1

In Penetration Testing Jobs (NOW HIRING)

Minimum six (6) years proven proficiency in performing extensive vulnerability assessment and penetration testing * Minimum three (3) years of experience with testing tools, including NESSUS ...

Senior Penetration Tester

Tampa, FL · On-site

$152K - $260K/yr

We are seeking candidates with a passion for offensive security, deep technical expertise in penetration testing, and a commitment to continuous learning and excellence. Job responsibilities * Plan ...

We are seeking candidates with a passion for offensive security, deep technical expertise in penetration testing, and a commitment to continuous learning and excellence. Job responsibilities * Plan ...

We are seeking candidates with a passion for offensive security, deep technical expertise in penetration testing, and a commitment to continuous learning and excellence. Job responsibilities * Plan ...

We are seeking candidates with a passion for offensive security, deep technical expertise in penetration testing, and a commitment to continuous learning and excellence. Job responsibilities * Plan ...

Minimum six (6) years proven proficiency in performing extensive vulnerability assessment and penetration testing * Minimum three (3) years of experience with testing tools, including NESSUS ...

Penetration Tester

Chantilly, VA · On-site

$90K - $130K/yr

Experience in cyber security with a focus on red teaming, penetration testing, or threat hunting. Desired Qualifications: * Strong understanding of network protocols and troubleshooting, server and ...

Minimum six (6) years proven proficiency in performing extensive vulnerability assessment and penetration testing * Minimum three (3) years of experience with testing tools, including NESSUS ...

next page

Showing results 1-20

In Penetration Testing information

See salary details

$22.5K

$119.9K

$168.5K

How much do in penetration testing jobs pay per year?

As of Jul 20, 2026, the average yearly pay for in penetration testing in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What jobs can I get with a security+ certification?

A Security+ certification qualifies you for roles such as security analyst, cybersecurity technician, or network security administrator. These positions involve implementing security measures, monitoring networks, and responding to security incidents, often requiring knowledge of security tools and protocols.

What are the key skills and qualifications needed to thrive as a Penetration Tester, and why are they important?

To thrive as a Penetration Tester, you need a deep understanding of network protocols, operating systems, security vulnerabilities, and commonly hold certifications like OSCP or CEH. Familiarity with tools such as Metasploit, Burp Suite, Nmap, and Kali Linux is typically required to conduct effective assessments. Strong analytical thinking, attention to detail, and clear communication skills set standout professionals apart in this field. These skills and qualities are crucial for identifying security weaknesses, delivering actionable recommendations, and helping organizations strengthen their cybersecurity defenses.

Will pentesters be replaced by AI?

Penetration testers perform manual security assessments that require critical thinking, creativity, and understanding of complex systems, which AI currently cannot fully replicate. While AI tools can assist in automating certain tasks like vulnerability scanning, human expertise remains essential for interpreting results and developing effective security strategies.

Can you make $500,000 a year in cyber security?

In penetration testing, earning $500,000 annually is possible for highly experienced professionals working in senior roles, consulting, or managing large security teams. Achieving this income typically requires advanced certifications, specialized skills, and extensive industry experience, often in high-demand sectors or with consulting firms. Most penetration testers earn between $70,000 and $150,000 per year, with top-tier experts reaching higher salaries through freelance work or leadership positions.

What is penetration testing?

Penetration testing, often called 'pen testing,' is a simulated cyberattack performed to identify and exploit vulnerabilities in an organization's computer systems, networks, or applications. The goal is to uncover security weaknesses that malicious hackers could exploit and to help organizations strengthen their defenses. Pen testers use various tools and techniques to mimic real-world attacks, providing valuable insights and recommendations for improving overall security. Regular penetration testing is essential for maintaining a robust cybersecurity posture and complying with industry regulations.

What is the difference between In Penetration Testing vs Vulnerability Assessment?

AspectIn Penetration TestingVulnerability Assessment
PurposeSimulates cyberattacks to identify exploitable vulnerabilitiesIdentifies and reports security weaknesses without exploiting them
DepthIn-depth, targeted testing with active exploitationBroad, automated or manual scanning for vulnerabilities
CertificationsOSCP, CEH, GPENOSCP, CEH, CISSP (common but less focused)
Work EnvironmentEngages in simulated attacks, often in controlled environmentsUses scanning tools, reports vulnerabilities

While both roles focus on identifying security issues, In Penetration Testing involves actively exploiting vulnerabilities to assess security defenses, whereas Vulnerability Assessment primarily identifies weaknesses without exploitation. Penetration testers provide deeper insights into potential attack vectors, making their work more targeted and detailed.

What are some common challenges faced by penetration testers during client engagements?

