1

Pen Tester Jobs (NOW HIRING)

Manual pen testing experience Need to be able to actually execute and understand tools/how to use. * If they have an ethical hacker certification, they will most likely meet the requirements of what ...

Manual pen testing experience Need to be able to actually execute and understand tools/how to use. * If they have an ethical hacker certification, they will most likely meet the requirements of what ...

Preferred At least 2 years of experience in Security Testing (Web & Network Pen testing and Secure code analysis) Hands on security tester with proficiency in tools like HP Fortify, Web Inspect ...

Preferred: • At least 2 years of experience in Security Testing (Web & Network Pen testing and Secure code analysis). • Hands on security tester with proficiency in tools like HP Fortify, Web ...

MFA (Multi Factor Authentication)

Philadelphia, PA · On-site

$115K - $158K/yr

Certified Information Systems Security Professional (CISSP), Licensed PEN Tester (LPT), Certified Ethical Hacker (CEH), Certified Secure Software Lifecycle Professional (CSSLP), Other software ...

$117K - $158K/yr

Evaluating, reviewing, and testing critical software. * Proposing, assessing, coordinating ... Performing web app pen tests. Performing vulnerability risk assessments. Performing physical pen ...

Penetration Tester

Washington, DC · Hybrid

$130K - $145K/yr

Active professional certifications such as CEH, OSCP, PNPT, GPEN, or similar security/pen testing certifications The salary range for this position is $130,000.00 - $145,000.00 commensurate on ...

next page

Showing results 1-20

Pen Tester information

See salary details

$10

$38

$62

How much do pen tester jobs pay per hour?

As of Jun 9, 2026, the average hourly pay for pen tester in the United States is $38.36, according to ZipRecruiter salary data. Most workers in this role earn between $21.39 and $50.72 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Pen Tester, and why are they important?

To thrive as a Pen Tester, you need a strong understanding of cybersecurity principles, network protocols, and common vulnerabilities, often supported by a degree in computer science or a related field. Familiarity with penetration testing tools like Metasploit, Burp Suite, and certifications such as OSCP or CEH are typically required. Analytical thinking, attention to detail, and clear communication help Pen Testers effectively identify risks and explain findings to technical and non-technical audiences. These skills are crucial for uncovering security weaknesses and helping organizations proactively defend against cyber threats.

What are some common challenges a Pen Tester faces when working with clients?

Pen Testers often encounter challenges such as limited access to necessary systems, incomplete documentation, or time constraints imposed by clients. Additionally, communicating technical findings in a way that is understandable to non-technical stakeholders can be difficult but is crucial to ensure remediation of vulnerabilities. Building trust with clients, maintaining confidentiality, and adapting to rapidly evolving security landscapes are also key aspects of the role.

What is the difference between Pen Tester vs Vulnerability Analyst?

AspectPen TesterVulnerability Analyst
CertificationsOSCP, CEH, GPENOSCP, CEH, CISSP
Work EnvironmentSimulated attacks, penetration testing labsVulnerability scanning, risk assessment
Employer & IndustryCybersecurity firms, IT departmentsSecurity teams, consulting firms

While both roles focus on security, Pen Testers actively exploit vulnerabilities to identify weaknesses, whereas Vulnerability Analysts primarily assess and report on security flaws. Pen Testers perform hands-on testing, often in simulated environments, while Vulnerability Analysts analyze scan results and recommend fixes. Both roles are essential in cybersecurity but differ in approach and daily tasks.

What are Pen Testers?

