1

In Penetration Testing Jobs (NOW HIRING)

... in business processes, application/services, to enhance overall security posture and assurance. * Identification of emerging vulnerabilities, exploit codes and cyber-attacks to develop testing ...

Minimum six (6) years proven proficiency in performing extensive vulnerability assessment and penetration testing * Minimum three (3) years of experience with testing tools, including NESSUS ...

... in business processes, application/services, to enhance overall security posture and assurance. * Identification of emerging vulnerabilities, exploit codes and cyber-attacks to develop testing ...

Conduct application, network, and wireless penetration testing in accordance with approved methodologies and rules of engagement. * Identify security flaws in computing platforms, applications, and ...

Responsibilities Independently performs penetration testing of applications, systems and enclaves Identifies security flaws in computing platforms and applications and devise strategies and ...

next page

Showing results 1-20

In Penetration Testing information

See salary details

$22.5K

$119.9K

$168.5K

How much do in penetration testing jobs pay per year?

As of Jun 30, 2026, the average yearly pay for in penetration testing in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Penetration Tester, and why are they important?

To thrive as a Penetration Tester, you need a deep understanding of network protocols, operating systems, security vulnerabilities, and commonly hold certifications like OSCP or CEH. Familiarity with tools such as Metasploit, Burp Suite, Nmap, and Kali Linux is typically required to conduct effective assessments. Strong analytical thinking, attention to detail, and clear communication skills set standout professionals apart in this field. These skills and qualities are crucial for identifying security weaknesses, delivering actionable recommendations, and helping organizations strengthen their cybersecurity defenses.

What is penetration testing?

Penetration testing, often called 'pen testing,' is a simulated cyberattack performed to identify and exploit vulnerabilities in an organization's computer systems, networks, or applications. The goal is to uncover security weaknesses that malicious hackers could exploit and to help organizations strengthen their defenses. Pen testers use various tools and techniques to mimic real-world attacks, providing valuable insights and recommendations for improving overall security. Regular penetration testing is essential for maintaining a robust cybersecurity posture and complying with industry regulations.

What is the difference between In Penetration Testing vs Vulnerability Assessment?

AspectIn Penetration TestingVulnerability Assessment
PurposeSimulates cyberattacks to identify exploitable vulnerabilitiesIdentifies and reports security weaknesses without exploiting them
DepthIn-depth, targeted testing with active exploitationBroad, automated or manual scanning for vulnerabilities
CertificationsOSCP, CEH, GPENOSCP, CEH, CISSP (common but less focused)
Work EnvironmentEngages in simulated attacks, often in controlled environmentsUses scanning tools, reports vulnerabilities

While both roles focus on identifying security issues, In Penetration Testing involves actively exploiting vulnerabilities to assess security defenses, whereas Vulnerability Assessment primarily identifies weaknesses without exploitation. Penetration testers provide deeper insights into potential attack vectors, making their work more targeted and detailed.

What are some common challenges faced by penetration testers during client engagements?

Penetration testers often encounter challenges such as limited timeframes for assessments, incomplete or outdated documentation about client systems, and varying levels of cooperation from internal teams. Navigating complex network architectures and adapting to unique security configurations can also be demanding. Effective communication is essential, as testers must clearly explain findings and remediation steps to both technical and non-technical stakeholders. These challenges require strong problem-solving skills, adaptability, and the ability to work collaboratively across departments.
More about In Penetration Testing jobs
What cities are hiring for In Penetration Testing jobs? Cities with the most In Penetration Testing job openings:
What states have the most In Penetration Testing jobs? States with the most job openings for In Penetration Testing jobs include:
What job categories do people searching In Penetration Testing jobs look for? The top searched job categories for In Penetration Testing jobs are:
Infographic showing various In Penetration Testing job openings in the United States as of June 2026, with employment types broken down into 11% As Needed, and 89% Contract. Highlights an 83% Physical, 3% Hybrid, and 14% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

Cyber Penetration Tester SME- Active TS (SCI and CI/Poly Eligible)

Vibrint

Reston, VA โ€ข On-site

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 3 days ago


Key responsibilities

  • Conduct advanced penetration testing across networks, systems, applications, and cloud environments to identify and validate security weaknesses.

  • Analyze security architectures and provide actionable remediation recommendations to strengthen defensive posture.

  • Train, mentor, and develop junior analysts in penetration testing methodologies and offensive security techniques.


Job description

Vibrint is a trusted provider of mission-critical systems and analysis that transform our customers' capacity and capability in harvesting and harnessing data. Working alongside many of the most talented professionals in public service, we work tirelessly to create and sustain new solutions and services that meet the stringent demands across a variety of customer missions.

