1

Mobile Penetration Tester Jobs (NOW HIRING)

WV · On-site

Conduct web, mobile, API, and microservices security testing using industrystandard tools and manual exploitation techniques. * Execute AWS cloud penetration testing within approved boundaries (IAM ...

Penetration Tester

Colorado Springs, CO · Hybrid

$130K - $145K/yr

Dark Wolf is actively seeking an experienced Penetration Tester to join our innovative team. This ... Proficiency in the testing and assessment of mobile operating systems, embedded systems, and/or IoT ...

Experience performing IoT, mobile, and cloud penetration testing * Experience supporting High Value Asset (HVA) assessments * Experience applying MITRE ATT&CK, OSSTMM, OWASP, NIST, PTES, and ISSAF ...

Plan, scope, and execute penetration testing engagements across a variety of environments, including web applications, APIs, cloud platforms, infrastructure, thick-client, and/or mobile applications.

Plan, scope, and execute penetration testing engagements across a variety of environments, including web applications, APIs, cloud platforms, infrastructure, thick-client, and/or mobile applications.

Senior Penetration Tester

Tampa, FL · On-site

$120 - $150/hr

Plan, scope, and execute penetration testing engagements across a variety of environments, including web applications, APIs, cloud platforms, infrastructure, thick-client, and/or mobile applications.

Experience with mobile application penetration testing. * Knowledge of regulations like HIPAA. * Experience with API testing Donato Technologies Inc. is a trusted IT staffing, consulting, and ...

Conduct tactical penetration testing assessments of web, mobile, and API applications against OWASP Top 10 threats and emerging risks, and collaborate with Application Security teams to provide ...

Plan, scope, and execute penetration testing engagements across a variety of environments, including web applications, APIs, cloud platforms, infrastructure, thick-client, and/or mobile applications.

Senior Penetration Tester

Tampa, FL · On-site

$156K - $260K/yr

Plan, scope, and execute penetration testing engagements across a variety of environments, including web applications, APIs, cloud platforms, infrastructure, thick-client, and/or mobile applications.

Conduct tactical penetration testing assessments of web, mobile, and API applications against OWASP Top 10 threats and emerging risks, and collaborate with Application Security teams to provide ...

Conduct tactical penetration testing assessments of web, mobile, and API applications against OWASP Top 10 threats and emerging risks, and collaborate with Application Security teams to provide ...

Conduct tactical penetration testing assessments of web, mobile, and API applications against OWASP Top 10 threats and emerging risks, and collaborate with Application Security teams to provide ...

Showing results 21-40

Mobile Penetration Tester information

See salary details

$22.5K

$119.9K

$168.5K

How much do mobile penetration tester jobs pay per year?

As of Aug 17, 2026, the average yearly pay for mobile penetration tester in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What is a mobile penetration tester?

A Mobile Penetration Tester evaluates the security of mobile applications, devices, and networks by simulating real-world attacks. They identify vulnerabilities, exploit weaknesses, and provide recommendations to strengthen security. This role requires knowledge of mobile operating systems (iOS, Android), reverse engineering, network security, and threat modeling. Testers use various tools and techniques to assess app security, including static and dynamic analysis. Their goal is to help organizations protect sensitive data and improve overall mobile security.

What skills and qualifications are needed to be a mobile penetration tester?

A Mobile Penetration Tester needs strong knowledge of mobile operating systems (Android and iOS), secure coding practices, and vulnerability assessment, typically supported by a background in cybersecurity or computer science. Familiarity with tools like Burp Suite, Frida, OWASP Mobile Security Testing Guide (MSTG), and certifications such as OSCP or GMOB are highly valued. Excellent analytical thinking, communication, and report-writing skills help testers clearly convey findings to both technical and non-technical stakeholders. These abilities are essential to identify and mitigate mobile security risks, ensuring robust defense measures for organizations.

What are common challenges faced by mobile penetration testers in their day-to-day work?

