1

On Call Cybersecurity Penetration Tester Jobs (NOW HIRING)

The Cybersecurity Penetration Tester is a hands-on technical role responsible for conducting simulated attacks on systems and networks to identify vulnerabilities and weaknesses that could be ...

The Cybersecurity Penetration Tester is a hands-on technical role responsible for conducting simulated attacks on systems and networks to identify vulnerabilities and weaknesses that could be ...

The Cybersecurity Penetration Tester is a hands-on technical role responsible for conducting simulated attacks on systems and networks to identify vulnerabilities and weaknesses that could be ...

... Penetration Tester responsible for supporting authorized penetration testing and security ... cybersecurity requirements. Responsibilities : • Supports execution of authorized penetration ...

They are seeking a Penetration Tester I to perform proactive cybersecurity penetration attacks on digital systems, document actions in detail, and create reports on security breaches.

Holds or is working toward penetration testing and offensive security certifications appropriate ... cybersecurity certifications. Required Education: BS/BA degree Required Experience: 5 years ...

ASRC Federal Technology Solutions is seeking an experienced Penetration Tester to lead advanced ... across cybersecurity disciplines. Work Location : Hybrid, DC (3 days per week onsite ...

Assists with planning, scoping, and execution of penetration tests in coordination with Government stakeholders and senior cybersecurity personnel. Conducts technical testing activities, including ...

Penetration Tester

Herndon, VA · On-site

$131K - $237K/yr

We are looking for a cyber security professional to conduct penetration testing and ethical hacking, to target, assess, and exploit risk and vulnerabilities of information systems. This candidate is ...

Penetration Tester

Chantilly, VA · On-site

$150K - $195K/yr

Possess extensive knowledge of cybersecurity frameworks, industry standards, and advanced security ... TS/SCI with Poly Level 2 Penetration Tester: Education: Bachelor's Degree or Higher, AND Pen Tester ...

Possess extensive knowledge of cybersecurity frameworks, industry standards, and advanced security ... TS/SCI with Poly Level 2 Penetration Tester: Education: Bachelor's Degree or Higher, AND Pen Tester ...

ASRC Federal Technology Solutions is seeking an experienced Penetration Tester to lead advanced ... across cybersecurity disciplines. Work Location : Hybrid, DC (3 days per week onsite ...

next page

Showing results 1-20

On Call Cybersecurity Penetration Tester information

See salary details

$22.5K

$119.9K

$168.5K

How much do on call cybersecurity penetration tester jobs pay per year?

As of Jul 30, 2026, the average yearly pay for on call cybersecurity penetration tester in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What are on call cybersecurity penetration testers?

On call cybersecurity penetration testers are security professionals who are available on an as-needed basis to simulate cyberattacks against an organization’s systems, networks, or applications. Their primary role is to identify vulnerabilities and weaknesses that could be exploited by malicious hackers. Being 'on call' means they can be engaged at short notice, often in response to incidents, urgent assessments, or compliance requirements. These testers use various tools and techniques to mimic real-world cyber threats and provide actionable recommendations to strengthen security. Their expertise is critical for organizations aiming to proactively protect their digital assets.

What are some unique challenges faced by on-call cybersecurity penetration testers compared to those in full-time roles?

On-call cybersecurity penetration testers often face the challenge of responding quickly to emerging threats or incidents, which can require irregular hours and rapid adaptation to new environments. Unlike full-time testers who may have ongoing projects and stable schedules, on-call testers must be prepared to work with diverse systems and teams on short notice. This role demands strong time management, effective communication with various stakeholders, and the ability to rapidly assess and prioritize vulnerabilities under pressure. Building rapport with new clients or internal teams quickly is essential for efficient collaboration and successful outcomes.

What are the key skills and qualifications needed to thrive as an On Call Cybersecurity Penetration Tester, and why are they important?

To thrive as an On Call Cybersecurity Penetration Tester, you need a deep understanding of network and application security, vulnerability assessment, and penetration testing methodologies, often backed by a relevant degree or certifications like OSCP or CEH. Mastery of tools such as Metasploit, Burp Suite, Nmap, and knowledge of operating systems and scripting languages is typically required. Strong analytical thinking, problem-solving abilities, and clear communication skills help you effectively identify vulnerabilities and deliver actionable recommendations to clients. These skills ensure thorough, accurate security assessments and enable rapid, effective responses to emerging threats in dynamic environments.

What is the difference between On Call Cybersecurity Penetration Tester vs Cybersecurity Analyst?

