1

Kali Linux Jobs in Illinois (NOW HIRING)

Uses offensive security tools and techniques to identify, validate, and demonstrate exploitability, including Kali Linux toolchain, Nessus/Tenable, Nmap, Burp Suite, Metasploit, and BloodHound, and ...

Uses offensive security tools and techniques to identify, validate, and demonstrate exploitability, including Kali Linux toolchain, Nessus/Tenable, Nmap, Burp Suite, Metasploit, and BloodHound, and ...

Kali Linux information

See Illinois salary details

$10

$57

$88

How much do kali linux jobs pay per hour?

As of Aug 12, 2026, the average hourly pay for kali linux in Illinois is $57.88, according to ZipRecruiter salary data. Most workers in this role earn between $46.59 and $65.00 per hour, depending on experience, location, and employer.

What jobs use Kali Linux?

Jobs that use Kali Linux typically include cybersecurity analyst, penetration tester, ethical hacker, security researcher, and network security engineer. These roles require knowledge of Linux, cybersecurity tools, and often involve vulnerability assessment, penetration testing, and security auditing.

What types of projects or assignments can a professional working with Kali Linux expect on the job?

Professionals specializing in Kali Linux often engage in a variety of cybersecurity projects, such as conducting vulnerability assessments, penetration tests, network security audits, and red team exercises. Daily responsibilities typically include using Kali Linux tools to emulate cyberattacks, discover system weaknesses, document findings, and recommend remediation strategies. Teamwork is essential, as these professionals frequently coordinate with IT departments, management, and sometimes even clients to ensure thorough testing and proper risk communication. This role offers opportunities to gain hands-on experience with cutting-edge security technologies and can serve as a strong foundation for advanced careers in cybersecurity and ethical hacking.

What are the key skills and qualifications needed to thrive in the Kali Linux position, and why are they important?

To excel in roles centered around Kali Linux, such as penetration tester or cybersecurity analyst, candidates need in-depth knowledge of cybersecurity principles, penetration testing methodologies, and familiarity with Linux operating systems, typically supported by a degree in computer science or a related field. Proficiency with the Kali Linux distribution and its suite of security tools, along with certifications like OSCP (Offensive Security Certified Professional) or CEH (Certified Ethical Hacker), are highly valued. Strong analytical thinking, problem-solving abilities, and clear communication skills help professionals document findings and collaborate with technical teams or clients. These competencies are crucial for identifying vulnerabilities, effectively mitigating risks, and maintaining strong security postures for organizations.

What is a Kali Linux?

A Kali Linux job typically involves cybersecurity roles such as penetration testing, ethical hacking, and security analysis. Professionals use Kali Linux, a specialized Linux distribution, for tasks like vulnerability assessment, digital forensics, and network security testing. These jobs often require expertise in tools like Metasploit, Nmap, and Wireshark. Common roles include ethical hacker, security analyst, and red team specialist.

What are the most commonly searched types of Kali Linux jobs in Illinois? The most popular types of Kali Linux jobs in Illinois are:
Infographic showing various Kali Linux job openings in Illinois as of August 2026, with employment types broken down into 100% Full Time. Highlights an 60% In-person, and 40% Hybrid job distribution, with an average salary of $120,398 per year, or $57.9 per hour.

