1

Penetration Tester Jobs (NOW HIRING)

SkyePoint Decisions is seeking a Penetration Tester to support the Diplomatic Security Cyber Mission (DSCM) program providing leading cyber and technology security experience to enable innovative ...

Responsibilities Peraton is seeking an experienced Cyber Penetration Tester to become part of Peratons' Federal Strategic Cyber programs. Location: Northern VA; Hybrid - flex as long as person can ...

Penetration Tester

Arlington, VA · On-site

$86K - $138K/yr

Responsibilities Peraton is seeking an experienced Cyber Penetration Tester to become part of Peratons' Federal Strategic Cyber programs. Location: Northern VA; Hybrid - flex as long as person can ...

Penetration Tester

Chantilly, VA · On-site

$150K - $195K/yr

Overview VTG is looking for multiple levels (Level 2, 3 & 4) of a Penetration Tester in Chantilly VA and Aurora CO. (Note: position is contingent upon program award and the postions are located in ...

Penetration Tester

Arlington, VA · On-site

$86K - $138K/yr

Responsibilities Peraton is seeking an experienced Cyber Penetration Tester to become part of Peratons' Federal Strategic Cyber programs. Location: Northern VA; Hybrid - flex as long as person can ...

Penetration Tester Location: Reston, VA Work Mode - Hybrid role, 2 days' Work from Office (Wednesday and Thursday) Must have Skill Set - Red team pentester * Network penetration testing and ...

Penetration Tester

Washington, DC · Hybrid

$130K - $145K/yr

Penetration Tester Washington DC Metro Area Dark Wolf is actively seeking an experienced Penetration Tester to join our innovative team. This individual will play a critical role in assessing and ...

Penetration Tester

Arlington, VA · On-site

$86K - $138K/yr

Responsibilities Peraton is seeking an experienced Cyber Penetration Tester to become part of Peratons' Federal Strategic Cyber programs. Location: Northern VA; Hybrid - flex as long as person can ...

Responsibilities Peraton is seeking an experienced Cyber Penetration Tester to become part of Peratons' Federal Strategic Cyber programs. Location: Northern VA; Hybrid - flex as long as person can ...

Overview VTG is looking for multiple levels (Level 2, 3 & 4) of a Penetration Tester in Chantilly VA and Aurora CO. (Note: position is contingent upon program award and the postions are located in ...

Penetration Tester Location: Arlington, VA Security Clearance:Secret Duties and Responsibilities The Penetration Tester supports this Transportation Security Administration Information Technology ...

Penetration Tester

Washington, DC · Hybrid

$130K - $145K/yr

Dark Wolf is actively seeking an experienced Penetration Tester to join our innovative team. This individual will play a critical role in assessing and enhancing the security of various products ...

Penetration Tester

Washington, DC · On-site

$130K - $145K/yr

Dark Wolf is actively seeking an experienced Penetration Tester to join our innovative team. This individual will play a critical role in assessing and enhancing the security of various products ...

Penetration Tester

Aberdeen, MD · On-site

$173K/yr

Penetration Tester Job Category: Information Technology Time Type: Full time Minimum Clearance Required to Start: Secret Employee Type: Regular Percentage of Travel Required: Up to 25% Type of Travel:

Penetration Tester Immediate need for a talented Penetration Tester. This is a 06+ Months Contract opportunity with long-term potential and is located in Johns Creek, GA (Hybrid). Please review the ...

Penetration Tester Exciting opportunity: join our dynamic team of penetration testers! Embark on an exhilarating journey with us as you join a vibrant team dedicated to solving intricate, multi ...

next page

Showing results 1-20

Penetration Tester information

See salary details

$22.5K

$119.9K

$168.5K

How much do penetration tester jobs pay per year?

As of Jun 15, 2026, the average yearly pay for penetration tester in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What qualifications does a penetration tester need?

A penetration tester typically needs a strong understanding of computer networks, operating systems, and security principles. Relevant certifications such as Certified Ethical Hacker (CEH) or Offensive Security Certified Professional (OSCP) are highly valued, along with experience in scripting, vulnerability assessment tools, and ethical hacking practices.

What Does a Penetration Tester Do?

As a penetration tester, your job is to test the security of a network by attempting to hack into an application, system, or computer. Penetration testing can occur in a variety of ways, from physical interaction with the machine you’re trying to hack to attacks sent over the web. Aside from helping clients test for vulnerabilities, your job also includes explaining how you got in and providing recommendations for stopping others from repeating your actions. In some cases, you may be asked to help investigate cyber crimes or explain methods and techniques in criminal trials. Success in this job is often measured by how many security holes you find and close.

What are some common challenges penetration testers face during client engagements?

Penetration testers often encounter challenges such as limited access to information, strict time constraints, and navigating complex or legacy systems. Additionally, they must balance thorough testing with minimizing disruptions to client operations. Effective communication is crucial, as testers need to clearly document findings and explain technical vulnerabilities to non-technical stakeholders to ensure remediation efforts are understood and prioritized.

