More meaningful engagements Experience fewer, higher-quality engagements versus consulting-style, high-volume work. KEY SKILLS: - Min of 3+ years experience with Manual Penetration Testing experience ...
More meaningful engagements Experience fewer, higher-quality engagements versus consulting-style, high-volume work. KEY SKILLS: - Min of 3+ years experience with Manual Penetration Testing experience ...
REQUIRED QUALIFICATIONS 5+ years of experience in security applications and systems Minimum of 5 years of Information Security Engineer/Consultant experience with application penetration testing.
REQUIRED QUALIFICATIONS 5+ years of experience in security applications and systems Minimum of 5 years of Information Security Engineer/Consultant experience with application penetration testing.
... consultation support to Application, Development, and Asset Owner teams during vulnerability remediation Mobile Application Penetration Testing • Conduct security testing of in-scope mobile ...
... consultation support to Application, Development, and Asset Owner teams during vulnerability remediation Mobile Application Penetration Testing • Conduct security testing of in-scope mobile ...
Penetration Testing
Santa Clara, CA · On-site
... consultation support to Application, Development, and Asset Owner teams during vulnerability remediation Mobile Application Penetration Testing • Conduct security testing of in-scope mobile ...
Penetration Testing
Santa Clara, CA · On-site
... consultation support to Application, Development, and Asset Owner teams during vulnerability remediation Mobile Application Penetration Testing • Conduct security testing of in-scope mobile ...
Penetration Tester
Charlotte, NC · On-site
Qualifications • Minimum of 5 years of Information Security Engineer/Consultant experience with application penetration testing. • Minimum of 5 years of demonstrated experience with automated ...
Penetration Tester
Charlotte, NC · On-site
Qualifications • Minimum of 5 years of Information Security Engineer/Consultant experience with application penetration testing. • Minimum of 5 years of demonstrated experience with automated ...
Consultant, Penetration Tester
$64K - $117K/yr
... testing priorities and deliver high-quality work on time • Collaborate with internal teams-PMs ... other consultants-to deliver exceptional client service • Create and maintain testing ...
Consultant, Penetration Tester
$64K - $117K/yr
... testing priorities and deliver high-quality work on time • Collaborate with internal teams-PMs ... other consultants-to deliver exceptional client service • Create and maintain testing ...
Required technical and professional expertise Technical / Professional Experience: · 10+ years of penetration testing experience · 10+ years of consulting experience · Ability to perform ...
Required technical and professional expertise Technical / Professional Experience: · 10+ years of penetration testing experience · 10+ years of consulting experience · Ability to perform ...
Penetration Tester
Herndon, VA · On-site +1
Push the boundaries of penetration testing innovation through research and development of novel TTPs * Contribute to Altus Consulting's thought leadership efforts via publications, presentations, and ...
Penetration Tester
Herndon, VA · On-site +1
Push the boundaries of penetration testing innovation through research and development of novel TTPs * Contribute to Altus Consulting's thought leadership efforts via publications, presentations, and ...
Web Application Penetration Testing Ampcus Inc. is a certified global provider of a broad range of Technology and Business consulting services. We are in search of a highly motivated candidate to ...
Web Application Penetration Testing Ampcus Inc. is a certified global provider of a broad range of Technology and Business consulting services. We are in search of a highly motivated candidate to ...
Required technical and professional expertise Technical / Professional Experience: · 10+ years of penetration testing experience · 10+ years of consulting experience · Ability to perform ...
Required technical and professional expertise Technical / Professional Experience: · 10+ years of penetration testing experience · 10+ years of consulting experience · Ability to perform ...
Penetration Tester
Herndon, VA · On-site
Push the boundaries of penetration testing innovation through research and development of novel TTPs * Contribute to Altus Consulting's thought leadership efforts via publications, presentations, and ...
Penetration Tester
Herndon, VA · On-site
Push the boundaries of penetration testing innovation through research and development of novel TTPs * Contribute to Altus Consulting's thought leadership efforts via publications, presentations, and ...
... consulting services projects. This role is responsible for the successful delivery of penetration testing in both classic hosted and also in cloud hosted environments. In this role, the selected ...
Quick apply
... consulting services projects. This role is responsible for the successful delivery of penetration testing in both classic hosted and also in cloud hosted environments. In this role, the selected ...
Penetration Tester
$35 - $40/hr
Conduct penetration testing on web applications, APIs, mobile applications, and Active Directory ... Pyramid Consulting, Inc. provides equal employment opportunities to all employees and applicants ...
