1

Penetration Testing Contract Jobs (NOW HIRING)

Contract Penetration Tester At Bishop Fox, security isn't just a job-it's our passion ... As leaders in continuous offensive security and penetration testing, we deliver world-class ...

Contract Penetration Tester At Bishop Fox, securityisn'tjust a job-it'sour passion ... As leaders in continuous offensive security and penetration testing, we deliver world-class ...

M9 Solutions is seeking a Penetration Tester II to work on-site in support of a government contract for a client located in Chandler, AZ or Washington, DC . An active Secret clearance is required.

M9 Solutions is seeking a Penetration Tester III to work on-site in support of a government contract for a client located in Chandler, AZ or Washington, DC . An active Secret clearance is required.

This role is responsible for conducting penetration testing and red team activities, assessing ... May be requested to work evenings and weekends to meet program and contract needs. Working at SOSi ...

This role is responsible for conducting penetration testing and red team activities, assessing ... May be requested to work evenings and weekends to meet program and contract needs. Working at SOSi ...

Overview Please note that this position is contingent upon the successful award of a contract ... Performs application and network penetration testing and wireless security assessments. * Applies ...

Penetration Tester

Aberdeen, MD · On-site

$173.90K/yr

Professional experience in penetration testing or threat hunting * Proven experience in grey and ... and contract wage rates, relevant prior work experience, specific skills and competencies ...

Overview Please note that this position is contingent upon the successful award of a contract ... Performs application and network penetration testing and wireless security assessments. * Applies ...

This role is responsible for conducting penetration testing and red team activities, assessing ... May be requested to work evenings and weekends to meet program and contract needs. Working at SOSi ...

Remote or Hoboken, NJ (REMOTE/Onsite) DURATION: 3+ Months Contract Job Summary: We are seeking an experienced Penetration Tester / Vulnerability Assessment Engineer with strong hands-on expertise in ...

New

Penetration Tester, Journeyman

Herndon, VA · On-site

$66K - $106K/yr

Execute penetration testing activities per CDAP mission plans: reconnaissance, exploitation ... and contract considerations. Depending on the position, employees may be eligible for overtime ...

Penetration Test Lead

Falls Church, VA · On-site

$180K - $210K/yr

Penetration Testing Lead Falls Church, Virginia. Full-time. Important Notice: This position is contingent upon contract award. Summary: Penetration Test Leads plan and execute complex offensive ...

Penetration Tester, Journeyman

Herndon, VA · On-site

$66K - $106K/yr

Execute penetration testing activities per CDAP mission plans: reconnaissance, exploitation ... and contract considerations. Depending on the position, employees may be eligible for overtime ...

Execute penetration testing activities per CDAP mission plans: reconnaissance, exploitation ... and contract considerations. Depending on the position, employees may be eligible for overtime ...

Penetration Tester II

Chandler, AZ · On-site

$60K - $180K/yr

M9 Solutions is seeking a Penetration Tester II to work on-site in support of a government contract ... Experience with continuous penetration testing methodologies. * Experience with planning and ...

next page

Showing results 1-20

Penetration Testing Contract information

See salary details

$22.5K

$119.9K

$168.5K

How much do penetration testing contract jobs pay per year?

As of May 29, 2026, the average yearly pay for penetration testing contract in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What is the difference between Penetration Testing Contract vs Penetration Tester?

AspectPenetration Testing ContractPenetration Tester
DefinitionA legal agreement outlining scope, deliverables, and terms for penetration testing services.A cybersecurity professional who performs security assessments to identify vulnerabilities.
CredentialsTypically no specific credentials; contractual terms are emphasized.Certifications like OSCP, CEH, or CISSP are common.
Work EnvironmentEngages with clients, often remotely or on-site, based on contract terms.Works within organizations or as a consultant, performing testing tasks.
PurposeDefines legal and operational scope for penetration testing projects.Conducts actual security assessments to find vulnerabilities.

