1

Metasploit Jobs (NOW HIRING)

Minimum three (3) years of experience with testing tools, including NESSUS, METASPLOIT, CANVAS, NMAP, Burp Suite, and Kismet * Minimum three (3) years of experience with network vulnerability ...

Offensive Security Engineer

Tempe, AZ · On-site

$100K - $120K/yr

Maintain tooling (Burp, Metasploit, C2 frameworks, custom scripts) for exploitation, detection validation, and security assessments. * Conduct API security testing (REST, GraphQL) including ...

Network Security Engineer

Albany, NY · Remote

$107K - $146K/yr

Experience with security tools like Wireshark, Nmap, Nessus, or Metasploit. * Experience with security frameworks such as NIST, CIS Controls, or MITRE ATT&CK. * Excellent analytical, problem-solving ...

CySA+, PenTest+, or SecurityX a plus Experience with SIEM, Metasploit, audit logging, vulnerability scanning/remediation, IAVM Experience with security documentation (SSPs, IRPs); CMMC Level 2 / NIST ...

Core Impact, Nmap, Burp, Metasploit, and Nessus). * Employee ethical hacking knowledge to exploit discovered vulnerabilities and misconfigurations associated with but not limited to operating systems ...

Two Years experience with testing tools including NESSUS, METASPLOIT, CANVAS, NMAP, Burp Suite and Kismet. * Minimum of 1 year of experience authoring formal penetration testing or security ...

Security Architect

New York, NY

$71 - $92/hr

Experience with penetration testing tools - Burp Suite, Kali Linux, Metasploit, NMAP, SQLMap, Cain and Able, Ettercap, etc Required: (Only W2 contract) Determines security requirements by evaluating ...

.Net Web Developer

Phoenix, AZ

$48 - $63.25/hr

Metasploit, Burp Suite) A minimum of 5 -8 years .NET Framework experience A minimum of 5 -8 years C# programming skills A minimum of 5 -8 years SQL Server 2005-2008 experience SQL experience using ...

Apply in-depth knowledge of industry-standard assessment and exploitation tools, including Metasploit, Nmap, Burp Suite, PowerSploit, and Cobalt Strike, to conduct comprehensive security evaluations.

... Metasploit * Experience in programming associated with Field Programmable Gate Arrays (FPGAs) * Experience with Digital Signal Processing (DSP) design or modeling and analysis of Software Defined ...

Pen Tester

Chicago, IL · On-site

$140K - $160K/yr

Familiarity with tools such as Burp Suite, Nmap, Metasploit , etc. * Knowledge of common vulnerabilities (e.g., OWASP Top 10) * Strong understanding of networking, operating systems, and security ...

... Metasploit * Experience in programming associated with Field Programmable Gate Arrays (FPGAs) * Experience with Digital Signal Processing (DSP) design or modeling and analysis of Software Defined ...

next page

Showing results 1-20

Metasploit information

See salary details

$12

$21

$40

How much do metasploit jobs pay per hour?

As of Jun 27, 2026, the average hourly pay for metasploit in the United States is $21.23, according to ZipRecruiter salary data. Most workers in this role earn between $14.66 and $25.00 per hour, depending on experience, location, and employer.

What does a typical day look like for someone using Metasploit in a cybersecurity role?

A typical day involves planning and conducting penetration tests, leveraging Metasploit to simulate real-world attack scenarios, and analyzing security vulnerabilities within networks or applications. Professionals document findings, create detailed reports, and collaborate closely with IT teams or clients to explain risks and recommend solutions. They may also spend time updating their knowledge of the latest exploits and security patches to ensure their assessments remain relevant. Teamwork and communication are key, as these roles often require coordination with other security professionals and stakeholders across the organization. This dynamic environment offers continuous opportunities to learn and advance in the ever-evolving field of cybersecurity.

What is Metasploit mainly used for?

