1

Oswe Jobs (NOW HIRING)

OSCP, OSWE, GXPN, GPEN, or equivalent • Familiarity with commonly used large-scale service components (webservers, databases, load balancers, caching servers, storage cluster, etc.) Company

CSSLP, GWEB, CASE, OSWE, OSCP, Security+, or equivalent preferred/required as applicable. Security Clearance: * Active Top Secret (TS) security clearance required. Compensation: $145,000.00 - $175 ...

... OSWE, or relevant cloud certifications. Preferred : • Verifiable contributions to vulnerability research (CVEs), exploit development, or open-source offsec projects. • Familiarity with AI prompt ...

Showing results 21-40

OSWE information

See salary details

$73.5K

$137.1K

$186.5K

How much do oswe jobs pay per year?

As of Aug 16, 2026, the average yearly pay for oswe in the United States is $137,131.00, according to ZipRecruiter salary data. Most workers in this role earn between $114,500.00 and $157,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as an OSWE?

To thrive as an OSWE (Offensive Security Web Expert), you need strong expertise in web application security, penetration testing, and vulnerability assessment, usually supported by advanced technical training or industry certifications such as the OSWE. Familiarity with tools like Burp Suite, various proxy tools, scripting languages (such as Python and JavaScript), and security testing platforms is essential. Persistence, analytical thinking, and clear communication skills make a candidate stand out in this security-focused role. These abilities are critical to effectively identifying, reporting, and helping mitigate security weaknesses in web applications, ensuring organizations’ digital safety.

What is an OSWE?

An OSWE (Offensive Security Web Expert) job involves conducting advanced web application penetration testing to identify security vulnerabilities. Professionals with this certification specialize in exploiting complex web applications, analyzing security risks, and providing remediation guidance. OSWE-certified individuals typically work as penetration testers, security consultants, or ethical hackers, ensuring web applications are secure against real-world attacks.

What types of projects or assessments does an OSWE typically work on?

An OSWE (Offensive Security Web Expert) is primarily engaged in hands-on security assessments of web applications, focusing on identifying and exploiting vulnerabilities through advanced penetration testing techniques. Daily tasks often include reviewing source code, conducting manual and automated testing, and producing detailed vulnerability reports for development teams. OSWE professionals commonly collaborate with software developers, security engineers, and IT managers to remediate discovered issues and improve application security. This role is both challenging and rewarding, offering opportunities to tackle complex security problems and continuously expand technical skillsets through real-world scenario testing.

More about OSWE jobs

What cities are hiring for Oswe jobs?

Cities with the most Oswe job openings:

What are the most commonly searched types of Oswe jobs?

The most popular types of Oswe jobs are:

What states have the most Oswe jobs?

States with the most job openings for Oswe jobs include:

Infographic showing various Oswe job openings in the United States as of August 2026, with employment types broken down into 89% Full Time, 3% Part Time, and 8% Contract. Highlights an 75% Physical, 8% Hybrid, and 17% Remote job distribution, with an average salary of $137,131 per year, or $65.9 per hour.

Senior Specialist, MAST Application Penetration Tester

KPMG US

Dallas, TX • On-site

Full-time

Re-posted 16 days ago


Job description

Job Summary:
KPMG is a leading advisory firm that offers excellent opportunities for career advancement. They are currently seeking a Senior Specialist, MAST Application Penetration Tester to conduct manual penetration testing and evaluate application security, while working independently and collaborating with both internal and external audiences.
Responsibilities:
• Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications
• Perform objective based on abstract penetration testing engagements
• Execute threat modeling, evaluate application business logic, and perform application architecture reviews
• Demonstrate application testing experience in real time via demos to both internal and external audiences
• Function independently in penetration testing engagements, with minimal oversight and guidance
• Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
Qualifications:
Required:
• Minimum three years of recent experience in application penetration testing of Application Programming Interface (API's), web applications, or mobile applications
• Bachelor's degree from an accredited college/university or equivalent industry experience
• Ability to communicate reporting results with technical and non-technical audiences and lead remediation conversations
• Experience with burp suite pro, and other app testing tools such as Netsparker and Checkmarx
• Ability to travel as required
• Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future.
Preferred:
• One or more major ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert (OSWE), Offensive Security Web Assessor (OSWA)
Company:
KPMG is one of the world’s leading professional services firms and the fastest growing Big Four accounting firm in the United States. Founded in 2010, the company is headquartered in New York, USA, with a team of 10001+ employees. The company is currently Late Stage.