1

Overnight Web App Penetration Testing Jobs (NOW HIRING)

Perform web app penetration testing (manual/automated). * Evaluate SAST/DAST findings and manage issues in Jira. * Validate bug bounty vulnerabilities. * Translate business requirements into ...

Perform web app pentests. * Perform vulnerability risk assessments. * Perform physical pentests and ... Must have experience with penetration testing tools. * Must have experience in web development and ...

GIAC Web Application Penetration Tester (GWAPT) * GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) * GIAC Assessing and Auditing Wireless Networks (GAWN) Blue Teaming Certifications:

GIAC Web Application Penetration Tester (GWAPT) * GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) * GIAC Assessing and Auditing Wireless Networks (GAWN) Blue Teaming Certifications:

GIAC Web Application Penetration Tester (GWAPT) * GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) * GIAC Assessing and Auditing Wireless Networks (GAWN) Blue Teaming Certifications:

next page

Showing results 1-20

Overnight Web App Penetration Testing information

See salary details

$11

$59

$86

How much do overnight web app penetration testing jobs pay per hour?

As of Jun 12, 2026, the average hourly pay for overnight web app penetration testing in the United States is $59.01, according to ZipRecruiter salary data. Most workers in this role earn between $51.20 and $66.83 per hour, depending on experience, location, and employer.

What is the difference between Overnight Web App Penetration Testing vs Web Application Security Analyst?

AspectOvernight Web App Penetration TestingWeb Application Security Analyst
Primary FocusSimulating cyberattacks to identify vulnerabilities in web applicationsMonitoring, analyzing, and improving overall web security posture
CertificationsOSCP, CEH, GPENCISSP, GIAC Web Application Security (GWAS)
Work EnvironmentIntensive, project-based, often during off-hoursOngoing security monitoring and analysis during regular hours
Job DurationTypically short-term, focused on specific testing windowsLong-term, continuous security management

While both roles involve web security, Overnight Web App Penetration Testing focuses on conducting simulated attacks to find vulnerabilities, often during off-hours. Web Application Security Analysts work on ongoing security monitoring and improving defenses. Both roles require similar certifications and industry knowledge but differ in scope and work style.

Where do Penetration Testers get paid the most?

Penetration testers, including those specializing in web app security, tend to earn the highest salaries in regions with a strong cybersecurity industry and high cost of living, such as major financial or tech hubs. Experience, certifications like OSCP or CISSP, and working for large organizations or consulting firms can also significantly increase earning potential.

Can you work remotely as a penetration tester?

Overnight web app penetration testers often have the opportunity to work remotely, especially when performing testing tasks that do not require physical access. Many companies and consulting firms support remote work, provided the tester has secure access to client environments and necessary tools like VPNs and remote desktops. However, some roles may require on-site presence for certain assessments or client interactions.

How much do web app pentesters make?

Web application penetration testers typically earn between $70,000 and $130,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in tools like Burp Suite or OWASP may command higher salaries, especially in high-demand markets.

Will pentesters be replaced by AI?

Overnight web app penetration testers perform manual security assessments that require critical thinking, creativity, and understanding of complex systems, which AI currently cannot fully replicate. While AI tools can assist in automating repetitive tasks and identifying common vulnerabilities, human expertise remains essential for nuanced analysis, interpreting results, and adapting to new threats. Therefore, pentesters are unlikely to be fully replaced by AI in the near future, but their roles may evolve to incorporate more automation and AI-assisted techniques.
What cities are hiring for Overnight Web App Penetration Testing jobs? Cities with the most Overnight Web App Penetration Testing job openings:
What are the most commonly searched types of Web App Penetration Testing jobs? The most popular types of Web App Penetration Testing jobs are:
What states have the most Overnight Web App Penetration Testing jobs? States with the most job openings for Overnight Web App Penetration Testing jobs include:
Penetration Tester

Penetration Tester

Open Systems Technologies Corporation

Annapolis Junction, MD โ€ข On-site

Other

Medical, Dental, Life, Retirement, PTO

Posted 6 days ago


Job description

Open Systems Technologies Corporation is a leader in the government contracting marketplace, providing Enterprise Security and Cloud Computing solutions to support large organizations. Our capabilities include supplying federal government entities and private businesses with software development, scientific and engineering technical assistance, systems integration, and enterprise security. Since its founding in 1996, OST has been committed to delivering high-quality, best-in-class results that bring added value to our clients while investing in our employeesโ€™ futures by providing exciting projects to work on, and robust benefits to include technical training and certifications, relocation assistance and a 401K match with immediate vesting.

