1

Penetration Tester Jobs in Decatur, GA (NOW HIRING)

Familiarity with offensive security and penetration testing methodologies and the ability to apply an attacker mindset when evaluating new technologies. * Experience evaluating applications or SaaS ...

Coordinate and assist with penetration testing activities * Install, configure and maintain security software and systems such as endpoint security, intrusion detection, prevention systems and ...

Showing results 41-60

Penetration Tester information

See Decatur, GA salary details

$22K

$117.1K

$164.5K

How much do penetration tester jobs pay per year?

As of Sep 5, 2026, the average yearly pay for penetration tester in Decatur, GA is $117,057.00, according to ZipRecruiter salary data. Most workers in this role earn between $93,700.00 and $137,700.00 per year, depending on experience, location, and employer.

What is a penetration tester?

Penetration Testers, also known as ethical hackers, are cybersecurity professionals who simulate cyberattacks on computer systems, networks, or applications to identify and address security vulnerabilities. Their work helps organizations discover weak points before malicious hackers can exploit them. Penetration testers use a variety of tools and techniques to mimic real-world threats and provide detailed reports with recommendations for improving security. They play a crucial role in maintaining the safety and integrity of an organization’s digital assets.

What does a penetration tester do?

As a penetration tester, your job is to test the security of a network by attempting to hack into an application, system, or computer. Penetration testing can occur in a variety of ways, from physical interaction with the machine you’re trying to hack to attacks sent over the web. Aside from helping clients test for vulnerabilities, your job also includes explaining how you got in and providing recommendations for stopping others from repeating your actions. In some cases, you may be asked to help investigate cyber crimes or explain methods and techniques in criminal trials. Success in this job is often measured by how many security holes you find and close.

What are the key skills and qualifications needed to thrive as a penetration tester, and why are they important?

To thrive as a Penetration Tester, you need a solid understanding of networking, operating systems, cybersecurity principles, and typically hold certifications like OSCP or CEH. Proficiency with tools such as Metasploit, Burp Suite, Nmap, and Wireshark is crucial for identifying and exploiting vulnerabilities. Strong analytical thinking, attention to detail, and clear communication skills help Penetration Testers effectively document findings and convey risks to clients. These skills and qualities are vital for uncovering security weaknesses and helping organizations strengthen their defenses against cyber threats.

What are some common challenges penetration testers face during client engagements?

Penetration testers often encounter challenges such as limited access to information, strict time constraints, and navigating complex or legacy systems. Additionally, they must balance thorough testing with minimizing disruptions to client operations. Effective communication is crucial, as testers need to clearly document findings and explain technical vulnerabilities to non-technical stakeholders to ensure remediation efforts are understood and prioritized.

What is the difference between Penetration Tester vs Vulnerability Analyst?

AspectPenetration TesterVulnerability Analyst
CertificationsOSCP, CEH, GPENCVE, CISSP, GIAC
Work EnvironmentHands-on testing, simulated attacksVulnerability scanning, risk assessment
Employer & IndustryCybersecurity firms, IT departmentsSecurity teams, compliance agencies
Search & Comparison IntentUnderstanding testing roles, skillsIdentifying vulnerabilities, analysis methods

While both roles focus on cybersecurity, a Penetration Tester actively exploits vulnerabilities to test security defenses, whereas a Vulnerability Analyst identifies and assesses weaknesses without exploiting them. Penetration Testers typically perform simulated attacks, requiring hands-on skills and certifications like OSCP or CEH. Vulnerability Analysts focus on scanning and reporting vulnerabilities, often working with tools like Nessus or Qualys. Both roles are essential for a comprehensive security strategy but differ in approach and responsibilities.

How much do penetration testers make?

Penetration testers typically earn between $70,000 and $130,000 annually, depending on experience, certifications, and location. Senior professionals with advanced skills and certifications like OSCP or CISSP can earn higher salaries, especially in high-demand markets.

Is penetration testing a hard job?

Penetration testing can be challenging as it requires strong technical skills, problem-solving abilities, and knowledge of security vulnerabilities. The job often involves staying updated on new threats and using tools like Kali Linux and Metasploit, which can be complex for beginners. Success in this role depends on continuous learning and practical experience.

What are the most commonly searched types of Penetration Tester jobs in Decatur, GA?

The most popular types of Penetration Tester jobs in Decatur, GA are:

What are popular job titles related to Penetration Tester jobs in Decatur, GA?

For Penetration Tester jobs in Decatur, GA, the most frequently searched job titles are:

What job categories do people searching Penetration Tester jobs in Decatur, GA look for?

The top searched job categories for Penetration Tester jobs in Decatur, GA are:

What cities near Decatur, GA are hiring for Penetration Tester jobs?

Cities near Decatur, GA with the most Penetration Tester job openings:

Infographic showing various Penetration Tester job openings in Decatur, GA as of August 2026, with employment types broken down into 94% Full Time, and 6% Contract. Highlights an 82% In-person, 3% Hybrid, and 15% Remote job distribution, with an average salary of $117,057 per year, or $56.3 per hour.

Security Engineer

Seyfarth Shaw LLP

Atlanta, GA • On-site

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 4 days ago


Key responsibilities

  • Perform technical security assessments of applications, SaaS platforms, browser extensions, integrations, and other technologies proposed for use within the firm.

  • Evaluate application architecture, permissions, data access, authentication methods, APIs, third-party dependencies, and security configurations.

  • Work with stakeholders to identify security gaps and recommend practical remediation or controls.


Job description

Why Seyfarth
At Seyfarth, we understand that great people are the key to our success, and we provide the opportunities to match. If you join us, you'll work with state-of-the-art technology in a friendly and professional environment, and we will continue to invest in your professional development. If you want the freedom to grow at a firm that is invested in your future, keep reading.
The Opportunity
As a Security Engineer - Application Security & Technology Risk, you will help evaluate and protect the Firm's technology environment by assessing the security risks associated with applications, SaaS platforms, browser extensions, integrations, and other technologies proposed for use within the Firm.
A significant part of this role will involve understanding how a technology works, the access and permissions it requires, the data it can access or process, how it integrates with the Firm's environment, and how it could potentially be abused or compromised. You will evaluate these technologies from both a defensive and adversarial perspective, considering vulnerabilities, software supply-chain risk, authentication and authorization controls, configuration weaknesses, and the ways an attacker could leverage a compromised application or integration.
The successful candidate will combine strong technical security knowledge with the ability to translate security findings into practical, risk-based recommendations for application owners, IT teams, and Firm leadership.
The Day-To-Day
On any given day, you will work with Security, IT, application owners, project teams, vendors, and other stakeholders on a variety of technology assessments and security initiatives. You will:
  • Perform technical security assessments of software applications, SaaS platforms, browser extensions, integrations, AI-enabled technologies, and other technologies proposed for use within the Firm.
  • Evaluate application architecture, permissions, data access, administrative controls, authentication methods, APIs, OAuth integrations, third-party dependencies, logging capabilities, and security configuration.
  • Assess how compromised or malicious applications could be leveraged as an attack vector, including credential theft, data exposure, persistence, privilege escalation, lateral movement, command and control, and software supply-chain compromise.
  • Review vendor and application security documentation, vulnerability information, threat intelligence, software dependencies, and publicly available security research to identify potential risks.
  • Evaluate authentication and authorization configurations including SSO, SAML, OAuth/OIDC, MFA, Microsoft Entra ID integrations, Conditional Access policies, service principals, application registrations, API permissions, and privileged access requirements.
  • Work with infrastructure, endpoint, cloud, identity, networking, and application teams to identify security design or configuration gaps and recommend practical remediation or compensating controls.
  • Review existing deployed applications to determine business need, usage, software versions, support status, known vulnerabilities, available updates, and potential security exposure.
  • Assist with application inventory and software lifecycle initiatives designed to identify unnecessary, obsolete, vulnerable, or unauthorized applications within the environment.
  • Validate approved application deployments to confirm that software, security controls, permissions, integrations, and configurations were implemented according to approved requirements.
  • Use vulnerability management, endpoint security, SIEM, identity, network, asset discovery, and other security telemetry to understand application behavior and identify potential security concerns.
  • Support Security Operations with threat hunting, security investigations, incident response, and other operational security activities as needed.
  • Clearly document findings, risk, technical impact, and recommended controls for both technical and non-technical audiences.
  • Exercise independent judgment, curiosity, and initiative when investigating unfamiliar technologies and security risks.