Mobile Penetration Testers often encounter the challenge of keeping up with rapidly evolving mobile platforms, frequent security patch releases, and diverse device configurations. Testing applications in various environments, dealing with obfuscated code, and adhering to strict project timelines can also add complexity. Collaboration with developers and IT teams is frequently required to ensure that security recommendations are implemented effectively. Adapting to new tools and methodologies is part of the role, making continuous learning a key aspect of success in this field.

More about Mobile Penetration Tester jobs

What cities are hiring for Mobile Penetration Tester jobs?

Cities with the most Mobile Penetration Tester job openings:

What are the most commonly searched types of Penetration Tester jobs?

The most popular types of Penetration Tester jobs are:

What states have the most Mobile Penetration Tester jobs?

States with the most job openings for Mobile Penetration Tester jobs include:

Infographic showing various Mobile Penetration Tester job openings in the United States as of August 2026, with employment types broken down into 78% Full Time, 15% Part Time, and 7% Contract. Highlights an 77% In-person, 4% Hybrid, and 19% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

Penetration Tester

GDIT

WV • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 9 days ago


General Dynamics Information Technology rating

7.8

Company rating: 7.8 out of 10

Based on 63 frontline employees who took The Breakroom Quiz

87th of 224 rated it services


Job description

Type of Requisition:

Regular

Clearance Level Must Currently Possess:

None

Clearance Level Must Be Able to Obtain:

None

Public Trust/Other Required:

Other

Job Family:

Cyber and IT Risk Management

Job Qualifications:

Skills:

Automated Testing, AWS Cloud Computing, Infrastructure Penetration Testing, Security Controls, Security Testing

Certifications:

None

Experience:

8 + years of related experience

US Citizenship Required:

No

Job Description:

The Penetration Tester supports the Case Management Modernization (CMM) Program for the Administrative Office of the U.S. Courts (AO) by conducting security, penetration, and vulnerability assessments required prior to Application ATO (Authority to Operate). This role ensures that CMM applications-built using React, NodeJS, AWS cloud services, and microservices-meet federal security standards and demonstrate resilience against realworld cyber threats.

Working within Agile DevSecOps teams, the Penetration Tester performs handson exploitation, validates security controls, identifies weaknesses, and collaborates with engineering teams to remediate findings. This role is critical to ensure that CMM systems comply with NIST 80053, RMF, and AO security requirements before production authorization.

Key Responsibilities:

  • Perform application, API, and cloud penetration tests on CMM systems prior to ATO submission.
  • Conduct web, mobile, API, and microservices security testing using industrystandard tools and manual exploitation techniques.
  • Execute AWS cloud penetration testing within approved boundaries (IAM, S3, Lambda, API Gateway, ECS/EKS, networking).
  • Perform static and dynamic analysis, including code review for security vulnerabilities.
  • Conduct credentialed and uncredentialed scans, privilege escalation testing, and lateral movement analysis.
  • Validate implementation of NIST 80053 controls, including AC, AU, IA, SC, SI, and CM families.
  • Support RMF Step 3 (Security Assessment) activities and provide evidence for ATO packages.
  • Identify vulnerabilities across application layers, cloud infrastructure, and CI/CD pipelines.
  • Work with developers, cloud engineers, and DevSecOps teams to validate fixes and retest vulnerabilities.
  • Provide detailed remediation guidance aligned with secure coding and cloud security best practices.
  • Track findings in Jira or equivalent tools and ensure closure prior to ATO milestones.
  • Prepare Security Assessment Reports (SAR), penetration test summaries, and risk findings for AO stakeholders.
  • Document exploitation steps, proofofconcepts, and risk severity aligned with federal scoring methodologies.
  • Contribute to System Security Plans (SSP), POA&Ms, and ATO evidence packages.
  • Support preATO readiness reviews, including control validation and security walkthroughs.
  • Participate in tabletop exercises, threat modeling sessions, and architecture reviews.
  • Validate system resilience through stress, failover, and adversarial resilience testing.
  • Ensure compliance with federal security standards, including NIST, FISMA, and AO-specific guidelines.
  • Work closely with development teams to integrate security testing into Agile sprints.
  • Provide security insights during sprint planning, backlog refinement, and release readiness reviews.
  • Support secure CI/CD pipeline enhancements, including automated security scanning.

