1

Pen Testing Jobs in New York (NOW HIRING)

You'll work directly with our Security Engineering, IT, Legal, and Compliance teams to drive initiatives from pen testing cycles to SOC 2 compliance. This is a hands-on role where you'll build ...

Partner with our Sales Engineering team to lead deep-dive sessions on autonomous pen-testing and offensive AI. * Drive PoCs: Lead the charge in converting interest into Proof of Concepts (PoCs ...

Senior Cybersecurity Engineer

New York, NY ยท Hybrid

$125K - $171K/yr

Security Information and Event Management (SIEM), security automation, Data Loss Prevention (DLP), endpoint security (EDR), sandboxing, threat intelligence, pen testing & vulnerability management ...

Sr. IT Project Manager

Secaucus, NJ ยท On-site

$132K - $133K/yr

... pen testing, threat intelligence; networking architecture - firewalls, routers, switches, WAN, LAN, WLAN. โ€ข Exceptional oral, written, presentation, and interpersonal skills. โ€ข Self-starter ...

Sr. IT Project Manager

Secaucus, NJ ยท On-site

$132K - $133K/yr

... pen testing, threat intelligence; networking architecture - firewalls, routers, switches, WAN, LAN, WLAN. โ€ข Exceptional oral, written, presentation, and interpersonal skills. โ€ข Self-starter ...

Senior Security Engineer

New York, NY ยท On-site

$125K - $171K/yr

Pen testing or bug bounty experience * Familiarity with GRC tools and frameworks #LI-Hybrid #LI-JL1 A little about us At Chime, we believe that everyone can achieve financial progress. We created ...

Sr. IT Project Manager

Secaucus, NJ ยท On-site

$66K - $88K/yr

... pen testing, threat intelligence * networking architecture - firewalls, routers, switches, WAN, LAN, WLAN * Exceptional oral, written, presentation, and interpersonal skills. * Self-starter ...

Knowledge of attack and mitigation methods in two or more of the following: network protocols and secure network design, web application security, security assessments and pen testing, authentication ...

next page

Showing results 1-20

Pen Testing information

See New York salary details

$10

$20

$34

How much do pen testing jobs pay per hour?

As of Aug 3, 2026, the average hourly pay for pen testing in New York is $20.94, according to ZipRecruiter salary data. Most workers in this role earn between $16.83 and $21.06 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Penetration Tester, and why are they important?

To thrive as a Penetration Tester, you need a solid understanding of network security, vulnerability assessment, and ethical hacking, often backed by a degree in computer science or cybersecurity and industry certifications like CEH or OSCP. Familiarity with tools such as Metasploit, Burp Suite, and Nmap, as well as various operating systems, is typically required. Strong analytical thinking, problem-solving skills, and effective communication set top performers apart when explaining findings to technical and non-technical stakeholders. These skills ensure that vulnerabilities are thoroughly identified and addressed, helping organizations protect critical data and systems.

What are some common challenges faced by penetration testers when working on client projects?

Penetration testers often encounter challenges such as limited timeframes to conduct thorough assessments, incomplete or outdated documentation from clients, and the need to clearly communicate technical findings to non-technical stakeholders. They may also face restrictions on testing certain systems due to business constraints or potential operational impact. Building trust with clients and ensuring testing activities do not disrupt critical services are also important aspects of the role.

What is the difference between Pen Testing vs Vulnerability Assessment?

AspectPen TestingVulnerability Assessment
PurposeSimulates attacks to identify exploitable vulnerabilitiesIdentifies and prioritizes security weaknesses
DepthIn-depth, targeted testingBroad, overview of vulnerabilities
CertificationsOSCP, CEH, GPENCISA, CISSP, CEH
Work EnvironmentHands-on, technical testingAnalysis and reporting

Pen Testing involves actively exploiting vulnerabilities to assess security defenses, while Vulnerability Assessment focuses on identifying and prioritizing potential weaknesses without exploiting them. Both are essential for a comprehensive security strategy but serve different roles in cybersecurity testing.

Is pen testing a good career?

Penetration testing, or pen testing, is a cybersecurity role focused on identifying vulnerabilities in systems and networks. It requires technical skills, knowledge of security tools, and often certifications like OSCP or CEH. The field offers high demand, competitive salaries, and opportunities for continuous learning, making it a strong career choice for those interested in cybersecurity.

What is pen testing?

Pen testing, short for penetration testing, is a cybersecurity practice where professionals simulate attacks on a computer system, network, or application to identify vulnerabilities that malicious hackers could exploit. The goal is to proactively find and fix security weaknesses before they can be used in real-world attacks. Pen testers use a variety of tools and techniques to mimic the methods of cybercriminals, and then provide detailed reports with recommendations for improving security. Organizations often conduct pen tests regularly as part of their overall security strategy.

