1

Penetration Testing Engineer Jobs (NOW HIRING)

REQUIRED QUALIFICATIONS 5+ years of experience in security applications and systems Minimum of 5 years of Information Security Engineer/Consultant experience with application penetration testing.

Qualifications • Minimum of 5 years of Information Security Engineer/Consultant experience with application penetration testing. • Minimum of 5 years of demonstrated experience with automated ...

Penetration Tester

Chantilly, VA · On-site

$90K - $130K/yr

CDT is looking for a Penetration Tester to This will be supporting a government customer onsite in ... testing, Information system engineering. * System certification activities and efforts related to ...

Penetration Tester

Chantilly, VA · On-site

$90K - $130K/yr

CDT is looking for a Penetration Tester to This will be supporting a government customer onsite in ... testing, Information system engineering. * System certification activities and efforts related to ...

Penetration Tester

Arlington, VA · On-site

$95K - $112K/yr

ISC2 Information Systems Security Engineering Professional (ISSEP) * One of the following certifications or an alternate, verifiable certification demonstrating practical penetration testing ...

Create and maintain documentation on penetration testing methodologies, tools, and techniques. * Remediation Support: * * Provide guidance and technical assistance to system owners and developers on ...

Required: 6 years minimum work experience directly related to Red Team assessments, and/or penetration testing (intranet, internet, web, wireless, social engineering), with a focus on Web Application ...

Penetration Tester

Arlington, VA · On-site

$86K - $138K/yr

ISC2 Information Systems Security Engineering Professional (ISSEP) * One of the following certifications or an alternate, verifiable certification demonstrating practical penetration testing ...

Penetration Tester

Arlington, VA · On-site

$86K - $138K/yr

ISC2 Information Systems Security Engineering Professional (ISSEP) * One of the following certifications or an alternate, verifiable certification demonstrating practical penetration testing ...

OSCP (Offensive Security Certified Professional)CPTS (Certified Penetration Testing Specialist)GPEN (GIAC Penetration Tester)GXPN (GIAC Exploit Programmer)CRTO (Certified Red Team Operator)Additional ...

Showing results 21-40

Penetration Testing Engineer information

See salary details

$11K

$109.6K

$183.5K

How much do penetration testing engineer jobs pay per year?

As of Sep 2, 2026, the average yearly pay for penetration testing engineer in the United States is $109,565.00, according to ZipRecruiter salary data. Most workers in this role earn between $80,000.00 and $143,000.00 per year, depending on experience, location, and employer.

What does a penetration testing engineer do?

A Penetration Testing Engineer, also known as a 'pen tester' or ethical hacker, is responsible for evaluating the security of computer systems, networks, and applications by simulating attacks. Their primary goal is to identify vulnerabilities that malicious hackers could exploit and to provide recommendations for strengthening defenses. Penetration Testing Engineers use a variety of tools and techniques to mimic real-world cyber threats, document their findings, and work with organizations to improve their security posture.

What skills and qualifications are needed to be a penetration testing engineer?

To thrive as a Penetration Testing Engineer, you need a solid understanding of cybersecurity principles, network protocols, operating systems, and vulnerability assessment, often supported by a degree in computer science or related fields. Familiarity with penetration testing tools like Metasploit, Burp Suite, Nmap, and industry certifications such as OSCP or CEH are typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify vulnerabilities and clearly report findings to stakeholders. These skills and qualities are crucial for uncovering security weaknesses and helping organizations strengthen their defenses against cyber threats.

What challenges does a penetration testing engineer face when working with clients?

Penetration Testing Engineers often encounter challenges such as limited information or access during assessments, varying levels of client security maturity, and tight project deadlines. Communicating technical findings to non-technical stakeholders can also be challenging, as it requires translating complex vulnerabilities into actionable business risks. Building trust with clients and ensuring that testing activities do not disrupt their operations are critical skills for success in this role.

What is the difference between Penetration Testing Engineer vs Security Analyst?

AspectPenetration Testing EngineerSecurity Analyst
CertificationsOSCP, CEH, GPENCompTIA Security+, CISSP
Work EnvironmentHands-on testing, simulated attacksMonitoring, analyzing security data
Primary FocusIdentifying vulnerabilities through penetration testsMonitoring security systems and incident response

While both roles focus on cybersecurity, a Penetration Testing Engineer actively tests systems for vulnerabilities, whereas a Security Analyst monitors and analyzes security data to prevent breaches. They often collaborate but have distinct responsibilities within an organization's security framework.

Infographic showing various Penetration Testing Engineer job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 85% Full Time, 10% Part Time, 3% Contract, and 1% Nights. Highlights an 87% Physical, 3% Hybrid, and 10% Remote job distribution, with an average salary of $109,565 per year, or $52.7 per hour.

Penetration Tester

Gemini

Charlotte, NC • On-site

Contractor

Re-posted 6 days ago


Job description

Job Description

REQUIRED QUALIFICATIONS
5+ years of experience in security applications and systems
Minimum of 5 years of Information Security Engineer/Consultant experience with application penetration testing.
Minimum of 5 years of demonstrated experience with automated penetration tools
Minimum of 5 years of demonstrated experience with manual penetration testing tools
Demonstrated experience with creating and communication of reports regarding web application vulnerabilities to various level of personnel within a large organization.

Qualifications


Minimum of 5 years of Information Security Engineer/Consultant experience with application penetration testing.
Minimum of 5 years of demonstrated experience with automated penetration tools
Minimum of 5 years of demonstrated experience with manual penetration testing tools

Additional Information

All your information will be kept confidential according to EEO guidelines.