Penetration testers often encounter challenges such as limited timeframes for assessments, incomplete or outdated documentation about client systems, and varying levels of cooperation from internal teams. Navigating complex network architectures and adapting to unique security configurations can also be demanding. Effective communication is essential, as testers must clearly explain findings and remediation steps to both technical and non-technical stakeholders. These challenges require strong problem-solving skills, adaptability, and the ability to work collaboratively across departments.

Is penetration testing a good career?

Penetration testing is a valuable cybersecurity role focused on identifying vulnerabilities in systems and networks. It requires technical skills, knowledge of security tools, and often certifications like OSCP or CEH. The field offers strong job growth, competitive salaries, and opportunities for continuous learning.
More about In Penetration Testing jobs
What cities are hiring for In Penetration Testing jobs? Cities with the most In Penetration Testing job openings:
What states have the most In Penetration Testing jobs? States with the most job openings for In Penetration Testing jobs include:
What job categories do people searching In Penetration Testing jobs look for? The top searched job categories for In Penetration Testing jobs are:
Infographic showing various In Penetration Testing job openings in the United States as of July 2026, with employment types broken down into 1% As Needed, 73% Full Time, 21% Part Time, 1% Temporary, and 4% Contract. Highlights an 92% Physical, 1% Hybrid, and 7% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

Penetration Testing Lead

OCH Technologies LLC

Washington, DC • Hybrid

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 12 days ago


Job description

Description

OCH Technologies is seeking a Penetration Testing Lead responsible for  planning, executing, and documenting all penetration testing activities performed under this contract, including network, system, application, and aircraft cybersecurity assessments. This individual develops Rules of Engagement with system owners, leads red and blue team exercises, and delivers comprehensive penetration test reports that provide actionable, technically sound findings and recommendations. The ideal candidate is an experienced offensive security professional who combines advanced technical expertise with the discipline, sound judgment, and attention to detail required to operate successfully in a highly regulated, safety-critical environment. 


 This position supports a proposal effort and is contingent upon award, customer approval, and successful onboarding requirements.  


Location 


Hybrid - Air Traffic Control System Command Center (ATCSCC) Washington, DC 

This position may require up to 50% travel to FAA facilities.

Core Responsibilities & Duties 

  • Serve as primary technical POC for all penetration testing activities, including network, system, application, aircraft cyber, and specialized assessments. 
  • Develop Rules of Engagement (ROE) with system owners and ACG for each penetration test. Ensure all parties understand scope, constraints, and reporting requirements before testing begins. 
  • Personally lead high-complexity penetration tests in NAS and Mission Support environments. Direct testing teams during execution. 
  • Plan and execute red team and blue team exercises in simulated environments as directed by the FAA. Design realistic attack scenarios that test the effectiveness of NAS cybersecurity defenses. 
  • Document all penetration test results in Penetration Test Reports (PTRs) including attack vectors tested, vulnerabilities discovered, exploitation paths, and recommended remediation actions. 
  • Assess and document impact when access is gained during testing, including potential cascading effects on associated systems and network infrastructure. Report high-risk findings immediately to the FAA. 
  • Lead regression penetration testing to validate that previously identified vulnerabilities have been effectively remediated. 
  • Manage and maintain penetration testing tools and environments. All tools must be FAA-approved. No circumvention of access controls or privilege escalation outside approved ROE. 
  • Attend all Program Management Reviews and report on penetration testing status, findings trends, and upcoming test schedules. 
  • Develop briefings to support POAM development and remediation activities. When requested, provide FAA leadership with prioritized remediation recommendations. 

Responsibilities may evolve over time to support team and organizational goals but will remain consistent with the overall scope of the role. 

Requirements

Minimum Qualifications 


Education 


Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, Physics, or a related technical discipline from an accredited institution. 

Master's degree in a related field preferred. 


Experience 

  • Minimum of fifteen (15) years of cybersecurity experience, including at least 5 years leading or supervising penetration testing teams. 
  • At least two (2) years of relevant experience must have been performed within the last 3 years. 
  • Demonstrated experience planning, executing, and documenting penetration testing engagements in complex, multi-system environments. 
  • Expert-level proficiency with penetration testing tools such as Metasploit, Burp Suite, Nmap, and related frameworks. 
  • Ability to conduct manual testing beyond automated tool output. 
  • Experience conducting manual testing and exploitation beyond automated scanner results. 
  • Deep understanding of NIST SP 800-115, PTES, OWASP, and industry-standard penetration testing methodologies. 
  • Experience developing and operating within formal Rules of Engagement (ROE) for penetration testing.  
  • Experience with red team / blue team exercises including scenario development, execution, and after-action reporting. 
  • Understanding of network exploitation across multi-vendor environments including wireless, routing (Layer 3), switching (Layer 2), firewalls, IDS/IPS, and cloud services. 

