1

Penetration Tester Jobs (NOW HIRING)

Penetration Tester

Herndon, VA · On-site

$100K - $200K/yr

Principal Penetration Tester Altus Consulting seeks a seasoned cybersecurity professional to spearhead our penetration testing initiatives. As a key member of our elite team, you'll play a crucial ...

Penetration Tester

Beltsville, MD · On-site

$60 - $70/hr

The Judge Group is currently seeking a Penetration Tester with an active secret clearance to support a classified customer in Beltsville, MD. This position is onsite five days per week. Core ...

Penetration Tester

Alexandria, VA · On-site

$75 - $85/hr

Coordinate and conduct Agency penetration testing on systems operated by and on behalf of NCUA, ensuring access occurs only through specified authentication methods and is limited to vetted personnel.

Cymertek Corporation is seeking a highly skilled and proactive Penetration Tester to join their cybersecurity team. In this role, you will identify vulnerabilities and test the security of networks ...

Be Seen First

Penetration Tester

Knoxville, TN · Remote

$120K - $145K/yr

At Zelvin, penetration testing is not about generating a list of vulnerabilities. Our testers think like attackers, follow the evidence, challenge assumptions, and determine which weaknesses create ...

Cymertek Corporation is seeking a highly skilled and proactive Penetration Tester to join their cybersecurity team. In this role, you will identify vulnerabilities and test the security of networks ...

They are seeking a highly skilled Penetration Tester to identify vulnerabilities and test the security of networks, applications, and systems by simulating real-world attacks, while collaborating ...

Penetration Tester

Alexandria, VA · On-site

$95 - $125/hr

Xcelerate Solutions is seeking a Penetration Tester to support CyberPRIMES cybersecurity, privacy, records and information management, and related enterprise support for DHRA, including DMDC and OUSD ...

Title: Penetration Tester / Security Analyst Location: San Francisco, CA, Onsite- Relocation works Duration: 6 Months (11/24/2025 - 5/27/2026) Video Interview Summary: Looking for an experienced ...

We are seeking a skilled Penetration Tester with a focus on Java application security is sought to identify, exploit, and fix vulnerabilities in Java applications to guard against cyber threats. Key ...

The Senior Penetration Tester will independently perform penetration testing of applications, systems and enclaves Identifies security flaws in computing platforms and applications and devise ...

Cymertek Corporation is seeking a highly skilled and proactive Penetration Tester to join their cybersecurity team. In this role, you will identify vulnerabilities and test the security of networks ...

Cymertek Corporation is seeking a highly skilled and proactive Penetration Tester to join their cybersecurity team. In this role, you will identify vulnerabilities and test the security of networks ...

Be Seen First

Penetration Tester

Knoxville, TN · Remote

$120K - $145K/yr

At Zelvin, penetration testing is not about generating a list of vulnerabilities. Our testers think like attackers, follow the evidence, challenge assumptions, and determine which weaknesses create ...

Showing results 41-60

Penetration Tester information

See salary details

$22.5K

$119.9K

$168.5K

How much do penetration tester jobs pay per year?

As of Sep 5, 2026, the average yearly pay for penetration tester in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What is a penetration tester?

Penetration Testers, also known as ethical hackers, are cybersecurity professionals who simulate cyberattacks on computer systems, networks, or applications to identify and address security vulnerabilities. Their work helps organizations discover weak points before malicious hackers can exploit them. Penetration testers use a variety of tools and techniques to mimic real-world threats and provide detailed reports with recommendations for improving security. They play a crucial role in maintaining the safety and integrity of an organization’s digital assets.

What does a penetration tester do?

As a penetration tester, your job is to test the security of a network by attempting to hack into an application, system, or computer. Penetration testing can occur in a variety of ways, from physical interaction with the machine you’re trying to hack to attacks sent over the web. Aside from helping clients test for vulnerabilities, your job also includes explaining how you got in and providing recommendations for stopping others from repeating your actions. In some cases, you may be asked to help investigate cyber crimes or explain methods and techniques in criminal trials. Success in this job is often measured by how many security holes you find and close.

What are the key skills and qualifications needed to thrive as a penetration tester, and why are they important?

To thrive as a Penetration Tester, you need a solid understanding of networking, operating systems, cybersecurity principles, and typically hold certifications like OSCP or CEH. Proficiency with tools such as Metasploit, Burp Suite, Nmap, and Wireshark is crucial for identifying and exploiting vulnerabilities. Strong analytical thinking, attention to detail, and clear communication skills help Penetration Testers effectively document findings and convey risks to clients. These skills and qualities are vital for uncovering security weaknesses and helping organizations strengthen their defenses against cyber threats.

What are some common challenges penetration testers face during client engagements?

Penetration testers often encounter challenges such as limited access to information, strict time constraints, and navigating complex or legacy systems. Additionally, they must balance thorough testing with minimizing disruptions to client operations. Effective communication is crucial, as testers need to clearly document findings and explain technical vulnerabilities to non-technical stakeholders to ensure remediation efforts are understood and prioritized.

What is the difference between Penetration Tester vs Vulnerability Analyst?