Pen Testers, or penetration testers, are cybersecurity professionals who simulate cyberattacks on computer systems, networks, or applications to identify security vulnerabilities that could be exploited by malicious hackers. Their goal is to find and help fix security weaknesses before they can be used in real attacks. Pen Testers use a combination of automated tools and manual techniques to assess security, report their findings, and recommend remediation strategies. They play a crucial role in helping organizations improve their security posture and comply with industry regulations.
More about Pen Tester jobs
What cities are hiring for Pen Tester jobs? Cities with the most Pen Tester job openings:
What are the most commonly searched types of Pen Tester jobs? The most popular types of Pen Tester jobs are:
What states have the most Pen Tester jobs? States with the most job openings for Pen Tester jobs include:
Security Engineer III (Pen Tester)

Security Engineer III (Pen Tester)

Deloitte

Rosslyn, VA

Other

Posted 12 days ago


Deloitte rating

8.1

Company rating: 8.1 out of 10

Based on 86 frontline employees who took The Breakroom Quiz

58th of 138 rated financial services


Job description

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

Work You'll Do

  • Engagement scoping & planning: Partner with stakeholders to define objectives, rules of engagement, in-scope assets, testing windows, and success criteria; ensure testing is authorized and safely executed.
  • Reconnaissance & enumeration: Perform passive and active discovery of attack surface, services, endpoints, APIs, and misconfigurations; map trust boundaries and data flows.
  • Manual application testing: Conduct deep testing of web apps, mobile apps (as applicable), and application programming interfaces (APIs), aligned to OWASP Top 10 and common design/implementation flaws.
  • Vulnerability validation & exploitation: Safely verify findings and demonstrate impact (where permitted), including:
    • Cross-site scripting (XSS)
    • SQL injection (SQLi)
    • Cross-site request forgery (CSRF)
    • Server-side request forgery (SSRF)
    • Authentication and authorization flaws (e.g., broken access control, privilege escalation)
    • Session management issues, insecure deserialization, security misconfiguration, and business logic vulnerabilities
  • Network and infrastructure testing: Identify and validate weaknesses such as exposed services, weak segmentation, insecure protocols, credential issues, and misconfigurations across on-prem and cloud assets.
  • Post-exploitation analysis (when in scope): Assess blast radius, lateral movement paths, sensitive data exposure, and persistence risks; collect evidence responsibly and minimize operational impact.
  • Reporting & remediation support: Deliver clear reports including reproduction steps, risk ratings, evidence, and prioritized fixes; communicate effectively with both engineers and non-technical stakeholders; retest fixes as needed.

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others

The Team

Deloitte's Government & Public Services (GPS) practice - our people, ideas, technology and outcomes - is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.

Our Cyber Defense & Resilience offering assists clients in defending against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence. Helps manage and protect dynamic attack surfaces and provides rapid crisis and cyber incident response, ensuring clients can be ready for, respond to, and recover from business disruptions.

The Project Delivery Talent Model is designed for professionals with specialized skills that align to a current client need. Team members focus on delivering services to clients, without additional expectations related to business development or promotion. Their employment is tied to their role on a project, and they are eligible for a benefits package that is competitive for project delivery-focused professionals.

Qualifications

Required: 

  • Bachelor's degree required.
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
  • Must be able to obtain and maintain the required clearance for this role.
  • 3+ years of hands-on experience in penetration testing to include the following :
    • Strong understanding of web application security, OWASP Top 10, and modern attack techniques against web apps and APIs.
    • Proficiency with industry-standard tools such as Burp Suite, Nmap, Metasploit, and scripting for automation (e.g., Python/PowerShell/Bash), plus comfort writing lightweight proof-of-concepts.
    • Demonstrated ability to distinguish false positives vs. exploitable issues, document evidence, and provide pragmatic, developer-friendly remediation guidance.
    • Familiarity with common auth patterns (OAuth 2.0, OpenID Connect, SAML), API paradigms (REST/GraphQL), and modern app architectures (microservices, containers) is strongly preferred.

Preferred:

  • Certifications such as OSCP, OSWEP, CRTO, or eJPT (eLearnSecurity Junior Penetration Tester) are highly desirable.
  • 1+ years experience within the following:
    • Experience with mobile (Android/iOS) testing, cloud penetration testing (AWS/Azure/GCP), or CI/CD and supply chain testing.
    • Relevant certifications (examples: OSCP, GWAPT, GPEN, PNPT) or equivalent proven experience.
    • Proven experience with adversary simulation, adversary emulation, or red team operations.
Qualifications:

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.

