1

Penetration Tester Jobs in Raleigh, NC (NOW HIRING)

The Technical Security Risk Assessment & Penetration Testing Lead Consultant will be responsible for designing and conducting technical security assessments, performing penetration testing activities ...

Network Penetration Testing (Internal, External) * Cloud Service penetration testing tradecraft and methodologies across multiple service providers (AWS, Azure, GCP) * Threat Modeling * Source-Code ...

Network Penetration Testing (Internal, External) * Cloud Service penetration testing tradecraft and methodologies across multiple service providers (AWS, Azure, GCP) * Threat Modeling * Source-Code ...

Lead, mentor, and direct a small team of offensive security specialists conducting internal penetration testing, validating findings, reviewing remediations, and coordinating follow-on testing.

Lead, mentor, and direct a small team of offensive security specialists conducting internal penetration testing, validating findings, reviewing remediations, and coordinating follow-on testing.

next page

Showing results 1-20

Penetration Tester information

See Raleigh, NC salary details

$21.9K

$116.5K

$163.8K

How much do penetration tester jobs pay per year?

As of Aug 1, 2026, the average yearly pay for penetration tester in Raleigh, NC is $116,547.00, according to ZipRecruiter salary data. Most workers in this role earn between $93,300.00 and $137,100.00 per year, depending on experience, location, and employer.

What Does a Penetration Tester Do?

As a penetration tester, your job is to test the security of a network by attempting to hack into an application, system, or computer. Penetration testing can occur in a variety of ways, from physical interaction with the machine you’re trying to hack to attacks sent over the web. Aside from helping clients test for vulnerabilities, your job also includes explaining how you got in and providing recommendations for stopping others from repeating your actions. In some cases, you may be asked to help investigate cyber crimes or explain methods and techniques in criminal trials. Success in this job is often measured by how many security holes you find and close.

What are some common challenges penetration testers face during client engagements?

Penetration testers often encounter challenges such as limited access to information, strict time constraints, and navigating complex or legacy systems. Additionally, they must balance thorough testing with minimizing disruptions to client operations. Effective communication is crucial, as testers need to clearly document findings and explain technical vulnerabilities to non-technical stakeholders to ensure remediation efforts are understood and prioritized.

What are Penetration Testers?

Penetration Testers, also known as ethical hackers, are cybersecurity professionals who simulate cyberattacks on computer systems, networks, or applications to identify and address security vulnerabilities. Their work helps organizations discover weak points before malicious hackers can exploit them. Penetration testers use a variety of tools and techniques to mimic real-world threats and provide detailed reports with recommendations for improving security. They play a crucial role in maintaining the safety and integrity of an organization’s digital assets.

What is the difference between Penetration Tester vs Vulnerability Analyst?

AspectPenetration TesterVulnerability Analyst
CertificationsOSCP, CEH, GPENCVE, CISSP, GIAC
Work EnvironmentHands-on testing, simulated attacksVulnerability scanning, risk assessment
Employer & IndustryCybersecurity firms, IT departmentsSecurity teams, compliance agencies
Search & Comparison IntentUnderstanding testing roles, skillsIdentifying vulnerabilities, analysis methods

While both roles focus on cybersecurity, a Penetration Tester actively exploits vulnerabilities to test security defenses, whereas a Vulnerability Analyst identifies and assesses weaknesses without exploiting them. Penetration Testers typically perform simulated attacks, requiring hands-on skills and certifications like OSCP or CEH. Vulnerability Analysts focus on scanning and reporting vulnerabilities, often working with tools like Nessus or Qualys. Both roles are essential for a comprehensive security strategy but differ in approach and responsibilities.

What are the key skills and qualifications needed to thrive as a Penetration Tester, and why are they important?

To thrive as a Penetration Tester, you need a solid understanding of networking, operating systems, cybersecurity principles, and typically hold certifications like OSCP or CEH. Proficiency with tools such as Metasploit, Burp Suite, Nmap, and Wireshark is crucial for identifying and exploiting vulnerabilities. Strong analytical thinking, attention to detail, and clear communication skills help Penetration Testers effectively document findings and convey risks to clients. These skills and qualities are vital for uncovering security weaknesses and helping organizations strengthen their defenses against cyber threats.
What are the most commonly searched types of Penetration Tester jobs in Raleigh, NC? The most popular types of Penetration Tester jobs in Raleigh, NC are:
What are popular job titles related to Penetration Tester jobs in Raleigh, NC? For Penetration Tester jobs in Raleigh, NC, the most frequently searched job titles are:
What job categories do people searching Penetration Tester jobs in Raleigh, NC look for? The top searched job categories for Penetration Tester jobs in Raleigh, NC are:
What cities near Raleigh, NC are hiring for Penetration Tester jobs? Cities near Raleigh, NC with the most Penetration Tester job openings:
Infographic showing various Penetration Tester job openings in Raleigh, NC as of July 2026, with employment types broken down into 95% Full Time, 4% Part Time, and 1% Contract. Highlights an 85% Physical, 4% Hybrid, and 11% Remote job distribution, with an average salary of $116,547 per year, or $56 per hour.

Principal, Cybersecurity Penetration Tester

Fidelity Investments

Durham, NC • On-site

Full-time

Re-posted 15 days ago


Fidelity Investments rating

8.7

Company rating: 8.7 out of 10

Based on 270 frontline employees who took The Breakroom Quiz

15th of 150 rated financial services


Job description

Job Description:

Position Description:

Performs security assessments of applications prior to production deployment using Static Code Analysis, dynamic testing tools, and manual techniques. Assists in establishing the strategy, policy, and standards of security for cybersecurity operations. Develop custom Python scripts to automate repetitive tasks. Defends enterprise against attacks, damage, and unauthorized access to information, data, and systems. Ensures threat and vulnerability reduction, deterrence, incident response, resiliency, and recovery policies and activities are up to date. Proactively identifies vulnerabilities in proprietary applications prior to production release and remediates identified vulnerabilities to prevent real-life cyberattacks.

Primary Responsibilities:

  • Performs advanced Web application source code auditing.
  • Analyzes codes, writes scripts, and exploits web vulnerabilities.
  • Analyzes test results, draw conclusions from results.
  • Identifies vulnerabilities by performing thorough evaluations of security vulnerabilities on Web and mobile applications.
  • Collaborates with application developers to mitigate risk and improve security posture.
  • Performs security testing on web and mobile applications to support production releases.
  • Models potential external threats by replicating the techniques and tools used by malicious attackers.
  • Prepares reports on completed assessments and present results to application owners, developers, and business unit information security teams.
  • Consults with operations and software development teams to ensure potential weaknesses are addressed.
  • Contributes to the research and development of tools to assist in the vulnerability discovery process.
  • Keeps abreast of current cybersecurity best practices and vulnerabilities.
  • Conducts peer reviews to facilitate continuous improvement across the team.

Education and Experience:

Bachelor's degree in Computer Science, Engineering, Information Technology, Information Systems, or a closely related field (or foreign education equivalent) and five (5) years of experience as a Principal, Cybersecurity Penetration Tester (or closely related occupation) performing black and white box testing to protect against cyber threats and ensure application security (web, mobile, API, and thick client).

Or, alternatively, Master's degree in Computer Science, Engineering, Information Technology, Information Systems, or a closely related field (or foreign education equivalent) and three (3) years of experience as a Principal, Cybersecurity Penetration Tester (or closely related occupation) performing black and white box testing to protect against cyber threats and ensure application security (web, mobile, API, and thick client).

Skills and Knowledge:

Candidate must also possess:

  • Demonstrated Expertise ("DE") estimating risks on security flaws uncovered during static or dynamic analysis in line with the OWASP testing guide; conducting pen-testing on applications to uncover security vulnerabilities - Injection attacks, Server-side attacks, Privilege escalation, GraphQL batching attacks, or JWT signature manipulation attacks - using BurpSuite Professional Edition, Fiddler, Kali Linux, and SQLMap.
  • DE analyzing source code for security weaknesses, writing custom scripts, exploiting security vulnerabilities, and conducting retests to determine mitigation measures implemented by development teams, through a combination of manual analysis by using BurpSuite Professional, and automated scans using GitHub Advanced Security(GHAS) and MEND.
  • DE analyzing Common Vulnerability Exposure (CVE) on third party libraries, using Veracode SCA, MEND, Exploit-DB, and NVD databases; and coordinating actions associated with the dismissal or reopening of policy violation alerts related to security, licensing, and coding standards using GitHub Advanced Security (GHAS).
  • DE crafting custom scripts to effectively automate labor-intensive manual tasks (logging security findings, preparing weekly status reports, verifying artifact correctness) and empower the efficient allocation of resources, enhancing the overall security assessment process, using Python or Selenium.

#PE1M2

#LI-DNI

Certifications:Category:Information Technology

Please be advised that Fidelity's business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.


What Fidelity Investments employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom