1

Penetration Testing Jobs (NOW HIRING)

The Penetration Testing Lead will analyze vulnerabilities, identify gaps in IT security policies and configurations, and deliver actionable recommendations to reduce organizational cyber risk. This ...

The Penetration Testing Lead will analyze vulnerabilities, identify gaps in IT security policies and configurations, and deliver actionable recommendations to reduce organizational cyber risk. This ...

The Penetration Testing Lead will analyze vulnerabilities, identify gaps in IT security policies and configurations, and deliver actionable recommendations to reduce organizational cyber risk. This ...

... testing. • Minimum of 5 years of demonstrated experience with automated penetration tools • Minimum of 5 years of demonstrated experience with manual penetration testing tools • Demonstrated ...

REQUIRED QUALIFICATIONS 5+ years of experience in security applications and systems Minimum of 5 years of Information Security Engineer/Consultant experience with application penetration testing.

Penetration Tester

Chantilly, VA · On-site

$90K - $130K/yr

Conduct penetration testing that uses both active and passive capabilities to expose and exploit IA vulnerabilities. * Review and evaluate information systems and recommend changes to the Government ...

We are seeking an experienced and results-driven Penetration Tester to perform comprehensive web application security assessments. The role involves conducting penetration tests, evaluating security ...

Performs application and network penetration testing and wireless security assessments. * Applies offensive cybersecurity testing techniques, coordinate testing projects with internal and external ...

Senior Penetration Tester

Washington, DC · On-site

$124K - $180K/yr

Lead, plan, and oversee penetration testing operations for systems, networks, cloud resources, and web‑based applications in a TS/SCI environment * Execute comprehensive vulnerability assessments ...

Experience with a variety of penetration testing tools and techniques (e.g., Rapid7 Nexpose, Appspider Pro, Metasploit, Cobalt Strike and/or Burp Suite). * Active Top-Secret Clearance REQUIRED ...

ASRC Federal Technology Solutions is seeking an experienced Penetration Tester to lead advanced ... This role combines hands-on testing with leadership, mentoring, and collaboration across ...

Penetration Tester

Arlington, VA · On-site

$95K - $112K/yr

Minimum of 2 years with penetration testing experience. * Possess one of the following certifications: * CCNA Cyber Ops, CCNA-Security, CEH, CFR, Cloud+, CySA+, GCIA, GCIH, GICSP, SCYBER, Security ...

Penetration Tester

Arlington, VA · On-site

$86K - $138K/yr

Minimum of 2 years with penetration testing experience. * Possess one of the following certifications, OR be able to obtain before start date: * CCNA Cyber Ops, CCNA-Security, CEH, CFR, Cloud+, CySA ...

next page

Showing results 1-20

Penetration Testing information

See salary details

$22.5K

$119.9K

$168.5K

How much do penetration testing jobs pay per year?

As of Sep 6, 2026, the average yearly pay for penetration testing in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What is penetration testing?

Penetration testing, also known as ethical hacking, is a security practice where professionals simulate cyberattacks on a computer system, network, or application to identify vulnerabilities before malicious hackers can exploit them. The goal is to find and safely exploit weaknesses, assess the impact of potential attacks, and provide recommendations to improve security. Penetration testers use a variety of tools and techniques, often mirroring real-world attack methods, to thoroughly evaluate an organization’s defenses. It is a proactive approach to improving an organization's cybersecurity posture.

What are some common challenges faced by penetration testers during client engagements?

Penetration testers often encounter challenges such as limited access to information, time constraints, and complex network environments that can hinder thorough assessments. Additionally, balancing the need to simulate real-world attacks while ensuring no disruption to client operations requires careful planning and communication. Collaborating effectively with IT teams and clearly documenting findings are crucial for ensuring that vulnerabilities are properly understood and addressed.

What is the difference between Penetration Testing vs Vulnerability Assessment?

AspectPenetration TestingVulnerability Assessment
PurposeSimulate cyberattacks to identify exploitable vulnerabilitiesIdentify and prioritize security weaknesses
DepthIn-depth, targeted testingBroad, comprehensive scanning
CertificationsOSCP, CEH, GPENOSCP, CEH, Security+
Work EnvironmentHands-on testing, simulated attacksAutomated scans, reports

While both roles focus on security weaknesses, Penetration Testing involves actively exploiting vulnerabilities to assess real-world impact, whereas Vulnerability Assessment identifies potential issues for prioritization. Penetration Testing provides a deeper, more targeted security evaluation, making it essential for comprehensive security testing.