Metasploit is a penetration testing framework used by cybersecurity professionals and ethical hackers to identify and exploit security vulnerabilities in computer systems and networks. It provides a collection of tools and exploits to simulate cyberattacks, helping organizations improve their security defenses. Knowledge of scripting and network protocols enhances its effective use in security assessments.

What is a Metasploit job?

A Metasploit job typically involves using the Metasploit Framework for penetration testing, security assessments, and vulnerability exploitation. Professionals in this role may work as ethical hackers, security consultants, or vulnerability analysts to identify and exploit weaknesses in networks, systems, and applications. They use Metasploit to simulate real-world attacks, test defenses, and help organizations improve their cybersecurity posture. Strong knowledge of cybersecurity principles, networking, and scripting is often required for this job.

Is Metasploit paid?

Metasploit is available in both free and paid versions. The free Community Edition provides basic features, while the commercial Pro version offers advanced tools and support for professional penetration testers and security analysts.

What are the key skills and qualifications needed to thrive in the Metasploit position, and why are they important?

To excel in roles focused on Metasploit, candidates should possess in-depth knowledge of penetration testing, vulnerability assessment, and network security. Experience with the Metasploit Framework, as well as relevant certifications like OSCP (Offensive Security Certified Professional) or CEH (Certified Ethical Hacker), are highly valued. Strong analytical thinking, problem-solving abilities, and effective written and verbal communication are crucial soft skills. Mastery of both technical and interpersonal competencies enables professionals to identify security weaknesses and clearly communicate remediation steps to both technical teams and non-technical stakeholders.

What jobs can I get with Pentest+?

Pentest+ certification prepares individuals for roles such as penetration tester, security analyst, vulnerability assessor, or cybersecurity consultant. These positions involve identifying security weaknesses, conducting penetration tests, and improving organizational security posture, often requiring knowledge of tools like Metasploit and network security principles.

Which company owns Metasploit?

Metasploit is owned by Rapid7, a cybersecurity company that acquired the Metasploit Framework in 2017. As a security professional using Metasploit, understanding its ownership helps in assessing support and updates for the tool.
More about Metasploit jobs
What cities are hiring for Metasploit jobs? Cities with the most Metasploit job openings:
What are the most commonly searched types of Metasploit jobs? The most popular types of Metasploit jobs are:
What states have the most Metasploit jobs? States with the most job openings for Metasploit jobs include:
Infographic showing various Metasploit job openings in the United States as of June 2026, with employment types broken down into 94% Full Time, 3% Part Time, and 3% Contract. Highlights an 89% Physical, 2% Hybrid, and 9% Remote job distribution, with an average salary of $44,166 per year, or $21.2 per hour.

Offensive Security Engineer

RunBuggy OMI Inc.

Tempe, AZ • Hybrid

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 22 days ago


Job description

Description

About Us:

RunBuggy is the most technically advanced automotive logistics platform on the market. Period.


Backed by Porsche Ventures and Hearst Ventures, RunBuggy is transforming the way cars move. Our cutting-edge technology is trusted by some of the largest OEMs, captive finance companies, and automotive lenders in the world to streamline vehicle transportation at scale.


RunBuggy's end-to-end platform connects car shippers and haulers in real time - eliminating the friction of traditional load boards and costly custom software. For shippers, RunBuggy integrates directly into existing management systems, reducing transportation costs and accelerating delivery timelines. For transporters, we offer a smarter, more profitable way to find, accept, and manage loads - all from a single app.


Since launching in 2019, RunBuggy has grown to over 190 team members, facilitated the movement of hundreds of thousands of vehicles, and attracted tens of thousands of transporters across the U.S.


We're not just building a better logistics platform - we're redefining the future of automotive transportation.



About the Role:

The Offensive Security Engineer is a hybrid role combining hands-on penetration testing, adversary simulation, and security engineering. This position is responsible for proactively identifying, exploiting, and validating vulnerabilities while also partnering with engineering teams to design, implement, and improve security controls across the environment. 


This position reports to our Cybersecurity Manager and is a hybrid role (3 days in office per week). 