Work You'll Do

  • Engagement scoping & planning: Partner with stakeholders to define objectives, rules of engagement, in-scope assets, testing windows, and success criteria; ensure testing is authorized and safely executed.
  • Reconnaissance & enumeration: Perform passive and active discovery of attack surface, services, endpoints, APIs, and misconfigurations; map trust boundaries and data flows.
  • Manual application testing: Conduct deep testing of web apps, mobile apps (as applicable), and application programming interfaces (APIs), aligned to OWASP Top 10 and common design/implementation flaws.
  • Vulnerability validation & exploitation: Safely verify findings and demonstrate impact (where permitted), including:
    • Cross-site scripting (XSS)
    • SQL injection (SQLi)
    • Cross-site request forgery (CSRF)
    • Server-side request forgery (SSRF)
    • Authentication and authorization flaws (e.g., broken access control, privilege escalation)
    • Session management issues, insecure deserialization, security misconfiguration, and business logic vulnerabilities
  • Network and infrastructure testing: Identify and validate weaknesses such as exposed services, weak segmentation, insecure protocols, credential issues, and misconfigurations across on-prem and cloud assets.
  • Post-exploitation analysis (when in scope): Assess blast radius, lateral movement paths, sensitive data exposure, and persistence risks; collect evidence responsibly and minimize operational impact.
  • Reporting & remediation support: Deliver clear reports including reproduction steps, risk ratings, evidence, and prioritized fixes; communicate effectively with both engineers and non-technical stakeholders; retest fixes as needed.

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others

The Team

Deloitte's Government & Public Services (GPS) practice - our people, ideas, technology and outcomes - is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.

Our Cyber Defense & Resilience offering assists clients in defending against advanced threats by transforming security operations, monitoring technology, data analytics, and threat intelligence. Helps manage and protect dynamic attack surfaces and provides rapid crisis and cyber incident response, ensuring clients can be ready for, respond to, and recover from business disruptions.

The Project Delivery Talent Model is designed for professionals with specialized skills that align to a current client need. Team members focus on delivering services to clients, without additional expectations related to business development or promotion. Their employment is tied to their role on a project, and they are eligible for a benefits package that is competitive for project delivery-focused professionals.

Qualifications

Required: 

  • Bachelor's degree required.
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
  • Must be able to obtain and maintain the required clearance for this role.
  • 3+ years of hands-on experience in penetration testing to include the following :
    • Strong understanding of web application security, OWASP Top 10, and modern attack techniques against web apps and APIs.
    • Proficiency with industry-standard tools such as Burp Suite, Nmap, Metasploit, and scripting for automation (e.g., Python/PowerShell/Bash), plus comfort writing lightweight proof-of-concepts.
    • Demonstrated ability to distinguish false positives vs. exploitable issues, document evidence, and provide pragmatic, developer-friendly remediation guidance.
    • Familiarity with common auth patterns (OAuth 2.0, OpenID Connect, SAML), API paradigms (REST/GraphQL), and modern app architectures (microservices, containers) is strongly preferred.

Preferred:

  • Certifications such as OSCP, OSWEP, CRTO, or eJPT (eLearnSecurity Junior Penetration Tester) are highly desirable.
  • 1+ years experience within the following:
    • Experience with mobile (Android/iOS) testing, cloud penetration testing (AWS/Azure/GCP), or CI/CD and supply chain testing.
    • Relevant certifications (examples: OSCP, GWAPT, GPEN, PNPT) or equivalent proven experience.
    • Proven experience with adversary simulation, adversary emulation, or red team operations.
Education:Bachelor's DegreeEmployment Type:

What Deloitte employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom