Conduct deep testing of web apps, mobile apps (as applicable), and application programming interfaces (APIs), aligned to OWASP Top 10 and common design/implementation flaws. * Vulnerability ...
Conduct deep testing of web apps, mobile apps (as applicable), and application programming interfaces (APIs), aligned to OWASP Top 10 and common design/implementation flaws. * Vulnerability ...
Manual pen testing experience Need to be able to actually execute and understand tools/how to use. * If they have an ethical hacker certification, they will most likely meet the requirements of what ...
Manual pen testing experience Need to be able to actually execute and understand tools/how to use. * If they have an ethical hacker certification, they will most likely meet the requirements of what ...
Penetration Tester
Dallas, TX · On-site
Manual pen testing experience Need to be able to actually execute and understand tools/how to use. * If they have an ethical hacker certification, they will most likely meet the requirements of what ...
Penetration Tester
Dallas, TX · On-site
Manual pen testing experience Need to be able to actually execute and understand tools/how to use. * If they have an ethical hacker certification, they will most likely meet the requirements of what ...
Conduct deep testing of web apps, mobile apps (as applicable), and application programming interfaces (APIs), aligned to OWASP Top 10 and common design/implementation flaws. * Vulnerability ...
Conduct deep testing of web apps, mobile apps (as applicable), and application programming interfaces (APIs), aligned to OWASP Top 10 and common design/implementation flaws. * Vulnerability ...
Application security Pen tester profile with some experience in development Technical Skills Strong understanding of internet architecture. Skilled in security testing (SAST, DAST, SCA, OWASP Top ...
Application security Pen tester profile with some experience in development Technical Skills Strong understanding of internet architecture. Skilled in security testing (SAST, DAST, SCA, OWASP Top ...
Penetration Tester
$126K - $243K/yr
The Pen Tester will also guide the integration of automated and AI‑assisted testing capabilities into the organization's Agentic AI architecture, improving speed, accuracy, and repeatability of ...
Penetration Tester
$126K - $243K/yr
The Pen Tester will also guide the integration of automated and AI‑assisted testing capabilities into the organization's Agentic AI architecture, improving speed, accuracy, and repeatability of ...
Data Intelligence is seeking a seasoned Security Software Engineer - Red Team / Penetration Tester to join a hands-on offensive security team supporting mission systems in the defense domain. This ...
Data Intelligence is seeking a seasoned Security Software Engineer - Red Team / Penetration Tester to join a hands-on offensive security team supporting mission systems in the defense domain. This ...
Security Testing
Sunnyvale, CA · On-site
Preferred At least 2 years of experience in Security Testing (Web & Network Pen testing and Secure code analysis) Hands on security tester with proficiency in tools like HP Fortify, Web Inspect ...
Security Testing
Sunnyvale, CA · On-site
Preferred At least 2 years of experience in Security Testing (Web & Network Pen testing and Secure code analysis) Hands on security tester with proficiency in tools like HP Fortify, Web Inspect ...
... Pen testing and Secure code analysis ... Hands on security tester with proficiency in tools like HP Fortify, Web Inspect, Nessus, BURP, IBM ...
... Pen testing and Secure code analysis ... Hands on security tester with proficiency in tools like HP Fortify, Web Inspect, Nessus, BURP, IBM ...
Certified Information Systems Security Professional (CISSP), Licensed PEN Tester (LPT), Certified Ethical Hacker (CEH), Certified Secure Software Lifecycle Professional (CSSLP), Other software ...
Certified Information Systems Security Professional (CISSP), Licensed PEN Tester (LPT), Certified Ethical Hacker (CEH), Certified Secure Software Lifecycle Professional (CSSLP), Other software ...
Network Security
Dallas, TX · On-site
$96K - $132K/yr
Credential Dumping, Socks Proxy Pen testing * Experience in Firewall configuration, IDS/IPS & DMZ. * Sniffing & Spoofing, * Honeypots
Network Security
Dallas, TX · On-site
$96K - $132K/yr
Credential Dumping, Socks Proxy Pen testing * Experience in Firewall configuration, IDS/IPS & DMZ. * Sniffing & Spoofing, * Honeypots
The candidate should be familiar with the app pen testing process. This role will manage pen tests, work with external testers and internal application development teams to schedule, conduct, review ...
