1

Internship Web App Penetration Testing Jobs in Springfield, VA

Proven experience conducting penetration tests of web applications, networks, and other systems. * Experience with a variety of penetration testing tools and techniques (e.g., Rapid7 Nexpose ...

Penetration Tester

Quantico, VA · On-site

$130K - $147K/yr

Penetration Testing: * Conduct penetration tests of web applications, mobile applications, networks, cloud environments, and other systems. * Utilize a variety of tools and techniques to identify ...

Network penetration testing and experience working with network infrastructure * An understanding ... Experience conducting web application security assessments * Experience working with a range of ...

Lead Penetration Tester

Washington, DC · On-site

$110 - $150K/hr

Yes - travel to agency sites required Project Description This position leads operational security assessments and penetration testing across a portfolio of federal agencies and web applications.

Senior Penetration Tester

Washington, DC · On-site

$124K - $180K/yr

Lead, plan, and oversee penetration testing operations for systems, networks, cloud resources, and web-based applications in a TS/SCI environment * Execute comprehensive vulnerability assessments and ...

The role will be in response to performing penetration testing engagements using major frameworks like OWASP and NIST, against a range of technologies such as web applications, servers, operating ...

Cleared Penetration Tester

Herndon, VA · Remote

$130K - $160K/yr

Work closely with all members of the team to conduct penetration testing of customer networks, applications (API, web, and mobile), and/or social engineering activities to achieve the customer ...

Penetration Tester

Alexandria, VA · On-site

$125K - $145K/yr

Perform a range of testing and detection activities - including red teaming, blue teaming ... Working knowledge of web application technologies and common vulnerability classes (OWASP Top 10: ...

Apply established penetration-testing methodologies and commercial or open-source offensive tools across networks, web applications, applications, and code, including support to Red and Blue Team ...

Cleared Penetration Tester

Herndon, VA · On-site

$130K - $160K/yr

Work closely with all members of the team to conduct penetration testing of customer networks, applications (API, web, and mobile), and/or social engineering activities to achieve the customer ...

Apply established penetration-testing methodologies and commercial or open-source offensive tools across networks, web applications, applications, and code, including support to Red and Blue Team ...

Showing results 21-40

Internship Web App Penetration Testing information

See Springfield, VA salary details

$5

$13

$20

How much do internship web app penetration testing jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for internship web app penetration testing in Springfield, VA is $13.08, according to ZipRecruiter salary data. Most workers in this role earn between $8.80 and $15.05 per hour, depending on experience, location, and employer.

What is an internship web app penetration tester?

An Internship Web App Penetration Tester is a student or entry-level professional who assists in assessing the security of web applications by simulating cyberattacks. Their role involves identifying vulnerabilities, exploiting potential weaknesses, and documenting findings under the guidance of experienced security professionals. This hands-on experience helps interns learn about common web application threats, security tools, and best practices in cybersecurity. The position is often part of a learning program to prepare individuals for a career in penetration testing or information security.

What types of tasks and projects can I expect to work on during an internship in web app penetration testing?

As an intern in Web App Penetration Testing, you'll typically assist with vulnerability assessments, security testing of web applications, and documentation of your findings. You'll likely use tools such as Burp Suite, OWASP ZAP, and manual testing methods to identify common vulnerabilities like SQL injection and cross-site scripting. Interns often work closely with experienced penetration testers and developers, learning how to communicate security risks and collaborating on solutions. This hands-on experience provides valuable insight into secure coding practices and real-world remediation processes.

What are the key skills and qualifications needed to thrive as an internship web app penetration tester, and why are they important?

To thrive as an Internship Web App Penetration Tester, you need a foundational understanding of web application architectures, common vulnerabilities (like those in OWASP Top 10), and basic programming or scripting knowledge. Familiarity with tools such as Burp Suite, OWASP ZAP, and basic command-line utilities, along with ongoing coursework or certifications like CompTIA Security+ or OSCP, is highly beneficial. Strong analytical thinking, attention to detail, and effective written communication make candidates stand out in this field. These skills ensure interns can identify, document, and help remediate security weaknesses, contributing to safer web applications.

What are the most commonly searched types of Web App Penetration Testing jobs in Springfield, VA?

The most popular types of Web App Penetration Testing jobs in Springfield, VA are:

What are popular job titles related to Internship Web App Penetration Testing jobs in Springfield, VA?

For Internship Web App Penetration Testing jobs in Springfield, VA, the most frequently searched job titles are:

What job categories do people searching Internship Web App Penetration Testing jobs in Springfield, VA look for?