You Have
  • At least three years of experience in cybersecurity, security engineering, application security, vulnerability management, penetration testing, security operations, or a related technical information technology role.
  • Strong understanding of common vulnerabilities, attack techniques, and the ways attackers compromise applications, endpoints, identities, cloud services, and enterprise environments.
  • Strong understanding of software supply-chain risk, including compromised software updates, malicious dependencies, third-party libraries, browser extensions, package repositories, software signing, and vendor compromise.
  • Familiarity with offensive security and penetration testing methodologies and the ability to apply an attacker mindset when evaluating new technologies.
  • Experience evaluating applications or SaaS platforms from a security perspective, including permissions, architecture, integrations, authentication, authorization, data access, and administrative controls.
  • Working knowledge of modern identity and authentication technologies including SSO, SAML, OAuth 2.0, OpenID Connect, MFA, Microsoft Entra ID, enterprise application registrations, and Conditional Access.
  • Understanding of Windows and cloud security concepts, endpoint security controls, networking, APIs, and common enterprise application deployment models.
  • Experience working with security technologies such as vulnerability scanners, endpoint detection and response platforms, SIEM platforms, identity security tools, network security platforms, or application security testing tools.
  • Familiarity with tools such as Qualys, CrowdStrike Falcon, Microsoft Sentinel, Microsoft Entra ID, Burp Suite, or comparable security platforms is preferred.
  • Ability to research unfamiliar technologies, understand how they operate, identify meaningful security concerns, and distinguish theoretical risk from realistic enterprise risk.
  • Strong analytical and troubleshooting skills with attention to technical detail.
  • Ability to communicate security findings clearly and work collaboratively with technical teams, application owners, vendors, and business stakeholders.
  • Scripting, API, or automation experience with PowerShell, Python, or similar technologies is preferred.
  • A strong desire to continuously learn about emerging technologies, vulnerabilities, attack techniques, and changes in the cyber threat landscape.

