1

Penetration Tester Jobs in Raleigh, NC (NOW HIRING)

Lead, mentor, and direct a small team of offensive security specialists conducting internal penetration testing, validating findings, reviewing remediations, and coordinating follow-on testing.

Lead, mentor, and direct a small team of offensive security specialists conducting internal penetration testing, validating findings, reviewing remediations, and coordinating follow-on testing.

Build and maintain documentation in support of vulnerability management, penetration testing, and incident response programs. * Collaborate with the Government, Risk, and Compliance team to enhance ...

New

Build and maintain documentation in support of vulnerability management, penetration testing, and incident response programs. * Collaborate with the Government, Risk, and Compliance team to enhance ...

Senior API Security Engineer

Raleigh, NC · On-site

$111K - $152K/yr

Performs security testing, and penetration testing tasks for assigned platforms and services, using defined methods to identify and remediate vulnerabilities. * Develop risk-based remediation ...

As a member of the Information Security leadership team, you will lead security architecture, risk remediation, threat intelligence, vulnerability & penetration testing, and control design across ...

Showing results 21-40

Penetration Tester information

See Raleigh, NC salary details

$21.9K

$116.5K

$163.8K

How much do penetration tester jobs pay per year?

As of Aug 8, 2026, the average yearly pay for penetration tester in Raleigh, NC is $116,541.00, according to ZipRecruiter salary data. Most workers in this role earn between $93,300.00 and $137,100.00 per year, depending on experience, location, and employer.

What does a penetration tester do?

As a penetration tester, your job is to test the security of a network by attempting to hack into an application, system, or computer. Penetration testing can occur in a variety of ways, from physical interaction with the machine you’re trying to hack to attacks sent over the web. Aside from helping clients test for vulnerabilities, your job also includes explaining how you got in and providing recommendations for stopping others from repeating your actions. In some cases, you may be asked to help investigate cyber crimes or explain methods and techniques in criminal trials. Success in this job is often measured by how many security holes you find and close.

What are some common challenges penetration testers face during client engagements?

Penetration testers often encounter challenges such as limited access to information, strict time constraints, and navigating complex or legacy systems. Additionally, they must balance thorough testing with minimizing disruptions to client operations. Effective communication is crucial, as testers need to clearly document findings and explain technical vulnerabilities to non-technical stakeholders to ensure remediation efforts are understood and prioritized.

What is a penetration tester?

Penetration Testers, also known as ethical hackers, are cybersecurity professionals who simulate cyberattacks on computer systems, networks, or applications to identify and address security vulnerabilities. Their work helps organizations discover weak points before malicious hackers can exploit them. Penetration testers use a variety of tools and techniques to mimic real-world threats and provide detailed reports with recommendations for improving security. They play a crucial role in maintaining the safety and integrity of an organization’s digital assets.

What is the difference between Penetration Tester vs Vulnerability Analyst?

AspectPenetration TesterVulnerability Analyst
CertificationsOSCP, CEH, GPENCVE, CISSP, GIAC
Work EnvironmentHands-on testing, simulated attacksVulnerability scanning, risk assessment
Employer & IndustryCybersecurity firms, IT departmentsSecurity teams, compliance agencies
Search & Comparison IntentUnderstanding testing roles, skillsIdentifying vulnerabilities, analysis methods

While both roles focus on cybersecurity, a Penetration Tester actively exploits vulnerabilities to test security defenses, whereas a Vulnerability Analyst identifies and assesses weaknesses without exploiting them. Penetration Testers typically perform simulated attacks, requiring hands-on skills and certifications like OSCP or CEH. Vulnerability Analysts focus on scanning and reporting vulnerabilities, often working with tools like Nessus or Qualys. Both roles are essential for a comprehensive security strategy but differ in approach and responsibilities.

What are the key skills and qualifications needed to thrive as a penetration tester, and why are they important?

To thrive as a Penetration Tester, you need a solid understanding of networking, operating systems, cybersecurity principles, and typically hold certifications like OSCP or CEH. Proficiency with tools such as Metasploit, Burp Suite, Nmap, and Wireshark is crucial for identifying and exploiting vulnerabilities. Strong analytical thinking, attention to detail, and clear communication skills help Penetration Testers effectively document findings and convey risks to clients. These skills and qualities are vital for uncovering security weaknesses and helping organizations strengthen their defenses against cyber threats.
What are the most commonly searched types of Penetration Tester jobs in Raleigh, NC? The most popular types of Penetration Tester jobs in Raleigh, NC are:
What are popular job titles related to Penetration Tester jobs in Raleigh, NC? For Penetration Tester jobs in Raleigh, NC, the most frequently searched job titles are:
What job categories do people searching Penetration Tester jobs in Raleigh, NC look for? The top searched job categories for Penetration Tester jobs in Raleigh, NC are:
What cities near Raleigh, NC are hiring for Penetration Tester jobs? Cities near Raleigh, NC with the most Penetration Tester job openings:
Infographic showing various Penetration Tester job openings in Raleigh, NC as of August 2026, with employment types broken down into 80% Full Time, and 20% Part Time. Highlights an 84% In-person, and 16% Remote job distribution, with an average salary of $116,541 per year, or $56 per hour.