How do I become a pen tester?

To become a penetration tester, you should gain a strong understanding of computer networks, operating systems, and security principles, often through a degree in cybersecurity, computer science, or related fields. Earning industry-recognized certifications such as Offensive Security Certified Professional (OSCP) or Certified Ethical Hacker (CEH) can improve job prospects, and practical experience with tools like Kali Linux, Metasploit, and Wireshark is essential.

What qualifications do you need to be a pen tester?

To become a penetration tester, candidates typically need a strong understanding of networking, operating systems, and security principles, along with proficiency in scripting and using security tools. Relevant certifications such as Certified Ethical Hacker (CEH) or Offensive Security Certified Professional (OSCP) are highly valued. Practical experience through labs, internships, or hands-on projects is also important for demonstrating skills in identifying vulnerabilities and exploiting security flaws.

How much can you make pen testing?

Penetration testers typically earn between $70,000 and $130,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in tools like Kali Linux or Metasploit can earn higher salaries, especially in high-demand industries or regions with a strong cybersecurity market.
Infographic showing various Pen Testing job openings in New York as of July 2026, with employment types broken down into 82% Full Time, 6% Part Time, 6% Temporary, and 6% Contract. Highlights an 81% In-person, 13% Hybrid, and 6% Remote job distribution, with an average salary of $43,550 per year, or $20.9 per hour.

AI Red Tester/Pen Tester/Ethical Hacker- Long Term Contract - Remote

MTSS

Montville Township, NJ โ€ข On-site

Contractor

Re-posted 13 days ago


Job description

AI Red Tester/Pen Tester/Ethical Hacker- Long Term Contract - Remote

For our direct client, a prestigious global firm, we seek an experienced hands-on AI Red Team tester to join their team, for a long-term contract.
This contract can be done remotely, is 40 hours/week, and is open to a credentialed security professional located in the US.

The Global Red Team Tester will conduct testing of AI models to find vulnerabilities, develop new evaluation frameworks, communicate risks to stakeholders across the global teams, collaborate with defensive and development teams, and mentor junior team members.

Key Responsibilities:  

  • Conduct red team exercises simulating real-world deployment scenarios and edge cases. Systematically probe for bias, toxicity, misinformation generation, and other harmful outputs across diverse contexts and demographics. Improve firm’s security posture against emerging AI threats. Concentration is on executing standardized security tests.
  • Design and execute comprehensive adversarial testing campaigns against AI models, including but not limited to large language models, multimodal systems, and autonomous agents.
  • Research attack vectors and prompt injection techniques to identify model vulnerabilities, jailbreaks, and unintended behaviors. Evaluate and introduce AI Security tools that decrease mean time to detect and respond to AI-specific threats.
  • Create adversarial datasets and benchmarks to evaluate model robustness under various attack conditions.
  • Collaborate with security teams (e.g., GSOC, member firm security teams, developers) to perform red teaming activities, and document and present findings, vulnerabilities, and remediation recommendations to drive the mitigation of identified risks
  • Develop and maintain process documentation, create reports on testing activities, track operational metrics, and perform other programmatic tasks as required to support the AI Red Team’s function.

Skills and experience desired:

  • Minimum 5 years of penetration testing or red team operations experience.
  • Background in AI red teaming, web application penetration testing, application/network penetration testing, red team operations, or cyber security.
  • Familiarity with threat intelligence.
  • Understanding of Artificial Intelligence, Machine Learning, software applications, cloud computing, and networking.
  • Excellent communication and stakeholder management skills.
  • Ability to work effectively across geographies and time zones.

Core technical skills include:
• Testing tools: SPLX, Garak, TextAttack, PyRIT, Burp Suite, Metasploit, Nessus, Cobalt Strike/Mythic/C2, NMAP, sqlmap, or similar tools (familiar with some of these tools or similar)
• Web application technologies and layer 7 protocols (HTTP, DNS, FTP)
• Technical experience in Generative AI, Agents, A2A, and/or MCP
• Programming languages: Python, Ruby, Go, PowerShell, bash or similar (familiar with some of these languages or similar)??????

  • Computer science, information technology, or cybersecurity degree (Bachelor’s or higher preferred) from an accredited college or university or equivalent work experience.

• Certifications: OSCP, GPEN, GPXN, AI Red Teamer Job Role Path (HackTheBox), AISEC+, or other industry AI or Red Team related certifications desired