1

Graduate Penetration Tester Jobs (NOW HIRING)

Code Review Software/Application Penetration Testing Architecture Security Analysis and Threat ... Top graduate in Computer Science, Engineering, Math or related field Compensation & Work Location:

SOC Analyst II

Raleigh, NC · On-site

$105K - $158K/yr

Whatever your role, working for WGU gives you a part to play in helping students graduate, creating ... Advanced experience with penetration testing, threat detection engineering, or digital forensics

SOC Analyst II

Raleigh, NC · On-site

$105K - $158K/yr

Whatever your role, working for WGU gives you a part to play in helping students graduate, creating ... Advanced experience with penetration testing, threat detection engineering, or digital forensics

Foundation Data Security Manager

Auburn, AL · On-site

$95K - $128K/yr

... and develops penetration testing, firewall and related infrastructure management, and network ... Auburn University is an institute of higher learning that offers undergraduate and graduate courses.

next page

Showing results 1-20

Graduate Penetration Tester information

See salary details

$22.5K

$119.9K

$168.5K

How much do graduate penetration tester jobs pay per year?

As of Jun 9, 2026, the average yearly pay for graduate penetration tester in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What are some common challenges faced by Graduate Penetration Testers during their first year on the job?

Graduate Penetration Testers often encounter challenges such as adapting to rapidly changing security technologies and learning to effectively document and communicate their findings to both technical and non-technical stakeholders. They must also develop strong time management skills to balance multiple assessments or projects at once and become familiar with a wide range of systems and environments. Working closely with experienced team members and participating in debrief meetings helps new testers quickly build their technical and soft skills.

What are graduate penetration testers?

Graduate penetration testers are entry-level cybersecurity professionals who assess the security of computer systems, networks, and applications by simulating cyberattacks. They identify vulnerabilities that malicious hackers could exploit, helping organizations strengthen their defenses. Typically, graduate penetration testers have recently completed a relevant degree or training and work under the supervision of experienced testers to develop their skills. Their work often involves conducting tests, preparing reports, and recommending security improvements.

What are the key skills and qualifications needed to thrive as a Graduate Penetration Tester, and why are they important?

To thrive as a Graduate Penetration Tester, you need a solid understanding of network security, operating systems, and vulnerability assessment, typically backed by a computer science degree or related qualification. Familiarity with tools like Metasploit, Burp Suite, and knowledge of industry certifications such as OSCP or CEH is highly advantageous. Analytical thinking, attention to detail, and strong written and verbal communication skills help you stand out in this role. These abilities are crucial for identifying security weaknesses, effectively reporting findings, and helping organizations strengthen their cybersecurity posture.

What is the difference between Graduate Penetration Tester vs Cybersecurity Analyst?

AspectGraduate Penetration TesterCybersecurity Analyst
CertificationsCompTIA Security+, CEH (Certified Ethical Hacker)CompTIA Security+, CISSP (entry-level roles)
Work EnvironmentHands-on security testing, simulated attacksMonitoring security systems, incident response
Industry UsageSecurity firms, consulting, internal security teamsOrganizations' security operations centers (SOCs)

While both roles focus on cybersecurity, a Graduate Penetration Tester specializes in identifying vulnerabilities through simulated attacks, requiring skills in ethical hacking. A Cybersecurity Analyst monitors and responds to security threats, focusing on defense and incident management. Both roles often share certifications like Security+ but differ in daily tasks and work environment.

More about Graduate Penetration Tester jobs
What job categories do people searching Graduate Penetration Tester jobs look for? The top searched job categories for Graduate Penetration Tester jobs are:
Infographic showing various Graduate Penetration Tester job openings in the United States as of June 2026, with employment types broken down into 45% Full Time, 16% Part Time, 38% Contract, and 1% Summer. Highlights an 59% Physical, 1% Hybrid, and 40% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

Full-time

Posted 2 days ago


Job description

Company Description

Cigital, Inc. headquartered in Dulles, Virginia (just outside of Washington, D.C.), is the world's largest consulting firm specializing in software security and is the global leader in helping organizations design, build, and maintain secure software. Our unique expertise, product technologies, and training services are a culmination of over twenty years of research and thousands of successful software security consulting engagements at leading public and private organizations throughout the world.


