1

Penetration Test Jobs (NOW HIRING)

Conduct security audits, network penetration tests, and web application, API and cloud assessments. * Draft security assessment reports that outline findings and provide a walkthrough of the ...

M9 Solutions is seeking a Penetration Tester III to work on-site in support of a government ... At least five (5) years of pen test experience, preferably seven (7) years. * Experience in ...

... penetration tests in coordination with Government stakeholders and senior cybersecurity personnel. • Conducts technical testing activities, including vulnerability exploitation, validation, and ...

Conduct security audits, network penetration tests, and web application, API and cloud assessments. * Draft security assessment reports that outline findings and provide a walkthrough of the ...

At least 5 years of pen test experience, preferably 7 years * Must have at least GPEN or GXPN ... Experience with continuous penetration testing methodologies * Experience with planning and ...

New

next page

Showing results 1-20

Penetration Test information

See salary details

$22.5K

$119.9K

$168.5K

How much do penetration test jobs pay per year?

As of May 30, 2026, the average yearly pay for penetration test in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Penetration Tester, and why are they important?

To thrive as a Penetration Tester, you need a solid understanding of network security, operating systems, and vulnerability assessment, often backed by a degree in computer science or cybersecurity and relevant certifications like OSCP or CEH. Familiarity with tools such as Metasploit, Burp Suite, and Nmap is typically required to identify and exploit system weaknesses. Strong analytical thinking, attention to detail, and effective communication skills help convey technical findings to both technical and non-technical stakeholders. These skills are crucial for identifying security risks, mitigating vulnerabilities, and ensuring the overall protection of organizational assets.

What are the typical challenges faced by penetration testers when working with clients?

Penetration testers often encounter challenges such as limited access to information, time constraints, and varying levels of security awareness among client staff. Navigating these obstacles requires strong communication skills to clarify the scope of work, as well as adaptability to different environments and technologies. Building trust with clients and providing actionable, clear reports are also essential, as they help ensure that identified vulnerabilities are understood and addressed effectively.

What is a penetration tester?

A penetration tester, often called a 'pen tester' or ethical hacker, is a cybersecurity professional who simulates cyberattacks on computer systems, networks, or applications to identify vulnerabilities that malicious hackers could exploit. Their goal is to uncover weaknesses before real attackers can find and exploit them, helping organizations strengthen their security. Penetration testers use a variety of tools and techniques, document their findings, and often provide recommendations for mitigation. This role requires knowledge of security protocols, programming, and the latest hacking methods.

What is the difference between Penetration Test vs Vulnerability Analyst?

AspectPenetration TestVulnerability Analyst
CertificationsOSCP, CEH, GPENCVE, CISSP, GIAC
Work EnvironmentSimulated attacks on systems to identify security gapsScanning and analyzing vulnerabilities in networks and applications
Employer & Industry UsageCybersecurity firms, IT departments, consultingSecurity teams, risk management, compliance

While both roles focus on cybersecurity, Penetration Testers actively exploit vulnerabilities to assess security defenses, whereas Vulnerability Analysts identify and prioritize vulnerabilities without exploiting them. Both roles are essential for a comprehensive security strategy and often collaborate within security teams.

More about Penetration Test jobs
What cities are hiring for Penetration Test jobs? Cities with the most Penetration Test job openings:
What are the most commonly searched types of Penetration Test jobs? The most popular types of Penetration Test jobs are:
What states have the most Penetration Test jobs? States with the most job openings for Penetration Test jobs include:
Infographic showing various Penetration Test job openings in the United States as of May 2026, with employment types broken down into 96% Full Time, and 4% Contract. Highlights an 20% Physical, 13% Hybrid, and 67% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

Avionics Penetration Tester - Midlevel with Security Clearance

Astrion

Edwards, CA

$120K - $140K/yr

Other

Posted 24 days ago


Job description

Overview Avionics Penetration Tester - Mid-Level - TGEE LOCATION: Edwards AFB, CA Salary Range: Estimated $120,000.00 USD - $140,000.00 USD annually JOB STATUS: Full-time CLEARANCE: Secret CERTIFICATION: See Below TRAVEL: 20% Astrion has an exciting opportunity for an SE-3 Cybersecurity Penetration Tester for the TMAS 2 96 CTG Task Order, supporting the 48 CTS / TGEE. The 48th CTS/Det 1 conducts Cyber Security Test & Evaluation of Embedded Avionics & Weapons Systems for multiple platforms within the Air Force. REQUIRED QUALIFICATIONS / SKILLS Core qualifications * Technical BS Degree and 3-10 years of applicable experience. Additional experience may be substituted for education. * Active Secret clearance is required and must be able to obtain/maintain a Top Secret clearance. U.S. Citizenship is required. * Must have or be able to obtain DOD 8140 qualifications at the start of employment and maintain qualifications throughout employment. * Prior understanding of aircraft avionics navigation, communication, and datalinks is desired (GPS, ACARS, Mode-S, Link-16, and etc.) * Proficiency in analyzing and/or manipulating avionics communication protocols, such as ARINC 429, MIL-STD-1553. * Military aircraft operations, maintenance, test or acquisition experience is desired. * Prior knowledge and applicable experience using various RF testing tools such as HackRF, SDR's, spectrum analyzers, and Wireshark. * Knowledge of common vulnerabilities and attack vectors in aviation systems, including but not limited to buffer overflows, injection attacks, and protocol manipulation. * Understanding of aircraft network architectures, including intra-aircraft networks and inter-aircraft networks (e.g., Air Traffic Management Data Link, Aircraft Communications Addressing and Reporting System). * Understanding of cryptographic principles and their application in aviation security, including key management, encryption algorithms, and digital signatures. Or * Familiarity with industry-standard frameworks and methodologies for conducting penetration tests, such as OWASP Testing Guide and NIST SP 800-115 * Knowledge of endpoint security technologies and techniques, such as antivirus, host-based intrusion detection/prevention systems (HIDS/HIPS), and privilege escalation exploits. * Experience in identifying and exploiting security vulnerabilities in web applications, including injection flaws, cross-site scripting (XSS), and insecure direct object references (IDOR). * Familiarity with common networking protocols and technologies, such as TCP/IP, DNS, DHCP, VLANs, VPNs, and SSL/TLS. * Proficiency in conducting vulnerability assessments and penetration tests on network infrastructure, including routers, switches, firewalls, and servers. * Ability to effectively communicate technical findings and recommendations to both technical and non-technical stakeholders through detailed reports and presentations. * Prior experience with the use of enterprise penetration test tools. (nmap, Nessus, BurpSuite, Hydra, Metasploit, BloodHound.) * Continuous learning and staying updated with the latest security trends, vulnerabilities, and attack techniques through self-study, training, and participation in industry conferences and events. * Experience with python, bash, and PowerShell scripts * Capable of rewriting preexisting scripts, tools, or exploits to work on target systems. * Conduct penetration tests on Active Directory environments, leveraging tools like BloodHound and PowerView for reconnaissance and enumeration, to identify vulnerabilities and attack paths. * Execute advanced attack techniques, including pass-the-hash and golden ticket attacks, to assess the effectiveness of Active Directory security controls and simulate real-world threat scenarios. * Provide actionable recommendations and remediation strategies to improve the security posture of Active Directory infrastructures, emphasizing best practices such as least privilege principles and strong password policies. * Demonstrate the ability to complete a CTF if requested DESIRED QUALIFICATIONS / SKILLS * Bachelor's Degree in either Engineering or Cybersecurity related Discipline desired. * Active TS/SCI preferred. * OSCP, CPTS, PNPT certifications desired. * Prior understanding of aircraft avionics navigation, communication, and datalinks is desired (GPS, ACARS, Mode-S, Link-16, and etc.) RESPONSIBILITIES * Execute test projects and program objectives with various DoD and federal agency customers
* Review technical documentation related to Avionics Embedded Systems and RF datalinks and identify potential design shortfalls that might result in a cybersecurity weakness
* Develop test corpus and test plans to validate the presence of weaknesses
* Analysis data from test events and present this data in a coherent and accurate manner for the customer
* Work with operational testers and pilots to identify vulnerabilities which might affect the cyber resiliency of the platform for a given mission
* Assist with developing cyber contested environments to demonstrate the resiliency of the platform under test
#LI-AD1 #CJ