Penetration Tester
$35 - $40/hr
Conduct penetration testing on web applications, APIs, mobile applications, and Active Directory ... Pyramid Consulting, Inc. provides equal employment opportunities to all employees and applicants ...
Extensive knowledge of and proven experience with penetration testing of web applications, and ... Thanks and Regards, Ajeet Singh Buxton Consulting 2010 Crow Canyon Place STE 100 San Ramon, CA ...
Extensive knowledge of and proven experience with penetration testing of web applications, and ... Thanks and Regards, Ajeet Singh Buxton Consulting 2010 Crow Canyon Place STE 100 San Ramon, CA ...
Penetration tester
Dallas, TX · On-site
Assisting in technical scoping of security testing activities curation and assessment of ... Provide consultative guidance to customers on findings identified in a clear and actionable fashion ...
Penetration tester
Dallas, TX · On-site
Assisting in technical scoping of security testing activities curation and assessment of ... Provide consultative guidance to customers on findings identified in a clear and actionable fashion ...
Provide consultative support with implementation of remediation steps, standards, and best ... Penetration testing, tester, penetrate, penetration, security, CEH, vulnerability, firewall ...
Provide consultative support with implementation of remediation steps, standards, and best ... Penetration testing, tester, penetrate, penetration, security, CEH, vulnerability, firewall ...
Penetration Tester
Herndon, VA · On-site
Responsibilities : • Conduct testing and analysis to identify vulnerabilities and potential ... Booz Allen Hamilton is a consulting firm that specializes in analytics, technology, and engineering.
Penetration Tester
Herndon, VA · On-site
Responsibilities : • Conduct testing and analysis to identify vulnerabilities and potential ... Booz Allen Hamilton is a consulting firm that specializes in analytics, technology, and engineering.
Lead Penetration Tester
Mountain View, CA · On-site
They are seeking a Lead Penetration Tester to oversee the penetration testing team and conduct ... AutoRoboto provides mechanical engineering, manufacturing consulting, hardware, software QA testing ...
Lead Penetration Tester
Mountain View, CA · On-site
They are seeking a Lead Penetration Tester to oversee the penetration testing team and conduct ... AutoRoboto provides mechanical engineering, manufacturing consulting, hardware, software QA testing ...
Minimum of 5 years of experience with penetration and vulnerability testing, web application assessments, social engineering, and other cyber-security consulting functions * Thorough understanding of ...
Minimum of 5 years of experience with penetration and vulnerability testing, web application assessments, social engineering, and other cyber-security consulting functions * Thorough understanding of ...
Penetration Tester
Alpharetta, GA · Hybrid
$35 - $40/hr
Conduct penetration testing on web applications, APIs, mobile applications, and Active Directory. * Identify and report vulnerabilities using industry-standard tools and methodologies. * Collaborate ...
Penetration Tester
Alpharetta, GA · Hybrid
$35 - $40/hr
Conduct penetration testing on web applications, APIs, mobile applications, and Active Directory. * Identify and report vulnerabilities using industry-standard tools and methodologies. * Collaborate ...
Penetration Testing Consultant information
See salary details
$22K - $35K
3% of jobs
$35K - $48K
4% of jobs
$48K - $61K
2% of jobs
$61K - $74K
5% of jobs
$74K - $87K
6% of jobs
$92.7K is the 25th percentile. Wages below this are outliers.
$87K - $100K
9% of jobs
$100K - $113K
7% of jobs
The median wage is $124.1K / yr.
$113K - $126K
15% of jobs
$126K - $139K
13% of jobs
$148.5K is the 75th percentile. Wages above this are outliers.
$139K - $152K
14% of jobs
$152K - $165K
21% of jobs
$22K
$118.6K
$165K
How much do penetration testing consultant jobs pay per year?
What is a Penetration Testing Consultant job?
A Penetration Testing Consultant is a cybersecurity professional who evaluates an organization's security by simulating real-world cyberattacks. They identify vulnerabilities in networks, applications, and systems, providing recommendations to strengthen defenses. Their role involves ethical hacking, security assessments, and compliance audits. They often work with clients to improve security posture and mitigate risks before malicious attackers can exploit them.
What are the key skills and qualifications needed to thrive in the Penetration Testing Consultant position, and why are they important?