What You Will Be Doing:

  • Experience with leveraging components of a modern software development stack to attack companies, including CI, container orchestration systems (Kubernetes/Docker), cloud providers (AWS), and be able to give hardening suggestions. 
  • Conduct offensive security engagements, including Red Team operations, threat-based evaluations, and vulnerability research and exploitation against both internal and external-facing systems.
  • Plan and execute black-box, grey-box, and white-box web application penetration tests against RunBuggy production and staging environments. 
  • Maintain tooling (Burp, Metasploit, C2 frameworks, custom scripts) for exploitation, detection validation, and security assessments.
  • Conduct API security testing (REST, GraphQL) including authentication bypass, injection, broken object-level authorization (BOLA/IDOR), and business logic flaws. 
  • Perform cloud configuration reviews (AWS) and assess infrastructure-level exposure where it intersects with web application attack surfaces. 
  • Produce clear, risk-ranked findings reports with reproducible proof-of-concept and actionable remediation guidance for both technical and non-technical audiences. 
  • Collaborate with engineering to validate fixes and re-test remediated vulnerabilities. 
  • Perform social engineering exercises (phishing, credential harvesting), where applicable.
  • Contribute to bug bounty triage, third-party assessment coordination, and security tooling selection. 
  • Support compliance efforts (SOC 2, PCI DSS) by providing evidence and attestation tied to pen test scope and outcomes. 
  • Stay current on emerging attack techniques and translate threat intelligence into test cases relevant to RunBuggy's stack. 
  • Other duties as assigned.


Requirements

What You Bring to the Team by Way of Skills and Experience:

  • Bachelor's degree in Cybersecurity or related field required. 
  • 3+ years of hands-on web application penetration testing experience in a professional or consulting capacity. 
  • Passion and demonstrated experience for challenging security assumptions.
  • Deep familiarity with MITRE ATT&CK, OWASP Top 10, OWASP API Security Top 10, and OWASP Top 10 for LLMs. 
  • Proficiency with standard tooling: Burp Suite, OWASP ZAP, Nmap, Metasploit, SQLmap, Nikto. 
  • Demonstrated ability to exploit and document authentication/authorization flaws, injection vulnerabilities, XXE, SSRF, deserialization issues, and insecure direct object references. 
  • Strong written communications: findings reports must be usable by both developers and executives. 
  • Experience testing RESTful and/or GraphQL APIs. 
  • Experience with AWS environment security assessment (IAM misconfiguration, S3 exposure, Lambda attack surface). 
  • Scripting proficiency in Python, Bash, or JavaScript for custom tooling and automation. 
  • Familiarity with automotive, logistics, or fintech regulatory requirements (PCI DSS, SOC 2 Type II). 
  • Prior experience in a startup or high-growth SaaS environment where speed and security have to coexist. 


Certificates, Licenses, and/or Registrations: 

  • OSCP, GWAPT, eWPT, or equivalent. CEH is accepted but is less weighted than practical certs. 



What is in it for You and Why you Should Apply:

  • Market-competitive pay based on education, experience, and location. 
  • Highly competitive medical, dental, vision, Life w/ AD&D, Short-Term Disability insurance, Long-Term Disability insurance, pet insurance, identity theft protection, and a 401(k) retirement savings plan.
  • Employee wellness program. 
  • Employee rewards, discounts, and recognition programs.
  • Generous company-paid holidays (12 per year), vacation, and sick time.
  • Paid paternity/maternity leave.
  • Monthly connectivity/home office stipend if working from home 5 days a week.
  • A supportive and positive space for you to grow and expand your career.



Pay Range Disclosure: 

The advertised range represents the expected pay range for this position at the time of posting based on education, experience, skills, location, and other factors. 



To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.


RunBuggy is an equal-opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination, harassment, and retaliation on the basis of race, color, religion, sex (including gender identity and sexual orientation), pregnancy, parental status, national origin, age, disability, genetic information, or any other status protected under federal, state, or local law.



Unsolicited resumes sent via email or LinkedIn Messenger will not be considered.


No agencies, please.