The top searched job categories for Internship Web App Penetration Testing jobs in Springfield, VA are:

What cities near Springfield, VA are hiring for Internship Web App Penetration Testing jobs?

Cities near Springfield, VA with the most Internship Web App Penetration Testing job openings:

Infographic showing various Internship Web App Penetration Testing job openings in Springfield, VA as of August 2026, with employment types broken down into 21% Internship, 34% Full Time, and 45% Contract. Highlights an 100% In-person job distribution, with an average salary of $27,215 per year, or $13.1 per hour.

Penetration Tester

asrcfh

Quantico, VA • Hybrid

Full-time

Re-posted yesterday


Job description

ASRC Federal is actively hiring a Penetration Tester in support of our Defense Counterintelligence Security Agency (DCSA) program based out of Quantico VA.

Remote flexibility available! Telework offered with a requirement to be onsite up to two (2) days a week at Quantico Marine Corps Base VA.

Position Description:

The Cybersecurity Penetration Tester is a hands-on technical role responsible for conducting simulated attacks on systems and networks to identify vulnerabilities and weaknesses that could be exploited by malicious actors. This role requires a deep understanding of security principles, hacking techniques, and attack methodologies. The Penetration Tester will plan, execute, and document penetration tests, provide recommendations for remediation, and contribute to the overall improvement of the organization's security posture.

Minimum Requirements: 

  • Minimum of 5 – 7 years of experience in security principles such as attack frameworks, threat landscapes, and attacker tactics, techniques and procedures. 
  • Proven experience conducting penetration tests of web applications, networks, and other systems.
  • Experience with a variety of penetration testing tools and techniques (e.g., Rapid7 Nexpose, Appspider Pro, Metasploit, Cobalt Strike and/or Burp Suite).
  • Active Top-Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI
  • Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent experience.
  • Must meet 8570 certification requirements at the time of hire.  IAT II Information Assurance Baseline (e.g., CASP+ CE, CCMP Security, CISA, CISSP, GCED, GCIH, Security+ CE or CCSP) In addition to the IA baseline, a CSSP Auditor cert is preferred (e.g., CEH, CySA+, CISA, GSNA, CFR or PenTest) 

 

Responsibilities:

  • Penetration Testing:
    • Conduct penetration tests of web applications, mobile applications, networks, cloud environments, and other systems.
    • Utilize a variety of tools and techniques to identify vulnerabilities, including SQL injection, cross-site scripting (XSS), buffer overflows, and other common attack vectors.
    • Perform reconnaissance to gather information about target systems and networks.
    • Develop and execute exploit code to demonstrate the impact of identified vulnerabilities.
    • Bypass security controls and evade detection.
  • Vulnerability Assessment:
    • Perform vulnerability assessments using automated scanning tools and manual techniques.
    • Analyze scan results to identify false positives and prioritize vulnerabilities.
    • Develop custom scripts and tools to automate vulnerability assessment tasks.
  • Reporting and Documentation:
    • Document all findings in detailed and comprehensive reports, including descriptions of vulnerabilities, methods used to exploit them, and recommendations for remediation.
    • Present findings to stakeholders, including technical teams and management.
    • Create and maintain documentation on penetration testing methodologies, tools, and techniques.
  • Remediation Support:
    • Provide guidance and technical assistance to system owners and developers on vulnerability remediation.
    • Validate remediation efforts to ensure that vulnerabilities have been properly addressed.
    • Conduct retests to verify the effectiveness of implemented security controls.
  • Research and Development:
    • Stay up-to-date on the latest security threats, vulnerabilities, and attack techniques.
    • Research and evaluate new penetration testing tools and methodologies.
    • Develop custom tools and scripts to enhance penetration testing capabilities.
    • Contribute to the development of security policies and procedures.
  • Collaboration:
    • Collaborate with other cybersecurity professionals, including security architects, incident responders, and security engineers.
    • Share knowledge and expertise with team members.
    • Participate in security training and awareness programs.
  • Ethical Hacking:
    • Conduct all penetration testing activities in a legal and ethical manner, adhering to established rules of engagement.
    • Protect the confidentiality and integrity of sensitive data.
    • Respect the privacy of users and systems.

Work Environment and Physical Demands: 

  • This is primarily a Telework position with a requirement to be onsite up to two (2) days a week
  • If alternate worksite is other than DCSA facilities or corporate office space, must have the reliable ability to communicate over voice (cell phone preferred) and stable, capable internet connection
  • Must be able to communicate complex technical ideas to a diverse customer base both verbally and in written form