1

In Penetration Testing Jobs (NOW HIRING)

In this role, you will work alongside government partners, engineers, and other industry teammates ... Collaborate with DoD and Government penetration testing organizations to plan, scope, and prepare ...

The Penetration Tester will assist in the development of cyber test plans, execute cyber tests, and ... Be able to accomplish testing independently * Ensure tests are conducted safely, in accordance with ...

What you bring * 5+ years of experience in penetration testing, application security, or security engineering. * Proactive communication and engagement with stakeholders. * Demonstrated impact using ...

Senior Penetration Testing Analyst

Gaithersburg, MD · On-site

$108K - $139K/yr

In this role, you will work alongside government partners, engineers, and other industry teammates ... Conduct penetration testing and vulnerability assessments across applications, infrastructure, and ...

Senior Penetration Testing Analyst

Alexandria, VA · On-site

$107K - $138K/yr

In this role, you will work alongside government partners, engineers, and other industry teammates ... Conduct penetration testing and vulnerability assessments across applications, infrastructure, and ...

What you bring * 5+ years of experience in penetration testing, application security, or security engineering. * Proactive communication and engagement with stakeholders. * Demonstrated impact using ...

Senior Penetration Testing Analyst

Alexandria, VA · On-site

$107K - $138K/yr

In this role, you will work alongside government partners, engineers, and other industry teammates ... Conduct penetration testing and vulnerability assessments across applications, infrastructure, and ...

Senior Penetration Testing Lead

Falls Church, VA · On-site

$122K - $167K/yr

Everforth ECS is seeking a Senior Penetration Testing Lead to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax . Please Note: This position is contingent upon ...

Proficiency in penetration testing tools like Metasploit, Burp Suite, or Nessus * Strong understanding of networking protocols and configurations * Expertise in scripting languages such as Python ...

Proficiency in penetration testing tools like Metasploit, Burp Suite, or Nessus * Strong understanding of networking protocols and configurations * Expertise in scripting languages such as Python ...

Proficiency in penetration testing tools like Metasploit, Burp Suite, or Nessus * Strong understanding of networking protocols and configurations * Expertise in scripting languages such as Python ...

Proficiency in penetration testing tools like Metasploit, Burp Suite, or Nessus * Strong understanding of networking protocols and configurations * Expertise in scripting languages such as Python ...

Proficiency in penetration testing tools like Metasploit, Burp Suite, or Nessus * Strong understanding of networking protocols and configurations * Expertise in scripting languages such as Python ...

Proficiency in penetration testing tools like Metasploit, Burp Suite, or Nessus * Strong understanding of networking protocols and configurations * Expertise in scripting languages such as Python ...

Proficiency in penetration testing tools like Metasploit, Burp Suite, or Nessus * Strong understanding of networking protocols and configurations * Expertise in scripting languages such as Python ...

next page

Showing results 1-20

In Penetration Testing information

See salary details

$22.5K

$119.9K

$168.5K

How much do in penetration testing jobs pay per year?

As of Jun 9, 2026, the average yearly pay for in penetration testing in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Penetration Tester, and why are they important?

To thrive as a Penetration Tester, you need a deep understanding of network protocols, operating systems, security vulnerabilities, and commonly hold certifications like OSCP or CEH. Familiarity with tools such as Metasploit, Burp Suite, Nmap, and Kali Linux is typically required to conduct effective assessments. Strong analytical thinking, attention to detail, and clear communication skills set standout professionals apart in this field. These skills and qualities are crucial for identifying security weaknesses, delivering actionable recommendations, and helping organizations strengthen their cybersecurity defenses.

What is penetration testing?

Penetration testing, often called 'pen testing,' is a simulated cyberattack performed to identify and exploit vulnerabilities in an organization's computer systems, networks, or applications. The goal is to uncover security weaknesses that malicious hackers could exploit and to help organizations strengthen their defenses. Pen testers use various tools and techniques to mimic real-world attacks, providing valuable insights and recommendations for improving overall security. Regular penetration testing is essential for maintaining a robust cybersecurity posture and complying with industry regulations.

What is the difference between In Penetration Testing vs Vulnerability Assessment?

AspectIn Penetration TestingVulnerability Assessment
PurposeSimulates cyberattacks to identify exploitable vulnerabilitiesIdentifies and reports security weaknesses without exploiting them
DepthIn-depth, targeted testing with active exploitationBroad, automated or manual scanning for vulnerabilities
CertificationsOSCP, CEH, GPENOSCP, CEH, CISSP (common but less focused)
Work EnvironmentEngages in simulated attacks, often in controlled environmentsUses scanning tools, reports vulnerabilities

While both roles focus on identifying security issues, In Penetration Testing involves actively exploiting vulnerabilities to assess security defenses, whereas Vulnerability Assessment primarily identifies weaknesses without exploitation. Penetration testers provide deeper insights into potential attack vectors, making their work more targeted and detailed.

What are some common challenges faced by penetration testers during client engagements?