Are penetration testers high in demand?

Penetration testers are in high demand due to increasing cybersecurity threats and the need for organizations to identify vulnerabilities. The role often requires skills in tools like Kali Linux and certifications such as OSCP, with job growth expected to remain strong in the cybersecurity field.

Is penetration testing a good career?

Penetration testing is a growing cybersecurity field that involves identifying vulnerabilities in computer systems and networks. It requires technical skills, knowledge of security tools, and often certifications like OSCP or CEH. The role offers high demand, competitive salaries, and opportunities for continuous learning, making it a viable career choice for those interested in cybersecurity.

What cities are hiring for Penetration Testing jobs?

Cities with the most Penetration Testing job openings:

What are the most commonly searched types of Penetration Testing jobs?

The most popular types of Penetration Testing jobs are:

What states have the most Penetration Testing jobs?

States with the most job openings for Penetration Testing jobs include:

Infographic showing various Penetration Testing job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 11% Part Time, 3% Contract, and 1% Nights. Highlights an 88% Physical, 2% Hybrid, and 10% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

Contractor

Posted 25 days ago


Job description

We are seeking experienced penetration testing professionals to join our network of trusted consultants and support client engagements on an as-needed basis. Consultants will perform security assessments for organizations across a variety of industries, including commercial enterprises, healthcare organizations, financial institutions, government contractors, and regulated environments.
Engagements may include internal and external network penetration testing, web application testing, mobile application testing, wireless security assessments, social engineering exercises, and adversary simulation activities.
This opportunity is ideal for experienced cybersecurity professionals seeking flexible, project-based consulting work while maintaining independence and control of their schedule.
Requirements
  • Conduct authorized penetration testing activities against client environments.
  • Perform internal and external network penetration tests.
  • Execute web application, mobile application, wireless, and social engineering assessments as applicable.
  • Validate vulnerabilities and document security findings.
  • Prepare clear, professional reports with supporting evidence and remediation recommendations.
  • Participate in project kickoff, status, and findings review meetings as needed.
  • Adhere to established testing methodologies, quality standards, and project timelines.
  • Maintain strict confidentiality of client information and assessment results.

Preferred Areas of Expertise
Candidates may possess expertise in one or more of the following areas:
  • Internal Network Penetration Testing
  • External Network Penetration Testing
  • Active Directory Security Assessments
  • Web Application Penetration Testing
  • Mobile Application Penetration Testing
  • Wireless Security Testing
  • Social Engineering Assessments
  • Red Team / Adversary Simulation Exercises
  • Cloud Security Assessments

Required Qualifications
  • Minimum three years of hands-on penetration testing experience.
  • Experience performing client-facing security assessments.
  • Strong understanding of attack methodologies, exploitation techniques, and common security weaknesses.
  • Experience with industry-standard penetration testing tools and methodologies.
  • Excellent written and verbal communication skills.
  • Ability to work independently and manage assignments with minimal supervision.
  • Ability to execute confidentiality and independent contractor agreements.

Preferred Certifications
One or more of the following certifications is required:
  • Offensive Security Certified Professional (OSCP) / preferred
  • Practical Network Penetration Tester (PNPT)
  • GIAC Penetration Tester (GPEN)
  • Offensive Security Web Expert (OSWE)
  • eLearnSecurity Web Application Penetration Tester (eWPT)
  • Certified Red Team Operator (CRTO)
  • Other relevant offensive security certifications

Engagement Model
  • Independent Contractor (1099)
  • Project-Based Assignments
  • Flexible Schedule
  • Primarily Remote
  • Occasional Travel May Be Required
  • Engagements may range from several days to multiple weeks depending on project scope

Desired Attributes
  • Professionalism and integrity
  • Strong attention to detail
  • Reliable project execution
  • Excellent client communication skills
  • Ability to translate technical findings into business-focused recommendations
  • Commitment to producing high-quality deliverables

Interested Consultants
We are continuously building a network of qualified penetration testing professionals for future project opportunities. Interested consultants are encouraged to submit the following information for consideration:
  • Current resume
  • Relevant certifications
  • Areas of specialization
  • Typical availability for project work
  • Desired hourly rate or project-based pricing information