1

Pen Tester Jobs (NOW HIRING)

PEN TESTER

San Jose, CA ยท On-site

Responsibilities Conduct black box ,white box security and penetration testing to assess and validate application security Perform manual pen-tests, ability to setup threat models and fuzzers. Be ...

Penetration Tester

Chantilly, VA ยท On-site

$150K - $195K/yr

Pen Testers are also responsible for performing security focused services to improve the security posture of NRO ISs. Travel: 25% estimate for pen testers (OCONUS travel 2x per year). What will you ...

Pen Testers are also responsible for performing security focused services to improve the security posture of NRO ISs. Travel: 25% estimate for pen testers (OCONUS travel 2x per year). What will you ...

Pen Testers are also responsible for performing security focused services to improve the security posture of NRO ISs. Travel: 25% estimate for pen testers (OCONUS travel 2x per year). What will you ...

Penetration Tester

Chantilly, VA ยท On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Pen Testers review and write Information Security Action Plans (ISAPs) and Technical Information System Security Requirements (TISSRs). The Pen Tester shall conduct testing approved by the Government ...

- Conduct black box, white box vulnerability and penetration testing - Setup threat modesla and protocol fuzzers - Experience in architecture & design reviews with developers at all levels - Develop ...

Company Description - Conduct black box, white box vulnerability and penetration testing - Setup threat modesla and protocol fuzzers - Experience in architecture & design reviews with developers at ...

Penetration Tester

Chantilly, VA ยท On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Pen Testers review and write Information Security Action Plans (ISAPs) and Technical Information System Security Requirements (TISSRs). The Pen Tester shall conduct testing approved by the Government ...

Pen Testers are also responsible for performing security focused services to improve the security posture of NRO ISs. Travel: 25% estimate for pen testers (OCONUS travel 2x per year). What will you ...

Senior Penetration Tester

Denver, CO ยท On-site

$124 - $163/hr

  • Medical

  • Dental

  • Retirement

Bachelor's degree or higher and 7 year of Pen tester experience. * Master's degree and 6 year of relevant work experience. * Experience in cyber security with a focus on red teaming, penetration ...

SME Penetration Tester

Denver, CO ยท On-site

$144K - $187K/yr

  • Medical

  • Dental

  • Retirement

Bachelor's degree or higher and 7 year of Pen tester experience. * Master's degree and 6 year of relevant work experience. * Experience in cyber security with a focus on red teaming, penetration ...

next page

Showing results 1-20

Pen Tester information

See salary details

$10

$38

$62

How much do pen tester jobs pay per hour?

As of Aug 18, 2026, the average hourly pay for pen tester in the United States is $38.36, according to ZipRecruiter salary data. Most workers in this role earn between $21.39 and $50.72 per hour, depending on experience, location, and employer.

What is a pen tester?

Pen Testers, or penetration testers, are cybersecurity professionals who simulate cyberattacks on computer systems, networks, or applications to identify security vulnerabilities that could be exploited by malicious hackers. Their goal is to find and help fix security weaknesses before they can be used in real attacks. Pen Testers use a combination of automated tools and manual techniques to assess security, report their findings, and recommend remediation strategies. They play a crucial role in helping organizations improve their security posture and comply with industry regulations.

What are the key skills and qualifications needed to thrive as a pen tester, and why are they important?

To thrive as a Pen Tester, you need a strong understanding of cybersecurity principles, network protocols, and common vulnerabilities, often supported by a degree in computer science or a related field. Familiarity with penetration testing tools like Metasploit, Burp Suite, and certifications such as OSCP or CEH are typically required. Analytical thinking, attention to detail, and clear communication help Pen Testers effectively identify risks and explain findings to technical and non-technical audiences. These skills are crucial for uncovering security weaknesses and helping organizations proactively defend against cyber threats.

What are some common challenges a pen tester faces when working with clients?

Pen Testers often encounter challenges such as limited access to necessary systems, incomplete documentation, or time constraints imposed by clients. Additionally, communicating technical findings in a way that is understandable to non-technical stakeholders can be difficult but is crucial to ensure remediation of vulnerabilities. Building trust with clients, maintaining confidentiality, and adapting to rapidly evolving security landscapes are also key aspects of the role.

What is the difference between Pen Tester vs Vulnerability Analyst?

AspectPen TesterVulnerability Analyst
CertificationsOSCP, CEH, GPENOSCP, CEH, CISSP
Work EnvironmentSimulated attacks, penetration testing labsVulnerability scanning, risk assessment
Employer & IndustryCybersecurity firms, IT departmentsSecurity teams, consulting firms

While both roles focus on security, Pen Testers actively exploit vulnerabilities to identify weaknesses, whereas Vulnerability Analysts primarily assess and report on security flaws. Pen Testers perform hands-on testing, often in simulated environments, while Vulnerability Analysts analyze scan results and recommend fixes. Both roles are essential in cybersecurity but differ in approach and daily tasks.

