1

Junior Penetration Testing Jobs (NOW HIRING)

Penetration Tester

Leesburg, VA · On-site

$125 - $155/hr

Your expertise in cloud penetration testing (FedRAMP and other compliance frameworks) and security ... Train and mentor junior team members * Interface with customers and other internal delivery team ...

Plan, scope, and execute penetration testing engagements across a variety of environments ... Experience conducting peer reviews of penetration test reports and mentoring junior testers.

Senior Penetration Tester

Manhattan, NY · On-site

$156K - $260K/yr

Plan, scope, and execute penetration testing engagements across a variety of environments ... Experience conducting peer reviews of penetration test reports and mentoring junior testers.

Showing results 41-60

Junior Penetration Testing information

See salary details

$33.5K

$71.8K

$109.5K

How much do junior penetration testing jobs pay per year?

As of Aug 20, 2026, the average yearly pay for junior penetration testing in the United States is $71,799.00, according to ZipRecruiter salary data. Most workers in this role earn between $48,500.00 and $80,000.00 per year, depending on experience, location, and employer.

What is a junior penetration tester?

Junior Penetration Testers are entry-level cybersecurity professionals who assist in identifying and exploiting vulnerabilities in computer systems, networks, and applications. They work under the guidance of experienced penetration testers to conduct security assessments, perform vulnerability scans, and document findings. Their main goal is to help organizations strengthen their security by simulating real-world attacks and providing recommendations for remediation. Junior Penetration Testers often use a variety of tools and follow industry best practices to ensure thorough testing. This role is crucial for organizations looking to protect sensitive data and maintain robust security defenses.

What are the key skills and qualifications needed to thrive as a junior penetration tester?

To thrive as a Junior Penetration Tester, you need a solid understanding of networking, operating systems, cybersecurity fundamentals, and preferably a relevant degree or certification such as CompTIA Security+ or CEH. Familiarity with tools like Metasploit, Burp Suite, Nmap, and Kali Linux is typically required to identify and exploit vulnerabilities. Strong analytical thinking, attention to detail, and clear communication help you convey technical findings to both technical and non-technical stakeholders. These skills and qualifications are essential to effectively assess security risks and support organizations in strengthening their defenses against cyber threats.

What are some common challenges a junior penetration tester might face during client engagements, and how can they overcome them?

Junior Penetration Testers often encounter challenges such as limited access to systems, incomplete documentation, or unclear testing scopes during client engagements. Communication is key—regularly clarifying objectives with clients and senior team members helps ensure the testing process stays on track. Additionally, adapting quickly to diverse IT environments and staying current with the latest security tools and techniques are essential. Seeking mentorship from experienced colleagues and leveraging collaborative team structures can greatly enhance learning and confidence in overcoming these hurdles.

What is the difference between Junior Penetration Testing vs Security Analyst?

AspectJunior Penetration TestingSecurity Analyst
CertificationsOSCP, CEH (entry-level)CompTIA Security+, CISSP (entry-level)
Work EnvironmentHands-on testing, simulated attacksMonitoring, incident response, policy development
Employer UsageCybersecurity firms, IT departmentsOrganizations, government agencies, corporations

Junior Penetration Testers focus on identifying vulnerabilities through simulated attacks, requiring technical certifications like OSCP or CEH. Security Analysts monitor security systems, analyze threats, and develop security policies, often holding certifications like Security+ or CISSP. While both roles are vital in cybersecurity, Junior Penetration Testers are more hands-on with testing, whereas Security Analysts focus on ongoing security monitoring and response.

More about Junior Penetration Testing jobs

What cities are hiring for Junior Penetration Testing jobs?

Cities with the most Junior Penetration Testing job openings:

What are the most commonly searched types of Penetration Testing jobs?

The most popular types of Penetration Testing jobs are:

What states have the most Junior Penetration Testing jobs?

States with the most job openings for Junior Penetration Testing jobs include:

Infographic showing various Junior Penetration Testing job openings in the United States as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $71,799 per year, or $34.5 per hour.

Penetration Tester

Fortreum

Leesburg, VA • On-site

$125 - $155/hr

Other

Medical, Dental, Vision, Life, Retirement

This job post has expired today. Applications are no longer accepted.


