1

Penetration Tester Jobs in Riverside, CA (NOW HIRING)

Security Engineer - Application Security

Ontario, CA · On-site

$59.75 - $79.75/hr

Triage programmatic source code findings and automate penetration testing to decrease potential introduction of vulnerabilities * Lead and collaborate with developers on secure coding techniques and ...

Perform application layer security reviews of the code developed by our application teams, across multiple languages and frameworks used internally * Assist with application layer penetration testing ...

Sr. Application Security Engineer

Redlands, CA · On-site

$59 - $79/hr

Required : • 5+ years of experience in application security, including manual and automated code reviews, manual penetration testing, dynamic application security testing, and false positive ...

next page

Showing results 1-20

Penetration Tester information

See Riverside, CA salary details

$23.5K

$125.1K

$175.8K

How much do penetration tester jobs pay per year?

As of Aug 8, 2026, the average yearly pay for penetration tester in Riverside, CA is $125,082.00, according to ZipRecruiter salary data. Most workers in this role earn between $100,200.00 and $147,100.00 per year, depending on experience, location, and employer.

What does a penetration tester do?

As a penetration tester, your job is to test the security of a network by attempting to hack into an application, system, or computer. Penetration testing can occur in a variety of ways, from physical interaction with the machine you’re trying to hack to attacks sent over the web. Aside from helping clients test for vulnerabilities, your job also includes explaining how you got in and providing recommendations for stopping others from repeating your actions. In some cases, you may be asked to help investigate cyber crimes or explain methods and techniques in criminal trials. Success in this job is often measured by how many security holes you find and close.

What are some common challenges penetration testers face during client engagements?

Penetration testers often encounter challenges such as limited access to information, strict time constraints, and navigating complex or legacy systems. Additionally, they must balance thorough testing with minimizing disruptions to client operations. Effective communication is crucial, as testers need to clearly document findings and explain technical vulnerabilities to non-technical stakeholders to ensure remediation efforts are understood and prioritized.

What is a penetration tester?

Penetration Testers, also known as ethical hackers, are cybersecurity professionals who simulate cyberattacks on computer systems, networks, or applications to identify and address security vulnerabilities. Their work helps organizations discover weak points before malicious hackers can exploit them. Penetration testers use a variety of tools and techniques to mimic real-world threats and provide detailed reports with recommendations for improving security. They play a crucial role in maintaining the safety and integrity of an organization’s digital assets.

What is the difference between Penetration Tester vs Vulnerability Analyst?

AspectPenetration TesterVulnerability Analyst
CertificationsOSCP, CEH, GPENCVE, CISSP, GIAC
Work EnvironmentHands-on testing, simulated attacksVulnerability scanning, risk assessment
Employer & IndustryCybersecurity firms, IT departmentsSecurity teams, compliance agencies
Search & Comparison IntentUnderstanding testing roles, skillsIdentifying vulnerabilities, analysis methods

While both roles focus on cybersecurity, a Penetration Tester actively exploits vulnerabilities to test security defenses, whereas a Vulnerability Analyst identifies and assesses weaknesses without exploiting them. Penetration Testers typically perform simulated attacks, requiring hands-on skills and certifications like OSCP or CEH. Vulnerability Analysts focus on scanning and reporting vulnerabilities, often working with tools like Nessus or Qualys. Both roles are essential for a comprehensive security strategy but differ in approach and responsibilities.

What are the key skills and qualifications needed to thrive as a penetration tester, and why are they important?

To thrive as a Penetration Tester, you need a solid understanding of networking, operating systems, cybersecurity principles, and typically hold certifications like OSCP or CEH. Proficiency with tools such as Metasploit, Burp Suite, Nmap, and Wireshark is crucial for identifying and exploiting vulnerabilities. Strong analytical thinking, attention to detail, and clear communication skills help Penetration Testers effectively document findings and convey risks to clients. These skills and qualities are vital for uncovering security weaknesses and helping organizations strengthen their defenses against cyber threats.
What are the most commonly searched types of Penetration Tester jobs in Riverside, CA? The most popular types of Penetration Tester jobs in Riverside, CA are:
What are popular job titles related to Penetration Tester jobs in Riverside, CA? For Penetration Tester jobs in Riverside, CA, the most frequently searched job titles are:
What job categories do people searching Penetration Tester jobs in Riverside, CA look for? The top searched job categories for Penetration Tester jobs in Riverside, CA are:
What cities near Riverside, CA are hiring for Penetration Tester jobs? Cities near Riverside, CA with the most Penetration Tester job openings:
Infographic showing various Penetration Tester job openings in Riverside, CA as of August 2026, with employment types broken down into 78% Full Time, and 22% Part Time. Highlights an 84% In-person, and 16% Remote job distribution, with an average salary of $125,082 per year, or $60.1 per hour.

External Network Penetration Tester

Xtreme Solutions Corporate

San Bernardino, CA • On-site

Full-time

Posted 7 days ago


Job description

Description:

Position Summary

Performs blind and intelligent penetration testing against internet-facing assets — web applications, firewalls, remote access (VPN/RDP), and internet postings — for all 47 County departments, attempting to obtain confidential/sensitive data using real-world threat intelligence-based techniques while evading detection.


Key Responsibilities

• Conduct external network and web application penetration testing and vulnerability assessments per NIST SP 800-115 methodology.

• Attempt to obtain ePHI, PII, financial data, and privileged communications from external sources without causing service disruption.

• Document all findings with risk ratings, evidence, and remediation recommendations for the Assessment report.

• Attempt to avoid detection and evade department response efforts during testing windows, as scoped.

Requirements:

Required Qualifications

• 4+ years of hands-on external network / web application penetration testing experience.

• Proficiency with industry-standard tools (Burp Suite, Nmap, Metasploit, or equivalent).

• Strong understanding of OWASP Top 10 and common network attack vectors.


Preferred Qualifications

• OSCP, GPEN, GWAPT, or CEH certification.

• Experience testing government or healthcare-sector environments.


Travel

Fully remote; must remain within the continental United States.