We provide a comprehensive range of software security services including consulting, training in both instructor-led and eLearning, mobile application security, and cloud services aimed at addressing the potential security risks associated with third-party or outsourced software. Whether it's a simple penetration test or deploying an end-to-end software security program, our expert consultants have both the depth of knowledge and breadth of real-world experience to understand the risks and challenges our clients face each day.


Cigital was established in 1992 with funding and contracts from DARPA and NASA. The creation of Cigital Labs Research in the mid 1990's resulted in some of the most important advancements in software security including the development of the first ever commercial Static Analysis tool, ITS4. The technology in this product was eventually licensed to Kleiner Perkins and used as the basis for the creation of Fortify Software in 1999. Fortify went on to become the global leader in the Static Analysis tool marketplace and was sold to Hewlett Packard in 2010. Cigital Labs has been awarded 8 different patents in areas dealing with software security. 

Job Description

As Cigital engages with clients in the application of our software security improvement methodologies, the Security Consultant joins in the execution and delivery of planned project deliverables and milestones that assist clients in learning, understanding, and applying Cigital's secure software development methodologies. The Security Consultant typically has task responsibility within one project and develops the capability to perform tasks within one or more of Cigital's security practices. The Security Consultant continuously learns and expands his/her technical competence. Security Consultants do some work from the office, but often go on site to help customers exterminate the bugs and untangle the flaws that make their systems insecure. Our Security Consultants make themselves and their team indispensable advisors to our customers: they build the relationships that help create and identify follow-on assignments.

The ideal candidate will possess expertise in several of the following areas:

Code Review

Software/Application Penetration Testing

Architecture Security Analysis and Threat Modeling

Secure Software Design, Architecture, and Engineering

Software/Application Reverse Engineering

Red Team Analysis (including network, wireless, physical, and social engineering techniques)

Database Security

Qualifications

Technical Skills

o Familiarity with software security weakness, vulnerability and secure code review a plus

o Familiarity with software attack and exploitation techniques a plus

o Familiarity with at least one software programming language and framework a plus

o Experience with C/C++, .NET, Java, multiple OS and RDBMS

o Experience with other languages (e.g. JavaScript, Python, Ruby, PHP, Perl, COBOL, SQL, or Assembly) (Desired)

o Experience conducting secure code review a plus

o Experience conducting reverse engineering a plus

o Experience performing web application penetration testing a plus

Consulting skills

o Ability to interface with clients, utilizing consulting and negotiating skills

o Ability to undertake and complete tasks independently, meet schedules and delivery timelines, and to move swiftly from concepts and theory to action

Team-oriented skills

o Ability to collaborate with project team members, take direction from the project lead and execute tasks consistently

Project Management

o Awareness of end-to-end project management life-cycle including planning, execution and closeout

Communication

o Written communication skills for use in preparing formal documentation, Statements of Work, proposals, white papers, and case studies

o Verbal skills that include the ability to clearly articulate thoughts and to deliver presentation and training to all levels of management

o Ability to persuade

Demeanor

o Enthusiasm and commitment along with professional interpersonal skills and an entrepreneurial drive

o Willingness to travel 40-60%

Additional Information


Education and Certifications:

Top graduate in Computer Science, Engineering, Math or related field

Compensation & Work Location:

Cigital is based in Dulles, Virginia, with offices in Amsterdam, Atlanta, Bloomington, Boston, Chicago, Dallas, London, New York, Dallas, San Diego, Santa Clara, Seattle, and works with clients worldwide. We offer a competitive salary, equity compensation, and benefits.