Job description

Fortreum is a trusted leader in cloud and cybersecurity services, ranked among the Top 5 FedRAMP Third Party Assessment Organizations (3PAO). With the addition of Kovr.AI, we have expanded our capabilities to include advanced cyber risk quantification and analytics, enabling organizations to better understand, measure, and communicate risk. Together, we deliver independent, third-party, vendor-agnostic regulatory assessment and advisory services, alongside advanced cybersecurity offensive and compliance technical solutions. Our comprehensive service portfolio spans regulatory compliance frameworks including FedRAMP, CMMC, FISMA, SOC, PCI, ISO, and HIPAA.

Working with Fortune 500 companies and leading cloud service providers, we’ve built our reputation on service-delivery excellence and an unwavering commitment to client success. Our continued rapid growth creates exceptional opportunities for driven professionals to make their mark in the cybersecurity industry—guided by our core values: quality above all, a customer-driven mindset, autonomy, and personal accountability.

The Opportunity

On our team, you will have the opportunity to work with the best and brightest in the field. Fortreum team members have supported the biggest cloud providers in the world, and you will have the opportunity to learn from the best. We're seeking a seasoned Penetration Tester to join our team. Your expertise in cloud penetration testing (FedRAMP and other compliance frameworks) and security best practices will be essential in helping our customers.

Key Responsibilities

This role will be responsible for conducting network, application (API, mobile, and web), and Social Engineering penetration testing. Specifically, you would:

  • Work closely with all members of the team to conduct penetration testing of customer networks, applications (API, web, and mobile), and/or social engineering activities to achieve the customer’s objectives of the engagement

  • Advise customers on details of vulnerabilities, remediation strategies, and compliance requirements

  • Prepare final deliverables for delivery to customers within established timelines

  • Establish and maintain positive relationships with customers and stakeholders

  • Coordinate project readiness with internal teams and customers

  • Pursue continuous professional development in by achieving industry specific certifications (must be willing to meet FedRAMP certification requirements as outlined by A2LA)

  • Perform project readouts with customers to notify them of the outcome of their penetration test

  • Train and mentor junior team members

  • Interface with customers and other internal delivery team members through entire engagement, interacting will all levels of customer organizations

This is a customer facing role. Travel is expected to be limited in nature; however, you may be required to travel to client locations to deliver professional services periodically when needed.

Basic Qualifications
  • Bachelor’s Degree or 4 years of equivalent job experience

  • 2+ years of professional services experience

  • 3+ years of web application and network penetration testing experience

  • Proficient in at least one or more scripting languages (i.e., bash, python, PowerShell, ruby, etc.)

  • Strong technical acumen with regards to penetration testing methodologies

  • Familiarity with best practices frameworks such as OWASP, MITRE ATT&CK, OSSTMM, and/or PTES

Preferred Skills
  • eCPPT, OSCP, OSCE, OSWE, or GPEN certifications

  • Ability to quickly assess new and leading-edge technologies and concepts

  • Ability to manage multiple priorities simultaneously

  • Proven analytical and problem-solving skills

  • Ability to develop technical content for website updates, whitepapers, and blog posts that can be used both internally and by our clients to assist them in evaluating/building out their security programs

  • Ability to develop and maintain strong relationships with team members and clients

  • Familiarity with commonly used network architecture, network devices/services, development platforms, and software suites

  • Ability to work in a team environment with compliance specialists who conduct security control assessments in parallel

  • Comfortable supporting fast-paced team environments

  • Familiarity of penetration testing in cloud environments encompassing a variety of technology stacks

Posted Salary Range

$125,000 - $155,000 annual salary

What Fortreum Offers

We offer a competitive compensation package, where you will be rewarded based on your performance/outcomes and recognized for the value you bring to our business. Our benefits package includes medical insurance, dental insurance, vision insurance, 401K plan with a 4% match, company paid short-term disability, company paid long-term disability, company paid AD&D and life insurance, flex time off, annual bonuses, training stipends, certification reimbursements, access to over 30,000 free online training courses, personal cell phone allowance, new hire and annual home office stipend, spot awards and eleven paid holidays.

An Affiant and Equal Opportunity Employer

Fortreum is an Affiant and Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability. If you’d like to view a copy of the company’s affirmative action plan or policy statement, please email hr@fortreum.com. If you have a disability and you believe you need a reasonable accommodation in order to search for a job opening or to submit an online application, please e-mail hr@fortreum.com or call 703-594-1460. This email and phone number is created exclusively to assist disabled job seekers whose disability prevents them from being able to apply online. Only messages left for this purpose will be returned. Messages left for other purposes, such as following up on an application or technical issues not related to a disability, will not receive a response.

In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.

#J-18808-Ljbffr