In summary, a Penetration Testing Contract is a legal agreement that sets the scope and terms for testing, while a Penetration Tester is the professional executing the security assessments. Both are essential in cybersecurity engagements but serve different roles.

More about Penetration Testing Contract jobs
What cities are hiring for Penetration Testing Contract jobs? Cities with the most Penetration Testing Contract job openings:
What are the most commonly searched types of Penetration Testing jobs? The most popular types of Penetration Testing jobs are:
What states have the most Penetration Testing Contract jobs? States with the most job openings for Penetration Testing Contract jobs include:
Infographic showing various Penetration Testing Contract job openings in the United States as of May 2026, with employment types broken down into 93% Full Time, and 7% Contract. Highlights an 81% Physical, 2% Hybrid, and 17% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.
Penetration Tester - Contract

Penetration Tester - Contract

Bishop Fox

Remote

Contractor

Posted 23 days ago


Job description

Contract Penetration Tester
At Bishop Fox, security isn't just a job-it's our passion. As leaders in continuous offensive security and penetration testing, we deliver world-class customer experiences. Trusted by over a quarter of the Fortune 100, half of the Fortune 10, and top global media companies, we help safeguard digital landscapes. Our Cosmos platform, honored as Best Emerging Technology by SC Media, exemplifies our commitment to innovation.
Joining Bishop Fox means collaborating with a curious and dedicated team. You'll tackle complex challenges for some of the world's most recognized organizations, securing their networks against real-world threats. With nearly 20 years of industry contributions-including 16 open-source tools and 50 security advisories published in the past five years-we're committed to making the digital world safer.
We're looking for talented, experienced professional hackers to help us secure some of the world's most complex software and sophisticated technologies. You'll be working alongside our US and internationally-based teams supporting clients across multiple industries.
Responsibilities
Bishop Fox is looking for experienced contract penetration testers with a primary focus in web application security and strong secondary expertise in cloud, mobile, source code, network, or AI/LLM security.
You'll work on a range of projects, from short-term assessments to longer-term program engagements with well-established clients. In this role, you'll identify vulnerabilities, validate risk, develop creative solutions, and clearly communicate findings and remediation guidance to both technical and executive stakeholders. As a trusted advisor, you'll help clients understand risk and make informed security decisions.
Experience
  • 5+ years of experience planning, conducting, and managing web application penetration tests
  • Deep understanding of application security fundamentals, OWASP Top 10, common vulnerabilities, and secure development best practices
  • Experience assessing vulnerabilities and developing exploits across diverse targets
  • Strong understanding of system and network security, authentication protocols, security protocols, and applied cryptography
  • Ability to communicate complex technical findings clearly and provide practical remediation guidance to technical and executive audiences

Preferred Experience
Deep experience in at least one of the following:
  • Cloud Security - Experience assessing AWS cloud environments, including technologies such as IAM, EC2, VPC, EBS, S3, CloudWatch, and Lambda.
  • Mobile Application Security - Experience testing iOS and/or Android applications, including mobile application architecture, API communication, data storage, authentication flows, and common mobile security vulnerabilities.
  • Source Assisted Application Assessments: Experience evaluating applications across multiple layers, including source code, APIs, infrastructure, and integrations. Strong proficiency in Golang is highly preferred, along with familiarity in languages such as Python, Ruby, PowerShell, Java, and JavaScript.
  • Network Security - Experience with network and system exploitation, including modern tactics, techniques, and procedures such as C2 frameworks, EDR bypass, privilege escalation, password cracking, and lateral movement.
  • AI/LLM Security -Experience assessing non-deterministic security controls.

Employment Sponsorship
This engagement is for independent contractors (1099) and is not eligible for any form of employment sponsorship. Applicants must be legally authorized to work in the United States without requiring visa sponsorship now or in the future. Applicants must be located in the United States.
All new hires must pass a background check as a condition of employment.
Bishop Fox is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law.