Our people know they'll be doing work that matters at the heart of the national security mission, exploring new possibilities at the cutting edge of technology. They know they will be well-rewarded and recognized for their commitment. Our people know they will enjoy plentiful opportunities to grow, thrive, and have fun as a member of the Vibrint family. Join Vibrint, where your career is a priority, and your future is our shared goal.

_____________________________________________________________

We are seeking a highly skilled and proactive Penetration Testing SME to join our Cybersecurity team. As a Penetration Testing SME, you will play a critical role in protecting our clients' infrastructure and data by identifying, testing, and validating security weaknesses across networks, systems, applications, and cloud environments. You will work closely with security engineers, incident responders, system owners, and other stakeholders to assess risk, recommend remediation strategies, and strengthen overall defensive posture. This role also requires the ability to train, mentor, and upskill analysts and team members in penetration testing methodologies, offensive security techniques, and adversary tradecraft.

Required Skills:

The candidate shall be able to:

  • Conduct advanced penetration testing across enterprise and government environments, including network, web application, wireless, and internal/external assessments
  • Perform authorized exploitation and post-exploitation activities to validate risk and demonstrate real-world attack impact
  • Develop and execute penetration testing methodologies, tactics, techniques, and procedures aligned with industry best practices
  • Analyze security architectures, configurations, and controls to identify gaps and provide actionable remediation recommendations
  • Produce clear, comprehensive technical reports and executive summaries outlining findings, risk, and mitigation strategies
  • Collaborate with blue teams, incident responders, system owners, and developers to improve security posture and validate remediation efforts
  • Stay current on adversary tactics, emerging vulnerabilities, and offensive security trends to continuously enhance testing capabilities
  • Provide technical leadership and oversight for penetration testing activities across the team
  • Train, mentor, and develop junior analysts through hands-on instruction, workshops, and knowledge-sharing sessions
  • Guide team members on offensive tools, methodologies, reporting standards, and operational best practices

Desired Skills:

  • Advanced Penetration Testing Expertise: Proven experience leading and conducting complex penetration tests in enterprise or federal environments, including adversary emulation, red team-style assessments, and validation of security controls against advanced threats
  • Technical Proficiency in Offensive Security Tooling: Hands-on experience with tools such as Kali Linux, Metasploit, Burp Suite Pro, Cobalt Strike, Nmap, Nessus, BloodHound, Impacket, and other offensive security platforms used for enumeration, exploitation, and reporting
  • Training and Mentorship Experience: Demonstrated ability to train analysts and junior personnel in penetration testing concepts, offensive tooling, attack lifecycle methodology, and reporting standards
  • Application and Infrastructure Security Knowledge: Strong understanding of web application security, Active Directory exploitation, privilege escalation, lateral movement, cloud security testing, and common attack vectors affecting modern enterprise environments
  • Analytical and Collaborative Mindset: Strong ability to analyze complex environments, simulate realistic attack scenarios, and work closely with defenders, engineers, and leadership to improve security controls and reduce organizational risk

Qualifications:

  • 10+ years of experience in penetration testing, red teaming, or offensive cybersecurity operations
  • Hands-on experience using industry-standard penetration testing and vulnerability assessment tools (e.g., Burp Suite, Metasploit, Nmap, Nessus, BloodHound, etc.)
  • Demonstrated experience conducting exploitation, privilege escalation, and lateral movement in authorized environments
  • Experience training, mentoring, or leading analysts in cybersecurity or offensive security disciplines
  • Strong understanding of common cyber threats, attack vectors, and adversary tactics (MITRE ATT&CK, etc.)
  • Bachelor's degree in computer science, Cybersecurity, or related field (or equivalent experience)
  • Relevant certifications such as OSCP, OSCE, GPEN, GXPN, CISSP, or GIAC preferred
  • Active Top-Secret Clearance (SCI Eligible) preferred

____________________________________________________________

Vibrint's comprehensive compensation package includes but is not limited to: competitive salary; annual merit-based salary increases and discretionary bonus program; 401(k) plan with a company contribution; 11 paid federal holidays; 160 hours of paid time off; medical, dental, vision, life and short- & long-term disability insurance; employee assistance program; and a generous professional development allowance.

Equal Opportunity Employer:

All applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, citizenship, family structure, marital status, disability, veteran or military status, or any other characteristic protected by law in all phases of the employment process and in compliance with applicable federal, state, and local laws and regulations.

An equal opportunity employer/disability/vet. Policy-Statement_EEO-EmployeesAndCandidates.pdf (vibrint.com).

Please apply for immediate consideration.