AspectOn Call Cybersecurity Penetration TesterCybersecurity Analyst
CertificationsOSCP, CEH, GPENCISSP, Security+, CEH
Work EnvironmentProject-based, client sites, or remote testingIn-house security team, monitoring, and incident response
Primary FocusSimulating attacks to find vulnerabilitiesMonitoring, analyzing security events, and implementing defenses
Employer & Industry UsageConsulting firms, security service providersCorporate, government, or enterprise organizations

While both roles require cybersecurity certifications and involve security work, the On Call Cybersecurity Penetration Tester focuses on actively testing systems for vulnerabilities through simulated attacks. In contrast, a Cybersecurity Analyst primarily monitors security systems, analyzes threats, and responds to incidents within an organization. The penetration tester's work is often project-based and external, whereas analysts work internally to maintain ongoing security posture.

What cities are hiring for On Call Cybersecurity Penetration Tester jobs? Cities with the most On Call Cybersecurity Penetration Tester job openings:
What are the most commonly searched types of Cybersecurity Penetration Tester jobs? The most popular types of Cybersecurity Penetration Tester jobs are:

Principal, Cybersecurity Penetration Tester

Fidelity Investments

Durham, NC • On-site

Full-time

Re-posted 13 days ago


Fidelity Investments rating

8.7

Company rating: 8.7 out of 10

Based on 270 frontline employees who took The Breakroom Quiz

15th of 150 rated financial services


Job description

Job Description:

Position Description:

Performs security assessments of applications prior to production deployment using Static Code Analysis, dynamic testing tools, and manual techniques. Assists in establishing the strategy, policy, and standards of security for cybersecurity operations. Develop custom Python scripts to automate repetitive tasks. Defends enterprise against attacks, damage, and unauthorized access to information, data, and systems. Ensures threat and vulnerability reduction, deterrence, incident response, resiliency, and recovery policies and activities are up to date. Proactively identifies vulnerabilities in proprietary applications prior to production release and remediates identified vulnerabilities to prevent real-life cyberattacks.

Primary Responsibilities:

  • Performs advanced Web application source code auditing.
  • Analyzes codes, writes scripts, and exploits web vulnerabilities.
  • Analyzes test results, draw conclusions from results.
  • Identifies vulnerabilities by performing thorough evaluations of security vulnerabilities on Web and mobile applications.
  • Collaborates with application developers to mitigate risk and improve security posture.
  • Performs security testing on web and mobile applications to support production releases.
  • Models potential external threats by replicating the techniques and tools used by malicious attackers.
  • Prepares reports on completed assessments and present results to application owners, developers, and business unit information security teams.
  • Consults with operations and software development teams to ensure potential weaknesses are addressed.
  • Contributes to the research and development of tools to assist in the vulnerability discovery process.
  • Keeps abreast of current cybersecurity best practices and vulnerabilities.
  • Conducts peer reviews to facilitate continuous improvement across the team.

Education and Experience:

Bachelor's degree in Computer Science, Engineering, Information Technology, Information Systems, or a closely related field (or foreign education equivalent) and five (5) years of experience as a Principal, Cybersecurity Penetration Tester (or closely related occupation) performing black and white box testing to protect against cyber threats and ensure application security (web, mobile, API, and thick client).

Or, alternatively, Master's degree in Computer Science, Engineering, Information Technology, Information Systems, or a closely related field (or foreign education equivalent) and three (3) years of experience as a Principal, Cybersecurity Penetration Tester (or closely related occupation) performing black and white box testing to protect against cyber threats and ensure application security (web, mobile, API, and thick client).

Skills and Knowledge:

Candidate must also possess:

  • Demonstrated Expertise ("DE") estimating risks on security flaws uncovered during static or dynamic analysis in line with the OWASP testing guide; conducting pen-testing on applications to uncover security vulnerabilities - Injection attacks, Server-side attacks, Privilege escalation, GraphQL batching attacks, or JWT signature manipulation attacks - using BurpSuite Professional Edition, Fiddler, Kali Linux, and SQLMap.
  • DE analyzing source code for security weaknesses, writing custom scripts, exploiting security vulnerabilities, and conducting retests to determine mitigation measures implemented by development teams, through a combination of manual analysis by using BurpSuite Professional, and automated scans using GitHub Advanced Security(GHAS) and MEND.
  • DE analyzing Common Vulnerability Exposure (CVE) on third party libraries, using Veracode SCA, MEND, Exploit-DB, and NVD databases; and coordinating actions associated with the dismissal or reopening of policy violation alerts related to security, licensing, and coding standards using GitHub Advanced Security (GHAS).
  • DE crafting custom scripts to effectively automate labor-intensive manual tasks (logging security findings, preparing weekly status reports, verifying artifact correctness) and empower the efficient allocation of resources, enhancing the overall security assessment process, using Python or Selenium.

#PE1M2

#LI-DNI

Certifications:Category:Information Technology

Please be advised that Fidelity's business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.


What Fidelity Investments employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom