1

Penetration Testing Engineer Jobs (NOW HIRING)

REQUIRED QUALIFICATIONS 5+ years of experience in security applications and systems Minimum of 5 years of Information Security Engineer/Consultant experience with application penetration testing.

Qualifications โ€ข Minimum of 5 years of Information Security Engineer/Consultant experience with application penetration testing. โ€ข Minimum of 5 years of demonstrated experience with automated ...

Penetration Tester

Chantilly, VA ยท On-site

$90K - $130K/yr

CDT is looking for a Penetration Tester to This will be supporting a government customer onsite in ... testing, Information system engineering. * System certification activities and efforts related to ...

Penetration Tester

Herndon, VA ยท Hybrid

$130K - $145K/yr

Analyzing and reverse engineering firmware and embedded systems to identify security weaknesses. * Testing and assessing the security of secure boot processes and Trusted Execution Environments (TEE)

ISC2 Information Systems Security Engineering Professional (ISSEP) * One of the following certifications or an alternate, verifiable certification demonstrating practical penetration testing ...

Penetration Tester

Washington, DC ยท Hybrid

$130K - $145K/yr

Analyzing and reverse engineering firmware and embedded systems to identify security weaknesses. * Testing and assessing the security of secure boot processes and Trusted Execution Environments (TEE)

next page

Showing results 1-20

Penetration Testing Engineer information

See salary details

$11K

$109.6K

$183.5K

How much do penetration testing engineer jobs pay per year?

As of Jul 20, 2026, the average yearly pay for penetration testing engineer in the United States is $109,565.00, according to ZipRecruiter salary data. Most workers in this role earn between $80,000.00 and $143,000.00 per year, depending on experience, location, and employer.

What is the difference between Penetration Testing Engineer vs Security Analyst?

AspectPenetration Testing EngineerSecurity Analyst
CertificationsOSCP, CEH, GPENCompTIA Security+, CISSP
Work EnvironmentHands-on testing, simulated attacksMonitoring, analyzing security data
Primary FocusIdentifying vulnerabilities through penetration testsMonitoring security systems and incident response

While both roles focus on cybersecurity, a Penetration Testing Engineer actively tests systems for vulnerabilities, whereas a Security Analyst monitors and analyzes security data to prevent breaches. They often collaborate but have distinct responsibilities within an organization's security framework.

What are some typical challenges a Penetration Testing Engineer faces when working with clients?

Penetration Testing Engineers often encounter challenges such as limited information or access during assessments, varying levels of client security maturity, and tight project deadlines. Communicating technical findings to non-technical stakeholders can also be challenging, as it requires translating complex vulnerabilities into actionable business risks. Building trust with clients and ensuring that testing activities do not disrupt their operations are critical skills for success in this role.

What does a Penetration Testing Engineer do?

A Penetration Testing Engineer, also known as a 'pen tester' or ethical hacker, is responsible for evaluating the security of computer systems, networks, and applications by simulating attacks. Their primary goal is to identify vulnerabilities that malicious hackers could exploit and to provide recommendations for strengthening defenses. Penetration Testing Engineers use a variety of tools and techniques to mimic real-world cyber threats, document their findings, and work with organizations to improve their security posture.

What are the key skills and qualifications needed to thrive as a Penetration Testing Engineer, and why are they important?

To thrive as a Penetration Testing Engineer, you need a solid understanding of cybersecurity principles, network protocols, operating systems, and vulnerability assessment, often supported by a degree in computer science or related fields. Familiarity with penetration testing tools like Metasploit, Burp Suite, Nmap, and industry certifications such as OSCP or CEH are typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify vulnerabilities and clearly report findings to stakeholders. These skills and qualities are crucial for uncovering security weaknesses and helping organizations strengthen their defenses against cyber threats.
More about Penetration Testing Engineer jobs

Penetration Tester, Embedded Devices

TP-Link Systems Inc.

Irvine, CA โ€ข On-site

$80K - $132K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Re-posted 6 days ago


Job description

About Us:

Headquartered in the United States, TP-Link Systems Inc. is a global provider of reliable networking devices and smart home products, consistently ranked as the world's top provider of Wi-Fi devices. The company is committed to delivering innovative products that enhance people's lives through faster, more reliable connectivity. With a commitment to excellence, TP-Link Systems serves customers in over 170 countries and continues to grow its global footprint.