REQUIREMENTS:

  • 8+ years of experience in penetration testing, application security, or ethical hacking security roles.
  • Experience documenting test plans, test procedures, and detailed security findings.
  • Experience supporting federal security assessments or enterprise-scale security testing.
  • Hands-on experience performing penetration tests on web applications, APIs, microservices, and cloud environments.
  • Strong proficiency with tools such as Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, Nikto, K6 Security, or custom scripts.
  • Experience testing applications built with NodeJS, ReactJS, REST APIs, and microservices.
  • Strong understanding of AWS security, including IAM, VPC, S3, Lambda, API Gateway, ECS/EKS, CloudTrail, and CloudWatch.
  • Experience with NIST 80053, RMF, FedRAMP, or federal ATO processes.
  • Ability to interpret logs, metrics, and security telemetry to identify attack paths.
  • Familiarity with SIEM and monitoring tools such as Datadog, ELK, CloudWatch, Grafana.
  • Experience with container security (Docker, Kubernetes, OpenShift).
  • Understanding of network security, distributed tracing, and adversarial testing techniques.
  • Strong analytical, communication, and documentation skills.

QUALIFICATIONS:

  • 8+ years of general experience in information systems with BS/BA Degree, or 6+ years with MA/MS Degree
  • 6+ years experience with in integration, regression, and system testing using automated testing tools in web-based applications
  • Experience in writing test cases, test plans, executing test scripts, reporting defects and preparing test results reports
  • Experience in the entire QA Life Cycle, to include designing, developing and execution on the entire QA process and documentation of test plans, test cases, test procedures and test scripts
  • Experience may be considered in lieu of degree

CERTIFICATIONS:

  • OSCP, OSWE, GWAPT, GPEN, or similar offensive security certifications.
  • AWS Security Specialty
  • SAFe, DevSecOps, or Agile certifications beneficial.

TOOLS & TECHNOLOGIES:

  • Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, Nikto
  • K6 Security, custom Python/JavaScript tools
  • AWS CloudWatch, CloudTrail, GuardDuty
  • Datadog, ELK Stack, Prometheus, Grafana
  • Jenkins, GitLab CI/CD, GitHub Actions
  • SAST/DAST tools (SonarQube, Checkmarx, Fortify)
  • Jira, Confluence, SharePoint, MS Teams
  • Power BI, Grafana dashboards

COMMUNICATION & ORGANIZATIONAL

  • Excellent presentation and communication (oral and written) skills.
  • Consultant mindset with the ability to work with high level customer stakeholders and build excellent customer relationship.
  • Experience identifying and applying industry tools, solutions, methods best practices, and emerging technologies.
  • Strong analytical skills and problem-solving skills with the ability to formulate and communicate recommendations for improvement.
  • Demonstrated ability to work effectively, independently, and as part of a team.
The likely salary range for this position is $123,250 - $166,750. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:

40

Travel Required:

None

Telecommuting Options:

Remote

Work Location:

Any Location / Remote

Additional Work Locations:

Total Rewards at GDIT:

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. GDIT typically provides new employees with 15 days of paid leave per calendar year to be used for vacations, personal business, and illness and an additional 10 paid holidays per year. Paid leave and paid holidays are prorated based on the employee's date of hire. The GDIT Paid Family Leave program provides a total of up to 160 hours of paid leave in a rolling 12 month period for eligible employees. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

Our Identity Verification Process:

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About Our Work:

We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.Join our Talent Community to stay up to date on our career opportunities and events at

gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

What General Dynamics Information Technology employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


General Dynamics Information Technology logo

About General Dynamics Information Technology

Sourced by ZipRecruiter

GDIT is a global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense, and intelligence community. Its 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. The company operates across 50+ countries worldwide, offering leading capabilities in digital modernization, AI/ML, cloud, cyber, and application development.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Falls Church, VA, US