1

On Call Web Penetration Tester Jobs (NOW HIRING)

Perform web application, infrastructure, and application-level penetration testing. Conduct security design reviews to ensure compliance with NATO security policies and directives. Provide ...

New

Responsibilities Peraton is seeking an experienced Cyber Penetration Tester to become part of ... Common web application vulnerabilities and exploits such as XSS, SQLi, LFI, file uploads, broken ...

Web Application Testing: * Conduct security assessments of agency web applications using OWASP Top ... Penetration Testing & Exploitation Validation: * Perform controlled penetration testing (internal ...

Penetration Tester Location: Reston, VA Work Mode - Hybrid role, 2 days' Work from Office ... Experience conducting web application security assessments * Experience working with a range of ...

Penetration Tester

Gaithersburg, MD · On-site

$100K - $130K/yr

Web Application Testing: Conduct security assessments of agency web applications using OWASP Top 10 ... Penetration Testing & Exploitation Validation: Perform controlled penetration testing (internal and ...

Proven experience conducting penetration tests of web applications, networks, and other systems. * Experience with a variety of penetration testing tools and techniques (e.g., Rapid7 Nexpose ...

Be Seen First

Penetration Tester

Knoxville, TN · Remote

$120K - $145K/yr

This role requires proven hands-on capability in both network and web application/API penetration testing. You'll combine manual analysis with appropriate tooling, identify and pursue viable attack ...

New

Senior Penetration Tester

Herndon, VA · On-site

$120 - $150/hr

* Perform penetration testing on networks, applications (including APIs, mobile apps, and web apps) * Utilize social engineering techniques * Provide mentoring to junior staff * Support Red Team ...

Penetration Tester

Gaithersburg, MD · On-site

$100K - $130K/yr

Web Application Testing: * Conduct security assessments of agency web applications using OWASP Top ... Penetration Testing & Exploitation Validation: * Perform controlled penetration testing (internal ...

Penetration Tester

Leesburg, VA · On-site

$155K/yr

Key Responsibilities This role will be responsible for conducting network, application (API, mobile, and web), and Social Engineering penetration testing. Specifically, you would: * Work closely with ...

... Penetration Tester to perform computer network evaluations and penetration security assessments ... common web application vulnerabilities like XSS, CSRF, Command Injection, SQLi, single sign-on ...

Penetration Tester

Albany, NY · On-site

$60/hr

Proficiency in web application security principles (e.g., OWASP). * Knowledge of common web vulnerabilities (e.g., SQL injection, XSS) and exploit techniques. * Experience with penetration testing ...

The role involves conducting penetration testing, managing projects, and leading Red Team ... Company : M9 Solutions is a national staffing firm focused on cloud, cyber security, web ...

They are seeking a Penetration Tester II to work on-site in support of a government contract ... Company : M9 Solutions is a national staffing firm focused on cloud, cyber security, web ...

Apply established penetration-testing methodologies and commercial or open-source offensive tools across networks, web applications, applications, and code, including support to Red and Blue Team ...

Senior Penetration Tester

Washington, DC · On-site

$145K - $180K/yr

Senior Penetration Tester Pay Type : SALARIED EXEMPT Location : Hybrid, Washington, DC US ... Maintain advanced knowledge of networking, cryptography, reverse engineering, web applications ...

Summary: The Senior Penetration Tester will independently perform penetration testing of ... Knowledge of databases, applications, and Web server design and implementation * Possess oral and ...

Showing results 21-40

On Call Web Penetration Tester information

See salary details

$22.5K

$119.9K

$168.5K

How much do on call web penetration tester jobs pay per year?

As of Aug 14, 2026, the average yearly pay for on call web penetration tester in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What is the difference between On Call Web Penetration Tester vs Web Security Analyst?

AspectOn Call Web Penetration TesterWeb Security Analyst
CertificationsOSCP, CEH, GPENCompTIA Security+, CISSP, CEH
Work EnvironmentProject-based, on-demand testing, often freelance or contractOngoing monitoring, policy development, and incident response
Employer & Industry UsageConsulting firms, cybersecurity companies, freelance rolesCorporate IT departments, security teams, government agencies

While both roles focus on web security, an On Call Web Penetration Tester performs targeted, time-specific security assessments to identify vulnerabilities, often on a contract basis. In contrast, a Web Security Analyst maintains ongoing security measures, monitors threats, and develops security policies within an organization.

More about On Call Web Penetration Tester jobs

What cities are hiring for On Call Web Penetration Tester jobs?

Cities with the most On Call Web Penetration Tester job openings:

What are the most commonly searched types of Web Penetration Tester jobs?

The most popular types of Web Penetration Tester jobs are:

Infographic showing various On Call Web Penetration Tester job openings in the United States as of August 2026, with employment types broken down into 1% Locum Tenens, 1% As Needed, 78% Full Time, 14% Part Time, and 6% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

Full-time

Posted 3 days ago

New


Job description

Spektrum supports apex purchasers (NATO, UN, EU, and National Government and Defence) and their Tier 1 supplier ecosystem with a wide range of specialist services. We provide our clients with professional services, specialised aerospace and defence sales, delivery, and operational subject matter expertise. We are looking for personnel to join our team and support key client projects.