What are Penetration Testers?

Penetration Testers, also known as ethical hackers, are cybersecurity professionals who simulate cyberattacks on computer systems, networks, or applications to identify and address security vulnerabilities. Their work helps organizations discover weak points before malicious hackers can exploit them. Penetration testers use a variety of tools and techniques to mimic real-world threats and provide detailed reports with recommendations for improving security. They play a crucial role in maintaining the safety and integrity of an organization’s digital assets.

Is penetration tester a good career?

A penetration tester is a cybersecurity professional who assesses computer systems and networks for vulnerabilities using tools like Kali Linux and Metasploit. The role offers high demand, competitive salaries, and opportunities for specialization and certification, making it a strong career choice in cybersecurity.

Can I make $200 a year in cyber security?

A penetration tester's salary typically exceeds $200 annually, with entry-level roles starting around $50,000 and experienced professionals earning over $100,000 per year. Achieving higher salaries often requires relevant certifications, technical skills, and experience in security tools and methodologies.

What is the difference between Penetration Tester vs Vulnerability Analyst?

AspectPenetration TesterVulnerability Analyst
CertificationsOSCP, CEH, GPENCVE, CISSP, GIAC
Work EnvironmentHands-on testing, simulated attacksVulnerability scanning, risk assessment
Employer & IndustryCybersecurity firms, IT departmentsSecurity teams, compliance agencies
Search & Comparison IntentUnderstanding testing roles, skillsIdentifying vulnerabilities, analysis methods

While both roles focus on cybersecurity, a Penetration Tester actively exploits vulnerabilities to test security defenses, whereas a Vulnerability Analyst identifies and assesses weaknesses without exploiting them. Penetration Testers typically perform simulated attacks, requiring hands-on skills and certifications like OSCP or CEH. Vulnerability Analysts focus on scanning and reporting vulnerabilities, often working with tools like Nessus or Qualys. Both roles are essential for a comprehensive security strategy but differ in approach and responsibilities.

Will pentesters be replaced by AI?

Penetration testers perform manual security assessments that require critical thinking, creativity, and understanding of complex systems, which AI currently cannot fully replicate. While AI tools can assist in automating certain tasks like vulnerability scanning, human expertise remains essential for interpreting results and developing effective security strategies.

What are the key skills and qualifications needed to thrive as a Penetration Tester, and why are they important?

To thrive as a Penetration Tester, you need a solid understanding of networking, operating systems, cybersecurity principles, and typically hold certifications like OSCP or CEH. Proficiency with tools such as Metasploit, Burp Suite, Nmap, and Wireshark is crucial for identifying and exploiting vulnerabilities. Strong analytical thinking, attention to detail, and clear communication skills help Penetration Testers effectively document findings and convey risks to clients. These skills and qualities are vital for uncovering security weaknesses and helping organizations strengthen their defenses against cyber threats.
What cities are hiring for Penetration Tester jobs? Cities with the most Penetration Tester job openings:
What are the most commonly searched types of Penetration Tester jobs? The most popular types of Penetration Tester jobs are:
Who are the top companies hiring for Penetration Tester jobs? The top employers for Penetration Tester jobs are:
What states have the most Penetration Tester jobs? States with the most job openings for Penetration Tester jobs include:
Penetration Tester

$95K - $112K/yr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 22 days ago


Job description

SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider headquartered in Dulles, Virginia with operations across the U.S. We provide innovative enterprise-wide solutions as well as targeted services addressing the complex challenges faced by our federal government clients. Our focus is on enabling our clients to deliver their mission most efficiently and effectively - anytime, anywhere, securely. We combine technical expertise, mission awareness, and an empowered workforce to produce meaningful results.

This is a contingent position based upon customer approval.

SkyePoint Decisions is seeking a Penetration Tester to support the Diplomatic Security Cyber Mission (DSCM) program providing leading cyber and technology security experience to enable innovative, effective, and secure business processes.

This position is located in Arlington, VA and will be onsite 5 days a week. No hybrid/telework allowed.

Responsibilities:

  • Support the Red Cell Team by performing and leading penetration tests to assess the security of customer systems.
  • Identify vulnerabilities and develop recommended remediations to satisfy mandated NIST 800-53 security controls.
  • Report and demonstrate findings to system owners and engineers.
  • Maintain Red Cell infrastructure.
  • Develop or modify tools to automate discovery or exploitation.