Senior IT Penetration Tester

BDO USA

Oak Brook, IL • On-site

Full-time

Retirement

Posted 5 days ago


Job description


Job Summary:
The Senior Cyber Security Penetration Tester performs offensive security testing for BDO clients and provides practical, risk-based remediation guidance. This role works with client stakeholders to define scope, rules of engagement, and objectives, executes testing to simulate realistic attacker behaviors, and communicates results clearly to both technical and executive audiences. Engagements may include external and internal network penetration testing, Active Directory attack path testing, web and API application testing, cloud and Microsoft 365 security assessments, and AI enabled application testing. The role may also support red team and purple team exercises in collaboration with client SOC teams and contributes to internal tooling and automation through shared repositories.
Job Duties:
  • Participates in client penetration testing and vulnerability assessment engagements across external and internal networks, Active Directory, web applications, APIs, cloud platforms, and Microsoft 365, including reconnaissance, attack surface discovery, and service enumeration
  • Uses offensive security tools and techniques to identify, validate, and demonstrate exploitability, including Kali Linux toolchain, Nessus/Tenable, Nmap, Burp Suite, Metasploit, and BloodHound, and validates exploitability end to end for High and Critical findings and when feasible for other findings
  • Performs authenticated testing when appropriate by coordinating access approvals, applying least privilege, safeguarding secrets, and confirming access removal or rotation at engagement closeout
  • Performs and reviews web and API security testing using Burp Suite and related techniques, focusing on authentication, session management, access control, injection, insecure deserialization, and business logic, and documents reproducible steps and payloads for remediation and retesting
  • Reviews AI-enabled applications and LLM integrations for common risks (for example, prompt injection, sensitive data exposure, insecure output handling, and tool or function calling abuse) and provides practical mitigation guidance aligned to OWASP Top 10 for LLM Applications
  • Supports scoping and delivery under the direction of an assigned Project Manager by documenting objectives and rules of engagement, coordinating technical logistics with client teams, providing timely status updates across concurrent engagements, and ensuring testing is performed safely within approved scope
  • For internal and Active Directory engagements, maps and demonstrates feasible attack paths, for example, using BloodHound or equivalent, including privilege escalation and lateral movement, validates root causes in configuration and permissions, and provides actionable remediation
  • Documents reproducible workpapers and evidence with appropriate data protection practices, participates in peer review and quality assurance, and escalates critical findings quickly to support timely mitigation
  • Produces high-quality client deliverables, including test plans, technical reports, and executive readouts, with clear evidence, proof-of-exploit artifacts, risk ratings, reproduction steps, and prioritized remediation recommendations, and facilitates results discussions and remediation workshops
  • Facilitates red team style engagements in collaboration with client SOC teams by coordinating deconfliction, leveraging SIEM telemetry to validate detection and response, and supporting threat hunting and purple team activities tied to observed attacker behaviors
  • Performs validation and retesting to confirm remediation effectiveness and documents retest results for client stakeholders
  • Maintains internal offensive security tooling, scripts, and reusable testing components, including automation and agent-based utilities, to improve assessment repeatability and quality. Contributes through Git workflows, pull requests, and code review
  • Other duties as required

Supervisory Responsibilities:
  • N/A

Qualifications, Knowledge, Skills, and Abilities:
Education:
  • High school diploma or GED, required
  • Bachelor's degree in Cybersecurity, Information Security, or Computer Science, preferred

Experience:
  • Four (4) or more years of hands-on penetration testing and security assessment experience (network, web, API, wireless, cloud, and/or Microsoft 365), including scoping, execution, reporting, and client presentations, required
  • Demonstrated experience producing professional services deliverables (test plans, technical reports, executive summaries) and communicating complex technical issues to non-technical stakeholders, required
  • Exposure to testing AI-enabled applications (including LLM-based features) and familiarity with emerging guidance such as OWASP Top 10 for LLM Applications, preferred
  • Experience supporting social engineering assessments, such as phishing, vishing, baiting, and tailgating, preferred
  • Strong fundamentals in Windows and Linux administration, TCP/IP networking, and DNS, required
  • Hands-on experience administering and troubleshooting Active Directory in enterprise environments, including users and groups, group policy, permissions, and DNS integration, plus foundational knowledge of authentication protocols and identity flows such as Kerberos, NTLM, SAML, OAuth 2.0, and OpenID Connect, required
  • Two (2) or more years of experience supporting IT Penetration and Security projects such as PTES, OWASP, SANS, or other cyber security frameworks, preferred
  • Experience working with SIEM platforms and core SOC workflows, including basic threat hunting and alert triage to validate detections during red team or purple team activities, preferred
  • Hands-on experience with scripting/automation and light tool development to improve testing efficiency and repeatability (e.g., Python, PowerShell, Bash), required
  • DevOps and engineering fundamentals, including Git version control, pull request workflows, and exposure to CI/CD and containers (for example, GitHub Actions, Azure DevOps pipelines, Docker), preferred
  • Experience conducting internal network and Active Directory penetration tests, including attack path mapping (for example, using BloodHound or equivalent), privilege escalation, lateral movement, and prioritized remediation guidance, preferred
  • Experience working within a national consulting organization or professional services, preferred