We believe technology changes the world for the better! At TP-Link Systems Inc, we are committed to crafting dependable, high-performance products to connect users worldwide with the wonders of technology.

Embracing professionalism, innovation, excellence, and simplicity, we aim to assist our clients in achieving remarkable global performance and enable consumers to enjoy a seamless, effortless lifestyle.

Overview:

TP-Link Systems Inc. is seeking a skilled and proactive Penetration Testing Engineer, Embedded Devices to support our embedded product projects under the guidance of senior team members. This role is designed for candidates with a foundational technical background in cybersecurity, particularly in embedded devices. Under the mentorship of senior engineers, the successful candidate will be involved in a range of security activities for a single product category, including penetration testing, threat modeling and security assessment for specific modules, contributing to investigation, risk assessment and verification for incident response.

The ideal candidate is eager to learn, capable of working within defined boundaries, and driven to enhance the security of TP-Link's embedded devices.

Key Responsibilities:

  • Penetration Testing: Perform penetration testing on embedded products to identify vulnerabilities. Provide remediation recommendations and write detailed penetration test reports.
  • Threat Modelling and security assessment: Perform threat modeling to identify and evaluate potential risks for specific modules.
  • Incident Response and Vulnerability Management: Responsible for specific area's incident response, including investigation, containment, remediation, and post-incident analysis. Coordinate with cross-functional teams to ensure effective resolution.
  • Product cybersecurity certification: Analyze specific product security certification requirements and collaborate with cross-functional teams to achieve product security certification.
  • Develop security tools: Assist in developing various pen-testing tools, automated testing platforms, and scripts to enhance testing efficiency and accuracy.
  • SDLC Integration: Participate in the development and improvement of the company's SDLC processes, ensuring security considerations are embedded during development.
  • Interpret global cybersecurity standards and regulatory requirements, supporting implementation of security requirements.

Requirements

Qualifications:

  • Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent work experience).
  • Proven 1-3 years' experience as a Security Engineer (Embedded devices) or in a similar role.
  • Strong knowledge of protocol security design, cryptography, security frameworks and common vulnerabilities.
  • Experience with security tools such as Burpsuite, Nmap, Kali, Nessus, Metasploit, IDA, Ghidra, etc.
  • Capability to optimize penetration testing tools and Fuzzing strategies.
  • Ability to analyze SAST results, conduct basic reverse engineering.
  • Proficient in at least one programming language (e.g., C/C++, Python, Bash, or PowerShell).
  • Relevant advanced security certifications (e.g., OSWP, etc.) are highly preferred.
  • Published CVEs are highly preferred.

Soft Skills:

  • Strong communication and interpersonal skills. Ability to work independently as well as collaborate with cross-functional teams.
  • Strong willingness to learn, able to work under guidance and take constructive feedback.
  • Team-oriented mindset, with the ability to follow technical direction and contribute constructively to group tasks.

Benefits

Salary range: $80,000-$132,000

  • Fully paid medical, dental, and vision insurance (partial premium coverage for dependents)
  • Employer quarterly contributions to 401k funds
  • 15 days accrued vacation
  • 11 paid holidays
  • Bi-annual reviews, and annual pay increases
  • Health and wellness benefits, including free gym membership
  • Quarterly team-building event

At TP-Link Systems Inc., we are continually searching for ambitious individuals who are passionate about their work. We believe that diversity fuels innovation, collaboration, and drives our entrepreneurial spirit. As a global company, we highly value diverse perspectives and are committed to cultivating an environment where all voices are heard, respected, and valued. We are dedicated to providing equal employment opportunities to all employees and applicants, and we prohibit discrimination and harassment of any kind based on race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws. Beyond compliance, we strive to create a supportive and growth-oriented workplace for everyone. If you share our passion and connection to this mission, we welcome you to apply and join us in building a vibrant and inclusive team at TP-Link Systems Inc.

Please, no third-party agency inquiries, and we are unable to offer visa sponsorships at this time.