Security Clearance Requirement 

Candidate must have the ability to obtain and maintain a Public Trust.  

Active Secret clearance is preferred.  


Certifications 

Security certification such as OSCP, OSCE, OSWP, OSWE, CEH, ECSA, CEH Practical, ECSA Practical, LPT Master, GCIH, GPEN, GWAPT, GXPN, GAWN, or an equivalent industry-recognized credential. 

Additional certifications in cyber defense, incident response, digital forensics, or threat detection disciplines are highly preferred, including CND, CNDA, GCIH, GCIA, GDAT, GDSA, GCED, GCFA, or comparable industry-recognized credentials. 


Preferred Qualifications 

  • Prior experience testing NAS systems, aviation systems, or other air traffic management infrastructure. 
  • Experience with aircraft cyber testing including avionics, flight control systems, or air-ground communications systems. 
  • Experience testing industrial control systems (ICS) or operational technology (OT) environments. 
  • Experience with wireless and satellite-based communication system security testing. 
  • Familiarity with DoD offensive/defensive cyber operations frameworks. 
  • Command-and-control frameworks (Cobalt Strike, Sliver, Mythic) for realistic adversary simulation during red team exercises. 
  • Active Directory attack path analysis tools (BloodHound, Impacket) for identifying lateral movement and privilege escalation paths. 
  • Nuclei for scalable automated vulnerability detection beyond legacy scanner coverage. 
  • Cloud-specific penetration testing tools (Pacu for AWS, AzureHound) for cloud-hosted NAS support systems. 
  • Software-defined radio (SDR/HackRF) tools for testing air-to-ground and wireless communications systems that do not traverse physical networks. 
  • AI-driven fuzzing and adaptive attack path discovery tools for expanding attack surface coverage across complex, interconnected NAS infrastructure. 

Other Required Skills and Abilities 

  • Ability and willingness to travel and lead on-site penetration testing events at FAA facilities nationwide. 
  • Demonstrated ability to operate safely and effectively within mission-critical and operationally sensitive environments. 





About Us: At OCH, we are more than just a government contracting firm; we are innovators and leaders in providing cutting-edge IT services and cybersecurity solutions. Driven by a set of fundamental values, we excel in creating secure, efficient, and forward-thinking solutions that empower the government agencies we work with. Our commitment to maintaining the highest standards of integrity, adapting swiftly to new challenges, and focusing on the people we serve ensures that we consistently exceed expectations and lead the industry in innovation and reliability. 

What Defines Us: 

  • Integrity - We act with unwavering honesty, ensuring every decision is rooted ethically. 
  • Adaptable - We swiftly adapt to changes, seizing opportunities to innovate and lead. 
  • People-Focused - We prioritize relationships, championing growth and mutual success. 
  • Accountable - We own our outcomes, striving for excellence through continuous improvement. 
  • Collaborative - We cultivate teamwork, harnessing diverse talents to forge groundbreaking solutions. 

Why Join Us? 

Step into a role at OCH where your contributions make a tangible impact. Join a team that values creativity and initiative, offering a platform to transform the landscape of government IT services. Here, your work is not just a career-it's a mission. Embrace the opportunity to grow, innovate, and excel alongside industry leaders who are as passionate about technology as they are about making a difference. Plus, we offer a comprehensive benefits package designed to support your wellbeing and work-life balance, including: 

  • Paid time off and Holidays 
  • Medical, Dental, and Vision Insurance 
  • Paid Parental Leave 
  • Short-term disability, long-term disability, and life insurance - Employer Paid! 
  • 401(k) 
  • Additional Voluntary Life Insurance 
  • Tuition Reimbursement 

& More! 


E-Verify Participation: OCH Technologies, LLC is a participant of E-Verify to verify the identity and employment eligibility of newly hired employees. 


Veteran's Preference and Accessibility Statement: At OCH Technologies, we deeply respect and appreciate the unique skills and experiences that veterans bring to our team. As a federal contractor, we encourage qualified veterans to apply and provide preference where permitted by law. Your service and dedication are valued here. 


We are committed to creating a workplace that is open, welcoming, and accessible to everyone. In accordance with the Americans with Disabilities Act (ADA) and Section 503 of the Rehabilitation Act, we provide reasonable accommodations throughout the hiring process to ensure individuals with disabilities can apply without barriers. If you need assistance or an accommodation, please contact us at hiring@ochtec.com.  


OCH Technologies, LLC is proud to be an equal opportunity employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, disability, gender identity, or any other protected characteristic as outlined by federal, state, or local laws.Â