Required Qualifications:

  • Bachelor of Science and 5 years of relevant experience in Cyber/IT, or a Master's of Science and 3 years of relevant experience in Cyber/IT. In lieu of a degree, 4 years of additional IT security or penetration testing experience may be considered.
  • Minimum of 2 years with penetration testing experience.
  • Possess one of the following certifications, OR be able to obtain before start date:
    • CCNA Cyber Ops, CCNA-Security, CEH, CFR, Cloud+, CySA+, GCIA, GCIH, GICSP, SCYBER, Security+ CE, SSCP

  • Demonstrated experience with Kali Linux.
  • Demonstrated penetration testing tools experience with Nmap, Burp Suite, Metasploit, etc.
  • Demonstrated ability in evaluating vulnerabilities, performing root cause analysis, and reporting findings utilizing assessment methodologies such as NIST SP 800-115, Penetration Testing Execution Standard (PTES), Information Systems Security Assessment Framework (ISSAF), OWASP Web Security Testing Guide (WTG), etc.
  • Demonstrated ability to lead a penetration test and guide Senior/Junior Penetration Testers.
  • U.S. citizenship required.
  • An active Secret security clearance.
    • Must have the ability to obtain a final Top Secret security clearance.


Preferred Qualifications:

  • Active Top Secret or TS/SCI clearance.
  • One of the following certifications or an alternate, verifiable certification demonstrating IT security competence:
    • CompTIA CASP+
    • ISC2 Certified Information Security Professional (CISSP)
    • ISC2 Certified Cloud Security Professional (CCSP)
    • ISC2 Information Systems Security Engineering Professional (ISSEP)

  • One of the following certifications or an alternate, verifiable certification demonstrating practical penetration testing competence:
    • Offensive Security Certified Professional (OSCP)
    • Offensive Security Certified Professional (OSCP)
    • Hack the Box Certified Penetration Testing Specialist (CPTS)
    • TCM Security Practical Network Penetration Tester (PNPT)
    • GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)
    • Zero Point Security Red Team Ops II

  • Advanced understanding of the following:
    • NIST Risk Management Framework (RMF) and the Assessment and Authorization (A&A) process.
    • Security principles such as CIA, IAAAA, access control models, risk management, etc.
    • Networking principles and technologies such as IP routing, TCP/UDP, VPNs, firewalls, NAT, etc.
    • Common network protocols such as SSH, FTP, SMTP, SMB, HTTP, etc.
    • Operating system principles such as process management, device management, user management, file systems, etc.
    • Data processing principles such as encoding, hashing, encryption, etc.
    • Scripting and programming languages such as Bash, Python, PowerShell, JavaScript, etc.
    • Common application vulnerabilities and exploits such as outdated components,
    • permissions mis-configurations, lack of input validation, logging/monitoring failures, etc.
    • Common web application vulnerabilities and exploits such as XSS, SQLi, LFI, file uploads, broken authentication mechanisms, etc.
    • Active Directory (AD) enumeration and attacks such as kerberoasting, AS-REP roasting, abusing mis-configuredprivileges, crafting golden tickets, etc.
    • Public Key Infrastructure (PKI) and navigating IT environments implementing multifactor authentication.
    • Cloud technologies and platforms such as Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), etc.



Compensation:

Salary Range: $95,000-$112,000

The SkyePoint Decisions salary range for this position is a general guideline only. It represents an estimated range for this position and is just one piece of our total compensation package.

Salary at SkyePoint is determined by various factors, including but not limited to location, work schedule, the candidate's combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability, market data and business considerations.

In addition to a competitive salary, SkyePoint offers benefits including a certification incentive program, PTO, floating federal holiday options, several insurance options including HMO and High Deductible plans with Health Savings Accounts [HSAs], Flex Spending Accounts [FSAs], Full Dental Plans, Vision, ST/LT Disability, Life Insurance, and 401k matched.

What We Can Offer You:

  • At SkyePoint, we go B.I.G. (beginning in GRATITUDE) by recognizing all we have and giving back to our employees, families, and communities. It instills a positive mindset that permeates all we do. By beginning in gratitude, SkyePoint can continue to spread living in gratitude each day.
  • Great Benefits: Several insurance options including HMO and High Deductible plans with Health Savings Accounts [HSAs], Flex Spending Accounts [FSAs], Full Dental Plans, ST/LT Disability, Life Insurance, floating federal holiday options, and 401k matched
  • Certificate Incentive Program: To promote professional development, we recognize and reward employees who obtain new certifications aligned with business needs.
  • Flexible Work Environment

SkyePoint Decisions is an established ISO 9001:2015 and ISO/IEC 27001:2013 certified small business and appraised at CMMI Level 3 for Services and Development. We possess a common vision of excellence and foster a collaborative team culture built upon individual performance and accountability. We invest in our people and systems to create value for our clients. It is the SkyePoint Way. We are grateful for the opportunity to work with exceptional people and give back to the communities we serve. Our employees value the flexibility at SkyePoint that allows them to balance quality work and their personal lives.

SkyePoint Decisions is a participating E-Verify Employer.

U.S. Citizenship is required for most positions.

Equal Opportunity Employer/Veterans/Disabled.

CCPA Disclosure Notice Here