Open Systems Technologies Corporation is looking for a Lead Penetration Testerย to join a high performing agile team that uses the Scaled Agile Framework (SAFe) methodology to support a nationally significant and fast-paced program.

A Lead Penetration Tester is needed to join a high performing agile team using the Scaled Agile Framework (SAFe) methodology on a large, complex program that provides system engineering, development, test, integration and operational support. The selected individual will work on a team of cyber Subject Matter Experts (SMEs) who are providing support to a large, complex technical program for preventing, identifying, containing and eradicating cyber threats to networks through monitoring, intrusion detection, and protective security services on information systems including local area networks/wide area networks (LAN/WAN), commercial Internet connections, public facing websites, security devices, servers and workstations. She/he will be responsible for the overall security of Enterprise-wide information systems, and will collect, investigate, and report any suspected and confirmed security violations.

Primary Responsibilities

  • Perform internal and external pentests against systems to determine vulnerabilities and develop mitigation strategies.
  • Perform web app pentests.
  • Perform vulnerability risk assessments.
  • Perform physical pentests and social engineering analysis.
  • Perform cyber incident response as needed.
  • Evaluate the impact of new development on the operational security posture of IT systems.
  • Evaluate, review, and test critical software.
  • Formulate security compliance requirements for new system features.
  • Identify and remediate security issues throughout the system.
  • Audit and assess system security configuration settings using common methodologies and tools.
  • Work with development teams to enrich team-wide understanding of different types of vulnerabilities, attack vectors, and remediation approaches.
  • Work closely with System Engineering, Test Engineering, and Integration teams to ensure hardware and software architecture and implementations meet strict security requirements.
  • Propose, assess, coordinate, implement, and enforce information systems security policies, standards, and methodologies.
  • Serve as a Subject Matter Expert in security architecture, to include providing advice to Program Managers, Customer technical experts, and internal program teams.

Basic Qualifications

  • Must have experience with penetration testing tools.
  • Must have experience in web development and programming languages such as Java, XML, Perl and HTML.
  • Must have experience with programming/scripting in Python, Powershell, C, JavaScript, etc.
  • Must have extensive experience performing IT security risk assessments.
  • Must have experience performing web app and physical pentests.
  • Must have experience with or strong familiarity of the following Web Application tools; Burp Suite, Web Inspect, Appdetective.
  • Must have experience with or strong familiarity of Kali.
  • Must have experience with or strong familiarity of IPS/IDS solutions.
  • Must have a strong understanding of the Cyber Kill Chain methodology.
  • Must have experience applying Risk Management Framework.
  • Must have experience with secure configurations of commonly used desktop and server operating systems.
  • Must have the ability to effectively collaborate with technical staff and customers to form mitigation strategies and plan for continuous modernization and legacy integration.
  • Must have experience managing multiple projects simultaneously and quickly and effectively adjusting to shifting priorities in resolving issues.

Preferred Qualifications

  • Bachelor's degree in a technical/information assurance field and at least 12 years of relevant experience.
  • Certifications in one or more of the following areas strongly preferred:
    • GIAC Web Applications Penetration Tester (GWAPT)
    • GIAC Penetration Tester (GPEN)
    • Certified Ethical Hacker (CEH)
    • Certified Information Security Manager (CISM)
    • Certified Web Application Defender (GWEB)
    • Certified Information System Security Professional (CISSP)
  • Extensive experience developing/implementing integrated security services management processes, such as assessing and auditing network penetration testing, anti-virus planning assistance, risk analysis, and incident response.
  • Extensive experience providing information assurance support for application development that includes system security certifications and project evaluations for firewalls that encompass development, design, and implementation.?

BENEFITS

OST is an Equal Opportunity Employer and has been operating since 1996 providing support on various contracts with Government agencies. We offer a comprehensive benefits package that includes 3 weeks paid time off, 11 Federal Holidays, medical/dental coverage, STD, LTD, Life Insurance, AD&D, 401k with up to 4% match, and end-of-year profit sharing.