To thrive as a Penetration Testing Consultant, you need expertise in cybersecurity principles, vulnerability assessment, and ethical hacking, often supported by a degree in information security or computer science. Familiarity with tools such as Kali Linux, Metasploit, Burp Suite, and certifications like OSCP or CEH is highly beneficial. Strong analytical thinking, effective communication, and the ability to explain complex technical findings to non-technical stakeholders are standout soft skills. These competencies ensure accurate risk assessments, clear client communication, and actionable security recommendations.
What does a typical day look like for a Penetration Testing Consultant?
A typical day for a Penetration Testing Consultant involves planning and executing security assessments of client networks, applications, or systems to identify vulnerabilities. Consultants spend time analyzing findings, documenting risks, and preparing detailed reports with remediation guidance. Collaboration is also a key part of the role, as consultants often communicate with IT teams, clients, and other security professionals to ensure thorough understanding of findings and best practices. The work environment tends to be dynamic and project-based, with opportunities to learn about new technologies and face new security challenges regularly.
- Penetration Testing Consulting
- Freelance Manual Software Testing
- Internship Penetration Testing Consultant
- Internship Penetration Tester Ethical Hacker
- Penetration Tester Ethical Hacker
- Penetration Testing Companies
- Freelance Cybersecurity Penetration Tester
- Entry Level Cybersecurity Penetration Tester
- Entry Level Gcih
- Entry Level Penetration Tester Red Team

Other
Medical, Life, Retirement
Posted 4 days ago
Job description
Application Deadline:
Address:
VIRTUAL43 - HomeRes - TXJob Family Group:
TechnologyJoin a team where your work goes beyond checklists protecting critical financial applications with real business and regulatory impact. Why join this team?
- High-impact, meaningful work
Directly influence the security of applications that matter to customers, regulators, and the business.
Depth over volume
Focus on deep, manual penetration testing (web, mobile, APIs)—not automated, scanner-driven assessments.Accelerated technical growth
Work in complex, enterprise-scale environments that expose you to advanced architectures and evolving threats.End-to-end ownership
Engage across the full lifecycle: scoping → testing → reporting → remediation, with visibility and influence throughout.Modern tools and techniques
Use advanced testing tools to enhance testing depth and efficiency.More meaningful engagements
Experience fewer, higher-quality engagements versus consulting-style, high-volume work.
- Min of 3+ years experience with Manual Penetration Testing experience in Web or API. This includes strong exposure for testing Web applications in the following areas:
A solid grasp of HTTP/S protocols, headers, cookies, sessions, and CORS behavior within your web testing experience
Experience testing authentication and authorization mechanisms (OAuth, JWT, session flaws, IDOR/BOLA)-
Strong proficiency with Burp Suite Professional , OWASP ZAP, IBM’s APP SCAN, (proxying, repeater, intruder, extensions)-
Deep practical knowledge of OWASP Top 10 (Web + API) and common vulnerabilities
- Ability to identify and exploit business logic vulnerabilities and multi-step attack paths
- Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. OSCP, GMOB, GWAPT, OSWE).
- Secure coding and architecture understanding
- Proficiency in at least one scripting language
- Proficiency in documenting reproducible steps for technical accurate findings -
CORE Responsibilities:
Provides information security consulting services for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs
Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs.
Understands and can explain to others the core processes, risks and mitigation techniques for designated areas.
Develops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associations.
Facilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks.
Additional Information:
Provides information security consulting services for BMO overall and businesses/groups. Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs. Leads the development of information security strategy by understanding business processes, policies, information and information systems. Builds exceptional relationships with internal and external stakeholders. Ensures that requirements and solutions align to a real business need, are approved by all relevant stakeholders, and meets essential information security standards. Provides thought leadership, promotes new processes and methodologies and emerging technologies, with the flexibility to align to the unique requirements of the business/group and deliverables.
- Acts as a trusted advisor to assigned business/group.
- Assists in the development of strategic plans.
- Understands and can explain to others the core processes, risks and mitigation techniques for designated areas.
- Supports the execution of strategic initiatives in collaboration with internal and external stakeholders.
- Helps determine business priorities and best sequence for execution of business/group strategy.
- Breaks down strategic problems, and analyses data and information to provide insights and recommendations.
- Acts as the day to day contact for vendors; supports the implementation, maintenance, and sustainment of vendor solutions.
- Understands the strategy, plans, activities and needs of all stakeholders and translates those business needs into solutions and makes recommendations.
- Provides advice, counsel and support on information security matters and recommends solutions to assigned business/group leaders on principles, frameworks, programs, approaches, trends, legislation and regulatory requirements including interpretation of policy and identification and management of risk.
