1

Pen Testing Jobs in New York (NOW HIRING)

Plan and perform product security assessments including architecture review threat modeling, code review, pen testing and general security consulting to proactively build security controls * Serve as ...

You'll conduct deep-dive penetration testing, red team exercises, and adversarial security ... Own the relationship with external pen test firms and drive remediation of findings to closure.

Head of Security

Manhattan, NY · On-site

$300K - $375K/yr

Manage relationships with auditors, pen testers, and security vendors Technical Security * Provide technical direction and oversight for application security, cloud security (AWS/GCP), and ...

Head of Security

Manhattan, NY · On-site

$300 - $375/hr

Manage relationships with auditors, pen testers, and security vendors Technical Security * Provide technical direction and oversight for application security, cloud security (AWS/GCP), and ...

Head of Security

New York, NY · On-site

$300K - $375K/yr

Manage relationships with auditors, pen testers, and security vendors Technical Security * Provide technical direction and oversight for application security, cloud security (AWS/GCP), and ...

SCA Analytic Linguist (Spanish)

New York, NY · On-site

$36.50 - $38.75/hr

Testing shall have occurred no more than five years prior to the analytic linguist commencing work ... Pen-Link Lincoln Intercept System - A digital communications intercept collection system used by ...

SCA Analytic Linguist (Spanish)

Newark, NJ

$34.75 - $37/hr

Testing shall have occurred no more than five years prior to the analytic linguist commencing work ... Pen-Link Lincoln Intercept System - A digital communications intercept collection system used by ...

SCA Analytic Linguist (Spanish)

Newark, NJ · On-site

$34.75 - $37/hr

Testing shall have occurred no more than five years prior to the analytic linguist commencing work ... Pen-Link Lincoln Intercept System - A digital communications intercept collection system used by ...

SCA Analytic Linguist (Spanish)

Newark, NJ

$34.75 - $37/hr

Testing shall have occurred no more than five years prior to the analytic linguist commencing work ... Pen-Link Lincoln Intercept System - A digital communications intercept collection system used by ...

Showing results 21-40

Pen Testing information

See New York salary details

$10

$20

$34

How much do pen testing jobs pay per hour?

As of Aug 11, 2026, the average hourly pay for pen testing in New York is $20.94, according to ZipRecruiter salary data. Most workers in this role earn between $16.83 and $21.06 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a penetration tester, and why are they important?

To thrive as a Penetration Tester, you need a solid understanding of network security, vulnerability assessment, and ethical hacking, often backed by a degree in computer science or cybersecurity and industry certifications like CEH or OSCP. Familiarity with tools such as Metasploit, Burp Suite, and Nmap, as well as various operating systems, is typically required. Strong analytical thinking, problem-solving skills, and effective communication set top performers apart when explaining findings to technical and non-technical stakeholders. These skills ensure that vulnerabilities are thoroughly identified and addressed, helping organizations protect critical data and systems.

What are some common challenges faced by penetration testers when working on client projects?

Penetration testers often encounter challenges such as limited timeframes to conduct thorough assessments, incomplete or outdated documentation from clients, and the need to clearly communicate technical findings to non-technical stakeholders. They may also face restrictions on testing certain systems due to business constraints or potential operational impact. Building trust with clients and ensuring testing activities do not disrupt critical services are also important aspects of the role.

What is the difference between Pen Testing vs Vulnerability Assessment?

AspectPen TestingVulnerability Assessment
PurposeSimulates attacks to identify exploitable vulnerabilitiesIdentifies and prioritizes security weaknesses
DepthIn-depth, targeted testingBroad, overview of vulnerabilities
CertificationsOSCP, CEH, GPENCISA, CISSP, CEH
Work EnvironmentHands-on, technical testingAnalysis and reporting

Pen Testing involves actively exploiting vulnerabilities to assess security defenses, while Vulnerability Assessment focuses on identifying and prioritizing potential weaknesses without exploiting them. Both are essential for a comprehensive security strategy but serve different roles in cybersecurity testing.

Is pen testing a good career?

Penetration testing, or pen testing, is a cybersecurity role focused on identifying vulnerabilities in systems and networks. It requires technical skills, knowledge of security tools, and often certifications like OSCP or CEH. The field offers high demand, competitive salaries, and opportunities for continuous learning, making it a strong career choice for those interested in cybersecurity.

What is pen testing?

Pen testing, short for penetration testing, is a cybersecurity practice where professionals simulate attacks on a computer system, network, or application to identify vulnerabilities that malicious hackers could exploit. The goal is to proactively find and fix security weaknesses before they can be used in real-world attacks. Pen testers use a variety of tools and techniques to mimic the methods of cybercriminals, and then provide detailed reports with recommendations for improving security. Organizations often conduct pen tests regularly as part of their overall security strategy.

How hard is it to get into pen testing?

Pen testing is a specialized cybersecurity role that typically requires a strong understanding of networks, operating systems, and security principles. Gaining relevant skills often involves learning programming, using tools like Kali Linux, and obtaining certifications such as the Offensive Security Certified Professional (OSCP), which can be challenging but achievable with dedicated effort.
What job categories do people searching Pen Testing jobs in New York look for? The top searched job categories for Pen Testing jobs in New York are:
Infographic showing various Pen Testing job openings in New York as of August 2026, with employment types broken down into 82% Full Time, 6% Part Time, 6% Temporary, and 6% Contract. Highlights an 81% In-person, 13% Hybrid, and 6% Remote job distribution, with an average salary of $43,550 per year, or $20.9 per hour.

Artificial Intelligence Security Specialist USA

Citigroup Inc

Manhattan, NY • On-site

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 12 days ago


Citibank rating

8.3

Company rating: 8.3 out of 10

Based on 177 frontline employees who took The Breakroom Quiz

39th of 171 rated banks


Job description

Why Citi

Citi, the leading global bank, has approximately 200 million customer accounts and does business in more than 160 countries and jurisdictions. Citi provides consumers, corporations, governments, and institutions with a broad range of financial products and services, including consumer banking and credit, corporate and investment banking, securities brokerage, transaction services, and wealth management.

As a bank with a brain and a soul, Citi creates economic value that is systemically responsible and in our clients’ best interests. As a financial institution that touches every region of the world and every sector that shapes your daily life, our Enterprise Operations & Technology teams are charged with a mission that rivals any large tech company. Our technology solutions are the foundations of everything we do from keeping the bank safe, managing global resources, and providing the technical tools our workers need to be successful to designing our digital architecture and ensuring our platforms provide a first-class customer experience. We reimagine client and partner experiences to deliver excellence through secure, reliable, and efficient services.

Our commitment to diversity includes a workforce that represents the clients we serve from all walks of life, backgrounds, and origins. We foster an environment where the best people want to work. We value and demand respect for others, promote individuals based on merit, and ensure opportunities for personal development are widely available to all. Ideal candidates are innovators with well-rounded backgrounds who bring their authentic selves to work and complement our culture of delivering results with pride. If you are a problem solver who seeks passion in your work, come join us. We’ll enable growth and progress together.

Why This Team

The Chief Information Security Office (CISO) is home to deeply talented colleagues that work to ensure the safety of Citi's clients', our revenue, our employees and our proprietary data. We manage information security as one end-to end program – one with a clear mandate and accountability. Our mission is a program that is fully anchored to modern control and architectural frameworks, is fully aligned with the enterprise architecture of the firm and is deeply integrated into the businesses and functions.

AI Security Specialist

AI models can now autonomously discover and exploit zero-day vulnerabilities in production software — and we're building the defensive capability to match. We're hiring across four CISO teams working at the intersection of AI and cyber security.

What Makes This Different

The problems we're solving don't have playbooks yet.

  • AI-driven vulnerability management. When frontier models can generate thousands of findings in a weekend, the bottleneck shifts from discovery to triage, verification, and remediation. We're building the pipeline that makes this sustainable.

  • Security architecture for the AI era. Defining how a global bank deploys, monitors, and governs agentic AI — from standards and evaluation frameworks to production runtime monitoring.

  • AI at scale, not in a lab. Citi has deployed AI tools to 180,000+ employees, equipped 30,000 developers with AI coding assistants, and is rolling out agentic AI capabilities firm wide. Securing that footprint and the platforms that underpin them is the job.

  • Securing AI agents that can behave like insider threats. Frontier models can harvest credentials, escape sandboxes, and adapt when they detect monitoring. We're designing the containment architectures and runtime controls to operate them safely at enterprise scale.

  • Real security engineering. This isn't a cyber seat where you'll spend your time in administration . You will be expected to understand the code, the architecture, the threats, and find solutions. You'll have the mandate and the backing to build something meaningful.

What You'll Work On

Depending on your background and interests, you could join one of four teams:

  • Offensive Security & Vulnerability Management — AI-assisted pen testing at a scale previously impossible. Automated exploit validation. Bridge the gap from "AI found a vulnerability" to "the application team has a PR to fix it."

  • AI & Emerging Technology Security — Define how the bank deploys AI safely. Security architecture and assurance for new implementations, plus building the next generation of AI-powered tools for our CISO colleagues. Test new models at the cutting edge of creation and influence.

  • Cyber Security AI Services — Own the AI products CISO depends on in production — security assurance, cyber security operations, governance and controls, vulnerability assessment. Keep them reliable, evolve them fast.

  • Cyber Security Operations — Detection, triage, and response for a world where adversaries use AI to find and exploit vulnerabilities faster than traditional detection can keep up. Behavioral analytics for AI agents. Playbooks for AI-originated attack scenarios.

What We're Looking For

The right person might come from AI/ML engineering, offensive security, detection engineering, software engineering, or security research. Depth in at least one; genuine curiosity about the intersection.

  • AI/ML Engineering — Hands-on LLM API experience (context management, tool use, evaluation, failure modes). Agentic systems design. AI safety at the infrastructure level, not just the prompt level.

  • Cyber Security — Vulnerability research, exploit development, or pen testing with real depth. Detection engineering for novel attack patterns. Threat modelling (STRIDE, ATT&CK). Security architecture.