Are pen testers in high demand?

Pen testers, or penetration testers, are in high demand due to increasing cybersecurity threats and the need for organizations to identify vulnerabilities. The role often requires knowledge of security tools, scripting, and certifications like OSCP or CEH, and job growth is expected to remain strong in the cybersecurity field.

How difficult is it to become a pen tester?

Becoming a penetration tester typically requires a strong understanding of networking, operating systems, and security principles, along with proficiency in tools like Kali Linux and scripting languages. Gaining relevant certifications such as the Offensive Security Certified Professional (OSCP) can improve job prospects, but the role often demands continuous learning and practical experience to stay current with evolving threats.

How do you become a pen tester?

To become a penetration tester, you typically need a strong foundation in computer networks, operating systems, and security principles, often gained through a degree in cybersecurity, computer science, or related fields. Gaining hands-on experience with tools like Kali Linux, Metasploit, and Wireshark, along with industry certifications such as the Offensive Security Certified Professional (OSCP), can improve job prospects. Continuous learning and staying updated on the latest vulnerabilities and attack techniques are essential in this field.

What qualifications do you need to be a pen tester?

To become a penetration tester, candidates typically need a strong understanding of computer networks, operating systems, and security principles. Relevant certifications such as Certified Ethical Hacker (CEH) or Offensive Security Certified Professional (OSCP) are highly valued, along with experience in scripting, programming, and using security tools like Kali Linux or Metasploit.
More about Pen Tester jobs

What cities are hiring for Pen Tester jobs?

Cities with the most Pen Tester job openings:

What are the most commonly searched types of Pen Tester jobs?

The most popular types of Pen Tester jobs are:

What states have the most Pen Tester jobs?

States with the most job openings for Pen Tester jobs include:

Infographic showing various Pen Tester job openings in the United States as of August 2026, with employment types broken down into 75% Full Time, 18% Part Time, and 7% Contract. Highlights an 57% Physical, 2% Hybrid, and 41% Remote job distribution, with an average salary of $79,791 per year, or $38.4 per hour.

Contractor

Re-posted 7 days ago


Job description

Job Description

Responsibilities

Conduct black box ,white box security and penetration testing to assess and validate application security

Perform manual pen-tests, ability to setup threat models and fuzzers. Be able to work in an ethical lab for hackers

Participate in architecture and design reviews with developers (all levels)/DevOps staff

Design, implement and support security tools and services

Influence and measure security policies and share best practices and recommendationsย 

Being able to track and monitor and use vulnerability tracking methods and tools

Explain and demonstrate vulnerabilities to application/system owners, and provide recommendations for mitigation

Issue reports on assigned application and system scans

Perform Secure Code Development Training to developers and relevant staffs

Support security policies and procedures

Participate in security compliance efforts

Participate in security operations support

Evaluate new and emerging security products and technologies


Required Skills and Experienceย 

5+ years of experience in web or mobile application security

5+ years of application development

Passion for security, and a deep technical understanding of enterprise systems architecture

Expert knowledge of information security principles, ethical hacking standards, along with a thorough knowledge of the current threat landscape and recent hacks and malware

Knowledge of cloud-based infrastructures/software and how they affect security needs

Familiarity and hands-on knowledge of with multiple languages and platforms (Java, Python, C/C++, Ruby, Perl and frameworks like Node.js, DoJo, and Angular.js ).

Experience with HTML and Javascript along with a solid understanding of HTTP protocol

Working Knowledge of SQL, Oracle, Mongo DB and PostgreSQLย 

Coding knowledge in one or more front end and web technologies like Java & Ruby, Python, Perl; mobile code development is a plus

In-depth knowledge and experience in OWASP 2013, SANS 25 and CWE

In-depth Experience in providing vulnerability remediation, with code examples, both web and mobile applications

Experience in working on AGILE projects and Waterfall Projects, along with fundamental project management and time management skills

Experience in the all parts of the SDLC, such as coding, integration testing, security analysis and audits, code reviews, designing etc.

Experience using vulnerability assessment tools/platforms such as IBM Appscan Enterprise, Coverity, CheckMarx, Nessus, Qualys, GFI, HP Fortify, Veracode, Burp Suite, MS Threat Modeler, Codenomicon etc.

Hands-on knowledge of cryptographic and encryption, PCI knowledge is a plus

Understanding of malware by device type

Expert problem solving and analytical skills; Advanced communication skills both spoken and written, to all levels of management

Self-driven and the ability to work with minimal supervision is required


Qualifications

Bachelor's degree in an Information Technology/Computer Science/Computer Engineering

Additional Information

This is IMMEDIATE requirement