cybersecurity operations. Develop custom Python scripts to automate repetitive tasks. Defends enterprise against attacks, damage, and unauthorized access to information, data, and systems. Ensures threat and vulnerability reduction, deterrence, incident response, resiliency, and recovery policies and activities are up to date. Proactively identifies vulnerabilities in proprietary applications prior to production release and remediates identified vulnerabilities to prevent real-life cyberattacks.

Primary Responsibilities:

  • Performs advanced Web application source code auditing.
  • Analyzes codes, writes scripts, and exploits web vulnerabilities.
  • Analyzes test results, draw conclusions from results.
  • Identifies vulnerabilities by performing thorough evaluations of security vulnerabilities on Web and mobile applications.
  • Collaborates with application developers to mitigate risk and improve security posture.
  • Performs security testing on web and mobile applications to support production releases.
  • Models potential external threats by replicating the techniques and tools used by malicious attackers.
  • Prepares reports on completed assessments and present results to application owners, developers, and business unit information security teams.
  • Consults with operations and software development teams to ensure potential weaknesses are addressed.
  • Contributes to the research and development of tools to assist in the vulnerability discovery process.
  • Keeps abreast of current cybersecurity best practices and vulnerabilities.
  • Conducts peer reviews to facilitate continuous improvement across the team.

Education and Experience:

Bachelor's degree in Computer Science, Engineering, Information Technology, Information Systems, or a closely related field (or foreign education equivalent) and five (5) years of experience as a Principal, Cybersecurity Penetration Tester (or closely related occupation) performing black and white box testing to protect against cyber threats and ensure application security (web, mobile, API, and thick client).

Or, alternatively, Master's degree in Computer Science, Engineering, Information Technology, Information Systems, or a closely related field (or foreign education equivalent) and three (3) years of experience as a Principal, Cybersecurity Penetration Tester (or closely related occupation) performing black and white box testing to protect against cyber threats and ensure application security (web, mobile, API, and thick client).

Skills and Knowledge:

Candidate must also possess:

  • Demonstrated Expertise ("DE") estimating risks on security flaws uncovered during static or dynamic analysis in line with the OWASP testing guide; conducting pen-testing on applications to uncover security vulnerabilities - Injection attacks, Server-side attacks, Privilege escalation, GraphQL batching attacks, or JWT signature manipulation attacks - using BurpSuite Professional Edition, Fiddler, Kali Linux, and SQLMap.
  • DE analyzing source code for security weaknesses, writing custom scripts, exploiting security vulnerabilities, and conducting retests to determine mitigation measures implemented by development teams, through a combination of manual analysis by using BurpSuite Professional, and automated scans using GitHub Advanced Security(GHAS) and MEND.
  • DE analyzing Common Vulnerability Exposure (CVE) on third party libraries, using Veracode SCA, MEND, Exploit-DB, and NVD databases; and coordinating actions associated with the dismissal or reopening of policy violation alerts related to security, licensing, and coding standards using GitHub Advanced Security (GHAS).
  • DE crafting custom scripts to effectively automate labor-intensive manual tasks (logging security findings, preparing weekly status reports, verifying artifact correctness) and empower the efficient allocation of resources, enhancing the overall security assessment process, using Python or Selenium.

#PE1M2

#LI-DNI

Certifications:Category:Information Technology

Please be advised that Fidelity's business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.


What Fidelity Investments employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom