1

Penetration Tester Jobs in Remote, OR (NOW HIRING)

Partner with engineering teams to implement security testing practices, including SAST, DAST, SCA, penetration testing, and automated security controls within development pipelines. * Support ...

... penetration and long-term agreements. * Lead specification activities by partnering with OEM ... Act as a technical-commercial partner, supporting testing, validation, and optimization of rope ...

... penetration and long-term agreements. * Lead specification activities by partnering with OEM ... Act as a technical-commercial partner, supporting testing, validation, and optimization of rope ...

Penetration Tester information

See Remote, OR salary details

$22.5K

$119.8K

$168.3K

How much do penetration tester jobs pay per year?

As of Aug 17, 2026, the average yearly pay for penetration tester in Remote, OR is $119,777.00, according to ZipRecruiter salary data. Most workers in this role earn between $95,900.00 and $140,900.00 per year, depending on experience, location, and employer.

What is a penetration tester?

Penetration Testers, also known as ethical hackers, are cybersecurity professionals who simulate cyberattacks on computer systems, networks, or applications to identify and address security vulnerabilities. Their work helps organizations discover weak points before malicious hackers can exploit them. Penetration testers use a variety of tools and techniques to mimic real-world threats and provide detailed reports with recommendations for improving security. They play a crucial role in maintaining the safety and integrity of an organization’s digital assets.

What does a penetration tester do?

As a penetration tester, your job is to test the security of a network by attempting to hack into an application, system, or computer. Penetration testing can occur in a variety of ways, from physical interaction with the machine you’re trying to hack to attacks sent over the web. Aside from helping clients test for vulnerabilities, your job also includes explaining how you got in and providing recommendations for stopping others from repeating your actions. In some cases, you may be asked to help investigate cyber crimes or explain methods and techniques in criminal trials. Success in this job is often measured by how many security holes you find and close.

What are the key skills and qualifications needed to thrive as a penetration tester, and why are they important?

To thrive as a Penetration Tester, you need a solid understanding of networking, operating systems, cybersecurity principles, and typically hold certifications like OSCP or CEH. Proficiency with tools such as Metasploit, Burp Suite, Nmap, and Wireshark is crucial for identifying and exploiting vulnerabilities. Strong analytical thinking, attention to detail, and clear communication skills help Penetration Testers effectively document findings and convey risks to clients. These skills and qualities are vital for uncovering security weaknesses and helping organizations strengthen their defenses against cyber threats.

What are some common challenges penetration testers face during client engagements?

Penetration testers often encounter challenges such as limited access to information, strict time constraints, and navigating complex or legacy systems. Additionally, they must balance thorough testing with minimizing disruptions to client operations. Effective communication is crucial, as testers need to clearly document findings and explain technical vulnerabilities to non-technical stakeholders to ensure remediation efforts are understood and prioritized.

What is the difference between Penetration Tester vs Vulnerability Analyst?

AspectPenetration TesterVulnerability Analyst
CertificationsOSCP, CEH, GPENCVE, CISSP, GIAC
Work EnvironmentHands-on testing, simulated attacksVulnerability scanning, risk assessment
Employer & IndustryCybersecurity firms, IT departmentsSecurity teams, compliance agencies
Search & Comparison IntentUnderstanding testing roles, skillsIdentifying vulnerabilities, analysis methods

While both roles focus on cybersecurity, a Penetration Tester actively exploits vulnerabilities to test security defenses, whereas a Vulnerability Analyst identifies and assesses weaknesses without exploiting them. Penetration Testers typically perform simulated attacks, requiring hands-on skills and certifications like OSCP or CEH. Vulnerability Analysts focus on scanning and reporting vulnerabilities, often working with tools like Nessus or Qualys. Both roles are essential for a comprehensive security strategy but differ in approach and responsibilities.

What are the most commonly searched types of Penetration Tester jobs in Remote, OR?

The most popular types of Penetration Tester jobs in Remote, OR are:

What are popular job titles related to Penetration Tester jobs in Remote, OR?

For Penetration Tester jobs in Remote, OR, the most frequently searched job titles are:

What job categories do people searching Penetration Tester jobs in Remote, OR look for?

The top searched job categories for Penetration Tester jobs in Remote, OR are:

What cities near Remote, OR are hiring for Penetration Tester jobs?

Cities near Remote, OR with the most Penetration Tester job openings:

Infographic showing various Penetration Tester job openings in Remote, OR as of August 2026, with employment types broken down into 77% Full Time, 11% Part Time, and 12% Contract. Highlights an 73% In-person, and 27% Remote job distribution, with an average salary of $119,777 per year, or $57.6 per hour.