Quick apply
The candidate should be familiar with the app pen testing process. This role will manage pen tests, work with external testers and internal application development teams to schedule, conduct, review ...
Preferred: • At least 2 years of experience in Security Testing (Web & Network Pen testing and Secure code analysis). • Hands on security tester with proficiency in tools like HP Fortify, Web ...
Preferred: • At least 2 years of experience in Security Testing (Web & Network Pen testing and Secure code analysis). • Hands on security tester with proficiency in tools like HP Fortify, Web ...
Security Consultant / Pen Testing Location: Atlanta, Ga. Duration; 6-12 months w RTH ($110k) Start: ASAP Need GC and USC Security Engineer II will have broad areas of responsibility including network ...
Security Consultant / Pen Testing Location: Atlanta, Ga. Duration; 6-12 months w RTH ($110k) Start: ASAP Need GC and USC Security Engineer II will have broad areas of responsibility including network ...
Senior ISSE/Penetration Tester
$117K - $158K/yr
Performing physical pen tests and security engineering analysis and assessing the vulnerabilities/solutions for the pen testing. Basic Qualifications * At least 10 years of relevant experience with ...
Quick apply
Senior ISSE/Penetration Tester
$117K - $158K/yr
Performing physical pen tests and security engineering analysis and assessing the vulnerabilities/solutions for the pen testing. Basic Qualifications * At least 10 years of relevant experience with ...
MFA (Multi Factor Authentication)
Philadelphia, PA · On-site
$115K - $158K/yr
Certified Information Systems Security Professional (CISSP), Licensed PEN Tester (LPT), Certified Ethical Hacker (CEH), Certified Secure Software Lifecycle Professional (CSSLP), Other software ...
MFA (Multi Factor Authentication)
Philadelphia, PA · On-site
$115K - $158K/yr
Certified Information Systems Security Professional (CISSP), Licensed PEN Tester (LPT), Certified Ethical Hacker (CEH), Certified Secure Software Lifecycle Professional (CSSLP), Other software ...
Senior ISSE/Penetration Tester
Annapolis Junction, MD · On-site
$117K - $158K/yr
Performing physical pen tests and security engineering analysis and assessing the vulnerabilities/solutions for the pen testing. Basic Qualifications * At least 10 years of relevant experience with ...
Senior ISSE/Penetration Tester
Annapolis Junction, MD · On-site
$117K - $158K/yr
Performing physical pen tests and security engineering analysis and assessing the vulnerabilities/solutions for the pen testing. Basic Qualifications * At least 10 years of relevant experience with ...
$117K - $158K/yr
Evaluating, reviewing, and testing critical software. * Proposing, assessing, coordinating ... Performing web app pen tests. Performing vulnerability risk assessments. Performing physical pen ...
$117K - $158K/yr
Evaluating, reviewing, and testing critical software. * Proposing, assessing, coordinating ... Performing web app pen tests. Performing vulnerability risk assessments. Performing physical pen ...
Senior ISSE/Penetration Tester TS/SCI Polygraph
Annapolis, MD · On-site
$105K - $143K/yr
Performing physical pen tests and security engineering analysis and assessing the vulnerabilities/solutions for the pen testing. Basic Qualifications * Bachelor's degree in Computer Science ...
Senior ISSE/Penetration Tester TS/SCI Polygraph
Annapolis, MD · On-site
$105K - $143K/yr
Performing physical pen tests and security engineering analysis and assessing the vulnerabilities/solutions for the pen testing. Basic Qualifications * Bachelor's degree in Computer Science ...
Penetration Tester
Washington, DC · Hybrid
$130K - $145K/yr
Active professional certifications such as CEH, OSCP, PNPT, GPEN, or similar security/pen testing certifications The salary range for this position is $130,000.00 - $145,000.00 commensurate on ...
Penetration Tester
Washington, DC · Hybrid
$130K - $145K/yr
Active professional certifications such as CEH, OSCP, PNPT, GPEN, or similar security/pen testing certifications The salary range for this position is $130,000.00 - $145,000.00 commensurate on ...
Pen Tester information
See salary details
$10.82 - $15.54
7% of jobs
$15.54 - $20.26
16% of jobs
$21.31 is the 25th percentile. Wages below this are outliers.