AspectPenetration TesterVulnerability Analyst
CertificationsOSCP, CEH, GPENCVE, CISSP, GIAC
Work EnvironmentHands-on testing, simulated attacksVulnerability scanning, risk assessment
Employer & IndustryCybersecurity firms, IT departmentsSecurity teams, compliance agencies
Search & Comparison IntentUnderstanding testing roles, skillsIdentifying vulnerabilities, analysis methods

While both roles focus on cybersecurity, a Penetration Tester actively exploits vulnerabilities to test security defenses, whereas a Vulnerability Analyst identifies and assesses weaknesses without exploiting them. Penetration Testers typically perform simulated attacks, requiring hands-on skills and certifications like OSCP or CEH. Vulnerability Analysts focus on scanning and reporting vulnerabilities, often working with tools like Nessus or Qualys. Both roles are essential for a comprehensive security strategy but differ in approach and responsibilities.

How much do penetration testers make?

Penetration testers typically earn between $70,000 and $130,000 annually, depending on experience, certifications, and location. Senior professionals with advanced skills and certifications like OSCP or CISSP can earn higher salaries, especially in high-demand markets.

Is penetration testing a hard job?

Penetration testing can be challenging as it requires strong technical skills, problem-solving abilities, and knowledge of security vulnerabilities. The job often involves staying updated on new threats and using tools like Kali Linux and Metasploit, which can be complex for beginners. Success in this role depends on continuous learning and practical experience.

What cities are hiring for Penetration Tester jobs?

Cities with the most Penetration Tester job openings:

What are the most commonly searched types of Penetration Tester jobs?

The most popular types of Penetration Tester jobs are:

Who are the top companies hiring for Penetration Tester jobs?

The top employers for Penetration Tester jobs are:

What states have the most Penetration Tester jobs?

States with the most job openings for Penetration Tester jobs include:

Infographic showing various Penetration Tester job openings in the United States as of August 2026, with employment types broken down into 83% Full Time, 13% Part Time, and 4% Contract. Highlights an 74% In-person, 4% Hybrid, and 22% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

$100K - $200K/yr

Full-time

Re-posted 12 days ago


Job description

Principal Penetration Tester
Altus Consulting seeks a seasoned cybersecurity professional to spearhead our penetration testing initiatives. As a key member of our elite team, you'll play a crucial role in safeguarding some of the world's most critical digital infrastructure.
Core Responsibilities:
  • Design and execute sophisticated penetration tests across complex networks, systems, and applications
  • Craft compelling, actionable reports that translate technical findings into clear business impact
  • Collaborate closely with clients to develop tailored remediation strategies that drive meaningful security improvements
  • Push the boundaries of penetration testing innovation through research and development of novel TTPs
  • Contribute to Altus Consulting's thought leadership efforts via publications, presentations, and industry forums
  • Lead quality assurance initiatives for our suite of penetration testing services
  • Engage in cross-functional collaboration to enhance our overall security offerings

Ideal Candidate Profile:
We are seeking candidates with a degree in Computer Science, Computer Engineering, or a related technical field. Alternatively, we will consider individuals with equivalent professional experience that demonstrates comparable skills and knowledge.
To be considered equivalent, candidates should be able to prove or quantify their experience through:
  • Relevant work history demonstrating hands-on experience in computer science/engineering principles
  • Completed projects or certifications that align with our technical requirements
  • Demonstrated proficiency in key skills like programming languages, algorithms, software design, etc.
  • Relevant coursework or training if transitioning from another field

We value both formal education and practical experience. Candidates who can show they have acquired equivalent knowledge through non-traditional means (e.g. self-study, online courses, bootcamps) are encouraged to apply.
Applicants should be prepared to discuss their qualifications in detail during the interview process.
Key Skills to Focus On:
  • Programming languages like Python, Java, C++, Linux scripting
  • Network and application security knowledge
  • Familiarity with security assessment tools
  • Threat modeling and cryptography skills
  • Knowledge of operating systems (Windows, Linux, macOS)
  • Experience with penetration testing frameworks and tools

Highly Valued Certifications:
  • OSCP (Offensive Security Certified Professional)
  • CPTS (Certified Penetration Testing Specialist)
  • GPEN (GIAC Penetration Tester)
  • GXPN (GIAC Exploit Programmer)
  • CRTO (Certified Red Team Operator)

Additional Considerations:
  • Familiarity with emerging threats and attack vectors in cloud and containerized environments
  • Experience with automated vulnerability scanning and exploitation platforms
  • Knowledge of security frameworks and regulations relevant to commercial companies
  • Track record of contributing to open-source security projects or publishing research in the field

What We Offer:
  • Competitive compensation and benefits package
  • Opportunities for professional development
  • Collaborative, dynamic work environment
  • Chance to work on cutting-edge security challenges

About Our Team:
Altus Consulting believes it's essential to keep innovating while safeguarding our digital infrastructure. Our team ensures that we maintain a secure operating environment and preserve the trust of our customers, partners, and stakeholders. We bring together a variety of services and capabilities to help prevent fraud, detect threats, and manage digital risk and access. In addition to mitigating attack risks and securing cloud transformation, we foster in our team members a culture of innovation and reliability.
Key Campaign Activities:
  • Execute full-scale, assumed breach, and transparent/collaborative campaigns
  • Develop, curate, and leverage offensive security tooling
  • Manage and configure campaign infrastructure
  • Research and develop attacks on vulnerable systems and defensive tooling (e.g., AntiVirus, EDR, XDR)
  • Provide ongoing consulting to defense teams as they design and implement responses to campaign findings
  • We're looking for candidates who can leverage their expertise in scripting, development, attack infrastructure, social engineering, and offensive security tooling to execute simulated attacks against our clients' networks and subsidiaries spanning the globe.
  • If you're passionate about pushing the boundaries of cybersecurity and want to join a team that's reshaping how organizations defend against modern threats, we encourage you to apply. Together, we can create a safer digital world for all.