... Penetration Tester (or closely related occupation) performing black and white box testing to protect against cyber threats and ensure application security (web, mobile, API, and thick client). Or ...
... Penetration Tester (or closely related occupation) performing black and white box testing to protect against cyber threats and ensure application security (web, mobile, API, and thick client). Or ...
Lead Penetration Tester
Raleigh, NC · On-site
Required...5 years • Conduct internal/external penetration testing, vulnerability identification, and exploit validation....Required...7 years • Develop a repeatable assessment methodology ...
Lead Penetration Tester
Raleigh, NC · On-site
Required...5 years • Conduct internal/external penetration testing, vulnerability identification, and exploit validation....Required...7 years • Develop a repeatable assessment methodology ...
The tester will assess organizational networks, applications, or systems for potential ... Plan and conduct application penetration tests of complex computer systems from a remote testing ...
The tester will assess organizational networks, applications, or systems for potential ... Plan and conduct application penetration tests of complex computer systems from a remote testing ...
The tester will assess organizational networks, applications, or systems for potential ... Plan and conduct application penetration tests of complex computer systems from a remote testing ...
The tester will assess organizational networks, applications, or systems for potential ... Plan and conduct application penetration tests of complex computer systems from a remote testing ...
The tester will assess organizational networks, applications, or systems for potential ... Plan and conduct application penetration tests of complex computer systems from a remote testing ...
The tester will assess organizational networks, applications, or systems for potential ... Plan and conduct application penetration tests of complex computer systems from a remote testing ...
Program Director- Expert
Raleigh, NC · On-site
The Technical Security Risk Assessment & Penetration Testing Lead Consultant will be responsible for designing and conducting technical security assessments, performing penetration testing activities ...
Program Director- Expert
Raleigh, NC · On-site
The Technical Security Risk Assessment & Penetration Testing Lead Consultant will be responsible for designing and conducting technical security assessments, performing penetration testing activities ...
Senior Product Security Engineer
Raleigh, NC · On-site
$168K - $210K/yr
Network Penetration Testing (Internal, External) * Cloud Service penetration testing tradecraft and methodologies across multiple service providers (AWS, Azure, GCP) * Threat Modeling * Source-Code ...
Senior Product Security Engineer
Raleigh, NC · On-site
$168K - $210K/yr
Network Penetration Testing (Internal, External) * Cloud Service penetration testing tradecraft and methodologies across multiple service providers (AWS, Azure, GCP) * Threat Modeling * Source-Code ...
Senior Product Security Engineer
Raleigh, NC · On-site
$168K - $210K/yr
Network Penetration Testing (Internal, External) * Cloud Service penetration testing tradecraft and methodologies across multiple service providers (AWS, Azure, GCP) * Threat Modeling * Source-Code ...
Senior Product Security Engineer
Raleigh, NC · On-site
$168K - $210K/yr
Network Penetration Testing (Internal, External) * Cloud Service penetration testing tradecraft and methodologies across multiple service providers (AWS, Azure, GCP) * Threat Modeling * Source-Code ...
SVP - Cyber Security Ops Center & Assurance
Raleigh, NC · On-site
$107K - $145K/yr
Direct internal and external penetration testing efforts, including ethical hacking simulations and red team operations. Analyze findings to recommend defensive improvements and enhance overall ...
SVP - Cyber Security Ops Center & Assurance
Raleigh, NC · On-site
$107K - $145K/yr
Direct internal and external penetration testing efforts, including ethical hacking simulations and red team operations. Analyze findings to recommend defensive improvements and enhance overall ...
CISSP, CISM, SANS, GIAC (or related), ethical hacking/penetration tester certification, and/or security risk assessment certification TECHNICAL SKILLS: • Advanced knowledge of security environments ...
CISSP, CISM, SANS, GIAC (or related), ethical hacking/penetration tester certification, and/or security risk assessment certification TECHNICAL SKILLS: • Advanced knowledge of security environments ...
SVP - Cyber Security Ops Center & Assurance
Raleigh, NC · Hybrid
$107K - $145K/yr
Direct internal and external penetration testing efforts, including ethical hacking simulations and red team operations. Analyze findings to recommend defensive improvements and enhance overall ...
SVP - Cyber Security Ops Center & Assurance
Raleigh, NC · Hybrid
$107K - $145K/yr
Direct internal and external penetration testing efforts, including ethical hacking simulations and red team operations. Analyze findings to recommend defensive improvements and enhance overall ...
Primary areas of expertise are IT infrastructure and information security compliance (HIPAA, SOX, PCI, Penetration Testing, etc.). Responsibilities: Drive SDL across ITS and business segments, for ...