$20.26 - $24.98
9% of jobs
$24.98 - $29.70
3% of jobs
$29.70 - $34.42
10% of jobs
The median wage is $36.31 / hr.
$34.42 - $39.14
10% of jobs
$39.14 - $43.86
7% of jobs
$43.86 - $48.58
9% of jobs
$49.21 is the 75th percentile. Wages above this are outliers.
$48.58 - $53.30
16% of jobs
$53.30 - $58.02
6% of jobs
$58.02 - $62.74
5% of jobs
$10
$38
$62
How much do pen tester jobs pay per hour?
What are the key skills and qualifications needed to thrive as a Pen Tester, and why are they important?
What are some common challenges a Pen Tester faces when working with clients?
What is the difference between Pen Tester vs Vulnerability Analyst?
| Aspect | Pen Tester | Vulnerability Analyst |
|---|---|---|
| Certifications | OSCP, CEH, GPEN | OSCP, CEH, CISSP |
| Work Environment | Simulated attacks, penetration testing labs | Vulnerability scanning, risk assessment |
| Employer & Industry | Cybersecurity firms, IT departments | Security teams, consulting firms |
While both roles focus on security, Pen Testers actively exploit vulnerabilities to identify weaknesses, whereas Vulnerability Analysts primarily assess and report on security flaws. Pen Testers perform hands-on testing, often in simulated environments, while Vulnerability Analysts analyze scan results and recommend fixes. Both roles are essential in cybersecurity but differ in approach and daily tasks.
What are Pen Testers?
Deloitte rating
8.1
Based on 86 frontline employees who took The Breakroom Quiz
58th of 138 rated financial services
Job description
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.
Work You'll Do
- Engagement scoping & planning: Partner with stakeholders to define objectives, rules of engagement, in-scope assets, testing windows, and success criteria; ensure testing is authorized and safely executed.
- Reconnaissance & enumeration: Perform passive and active discovery of attack surface, services, endpoints, APIs, and misconfigurations; map trust boundaries and data flows.
- Manual application testing: Conduct deep testing of web apps, mobile apps (as applicable), and application programming interfaces (APIs), aligned to OWASP Top 10 and common design/implementation flaws.
- Vulnerability validation & exploitation: Safely verify findings and demonstrate impact (where permitted), including:
- Cross-site scripting (XSS)
- SQL injection (SQLi)
- Cross-site request forgery (CSRF)
- Server-side request forgery (SSRF)
- Authentication and authorization flaws (e.g., broken access control, privilege escalation)
- Session management issues, insecure deserialization, security misconfiguration, and business logic vulnerabilities
- Network and infrastructure testing: Identify and validate weaknesses such as exposed services, weak segmentation, insecure protocols, credential issues, and misconfigurations across on-prem and cloud assets.
- Post-exploitation analysis (when in scope): Assess blast radius, lateral movement paths, sensitive data exposure, and persistence risks; collect evidence responsibly and minimize operational impact.
- Reporting & remediation support: Deliver clear reports including reproduction steps, risk ratings, evidence, and prioritized fixes; communicate effectively with both engineers and non-technical stakeholders; retest fixes as needed.
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The Team
Deloitte's Government & Public Services (GPS) practice - our people, ideas, technology and outcomes - is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.
Our Cyber Defense & Resilience offering assists clients in defending against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence. Helps manage and protect dynamic attack surfaces and provides rapid crisis and cyber incident response, ensuring clients can be ready for, respond to, and recover from business disruptions.
The Project Delivery Talent Model is designed for professionals with specialized skills that align to a current client need. Team members focus on delivering services to clients, without additional expectations related to business development or promotion. Their employment is tied to their role on a project, and they are eligible for a benefits package that is competitive for project delivery-focused professionals.
Qualifications
Required:
- Bachelor's degree required.
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
- Must be able to obtain and maintain the required clearance for this role.
- 3+ years of hands-on experience in penetration testing to include the following :
- Strong understanding of web application security, OWASP Top 10, and modern attack techniques against web apps and APIs.
- Proficiency with industry-standard tools such as Burp Suite, Nmap, Metasploit, and scripting for automation (e.g., Python/PowerShell/Bash), plus comfort writing lightweight proof-of-concepts.