Full-time

Re-posted 22 days ago


Job description

Computer World Services (CWS) is seeking an experienced Security Analyst to support enterprise cybersecurity operations within a Federal IT environment. The Security Analyst will be responsible for administering and maintaining security technologies, identifying and mitigating vulnerabilities, supporting vulnerability management initiatives, and serving as a technical advisor to infrastructure and application teams.

The successful candidate will possess strong experience with vulnerability management, firewall administration, security monitoring, and Federal cybersecurity compliance. This individual will work closely with infrastructure engineers, application developers, and security stakeholders to improve the organization's security posture while ensuring compliance with NIST, FISMA, NIH/HHS, and other Federal security requirements.

Key Tasks & Responsibilities

Essential Duties and Responsibilities

Vulnerability Management

  • Serve as the primary administrator for Tenable Security Center (SC) and Nessus vulnerability scanners.
  • Perform authenticated and unauthenticated vulnerability scans across enterprise systems.
  • Analyze scan results and prioritize remediation activities using CVSS scores, CISA Known Exploited Vulnerabilities (KEV), and organizational risk criteria.
  • Produce recurring vulnerability reports for management, system owners, and compliance activities.
  • Track remediation progress and validate vulnerability closures.
  • Manage vulnerability waivers, risk acceptance documentation, and exception tracking.
  • Monitor End-of-Life (EOL), End-of-Support (EOS), and Binding Operational Directive (BOD) vulnerability requirements.
  • Coordinate with stakeholders across technical teams to drive timely vulnerability remediation efforts.

Security Operations

  • Experience with:
    • Firewall Management
      • Cisco
      • Checkpoint
    • IDS/IPS technologies
    • Log aggregation systems (Splunk)
    • File integrity monitoring solutions
    • Red Hat Linux
    • Windows workstation and server OS
    • MacOS
  • Participate in incident investigations and support cybersecurity response activities.
  • Assist with security assessments and continuous monitoring activities.

Application & Infrastructure Security

  • Perform application vulnerability scanning.
  • Coordinate vulnerability remediation with application owners.
  • Support troubleshooting for application security issues.
  • Partner with the Application Development team to identify security improvements throughout the software lifecycle.

Compliance & Reporting

Support organizational compliance initiatives including:

  • NIST 800-53
  • FISMA
  • NIH/HHS cybersecurity policies
  • CISA Binding Operational Directives (BODs)
  • Continuous Monitoring (ConMon)

Prepare:

  • Executive vulnerability reports
  • Compliance dashboards
  • Monthly security metrics
  • Remediation status reports

Penetration Testing Remediation Support

Serve as the primary coordinator for annual penetration testing activities.

Responsibilities include:

  • Coordinating testing schedules
  • Supporting external penetration testing teams
  • Managing findings
  • Tracking remediation efforts
  • Validating corrective actions
  • Producing final response documentation

Operational Support

Provide day-to-day operational cybersecurity support including:

  • Customer requests
  • Security consultations
  • Incident investigations
  • Security engineering support
  • Technical documentation

Security Frameworks

Working knowledge of:

  • NIST 800-53
  • NIST Cybersecurity Framework (CSF)
  • Risk Management Framework (RMF)
  • FISMA
  • CISA Binding Operational Directives (BODs)
  • Continuous Monitoring (ConMon)
Education & Experience

Education

  • Bachelor's degree in Computer Science, Information Systems, Engineering, or related field. Equivalent experience.

Experience

  • 5-8 years of experience in information security, network security, or related fields.
Experience working in Data Center or hybrid infrastructure environments  
Certifications

One or more of the following preferred:

  • CompTIA Security+
  • Tenable Certified Professional (TCP) 
  • ITIL certification preferred.
Security Clearance
  • Applicants must be able to obtain a Public Trust clearance
Computer World Services is an affirmative action and equal employment opportunity employer. Current employees and/or qualified applicants will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, disability, protected veteran status, genetic information or any other characteristic protected by local, state, or federal laws, rules, or regulations.
Computer World Services is committed to the full inclusion of all qualified individuals. As part of this commitment, Computer World Services will ensure that individuals with disabilities (IWD) are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact Human Resources at [email protected]. 
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
apply for this job