Primary areas of expertise are IT infrastructure and information security compliance (HIPAA, SOX, PCI, Penetration Testing, etc.). Responsibilities: Drive SDL across ITS and business segments, for ...
Primary areas of expertise are IT infrastructure and information security compliance (HIPAA, SOX, PCI, Penetration Testing, etc.). Responsibilities: • Drive SDL across ITS and business segments ...
Primary areas of expertise are IT infrastructure and information security compliance (HIPAA, SOX, PCI, Penetration Testing, etc.). Responsibilities: • Drive SDL across ITS and business segments ...
Security Analyst
Morrisville, NC · On-site
Remediation status reports Penetration Testing Remediation Support Serve as the primary coordinator for annual penetration testing activities. Responsibilities include: * Coordinating testing ...
Security Analyst
Morrisville, NC · On-site
Remediation status reports Penetration Testing Remediation Support Serve as the primary coordinator for annual penetration testing activities. Responsibilities include: * Coordinating testing ...
Remediation status reports Penetration Testing Remediation Support Serve as the primary coordinator for annual penetration testing activities. Responsibilities include: * Coordinating testing ...
Remediation status reports Penetration Testing Remediation Support Serve as the primary coordinator for annual penetration testing activities. Responsibilities include: * Coordinating testing ...
Security Analyst
Morrisville, NC · Hybrid
Remediation status reports Penetration Testing Remediation Support Serve as the primary coordinator for annual penetration testing activities. Responsibilities include: * Coordinating testing ...
Security Analyst
Morrisville, NC · Hybrid
Remediation status reports Penetration Testing Remediation Support Serve as the primary coordinator for annual penetration testing activities. Responsibilities include: * Coordinating testing ...
... penetration testing. Plans, builds, and enhances cybersecurity technologies by baselining systems, analyzing trends, andpreparing forfuture requirements to deliver reliable, scalable, and secure ...
... penetration testing. Plans, builds, and enhances cybersecurity technologies by baselining systems, analyzing trends, andpreparing forfuture requirements to deliver reliable, scalable, and secure ...
... penetration testing for the platforms and services in scope, using structured analysis to identify and remediate significant vulnerabilities. • Integrates and configures information security ...
... penetration testing for the platforms and services in scope, using structured analysis to identify and remediate significant vulnerabilities. • Integrates and configures information security ...
Manager, Product Security Lead
Cary, NC · On-site +1
Lead, mentor, and direct a small team of offensive security specialists conducting internal penetration testing, validating findings, reviewing remediations, and coordinating follow-on testing.
Manager, Product Security Lead
Cary, NC · On-site +1
Lead, mentor, and direct a small team of offensive security specialists conducting internal penetration testing, validating findings, reviewing remediations, and coordinating follow-on testing.
Manager, Product Security Lead
Cary, NC · On-site
Lead, mentor, and direct a small team of offensive security specialists conducting internal penetration testing, validating findings, reviewing remediations, and coordinating follow-on testing.
Manager, Product Security Lead
Cary, NC · On-site
Lead, mentor, and direct a small team of offensive security specialists conducting internal penetration testing, validating findings, reviewing remediations, and coordinating follow-on testing.
Penetration Tester information
See Raleigh, NC salary details
$21.9K - $34.8K
0% of jobs
$34.8K - $47.7K
0% of jobs
$47.7K - $60.6K
2% of jobs
$60.6K - $73.5K
3% of jobs
$73.5K - $86.4K
1% of jobs
$98.3K is the 25th percentile. Wages below this are outliers.
$86.4K - $99.3K
20% of jobs
$99.3K - $112.2K
14% of jobs
The median wage is $117K / yr.
$112.2K - $125.1K
26% of jobs
$134.2K is the 75th percentile. Wages above this are outliers.
$125.1K - $138K
13% of jobs
$138K - $150.9K
13% of jobs
$150.9K - $163.8K
9% of jobs
$21.9K
$116.5K
$163.8K
How much do penetration tester jobs pay per year?
What Does a Penetration Tester Do?
As a penetration tester, your job is to test the security of a network by attempting to hack into an application, system, or computer. Penetration testing can occur in a variety of ways, from physical interaction with the machine you’re trying to hack to attacks sent over the web. Aside from helping clients test for vulnerabilities, your job also includes explaining how you got in and providing recommendations for stopping others from repeating your actions. In some cases, you may be asked to help investigate cyber crimes or explain methods and techniques in criminal trials. Success in this job is often measured by how many security holes you find and close.
What are some common challenges penetration testers face during client engagements?
What are Penetration Testers?
