1

Penetration Tester Jobs in Normal, IL (NOW HIRING)

Ensure ongoing compliance with FedRAMP policy and requirements through monthly deliverables, regular vulnerability scanning, penetration testing, contingency testing, and annual security assessments ...

Penetration Tester information

See Normal, IL salary details

$22K

$117.2K

$164.7K

How much do penetration tester jobs pay per year?

As of Sep 6, 2026, the average yearly pay for penetration tester in Normal, IL is $117,217.00, according to ZipRecruiter salary data. Most workers in this role earn between $93,900.00 and $137,800.00 per year, depending on experience, location, and employer.

What is a penetration tester?

Penetration Testers, also known as ethical hackers, are cybersecurity professionals who simulate cyberattacks on computer systems, networks, or applications to identify and address security vulnerabilities. Their work helps organizations discover weak points before malicious hackers can exploit them. Penetration testers use a variety of tools and techniques to mimic real-world threats and provide detailed reports with recommendations for improving security. They play a crucial role in maintaining the safety and integrity of an organization’s digital assets.

What does a penetration tester do?

As a penetration tester, your job is to test the security of a network by attempting to hack into an application, system, or computer. Penetration testing can occur in a variety of ways, from physical interaction with the machine you’re trying to hack to attacks sent over the web. Aside from helping clients test for vulnerabilities, your job also includes explaining how you got in and providing recommendations for stopping others from repeating your actions. In some cases, you may be asked to help investigate cyber crimes or explain methods and techniques in criminal trials. Success in this job is often measured by how many security holes you find and close.

What are the key skills and qualifications needed to thrive as a penetration tester, and why are they important?

To thrive as a Penetration Tester, you need a solid understanding of networking, operating systems, cybersecurity principles, and typically hold certifications like OSCP or CEH. Proficiency with tools such as Metasploit, Burp Suite, Nmap, and Wireshark is crucial for identifying and exploiting vulnerabilities. Strong analytical thinking, attention to detail, and clear communication skills help Penetration Testers effectively document findings and convey risks to clients. These skills and qualities are vital for uncovering security weaknesses and helping organizations strengthen their defenses against cyber threats.

What are some common challenges penetration testers face during client engagements?

Penetration testers often encounter challenges such as limited access to information, strict time constraints, and navigating complex or legacy systems. Additionally, they must balance thorough testing with minimizing disruptions to client operations. Effective communication is crucial, as testers need to clearly document findings and explain technical vulnerabilities to non-technical stakeholders to ensure remediation efforts are understood and prioritized.

What is the difference between Penetration Tester vs Vulnerability Analyst?

AspectPenetration TesterVulnerability Analyst
CertificationsOSCP, CEH, GPENCVE, CISSP, GIAC
Work EnvironmentHands-on testing, simulated attacksVulnerability scanning, risk assessment
Employer & IndustryCybersecurity firms, IT departmentsSecurity teams, compliance agencies
Search & Comparison IntentUnderstanding testing roles, skillsIdentifying vulnerabilities, analysis methods

While both roles focus on cybersecurity, a Penetration Tester actively exploits vulnerabilities to test security defenses, whereas a Vulnerability Analyst identifies and assesses weaknesses without exploiting them. Penetration Testers typically perform simulated attacks, requiring hands-on skills and certifications like OSCP or CEH. Vulnerability Analysts focus on scanning and reporting vulnerabilities, often working with tools like Nessus or Qualys. Both roles are essential for a comprehensive security strategy but differ in approach and responsibilities.

How much do penetration testers make?

Penetration testers typically earn between $70,000 and $130,000 annually, depending on experience, certifications, and location. Senior professionals with advanced skills and certifications like OSCP or CISSP can earn higher salaries, especially in high-demand markets.

Is penetration testing a hard job?

Penetration testing can be challenging as it requires strong technical skills, problem-solving abilities, and knowledge of security vulnerabilities. The job often involves staying updated on new threats and using tools like Kali Linux and Metasploit, which can be complex for beginners. Success in this role depends on continuous learning and practical experience.

What are the most commonly searched types of Penetration Tester jobs in Normal, IL?

The most popular types of Penetration Tester jobs in Normal, IL are:

What are popular job titles related to Penetration Tester jobs in Normal, IL?

For Penetration Tester jobs in Normal, IL, the most frequently searched job titles are:

What job categories do people searching Penetration Tester jobs in Normal, IL look for?

The top searched job categories for Penetration Tester jobs in Normal, IL are:

What cities near Normal, IL are hiring for Penetration Tester jobs?

Cities near Normal, IL with the most Penetration Tester job openings:

Infographic showing various Penetration Tester job openings in Normal, IL as of August 2026, with employment types broken down into 93% Full Time, and 7% Contract. Highlights an 82% In-person, 3% Hybrid, and 15% Remote job distribution, with an average salary of $117,217 per year, or $56.4 per hour.