  • Software Engineering — You've built and operated production systems, not just prototypes. Strong Python and/or systems programming. Bonus if you're comfortable reading disassembly or tracing through kernel code.

  • Research & Communication — Can digest dense technical research and turn it into actionable security recommendations. Published research, conference talks, or open-source contributions.

  • Mindset - You love to engineer solutions to problems vs purchasing tools, and you see problems as opportunities

  • At any level: genuinely curious, comfortable with ambiguity, biased toward building, able to work across disciplines.

Levels

  • Assistant Vice President (C12 Mid - Senior Level): 5-7+ years. Own workstreams end-to-end with real autonomy. You'll go deep on problems that most organizations don't even know they have yet.

  • Vice President (C13 Senior - Lead/Staff Level): 8-10+ years. Define technical approach, make architectural decisions, mentor others. The scope here is wider than most senior IC roles — you're not optimizing an existing system; you're designing ones that don't exist yet.

  • Senior Vice President (C14 Lead/Staff - Principal Level): 10+ years. Set technical direction for a function and influence the firm's approach to AI security. If you've hit a ceiling elsewhere because the problem space isn't big enough, it's big enough here.

Why Citi, Why Now

  • Real and urgent. Not an innovation lab. The threats are active, the work ships into production, and it protects one of the world's largest financial institutions.

  • Technical teams. These are engineering-led functions. Small teams, high autonomy, minimal governance overhead. We build tools, ship code, and measure ourselves by what we deliver — not slide decks.

  • Strong mandate. Executive sponsorship to move fast. You'll have the backing and resources to act on what you find.

  • Unique scope. Very few organizations operate at this intersection at this scale. The solutions you build will influence how the industry responds.

Education

  • Bachelor’s degree/University degree or equivalent experience

  • Master’s degree preferred

We have multiple openings across various experience levels, from senior to principal, offering a dynamic environment for growth and impact. Location and compensation packages may be flexible and will be commensurate with experience and qualifications.

This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required.

Job Family Group:

Technology

Job Family:

Information Security

Time Type:

Full time

Primary Location:

New York New York United States

Primary Location Full Time Salary Range:

$109,120.00 - $265,080.00

In addition to salary, Citi’s offerings may also include, for eligible employees, discretionary and formulaic incentive and retention awards. Citi offers competitive employee benefits, including: medical, dental & vision coverage; 401(k); life, accident, and disability insurance; and wellness programs. Citi also offers paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays. For additional information regarding Citi employee benefits, please visit citibenefits.com. Available offerings may vary by jurisdiction, job level, and date of hire.

Most Relevant Skills

Please see the requirements listed above.

Other Relevant Skills

Agentic Design, Artificial Intelligence (AI), Cybersecurity, Cyber Security Architecture, Large Language Models (LLMs), Python (Programming Language), Security Engineering, Security Research, Threat Modeling, Vulnerability Assessments, Vulnerability Management.

Anticipated Posting Close Date:

Aug 19, 2026

Automated Processing and AI

We use automated processing, including artificial intelligence, for our legitimate business interests (or our reasonable and appropriate business purposes) to identify and align the candidate's skills and abilities with a specific job opening. Additionally, if you so choose, or consent, we can match your skills and abilities to other suitable roles at Citi.

Importantly, all our hiring processes and decisions, including determining your suitability for a role, are conducted, checked, and decided by individuals. Our automated processing and AI do not involve relying on automatic or autonomous decision-making. Please refer to any Jurisdictional Considerations, with specific provisions for your country (where relevant) for further details.

Illinois residents – AI Notice and Right (https://tbcdn.talentbrew.com/company/287/cms/v3/docs/policies/Illinois_Career_Supplement_a11y.pdf)

Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law.

If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi (https://www.citigroup.com/citi/accessibility/application-accessibility.htm) .

View Citi’s EEO Policy Statement (https://www.citigroup.com/global/eeo-aa-policy) and the Know Your Rights (https://www.eeoc.gov/sites/default/files/2023-06/22-088_EEOC_KnowYourRights6.12ScreenRdr.pdf) poster.

Citi is an equal opportunity and affirmative action employer.

Minority/Female/Veteran/Individuals with Disabilities/Sexual Orientation/Gender Identity.


What Citibank employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Citigroup Inc logo

About Citigroup Inc

Sourced by ZipRecruiter

We live in an increasingly complex world. Companies these days are either born global or are going global at record speed. Business and geopolitics are forging an entirely new dynamic and consumers now expect financial services to be a seamless part of their digital lives. Citi is a bank that’s uniquely positioned for this moment. Through our vast global network and our on-the-ground expertise, we can connect the dots, anticipate change and empathize the needs of our clients and customers in ways that other banks simply cannot. Citi's mission is to serve as a trusted partner to our clients by responsibly providing financial services that enable growth and economic progress. We have set expectations for how we must act to bring our mission to life. These expectations are at the heart of our Leadership Principles – we take ownership, we deliver with pride and we succeed together.

Industry

Banking and credit intermediation

Company size

5,001 - 10,000 Employees

Headquarters location

New York City, NY, US