What is the difference between Penetration Tester vs Vulnerability Analyst?
| Aspect | Penetration Tester | Vulnerability Analyst |
|---|---|---|
| Certifications | OSCP, CEH, GPEN | CVE, CISSP, GIAC |
| Work Environment | Hands-on testing, simulated attacks | Vulnerability scanning, risk assessment |
| Employer & Industry | Cybersecurity firms, IT departments | Security teams, compliance agencies |
| Search & Comparison Intent | Understanding testing roles, skills | Identifying vulnerabilities, analysis methods |
While both roles focus on cybersecurity, a Penetration Tester actively exploits vulnerabilities to test security defenses, whereas a Vulnerability Analyst identifies and assesses weaknesses without exploiting them. Penetration Testers typically perform simulated attacks, requiring hands-on skills and certifications like OSCP or CEH. Vulnerability Analysts focus on scanning and reporting vulnerabilities, often working with tools like Nessus or Qualys. Both roles are essential for a comprehensive security strategy but differ in approach and responsibilities.
What are the key skills and qualifications needed to thrive as a Penetration Tester, and why are they important?

Full-time
Re-posted 15 days ago
Fidelity Investments rating
8.7
Based on 270 frontline employees who took The Breakroom Quiz
15th of 150 rated financial services
Job description
Position Description:
Performs security assessments of applications prior to production deployment using Static Code Analysis, dynamic testing tools, and manual techniques. Assists in establishing the strategy, policy, and standards of security for cybersecurity operations. Develop custom Python scripts to automate repetitive tasks. Defends enterprise against attacks, damage, and unauthorized access to information, data, and systems. Ensures threat and vulnerability reduction, deterrence, incident response, resiliency, and recovery policies and activities are up to date. Proactively identifies vulnerabilities in proprietary applications prior to production release and remediates identified vulnerabilities to prevent real-life cyberattacks.
Primary Responsibilities:
- Performs advanced Web application source code auditing.
- Analyzes codes, writes scripts, and exploits web vulnerabilities.
- Analyzes test results, draw conclusions from results.
- Identifies vulnerabilities by performing thorough evaluations of security vulnerabilities on Web and mobile applications.
- Collaborates with application developers to mitigate risk and improve security posture.
- Performs security testing on web and mobile applications to support production releases.
- Models potential external threats by replicating the techniques and tools used by malicious attackers.
- Prepares reports on completed assessments and present results to application owners, developers, and business unit information security teams.
- Consults with operations and software development teams to ensure potential weaknesses are addressed.
- Contributes to the research and development of tools to assist in the vulnerability discovery process.
- Keeps abreast of current cybersecurity best practices and vulnerabilities.
- Conducts peer reviews to facilitate continuous improvement across the team.
Education and Experience:
Bachelor's degree in Computer Science, Engineering, Information Technology, Information Systems, or a closely related field (or foreign education equivalent) and five (5) years of experience as a Principal, Cybersecurity Penetration Tester (or closely related occupation) performing black and white box testing to protect against cyber threats and ensure application security (web, mobile, API, and thick client).
Or, alternatively, Master's degree in Computer Science, Engineering, Information Technology, Information Systems, or a closely related field (or foreign education equivalent) and three (3) years of experience as a Principal, Cybersecurity Penetration Tester (or closely related occupation) performing black and white box testing to protect against cyber threats and ensure application security (web, mobile, API, and thick client).
Skills and Knowledge:
Candidate must also possess:
- Demonstrated Expertise ("DE") estimating risks on security flaws uncovered during static or dynamic analysis in line with the OWASP testing guide; conducting pen-testing on applications to uncover security vulnerabilities - Injection attacks, Server-side attacks, Privilege escalation, GraphQL batching attacks, or JWT signature manipulation attacks - using BurpSuite Professional Edition, Fiddler, Kali Linux, and SQLMap.
- DE analyzing source code for security weaknesses, writing custom scripts, exploiting security vulnerabilities, and conducting retests to determine mitigation measures implemented by development teams, through a combination of manual analysis by using BurpSuite Professional, and automated scans using GitHub Advanced Security(GHAS) and MEND.
- DE analyzing Common Vulnerability Exposure (CVE) on third party libraries, using Veracode SCA, MEND, Exploit-DB, and NVD databases; and coordinating actions associated with the dismissal or reopening of policy violation alerts related to security, licensing, and coding standards using GitHub Advanced Security (GHAS).
- DE crafting custom scripts to effectively automate labor-intensive manual tasks (logging security findings, preparing weekly status reports, verifying artifact correctness) and empower the efficient allocation of resources, enhancing the overall security assessment process, using Python or Selenium.
#PE1M2
#LI-DNI
Certifications:Category:Information TechnologyPlease be advised that Fidelity's business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.
What Fidelity Investments employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Fidelity
Sourced by ZipRecruiter