- Demonstrated ability to distinguish false positives vs. exploitable issues, document evidence, and provide pragmatic, developer-friendly remediation guidance.
- Familiarity with common auth patterns (OAuth 2.0, OpenID Connect, SAML), API paradigms (REST/GraphQL), and modern app architectures (microservices, containers) is strongly preferred.
Preferred:
- Certifications such as OSCP, OSWEP, CRTO, or eJPT (eLearnSecurity Junior Penetration Tester) are highly desirable.
- 1+ years experience within the following:
- Experience with mobile (Android/iOS) testing, cloud penetration testing (AWS/Azure/GCP), or CI/CD and supply chain testing.
- Relevant certifications (examples: OSCP, GWAPT, GPEN, PNPT) or equivalent proven experience.
- Proven experience with adversary simulation, adversary emulation, or red team operations.
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.
Work You'll Do
- Engagement scoping & planning: Partner with stakeholders to define objectives, rules of engagement, in-scope assets, testing windows, and success criteria; ensure testing is authorized and safely executed.
- Reconnaissance & enumeration: Perform passive and active discovery of attack surface, services, endpoints, APIs, and misconfigurations; map trust boundaries and data flows.
- Manual application testing: Conduct deep testing of web apps, mobile apps (as applicable), and application programming interfaces (APIs), aligned to OWASP Top 10 and common design/implementation flaws.
- Vulnerability validation & exploitation: Safely verify findings and demonstrate impact (where permitted), including:
- Cross-site scripting (XSS)
- SQL injection (SQLi)
- Cross-site request forgery (CSRF)
- Server-side request forgery (SSRF)
- Authentication and authorization flaws (e.g., broken access control, privilege escalation)
- Session management issues, insecure deserialization, security misconfiguration, and business logic vulnerabilities
- Network and infrastructure testing: Identify and validate weaknesses such as exposed services, weak segmentation, insecure protocols, credential issues, and misconfigurations across on-prem and cloud assets.
- Post-exploitation analysis (when in scope): Assess blast radius, lateral movement paths, sensitive data exposure, and persistence risks; collect evidence responsibly and minimize operational impact.
- Reporting & remediation support: Deliver clear reports including reproduction steps, risk ratings, evidence, and prioritized fixes; communicate effectively with both engineers and non-technical stakeholders; retest fixes as needed.
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The Team
Deloitte's Government & Public Services (GPS) practice - our people, ideas, technology and outcomes - is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.
Our Cyber Defense & Resilience offering assists clients in defending against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence. Helps manage and protect dynamic attack surfaces and provides rapid crisis and cyber incident response, ensuring clients can be ready for, respond to, and recover from business disruptions.
The Project Delivery Talent Model is designed for professionals with specialized skills that align to a current client need. Team members focus on delivering services to clients, without additional expectations related to business development or promotion. Their employment is tied to their role on a project, and they are eligible for a benefits package that is competitive for project delivery-focused professionals.
Qualifications
Required:
- Bachelor's degree required.
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
- Must be able to obtain and maintain the required clearance for this role.
- 3+ years of hands-on experience in penetration testing to include the following :
- Strong understanding of web application security, OWASP Top 10, and modern attack techniques against web apps and APIs.
- Proficiency with industry-standard tools such as Burp Suite, Nmap, Metasploit, and scripting for automation (e.g., Python/PowerShell/Bash), plus comfort writing lightweight proof-of-concepts.
- Demonstrated ability to distinguish false positives vs. exploitable issues, document evidence, and provide pragmatic, developer-friendly remediation guidance.
- Familiarity with common auth patterns (OAuth 2.0, OpenID Connect, SAML), API paradigms (REST/GraphQL), and modern app architectures (microservices, containers) is strongly preferred.
Preferred:
- Certifications such as OSCP, OSWEP, CRTO, or eJPT (eLearnSecurity Junior Penetration Tester) are highly desirable.
- 1+ years experience within the following:
- Experience with mobile (Android/iOS) testing, cloud penetration testing (AWS/Azure/GCP), or CI/CD and supply chain testing.
- Relevant certifications (examples: OSCP, GWAPT, GPEN, PNPT) or equivalent proven experience.
- Proven experience with adversary simulation, adversary emulation, or red team operations.