Red-Team / Adversarial Security Lead

Steampunk

Bloomington, IL • On-site

$85 - $170/hr

Other

Posted 4 days ago


Key responsibilities

  • Develop threat models, identify attack paths and vulnerabilities, and evaluate security risks across systems and environments.

  • Develop and execute red-team and adversarial security assessment plans, perform penetration testing, and validate vulnerabilities.

  • Analyze assessment results, communicate findings and remediation recommendations, and support pass/fail safety-gate determinations.


Job description

Overview

We are seeking a Red-Team / Adversarial Security Lead responsible for planning and executing adversarial security assessments across complex enterprise environments. This role develops threat models, identifies potential attack paths and vulnerabilities, develops and executes red-team assessment plans, and evaluates the effectiveness of security controls.

The Red-Team / Adversarial Security Lead will analyze and document assessment results, communicate identified risks and vulnerabilities, recommend appropriate remediation actions, and support pass/fail safety-gate determinations based on established security criteria. This role requires strong technical cybersecurity experience across operating systems, infrastructure, and cloud environments.

Contributions
  • Develop threat models to identify potential threats, attack vectors, vulnerabilities, and security risks across systems and environments
  • Develop and execute red-team and adversarial security assessment plans based on defined objectives and security criteria
  • Perform penetration testing and adversarial testing to identify and validate vulnerabilities, weaknesses, and potential attack paths
  • Evaluate the effectiveness of existing security controls through technical testing and adversarial techniques
  • Analyze vulnerabilities and assessment findings to determine exploitability, potential impact, and associated security risk
  • Conduct security assessments across diverse operating systems and enterprise technology environments
  • Assess security risks and attack paths within cloud environments, including AWS, Azure, and Google Cloud Platform (GCP)
  • Analyze and document assessment results, technical findings, supporting evidence, and recommended remediation actions
  • Evaluate assessment results against established security and safety-gate criteria and support pass/fail determinations
  • Communicate vulnerabilities, assessment findings, recommended remediation steps, and security risks to technical teams and program stakeholders
  • Collaborate with cybersecurity, infrastructure, cloud, engineering, and architecture teams to understand system environments and evaluate identified risks
  • Validate remediation of identified vulnerabilities and security weaknesses through follow-up testing
  • Maintain awareness of evolving threats, vulnerabilities, attack techniques, and adversarial security testing practices
  • Support the development and refinement of red-team methodologies, assessment procedures, and security testing criteria
Qualifications

Required:

  • Ability to obtain and maintain a government security clearance
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field, or equivalent relevant experience
  • 5+ years of experience in cybersecurity, including hands-on experience with penetration testing, red-team operations, adversarial security testing, vulnerability assessment, or related security disciplines
  • Experience applying threat modeling methodologies or frameworks, such as STRIDE or equivalent approaches, to identify potential threats, attack vectors, vulnerabilities, and security risks
  • Experience planning and executing technical security assessments, penetration tests, or adversarial security assessments
  • Deep technical experience across operating systems and associated security concepts, including environments such as Windows and Linux
  • Experience identifying, validating, and assessing vulnerabilities and potential attack paths
  • Knowledge of common attack techniques, exploitation methods, security vulnerabilities, and defensive controls
  • Experience with cloud architecture and security concepts across AWS, Azure, and/or GCP
  • Ability to analyze technical security findings and evaluate their potential impact and risk
  • Experience documenting technical findings, supporting evidence, and remediation recommendations
  • Strong analytical, problem-solving, communication, and collaboration skills

Preferred:

  • Experience conducting red-team assessments across complex enterprise environments
  • Experience with multiple cloud platforms, including AWS, Azure, and GCP
  • Experience with adversary emulation and penetration testing tools and methodologies
  • Knowledge of MITRE ATT&CK and related adversarial tactics, techniques, and procedures
  • Experience evaluating security assessment results against defined acceptance, release, or safety-gate criteria
  • Experience working within federal government or other highly regulated environments
  • Offensive Security Certified Professional (OSCP) or comparable hands‑on offensive security/penetration testing certification strongly preferred; comparable certifications may include GIAC Penetration Tester (GPEN), Practical Network Penetration Tester (PNPT), Hack The Box Certified Penetration Testing Specialist (HTB CPTS), or equivalent
About steampunk

Steampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $85,000 to $170,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk’s total compensation package for employees. Learn more about additional Steampunk benefits here.

Identity Statement

As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. If you want to learn more about our story, visit http://www.steampunk.com.

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.Steampunk participates in the E-Verify program.

#J-18808-Ljbffr