Product Cybersecurity Architect

Bausch + Lomb

OR • On-site, Remote

Full-time

Dental, Vision, Life, Retirement, PTO

Re-posted 6 days ago


Bausch & Lomb rating

8.6

Company rating: 8.6 out of 10

Based on 39 frontline employees who took The Breakroom Quiz

22nd of 540 rated manufacturers


Job description

Bausch + Lomb (NYSE/TSX: BLCO) is a leading global eye health company dedicated to protecting and enhancing the gift of sight for millions of people around the world-from the moment of birth through every phase of life. Our mission is simple, yet powerful: helping you see better, to live better.
Our comprehensive portfolio of over 400 products is fully integrated and built to serve our customers across the full spectrum of their eye health needs throughout their lives. Our iconic brand is built on the deep trust and loyalty of our customers established over our 170-year history. We have a significant global research, development, manufacturing and commercial footprint of approximately 13,000 employees and a presence in approximately 100 countries, extending our reach to billions of potential customers across the globe. We have long been associated with many of the most significant advances in eye health, and we believe we are well positioned to continue leading the advancement of eye health in the future.
Why this Role Matters
Join the Surgical R&D organization in a role where you will help ensure the cybersecurity, safety, and reliability of innovative surgical products that support patient care. In this position, you will be responsible for embedding secure-by-design practices throughout the product lifecycle while partnering with engineering, quality, regulatory, and corporate security teams to deliver compliant and resilient solutions. This is a strong opportunity for someone who brings deep product security expertise, strong cross-functional collaboration skills, and a passion for advancing cybersecurity within a regulated medical device environment.
What You'll Do
  • Architect and implement a consistent cybersecurity strategy across surgical capital equipment product lines to establish a scalable and secure product ecosystem.
  • Embed secure-by-design principles throughout the product lifecycle, providing guidance on secure architecture, threat modeling, design controls, cryptography, and secure communication protocols.
  • Lead execution of cybersecurity requirements across development programs, ensuring alignment with regulatory expectations, corporate standards, and product quality objectives.
  • Coordinate vulnerability management activities, including intake, triage, risk assessment, remediation tracking, and documentation of product security issues through closure.
  • Serve as the Surgical R&D cybersecurity representative for vulnerability disclosure and incident response activities, supporting investigations, impact assessments, root cause analyses, and remediation efforts.
  • Partner with engineering teams to implement security testing practices, including SAST, DAST, SCA, penetration testing, and automated security controls within development pipelines.
  • Support supplier and third-party security initiatives by defining security requirements, managing software supply chain risks, and maintaining Software Bill of Materials (SBOM) processes.
  • Collaborate with Quality, Regulatory Affairs, IT, and Corporate Product Security teams to ensure compliance with evolving cybersecurity regulations and industry standards while enabling efficient product delivery.

What You'll Bring
Required Education & Experience:
  • Bachelor's degree in Engineering, Computer Science, Cybersecurity, or a related technical discipline.
  • 7+ years of experience in product security, application security, medical device cybersecurity, or software security within a regulated environment.
  • Demonstrated experience supporting or leading cybersecurity activities for medical device or other regulated product development programs.
  • Strong communication, collaboration, stakeholder management, and problem-solving skills.
  • Ability to translate technical cybersecurity risks into clear, actionable guidance for engineering, quality, and regulatory stakeholders.

Specialized Technical, Regulatory & Industry Skills & Knowledge
  • Strong expertise in secure product design, threat modeling, vulnerability management, and secure software development practices.
  • Working knowledge of connected device security, embedded systems, and software-enabled product architectures.
  • Experience with security testing tools and methodologies, including SAST, DAST, SCA, and penetration testing.
  • Understanding of software supply chain security practices, including SBOM development and third-party risk management.
  • Experience working across cross-functional and global teams to drive cybersecurity outcomes and influence stakeholders without direct authority.
  • Knowledge of secure development lifecycle (SDLC) frameworks, vulnerability disclosure processes, and product incident response activities.
  • Familiarity with cybersecurity governance, risk assessment, and compliance processes within regulated industries.

Preferred
  • Advanced degree in Cybersecurity, Computer Science, Engineering, or a related field.
  • Relevant industry certifications such as CISSP, CSSLP, OSCP, GWAPT, or equivalent.
  • Experience in medical device, healthcare, or other regulated industries, and/or working within a quality-managed or GxP regulated environment.
  • Working knowledge of medical device cybersecurity regulations and standards (e.g., FDA premarket/post market guidance, IEC 81001-5-1, AAMI TIR57, UL 2900, NIST frameworks).
  • Experience developing cybersecurity documentation to support regulatory submissions and audits.

This position may be available in the following location(s): US - Remote
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
For U.S. locations that require disclosure of compensation, the starting pay for this role is between $140,000 and $180,000. The estimated salary range reflects an anticipated range for this position. The actual base salary offered may depend on a variety of factors.
U.S. based employees may be eligible for short-term and/or long-term incentives. They may also be eligible to participate in medical, dental, vision insurance, disability and life insurance, a 401(k) plan and company match, a tuition reimbursement program (select degrees), company holidays, and well-being benefits, among others. U.S. based employees are also eligible to receive sick time, floating holidays and paid vacation.
Job Applicants should be aware of job offer scams perpetrated through the use of the Internet and social media platforms.
To learn more please read Bausch + Lomb's Job Offer Fraud Statement.
Applicants must be authorized to work for ANY employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa at this time.

What Bausch & Lomb employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Bausch & Lomb logo

About Bausch & Lomb

Sourced by ZipRecruiter

Bausch + Lomb (NYSE/TSX: BLCO) is a leading global eye health company dedicated to protecting and enhancing the gift of sight for millions of people around the world--from the moment of birth through every phase of life. Our mission is simple, yet powerful: helping you see better, to live better. Our comprehensive portfolio of over 400 products is fully integrated and built to serve our customers across the full spectrum of their eye health needs throughout their lives. Our iconic brand is built on the deep trust and loyalty of our customers established over our nearly 170-year history. We have a significant global research, development, manufacturing and commercial footprint of approximately 12,500 employees and a presence in approximately 100 countries, extending our reach to billions of potential customers across the globe. We have long been associated with many of the most significant advances in eye health, and we believe we are well positioned to continue leading the advancement of eye health in the future.

Industry

Medical equipment and supplies manufacturing

Company size

10,000+ Employees

Headquarters location

Bridgewater, NJ, US

Year founded

1853