1

On Call Cybersecurity Penetration Tester Jobs (NOW HIRING)

The Cybersecurity Penetration Tester is a hands-on technical role responsible for conducting simulated attacks on systems and networks to identify vulnerabilities and weaknesses that could be ...

The Cybersecurity Penetration Tester is a hands-on technical role responsible for conducting simulated attacks on systems and networks to identify vulnerabilities and weaknesses that could be ...

Penetration Tester

Quantico, VA · On-site

$130K - $147K/yr

The Cybersecurity Penetration Tester is a hands-on technical role responsible for conducting simulated attacks on systems and networks to identify vulnerabilities and weaknesses that could be ...

ASRC Federal Technology Solutions is seeking an experienced Penetration Tester to lead advanced ... across cybersecurity disciplines. Work Location : Hybrid, DC (3 days per week onsite ...

Penetration Tester

Chantilly, VA · On-site

$90K - $130K/yr

Experience in cyber security with a focus on red teaming, penetration testing, or threat hunting. Desired Qualifications: * Strong understanding of network protocols and troubleshooting, server and ...

Penetration Tester

Herndon, VA · On-site

$131K - $237K/yr

We are looking for a cyber security professional to conduct penetration testing and ethical hacking, to target, assess, and exploit risk and vulnerabilities of information systems. This candidate is ...

Assists with planning, scoping, and execution of penetration tests in coordination with Government stakeholders and senior cybersecurity personnel. Conducts technical testing activities, including ...

Penetration Tester

Chantilly, VA · On-site

$150K - $195K/yr

Possess extensive knowledge of cybersecurity frameworks, industry standards, and advanced security ... TS/SCI with Poly Level 2 Penetration Tester: Education: Bachelor's Degree or Higher, AND Pen Tester ...

Penetration Tester

Chantilly, VA · On-site

$90K - $130K/yr

Experience in cyber security with a focus on red teaming, penetration testing, or threat hunting. Desired Qualifications: * Strong understanding of network protocols and troubleshooting, server and ...

Penetration Tester

Chantilly, VA · On-site

$150K - $195K/yr

Possess extensive knowledge of cybersecurity frameworks, industry standards, and advanced security ... TS/SCI with Poly Level 2 Penetration Tester: Education: Bachelor's Degree or Higher, AND Pen Tester ...

ASRC Federal Technology Solutions is seeking an experienced Penetration Tester to lead advanced ... across cybersecurity disciplines. Work Location : Hybrid, DC (3 days per week onsite ...

Possess extensive knowledge of cybersecurity frameworks, industry standards, and advanced security ... TS/SCI with Poly Level 2 Penetration Tester: Education: Bachelor's Degree or Higher, AND Pen Tester ...

Providing intelligence, IT, cyber security, training, logistics, administrative, acquisition, and background investigation services. Summary: The Senior Penetration Tester will independently perform ...

next page

Showing results 1-20

On Call Cybersecurity Penetration Tester information

See salary details

$22.5K

$119.9K

$168.5K

How much do on call cybersecurity penetration tester jobs pay per year?

As of Aug 6, 2026, the average yearly pay for on call cybersecurity penetration tester in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What is an on call cybersecurity penetration tester?

On call cybersecurity penetration testers are security professionals who are available on an as-needed basis to simulate cyberattacks against an organization’s systems, networks, or applications. Their primary role is to identify vulnerabilities and weaknesses that could be exploited by malicious hackers. Being 'on call' means they can be engaged at short notice, often in response to incidents, urgent assessments, or compliance requirements. These testers use various tools and techniques to mimic real-world cyber threats and provide actionable recommendations to strengthen security. Their expertise is critical for organizations aiming to proactively protect their digital assets.

What are some unique challenges faced by on call cybersecurity penetration testers compared to those in full-time roles?

On-call cybersecurity penetration testers often face the challenge of responding quickly to emerging threats or incidents, which can require irregular hours and rapid adaptation to new environments. Unlike full-time testers who may have ongoing projects and stable schedules, on-call testers must be prepared to work with diverse systems and teams on short notice. This role demands strong time management, effective communication with various stakeholders, and the ability to rapidly assess and prioritize vulnerabilities under pressure. Building rapport with new clients or internal teams quickly is essential for efficient collaboration and successful outcomes.

What are the key skills and qualifications needed to thrive as an on call cybersecurity penetration tester, and why are they important?

To thrive as an On Call Cybersecurity Penetration Tester, you need a deep understanding of network and application security, vulnerability assessment, and penetration testing methodologies, often backed by a relevant degree or certifications like OSCP or CEH. Mastery of tools such as Metasploit, Burp Suite, Nmap, and knowledge of operating systems and scripting languages is typically required. Strong analytical thinking, problem-solving abilities, and clear communication skills help you effectively identify vulnerabilities and deliver actionable recommendations to clients. These skills ensure thorough, accurate security assessments and enable rapid, effective responses to emerging threats in dynamic environments.

What is the difference between On Call Cybersecurity Penetration Tester vs Cybersecurity Analyst?