What We Provide
Seyfarth provides competitive salary and benefits at all levels, and our culture embraces the entrepreneurial spirit of its professionals like no other firm. Our professional staff are a collaborative team, helping to define the unique client experience offered by the firm. We understand that it takes more than attorneys to build a successful legal practice; everyone participates in our commitment to excellence.
More About Seyfarth
With approximately 1,000 lawyers across 19 offices, Seyfarth Shaw LLP provides advisory, litigation, and transactional legal services to clients worldwide. Learn more about The Seyfarth Experience at www.seyfarth.com/careers/.
Seyfarth Shaw is committed to equal employment opportunity and providing reasonable accommodations to applicants with physical and/or mental disabilities. We value and encourage diversity and solicit applications from all qualified applicants without regard to race, color, gender, sex, age, religion, creed, national origin, ancestry, citizenship, marital status, sexual orientation, physical or mental disability, medical condition, military and veteran status, gender identity or expression, genetic information, change of sex or transgender status, genetic information or any other basis protected by federal, state or local law.
If you would like more information about your EEO rights as an applicant under the law, please click EEO is the LAW and the Supplement poster through the following link: https://www.eeoc.gov/sites/default/files/migrated_files/employers/poster_screen_reader_optimized.pdf
Location Specific Language
The salary range for this role is $118,000 to $135,000 annually, which is based on a 40 hour work week. This range is only applicable for jobs to be performed in Chicago. This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. An employee's pay within the salary range will be based on numerous factors including, but not limited to, relevant education, qualifications, experience, skills, and business or organizational needs. This job is also eligible for an annual merit increase and bonus pay.
We offer a comprehensive package of benefits including paid time off, medical/dental/vision insurance, and 401(k).
#LI-Remote
This position is based in Atlanta, GA 30309
This position is based in Charlotte, NC 28202
This position is based in Chicago, IL 60606
This position is based in Dallas, TX 75201
This position is based in Houston, TX 77002
This position is based in Miami, FL 33131
  • At least three years of experience in cybersecurity, security engineering, application security, vulnerability management, penetration testing, security operations, or a related technical information technology role.
  • Strong understanding of common vulnerabilities, attack techniques, and the ways attackers compromise applications, endpoints, identities, cloud services, and enterprise environments.
  • Strong understanding of software supply-chain risk, including compromised software updates, malicious dependencies, third-party libraries, browser extensions, package repositories, software signing, and vendor compromise.
  • Familiarity with offensive security and penetration testing methodologies and the ability to apply an attacker mindset when evaluating new technologies.
  • Experience evaluating applications or SaaS platforms from a security perspective, including permissions, architecture, integrations, authentication, authorization, data access, and administrative controls.
  • Working knowledge of modern identity and authentication technologies including SSO, SAML, OAuth 2.0, OpenID Connect, MFA, Microsoft Entra ID, enterprise application registrations, and Conditional Access.
  • Understanding of Windows and cloud security concepts, endpoint security controls, networking, APIs, and common enterprise application deployment models.
  • Experience working with security technologies such as vulnerability scanners, endpoint detection and response platforms, SIEM platforms, identity security tools, network security platforms, or application security testing tools.
  • Familiarity with tools such as Qualys, CrowdStrike Falcon, Microsoft Sentinel, Microsoft Entra ID, Burp Suite, or comparable security platforms is preferred.
  • Ability to research unfamiliar technologies, understand how they operate, identify meaningful security concerns, and distinguish theoretical risk from realistic enterprise risk.
  • Strong analytical and troubleshooting skills with attention to technical detail.
  • Ability to communicate security findings clearly and work collaboratively with technical teams, application owners, vendors, and business stakeholders.
  • Scripting, API, or automation experience with PowerShell, Python, or similar technologies is preferred.
  • A strong desire to continuously learn about emerging technologies, vulnerabilities, attack techniques, and changes in the cyber threat landscape.

On any given day, you will work with Security, IT, application owners, project teams, vendors, and other stakeholders on a variety of technology assessments and security initiatives. You will:
  • Perform technical security assessments of software applications, SaaS platforms, browser extensions, integrations, AI-enabled technologies, and other technologies proposed for use within the Firm.
  • Evaluate application architecture, permissions, data access, administrative controls, authentication methods, APIs, OAuth integrations, third-party dependencies, logging capabilities, and security configuration.
  • Assess how compromised or malicious applications could be leveraged as an attack vector, including credential theft, data exposure, persistence, privilege escalation, lateral movement, command and control, and software supply-chain compromise.
  • Review vendor and application security documentation, vulnerability information, threat intelligence, software dependencies, and publicly available security research to identify potential risks.
  • Evaluate authentication and authorization configurations including SSO, SAML, OAuth/OIDC, MFA, Microsoft Entra ID integrations, Conditional Access policies, service principals, application registrations, API permissions, and privileged access requirements.
  • Work with infrastructure, endpoint, cloud, identity, networking, and application teams to identify security design or configuration gaps and recommend practical remediation or compensating controls.
  • Review existing deployed applications to determine business need, usage, software versions, support status, known vulnerabilities, available updates, and potential security exposure.
  • Assist with application inventory and software lifecycle initiatives designed to identify unnecessary, obsolete, vulnerable, or unauthorized applications within the environment.
  • Validate approved application deployments to confirm that software, security controls, permissions, integrations, and configurations were implemented according to approved requirements.
  • Use vulnerability management, endpoint security, SIEM, identity, network, asset discovery, and other security telemetry to understand application behavior and identify potential security concerns.
  • Support Security Operations with threat hunting, security investigations, incident response, and other operational security activities as needed.
  • Clearly document findings, risk, technical impact, and recommended controls for both technical and non-technical audiences.
  • Exercise independent judgme