License(s)/Certification(s):
  • OSCP (or equivalent hands-on penetration testing certification), strongly preferred; additional certifications such as OSCE, OSWE/OSWA, GIAC (GPEN, GXPN), CRTO (or equivalent), CEH, LPT, CompTIA PenTest+, CISSP, or other relevant certifications, preferred
  • AWS Cloud Practitioner or Microsoft 365 Certified: Security Administrator Associate, preferred

Software:
  • Proficient with offensive security and assessment toolsets (e.g., Kali Linux toolchain, Burp Suite, Metasploit, Nmap, Nessus/Tenable, and common AD assessment tooling such as BloodHound), including scan configuration/tuning, manual verification, and evidence collection, required
  • Proficient with Git-based source control and collaboration platforms (for example, GitHub), including branching, pull requests, and peer review, required
  • Proficient in the use of Windows and Microsoft Office Suite, specifically Word, Excel, and PowerPoint, required
  • Familiarity with SIEM tooling and log investigation workflows (for example, Splunk and Microsoft Sentinel) to support validation of detection and response during engagements, preferred
  • Experience using AI-assisted development tools (for example, GitHub Copilot and Claude Code) to accelerate scripting and tool development, with the ability to use these tools responsibly without exposing client confidential data or sensitive credentials, preferred
  • Experience with cloud platforms and identity/security services (e.g., Microsoft Azure and Microsoft 365) and the ability to script/automate tasks (e.g., Python, PowerShell, Bash), preferred
  • Familiarity with AI/LLM security testing approaches and tooling (e.g., structured prompt testing, abuse-case libraries, and API-driven test harnesses) and the ability to use AI-assisted tooling responsibly without exposing client confidential data, preferred

Language(s):
  • Multilingual capabilities (read, speak and/or write), preferred

Other Knowledge, Skills, & Abilities:
  • Ability to maintain a high level of confidentiality and professionalism
  • Ability to communicate with professionals at all organizational levels
  • Ability to build and maintain strong relationships with BDO and client personnel
  • Solid organizational and excellent verbal and written communication skills
  • Ability to successfully multi-task while working independently or within a group environment
  • Ability to translate technical vulnerabilities into clear risk statements and actionable remediation guidance, including prioritization and validation steps

Keyword: Cyber, Security, Penetration Tester, Black Box Testing, Certified Ethical Hacker, Microsoft 365 Azure Cloud, AWS Cloud, GIAC, GPEN, GXPN, Licensed Penetration Tester Master, LPT, Security Administrator, IT Network Security Assessments, Wired, Wireless
Individual salaries that are offered to a candidate are determined after consideration of numerous factors including but not limited to the candidate's qualifications, experience, skills, and geography.
National Range: $120,000 - $160,000
Maryland Range: $120,000 - $160,000
NYC/Long Island/Westchester Range: $120,000 - $160,000
About Us
At BDO, how we show up matters. We build strong relationships by supporting one another, our clients, and our communities with care, curiosity, and a commitment to helping one another grow and succeed. Here, you'll find meaningful work, leaders invested in your success, and opportunities to build a career around what matters most to you.
Our purpose is to be the people our clients count on to grow with confidence and achieve what matters most. Our values guide how we bring that purpose to life each day. Together, they shape how we work with one another, serve our clients, and create meaningful impact.
BDO provides assurance, tax, and advisory services to clients across the U.S. and around the world. No matter your role, you'll be part of a team helping clients navigate complexity and move forward with clarity.
We are proud to be an ESOP company, offering participants a stake in the firm's success through beneficial ownership and a unique opportunity to enhance their financial well-being. As a qualified retirement plan, the ESOP is a meaningful addition to our comprehensive compensation and Total Rewards benefits* offerings. It also reinforces an ownership mindset that strengthens our connection to one another, our clients, and the future we're building together.
Learn more about our benefits: BDO Total Rewards encompass more than traditional benefits. Click here to find out more!
*Benefits may be subject to eligibility requirements.
Equal Opportunity Employer, including disability/vets
Click here to find out more!