... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
Senior Manual Ethical Hacker
Denver, CO · On-site
$109K - $148K/yr
... will lead ethical hacking assessments to evaluate the security resilience of the bank ... penetration testing tools, triage, and support incidents, and produce high value findings • ...
Senior Manual Ethical Hacker
Denver, CO · On-site
$109K - $148K/yr
... will lead ethical hacking assessments to evaluate the security resilience of the bank ... penetration testing tools, triage, and support incidents, and produce high value findings • ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
... ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert ...
Senior Penetration Tester
$90K - $150K/yr
Possess a certification in penetration testing, such as: * Licensed Penetration Tester (LPT) * Certified Expert Penetration Tester (CEPT) * Certified Ethical Hacker (CEH) * Global Information ...
Senior Penetration Tester
$90K - $150K/yr
Possess a certification in penetration testing, such as: * Licensed Penetration Tester (LPT) * Certified Expert Penetration Tester (CEPT) * Certified Ethical Hacker (CEH) * Global Information ...
Penetration Tester
Dallas, TX · On-site
Heavy Penetration Testing Experience Needed -Manual AND automated testing -Manual pen testing ... how to use. -If they have an ethical hacker certification, they will most likely meet the ...
Penetration Tester
Dallas, TX · On-site
Heavy Penetration Testing Experience Needed -Manual AND automated testing -Manual pen testing ... how to use. -If they have an ethical hacker certification, they will most likely meet the ...
Penetration Tester
Washington, DC · Hybrid
This role combines hands-on testing with leadership, mentoring, and collaboration across ... CEH (Certified Ethical Hacker) * CISSP (Certified Information Systems Security Professional ...
Penetration Tester
Washington, DC · Hybrid
This role combines hands-on testing with leadership, mentoring, and collaboration across ... CEH (Certified Ethical Hacker) * CISSP (Certified Information Systems Security Professional ...
Penetration Tester
Plano, TX · Remote
$60 - $70/hr
We are seeking a highly skilled Penetration Tester with a strong focus on AI-enabled security ... vulnerabilities through ethical hacking and remediation testing. * Plan and execute red team ...
Quick apply
Penetration Tester
Plano, TX · Remote
$60 - $70/hr
We are seeking a highly skilled Penetration Tester with a strong focus on AI-enabled security ... vulnerabilities through ethical hacking and remediation testing. * Plan and execute red team ...
Penetration Testing Ethical Hacking information
See salary details
$22.5K - $35.8K
0% of jobs
$35.8K - $49K
0% of jobs
$49K - $62.3K
2% of jobs
$62.3K - $75.6K
3% of jobs
$75.6K - $88.9K
1% of jobs
$101.1K is the 25th percentile. Wages below this are outliers.
$88.9K - $102.1K
20% of jobs
$102.1K - $115.4K
14% of jobs
The median wage is $120.4K / yr.
$115.4K - $128.7K
26% of jobs
$138.1K is the 75th percentile. Wages above this are outliers.
$128.7K - $142K
13% of jobs
$142K - $155.2K
13% of jobs
$155.2K - $168.5K
9% of jobs
$22.5K
$119.9K
$168.5K
How much do penetration testing ethical hacking jobs pay per year?
What is penetration testing ethical hacking?
A Penetration Testing Ethical Hacking job involves assessing an organization's cybersecurity defenses by simulating real-world attacks. Ethical hackers use various tools and techniques to identify vulnerabilities in networks, applications, and systems. Their goal is to help organizations strengthen their security by fixing weaknesses before malicious hackers can exploit them. This role requires technical expertise, problem-solving skills, and knowledge of security standards and best practices.
What are the key skills and qualifications needed to thrive in penetration testing ethical hacking, and why are they important?
To thrive in Penetration Testing Ethical Hacking, you need a strong understanding of network security, vulnerability assessment, coding/scripting, and a background in computer science or cybersecurity. Familiarity with tools such as Metasploit, Burp Suite, Nmap, as well as certifications like CEH (Certified Ethical Hacker) or OSCP (Offensive Security Certified Professional) are highly valued. Strong problem-solving, critical thinking, and clear communication are essential soft skills for success in this position. These abilities are crucial because they enable professionals to effectively identify security weaknesses, communicate risks, and recommend solutions to protect organizational assets.
What are the typical daily responsibilities of a penetration testing ethical hacker?
Typical daily responsibilities for a penetration testing ethical hacker include planning and conducting simulated cyberattacks on client systems, documenting and analyzing security vulnerabilities, and compiling detailed reports of findings and recommendations. You may also participate in meetings with stakeholders to discuss risks and remediation strategies, as well as stay up to date with emerging threats and security tools. Collaborative work with IT, DevOps, and security teams is common to ensure thorough assessment and implementation of cybersecurity best practices. This dynamic and analytical role offers variety, challenge, and opportunities for continuous learning in the rapidly evolving field of information security.

Full-time
Re-posted 12 days ago
Job description
KPMG is currently seeking a Senior Specialist, MAST Application Penetration Tester to join our Managed Services practice. The role involves conducting manual application penetration testing and executing threat modeling while ensuring high professional standards in a collaborative environment.
Responsibilities:
• Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications
• Perform objective based on abstract penetration testing engagements
• Execute threat modeling, evaluate application business logic, and perform application architecture reviews
• Demonstrate application testing experience in real time via demos to both internal and external audiences
• Function independently in penetration testing engagements, with minimal oversight and guidance
• Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
Qualifications:
Required:
• Minimum three years of recent experience in application penetration testing of Application Programming Interface (API's), web applications, or mobile applications
• Bachelor's degree from an accredited college/university or equivalent industry experience
• Ability to communicate reporting results with technical and non-technical audiences and lead remediation conversations
• Experience with burp suite pro, and other app testing tools such as Netsparker and Checkmarx
• Ability to travel as required
• Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa)
Preferred:
• One or more major ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert (OSWE), Offensive Security Web Assessor (OSWA)
Company:
KPMG is one of the world’s leading professional services firms and the fastest growing Big Four accounting firm in the United States. Founded in 2010, the company is headquartered in New York, USA, with a team of 10001+ employees. The company is currently Late Stage.