AspectOn Call Cybersecurity Penetration TesterCybersecurity Analyst
CertificationsOSCP, CEH, GPENCISSP, Security+, CEH
Work EnvironmentProject-based, client sites, or remote testingIn-house security team, monitoring, and incident response
Primary FocusSimulating attacks to find vulnerabilitiesMonitoring, analyzing security events, and implementing defenses
Employer & Industry UsageConsulting firms, security service providersCorporate, government, or enterprise organizations

While both roles require cybersecurity certifications and involve security work, the On Call Cybersecurity Penetration Tester focuses on actively testing systems for vulnerabilities through simulated attacks. In contrast, a Cybersecurity Analyst primarily monitors security systems, analyzes threats, and responds to incidents within an organization. The penetration tester's work is often project-based and external, whereas analysts work internally to maintain ongoing security posture.

What cities are hiring for On Call Cybersecurity Penetration Tester jobs? Cities with the most On Call Cybersecurity Penetration Tester job openings:
What are the most commonly searched types of Cybersecurity Penetration Tester jobs? The most popular types of Cybersecurity Penetration Tester jobs are:

Penetration Tester

asrcfh

Quantico, VA • Hybrid

Other

Posted 15 days ago


Job description

ASRC Federal is actively hiring an Assured Compliance Assessment Solution (ACAS) Engineer in support of our Defense Counterintelligence Security Agency (DCSA) program based out of Quantico VA.

Remote flexibility available! Telework offered with a requirement to be onsite up to two (2) days a week at Quantico Marine Corps Base VA.

Position Description:

The Cybersecurity Penetration Tester is a hands-on technical role responsible for conducting simulated attacks on systems and networks to identify vulnerabilities and weaknesses that could be exploited by malicious actors. This role requires a deep understanding of security principles, hacking techniques, and attack methodologies. The Penetration Tester will plan, execute, and document penetration tests, provide recommendations for remediation, and contribute to the overall improvement of the organization's security posture.

Minimum Requirements: 

  • Minimum of 5 – 7 years of experience in security principles such as attack frameworks, threat landscapes, and attacker tactics, techniques and procedures. 
  • Proven experience conducting penetration tests of web applications, networks, and other systems.
  • Experience with a variety of penetration testing tools and techniques (e.g., Rapid7 Nexpose, Appspider Pro, Metasploit, Cobalt Strike and/or Burp Suite).
  • Active Top-Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI
  • Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent experience.
  • Must meet 8570 certification requirements at the time of hire.  IAT II Information Assurance Baseline (e.g., CASP+ CE, CCMP Security, CISA, CISSP, GCED, GCIH, Security+ CE or CCSP) In addition to the IA baseline, a CSSP Auditor cert is preferred (e.g., CEH, CySA+, CISA, GSNA, CFR or PenTest) 

 

Responsibilities:

  • Penetration Testing:
    • Conduct penetration tests of web applications, mobile applications, networks, cloud environments, and other systems.
    • Utilize a variety of tools and techniques to identify vulnerabilities, including SQL injection, cross-site scripting (XSS), buffer overflows, and other common attack vectors.
    • Perform reconnaissance to gather information about target systems and networks.
    • Develop and execute exploit code to demonstrate the impact of identified vulnerabilities.
    • Bypass security controls and evade detection.
  • Vulnerability Assessment:
    • Perform vulnerability assessments using automated scanning tools and manual techniques.
    • Analyze scan results to identify false positives and prioritize vulnerabilities.
    • Develop custom scripts and tools to automate vulnerability assessment tasks.
  • Reporting and Documentation:
    • Document all findings in detailed and comprehensive reports, including descriptions of vulnerabilities, methods used to exploit them, and recommendations for remediation.
    • Present findings to stakeholders, including technical teams and management.
    • Create and maintain documentation on penetration testing methodologies, tools, and techniques.
  • Remediation Support:
    • Provide guidance and technical assistance to system owners and developers on vulnerability remediation.
    • Validate remediation efforts to ensure that vulnerabilities have been properly addressed.
    • Conduct retests to verify the effectiveness of implemented security controls.
  • Research and Development:
    • Stay up-to-date on the latest security threats, vulnerabilities, and attack techniques.
    • Research and evaluate new penetration testing tools and methodologies.
    • Develop custom tools and scripts to enhance penetration testing capabilities.
    • Contribute to the development of security policies and procedures.
  • Collaboration:
    • Collaborate with other cybersecurity professionals, including security architects, incident responders, and security engineers.
    • Share knowledge and expertise with team members.
    • Participate in security training and awareness programs.
  • Ethical Hacking:
    • Conduct all penetration testing activities in a legal and ethical manner, adhering to established rules of engagement.
    • Protect the confidentiality and integrity of sensitive data.
    • Respect the privacy of users and systems.

Work Environment and Physical Demands: 

  • This is primarily a Telework position with a requirement to be onsite up to two (2) days a week
  • If alternate worksite is other than DCSA facilities or corporate office space, must have the reliable ability to communicate over voice (cell phone preferred) and stable, capable internet connection
  • Must be able to communicate complex technical ideas to a diverse customer base both verbally and in written form