1

Mid Penetration Tester Jobs (NOW HIRING)

We are seeking a skilled Penetration Tester with a focus on Java application security is sought to ... We work closely with small to mid-sized organizations to provide flexible, high-quality services ...

Role Description Penetration Tester (Mid-Senior) Full-Time Remote (US) As a penetration tester on BreachLock's US Strategic delivery team, you'll execute manual, methodology-driven engagements across ...

next page

Showing results 1-20

Mid Penetration Tester information

See salary details

$22.5K

$119.9K

$168.5K

How much do mid penetration tester jobs pay per year?

As of Aug 17, 2026, the average yearly pay for mid penetration tester in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What is a mid penetration tester?

Mid Penetration Testers are cybersecurity professionals with intermediate experience who assess and identify vulnerabilities in computer systems, networks, and applications. They simulate cyberattacks to find security weaknesses that could be exploited by malicious hackers. Typically, they analyze results, document findings, and provide recommendations to improve an organization's security posture. Mid-level testers often work as part of a larger security team and may lead smaller projects or mentor junior testers. Their work helps protect sensitive data and maintain compliance with industry standards.

What are the typical daily responsibilities of a mid penetration tester?

As a Mid Penetration Tester, your daily tasks commonly include planning and conducting security assessments on networks, applications, and systems to identify vulnerabilities. You’ll often be documenting findings, preparing comprehensive reports for clients or internal teams, and sometimes providing recommendations for remediation. Collaboration with security analysts, IT administrators, and developers is frequent to ensure discovered vulnerabilities are addressed effectively. Additionally, you may spend time researching emerging threats and updating testing methodologies to stay current with industry standards.

What are the key skills and qualifications needed to thrive as a mid penetration tester, and why are they important?

To thrive as a Mid Penetration Tester, you need a solid grounding in network security, vulnerability assessment, and ethical hacking, typically backed by a relevant degree or certifications such as CEH or OSCP. Familiarity with tools like Metasploit, Burp Suite, Nmap, and reporting systems is essential for conducting thorough security evaluations. Strong analytical thinking, attention to detail, and clear communication skills help you effectively identify threats and convey findings to technical and non-technical stakeholders. These skills are crucial for accurately assessing organizational security and helping teams remediate vulnerabilities to protect critical assets.

What is the difference between Mid Penetration Tester vs Penetration Tester?

AspectMid Penetration TesterPenetration Tester
CertificationsCEH, OSCP, CompTIA Security+CEH, OSCP, GPEN, CISSP (entry-level to mid)
Work EnvironmentMid-sized to large organizations, security teamsVaried environments, consulting firms, security firms
Employer & Industry UsageIT security teams, cybersecurity firmsConsulting firms, internal security teams

The Mid Penetration Tester typically has more experience and handles complex security assessments within organizations, whereas the Penetration Tester may be at an earlier stage or handle more straightforward testing. Both roles require similar certifications and work environments, but Mid Penetration Testers often take on more advanced projects and responsibilities.

More about Mid Penetration Tester jobs

What cities are hiring for Mid Penetration Tester jobs?

Cities with the most Mid Penetration Tester job openings:

What states have the most Mid Penetration Tester jobs?

States with the most job openings for Mid Penetration Tester jobs include:

Infographic showing various Mid Penetration Tester job openings in the United States as of August 2026, with employment types broken down into 77% Full Time, 15% Part Time, and 8% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

Penetration Tester

Donato Technologies, Inc

Albany, NY • On-site

$60/hr

Contractor

Re-posted 5 days ago


Job description

We are seeking a skilled Penetration Tester with a focus on Java application security is sought to identify, exploit, and fix vulnerabilities in Java applications to guard against cyber threats. 

Key Responsibilities
  • Conduct penetration tests and vulnerability assessments for Java applications and infrastructure.
  • Identify security flaws in Java code using automated and manual methods.
  • Create and use custom exploits to test application security, simulating attacker tactics.
  • Collaborate with Development teams to understand application architecture and find security weaknesses early.
  • Collaborate with Testing teams to integrate with manual and automation testing.
  • Provide guidance on secure coding and how to fix vulnerabilities.
  • Stay updated on Java security threats and best practices.
  • Help improve secure development processes (SDLC).
  • Assist in responding to security incidents related to Java vulnerabilities, current published NIST CVE.
  • Clearly document and report findings, including technical details, risk assessment, and recommended solutions.
  • Communicate findings and recommendations to both technical and non-technical staff.
  • Contribute to security policies for Java development and deployment.
  • Manipulate URLs, query parameters and Application browser data to look for penetration avenues. Validate and asses’ browser tokens and cache manipulation and Production vs. none prod architecture.
  • Familiar with MITRE ATT&CK Framework.
Required Qualifications
  • Bachelor’s degree in a related software field with 6+ years in a Dev Sec role.
  • Core Java coding experience.
  • Previous job background as an engineer and Dev Sec position on a large scale public enterprise scale application.
  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • Minimum of 6 years of Development/Security experience
  • Experience in Penetration Testing/Ethical Hacking with a focus on Java application security.
  • Strong knowledge of Java programming and its security practices as well as scripting experience.
  • Proficiency in web application security principles (e.g., OWASP).
  • Knowledge of common web vulnerabilities (e.g., SQL injection, XSS) and exploit techniques.
  • Experience with penetration testing tools like Burp Suite, Metasploit.
  • Familiarity with Fortify on Demand SAST and DAST tools.
  • Strong understanding of cryptography and secure communication protocols (e.g., SSL/TLS).
  • Excellent problem-solving and analytical skills.
  • Strong communication skills.
  • High ethical standards and confidentiality.
Desired Qualifications
  • Certifications such as OSCP, GWAPT, GXPN, GPEN, LPT, CEH, CISSP or other industry security certifications.
  • Experience with scripting languages (e.g., Python, Bash).
  • Experience with secure code review for Java.
  • Familiarity with cloud security testing.
  • Experience with mobile application penetration testing.
  • Knowledge of regulations like HIPAA. 
  • Experience with API testing

Donato Technologies Inc. is a trusted IT staffing, consulting, and software development partner headquartered in Dallas, Texas. We support clients across industries by understanding their unique business needs and delivering tailored technology and workforce solutions. Our focus is on connecting the right talent with the right opportunity-ensuring clients receive dependable, skilled professionals and candidates receive meaningful career growth and support. We work closely with small to mid-sized organizations to provide flexible, high-quality services that drive performance, innovation, and long-term success.