Who we are supporting 

The NATO Communication and Information Agency (NCIA) is responsible for providing secure and effective communications and information technology (IT) services to NATO's member countries and its partners. The agency was established in 2012 and is headquartered in Brussels, Belgium.

The NCIA provides a wide range of services, including:

  • Cyber Security: The NCIA provides advanced cybersecurity solutions to protect NATO's communication networks and information systems against cyber threats.
  • Command and Control Systems: The NCIA develops and maintains the systems used by NATO's military commanders to plan and execute operations.
  • Satellite Communications: The NCIA provides satellite communications services to enable secure and reliable communications between NATO forces.
  • Electronic Warfare: The NCIA provides electronic warfare services to support NATO's mission to detect, deny, and defeat threats to its communication networks.
  • Information Management: The NCIA manages NATO's information technology infrastructure, including its databases, applications, and servers.

Overall, the NCIA plays a critical role in ensuring the security and effectiveness of NATO's communication and information technology capabilities.

The program

Assistance and Advisory Service (AAS)

The NATO Communications and Information Agency (NCI Agency) is NATO's principal C3 capability deliverer and CIS service provider. It provides, maintains and defends the NATO enterprise-wide information technology infrastructure to enable Allies to consult together under Article IV, and, when required, stand together in the face of attack under Article V.

To provide these critical services, in the modern evolving dynamic environment the NCI Agency needs to build and maintain high performance-engaged workforce. The NCI Agency workforce strategically consists of three major categorise's: NATO International Civilians (NIC)'s, Military (Mil), and Interim Workforce Consultants (IWC)'s. The IWCs are a critical part of the overall NCI Agency workforce and make up approximately 15 percent of the total workforce.


Penetration Tester

Role ID - C004912

Role Background

The Penetration Tester will support NATO security activities by
performing penetration testing, security assessments, and security design
reviews across web applications, IT infrastructure, networks, and
applications. The role also supports NATO military exercises through Red
and Blue Team activities and provides security advice to technical teams,
projects, and senior stakeholders.

Role Duties and Responsibilities

Lead or participate in Red Team and Blue Team activities during
NATO military exercises.
Perform web application, infrastructure, and application-level
penetration testing.
Conduct security design reviews to ensure compliance with NATO
security policies and directives.
Provide cybersecurity consultancy and technical security advice to
projects, plans, and other stakeholders.
Identify and assess security vulnerabilities across operating
systems, software, protocols, applications, and networks.
Evaluate cybersecurity risks and recommend appropriate mitigation
and remediation actions.
Research and assess security products, tools, and technologies.
Work closely with internal and external stakeholders involved in
security accreditation.
Coordinate with the NCIA Configuration Control Board, Security
Accreditation Boards, NATO Security Accreditation Authorities, and
relevant NCI Agency teams.
Prepare clear and structured penetration testing and security
assessment reports.
Present security findings and testing outcomes to both technical and
executive audiences, including senior leadership.
Coordinate closely with the Head of the Penetration Testing Cell and
maintain effective stakeholder collaboration.
Essential Skills
Strong knowledge of web application penetration testing.
Strong knowledge of IT infrastructure penetration testing.
Knowledge of network security architecture and design.
Ability to identify and assess vulnerabilities in operating systems,
software, protocols, and networks.
Experience using penetration testing tools, techniques, and
recognized testing methodologies.
Knowledge of UNIX and Windows system and network
administration.
Scripting skills in at least one of the following:
o Python
o Perl
o Ruby
o Bash or other shell scripting
Strong technical knowledge of:
o System and network security
o Authentication and security protocols
o Cryptography
o Application security
o Malware infection techniques
o Malware protection technologies
Ability to evaluate cybersecurity risks and develop mitigation plans.
Strong technical reporting skills, including writing executive
summaries, technical findings, and remediation plans for different
audiences.
Strong stakeholder communication and presentation skills.

Experience

More than 3 years of relevant professional experience in
penetration testing and the required cybersecurity areas.
Hands-on experience with web application and infrastructure
penetration testing.
Experience assessing security vulnerabilities across networks,
systems, applications, software, and protocols.
Experience using established penetration testing methodologies and
security testing tools.
Experience researching and evaluating cybersecurity technologies
and products.
Experience communicating technical security findings to both
technical and senior/executive stakeholders.

Working Location

The Hague, Netherlands

Working Policy

Full-time on-site position in The Hague.
Normal office working conditions.
Approximately 10 days of travel are expected for this
assignment.
Required start date: 29 September 2026.
Contract end date: 31 December 2026.
Total scope: 697 hours.
NATO Secret Security Clearance is required.

Travel

Some travel to other NATO sites may be required

Security Clearance

Valid NATO Secret security clearance.
 
 
 
Â