Penetration testers often encounter challenges such as limited timeframes for assessments, incomplete or outdated documentation about client systems, and varying levels of cooperation from internal teams. Navigating complex network architectures and adapting to unique security configurations can also be demanding. Effective communication is essential, as testers must clearly explain findings and remediation steps to both technical and non-technical stakeholders. These challenges require strong problem-solving skills, adaptability, and the ability to work collaboratively across departments.
More about In Penetration Testing jobs
What cities are hiring for In Penetration Testing jobs? Cities with the most In Penetration Testing job openings:
What states have the most In Penetration Testing jobs? States with the most job openings for In Penetration Testing jobs include:
What job categories do people searching In Penetration Testing jobs look for? The top searched job categories for In Penetration Testing jobs are:
SME Penetration Testing Analyst

SME Penetration Testing Analyst

Leidos

Alexandria, VA • On-site

Full-time

Posted 18 days ago


Leidos rating

8.4

Company rating: 8.4 out of 10

Based on 146 frontline employees who took The Breakroom Quiz

55th of 426 rated business services


Job description

This Department of War enterprise data and analytics program delivers mission-critical capabilities that enable leaders across the Department to make faster, better-informed decisions using trusted data at scale. Leidos Digital Modernization sector is seeking an experienced SME Penetration Testing Analyst to support the delivery, enhancement, and adoption of enterprise data and analytics products used across multiple DoD organizations.

In this role, you will work alongside government partners, engineers, and other industry teammates to translate operational and strategic requirements into scalable, production-ready solutions. You will contribute directly to product planning, execution, and continuous improvement-helping ensure capabilities are delivered efficiently, aligned to mission priorities, and positioned for sustained success.

This position offers the opportunity to work on a high-visibility, enterprise program at the intersection of data, analytics, and emerging AI technologies. Ideal candidates are motivated by mission impact, comfortable operating in complex stakeholder environments, and interested in building deep domain expertise while delivering capabilities with real-world national security outcomes.

Primary Responsibilities:

  • Develop and maintain comprehensive plans and objectives for conducting penetration testing of the System.

  • Assist the government in identifying and retaining qualified DoD or Government penetration testing organizations.

  • Plan, coordinate, and oversee individual penetration test events.

  • Collaborate with DoD and Government penetration testing organizations to plan, scope, and prepare for penetration test events.

  • Work with the System Operations team to prepare the System for penetration testing operations.

  • Assist System engineers and software developers in understanding penetration test results.

  • Schedule remediation actions into future System software cycles based on penetration test results.

  • Ensure compliance with DoD and Government guidelines and standards for penetration testing.

  • Provide technical leadership and guidance to the penetration testing team.

  • Coordinate with other teams to ensure seamless integration of penetration testing activities.

  • Report on penetration testing activities, findings, and remediation progress to senior management and stakeholders.

  • Stay updated with the latest penetration testing tools, techniques, and industry best practices.

  • Ensure the security and integrity of the System through rigorous testing and analysis.

  • Support the continuous improvement of penetration testing processes and methodologies.

Basic Qualifications:

  • Active Top Secret (TS) clearance with SCI eligibility.

  • Bachelor's degree in Cybersecurity, Computer Science, Information Assurance, Engineering, or related technical discipline OR equivalent training/experience aligned to DoD 8140 pathways.

  • At least one of the following foundational qualification pathways consistent with DoD 8140 requirements:

    • Current DoD 8570/8140 baseline certification appropriate for Advanced Cyber Defense Analyst roles (e.g., CASP+, GCED, GCIH, or equivalent),

    • Offerings listed in the DoD 8140 Training Repository,

    • Demonstrated equivalent training and experience qualifying under DoD 8140 foundational qualification alternatives.

  • 12-15 years of relevant experience in cybersecurity, penetration testing, or vulnerability assessment.

  • Minimum of 8 years of experience in penetration testing or related cybersecurity roles.

  • At least 3 years of experience in one or more of the following:

    • Incident detection and response

    • Malware analysis

    • Cyber forensics

  • Proficiency with at least three of the following tools:

    • Kali Linux

    • Metasploit

    • Burp Suite

    • Cobalt Strike

    • Tenable Nessus

    • WebInspect

    • Scuba

    • AppDetective

  • Proven experience in planning, coordinating, and conducting penetration tests.

  • Strong understanding of penetration testing tools, techniques, and methodologies.

  • Experience working with DoD or Government penetration testing organizations.

  • Ability to interpret and communicate penetration test results to technical and non-technical stakeholders.

  • Experience in scheduling and managing remediation actions based on penetration test findings.

  • Excellent communication and interpersonal skills.

Preferred Qualifications:

  • Active TS/SCI clearance.

  • Advanced certifications such as OSCP, CEH, CISSP, or similar.

  • Experience with the System or similar DoD data, analytics, and AI platforms.

  • Familiarity with DoD cybersecurity policies, standards, and guidelines.

  • Experience in a systems engineering or software development environment.

  • Knowledge of cloud-based data, analytics, and AI capabilities.

  • Strong problem-solving and analytical skills.

  • Experience in a customer-facing role, with a focus on customer success and outreach.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.

Original Posting:April 20, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:Pay Range $131,300.00 - $237,350.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.


What Leidos employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Leidos logo

About Leidos

Sourced by ZipRecruiter

At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success. We empower our teams, contribute to our communities, and operate sustainable practices. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Reston, VA, US

Social media