- Builds credibility and influences/negotiates effectively to drive business performance through development and delivery of information security solutions.
- Tracks metrics and milestones, providing recommendations for resolution and escalating as appropriate when issues arise.
- Facilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks.
- Promotes process improvements and methodologies; keeps emerging information security issues and trends in mind and ensures standards are followed.
- Creates professional presentations and deliver them in a meaningful concise way.
- Assesses information security impact to a project’s benefits and risks when scope changes.
- Develops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associations.
- Gathers, examines and interprets data and information to extract meaningful insights, answer business questions and provide actionable recommendations.
- Assists with continuous improvement activities and root cause analysis with the goal of strengthening information security capabilities.
- Ensures consistent, high quality practices/work and the achievement of business results in alignment with business/group strategies and with productivity goals.
- Focus is primarily on business/group within BMO; may have broader, enterprise-wide focus.
- Provides specialized consulting, analytical and technical support.
- Exercises judgment to identify, diagnose, and solve problems within given rules.
- Works independently and regularly handles non-routine situations.
- Broader work or accountabilities may be assigned as needed.
- Take measured risks while protecting the bank by applying our Risk Management Framework in the execution of your role, in line with our Risk Culture and within our approved Risk Appetite, making sound and risk informed decisions that align to business strategy, protect assets, and adhere to applicable policy documents (Frameworks, Policies, Standards, Procedures and Supporting documents), laws and regulations.
Qualifications:
- Typically between 4 - 7 years of relevant experience and a post-secondary degree in Information Security, Computer Science, Engineering, and/or Information Systems or a related field of study or an equivalent combination of education and experience.
- Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS).
- Understanding of industry standards and frameworks e.g. NIST Cyber Security Framework (CSF), ISO 27001 and 27002, Payment Card Industry (PCI) Data Security Standard (DSS), etc. - In-depth.
- Experience in information security concepts and methodology.
- Knowledge of business analysis, project delivery practices and standards across the project lifecycle - In-depth.
- Knowledge of information security processes, procedures and controls - In-depth.
- Understanding of and problem solving ability for information security issues within their business group - Working.
- Understanding of information security risk and regulatory requirements - Working.
- Deep knowledge and technical proficiency gained through extensive education and business experience.
- Verbal & written communication skills - In-depth.
- Collaboration & team skills - In-depth.
- Analytical and problem solving skills - In-depth.
- Influence skills - In-depth.
- Data driven decision making - In-depth.
Salary:
$88,800.00 - $165,600.00Pay Type:
SalariedThe above represents BMO Financial Group’s pay range and type.
Salaries will vary based on factors such as location, skills, experience, education, and qualifications for the role, and may include a commission structure. Salaries for part-time roles will be pro-rated based on number of hours regularly worked. For commission roles, the salary listed above represents BMO Financial Group’s expected target for the first year in this position.
BMO Financial Group’s total compensation package will vary based on the pay type of the position and may include performance-based incentives, discretionary bonuses, as well as other perks and rewards. BMO also offers health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans. To view more details of our benefits, please visit: https://jobs.bmo.com/global/en/Total-Rewards
About Us
At BMO we are driven by a shared Purpose: Boldly Grow the Good in business and life. It calls on us to create lasting, positive change for our customers, our communities and our people. By working together, innovating and pushing boundaries, we transform lives and businesses, and power economic growth around the world.
As a member of the BMO team you are valued, respected and heard, and you have more ways to grow and make an impact. We strive to help you make an impact from day one – for yourself and our customers. We’ll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs. From in-depth training and coaching, to manager support and network-building opportunities, we’ll help you gain valuable experience, and broaden your skillset.
To find out more visit us at http://jobs.bmo.com/us/en
BMO is proud to be an equal employment opportunity employer. We evaluate applicants without regard to race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or any other legally protected characteristics. We also consider applicants with criminal histories, consistent with applicable federal, state and local law.
BMO is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please send an e-mail to BMOCareers.Support@bmo.com and let us know the nature of your request and your contact information.
Note to Recruiters: BMO does not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to BMO, directly or indirectly, will be considered BMO property. BMO will not pay a fee for any placement resulting from the receipt of an unsolicited resume. A recruiting agency must first have a valid, written and fully executed agency agreement contract for service to submit resumes.
About BMO Financial Group
Sourced by ZipRecruiter
Industry
Banking and credit intermediation
Company size
10,000+ Employees
Headquarters location
Toronto, Ontario, CA