1

Penetration Testing Salary Jobs (NOW HIRING)

Be Seen First

Penetration Tester

Knoxville, TN · Remote

$120K - $145K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

At Zelvin, penetration testing is not about generating a list of vulnerabilities. Our testers think ... Base salary is determined by experience, technical capability, certifications, and overall ...

New

Senior Penetration Tester

Middletown, RI

$118K - $128K/yr

  • Medical

  • Retirement

  • PTO

Penetration Testing: Plan, execute, and report on penetration tests and security assessments on ... The salary range for this position is USD $118,000.00/Yr. - USD $128,000/Yr. Actual compensation ...

Senior Penetration Tester

Tampa, FL · On-site

  • Medical

  • Retirement

Plan, scope, and execute penetration testing engagements across a variety of environments ... We offer a competitive total rewards package including base salary determined based on the role ...

SME Penetration Tester

Chantilly, VA · On-site

$150K - $190K/yr

  • Medical

  • Dental

  • Retirement

... Penetration Testing will help shape the future of cybersecurity and engineering solutions. Compensation and Benefits: * Competitive salary based on experience. * Comprehensive benefits package ...

Data Architect

Quantico, VA · Hybrid

$133K - $222K/yr

  • Medical

  • Retirement

  • PTO

The salary range for this position is USD $133,000.00/Yr. - USD $222,100.00/Yr. Actual compensation will be determined based on several factors permitted by law. AMERICAN SYSTEMS provides for the ...

Cleared Penetration Tester

Herndon, VA · On-site

$130K - $160K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Familiarity of penetration testing in cloud environments encompassing a variety of technology stacks Posted Salary Range $130,000 - $160,000 annual salary What Fortreum Offers We offer a competitive ...

Senior Penetration Tester

Denver, CO · On-site

$124 - $163/hr

  • Medical

  • Dental

  • Retirement

... Penetration Testing will help shape the future of cybersecurity and engineering solutions. Compensation and Benefits * Competitive salary based on experience. * Comprehensive benefits package ...

Senior Penetration Tester

Tampa, FL · On-site

$156K - $260K/yr

  • Medical

  • Retirement

Plan, scope, and execute penetration testing engagements across a variety of environments ... We offer a competitive total rewards package including base salary determined based on the role ...

Senior Penetration Tester

Tampa, FL · On-site

  • Medical

  • Retirement

Plan, scope, and execute penetration testing engagements across a variety of environments ... We offer a competitive total rewards package including base salary determined based on the role ...

Be Seen First

Penetration Tester

Knoxville, TN · Remote

$120K - $145K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

At Zelvin, penetration testing is not about generating a list of vulnerabilities. Our testers think ... Base salary is determined by experience, technical capability, certifications, and overall ...

New

SME Penetration Tester

Denver, CO · On-site

$144K - $187K/yr

  • Medical

  • Dental

  • Retirement

... Penetration Testing will help shape the future of cybersecurity and engineering solutions. Compensation and Benefits: * Competitive salary based on experience. * Comprehensive benefits package ...

Penetration Tester II

Chandler, AZ · On-site

$60K - $180K/yr

Experience with continuous penetration testing methodologies. * Experience with planning and ... M9 Benefits - Salary Range $60,000-$180,000 USD M9 Solutions, LLC (M9) is a Federal sub-contractor ...

Showing results 41-60

Penetration Testing Salary information

See salary details

$22.5K

$119.9K

$168.5K

How much do penetration testing salary jobs pay per year?

As of Aug 15, 2026, the average yearly pay for penetration testing salary in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a penetration tester, and why are they important?

To thrive as a Penetration Tester, you need a solid understanding of cybersecurity principles, networking, ethical hacking methodologies, and typically a degree in computer science or a related field. Mastery of tools such as Metasploit, Burp Suite, and knowledge of operating systems like Linux, as well as certifications like OSCP or CEH, are highly valued. Critical thinking, problem-solving, and effective communication are essential soft skills for translating technical findings into actionable recommendations. These abilities are crucial for identifying vulnerabilities, safeguarding organizations, and clearly conveying risks to both technical and non-technical stakeholders.

What is the difference between Penetration Testing Salary vs Vulnerability Analyst Salary?

AspectPenetration Testing SalaryVulnerability Analyst Salary
Required CredentialsCertifications like OSCP, CEH, GPENCertifications like CISSP, GIAC, CEH
Work EnvironmentEngages in simulated attacks, penetration testsIdentifies and reports security vulnerabilities
Employer & Industry UsageUsed by security firms, IT departments, consultingUsed by security teams, risk management, compliance

Penetration Testing Salary and Vulnerability Analyst Salary share similar credentials and work environments but differ in focus. Penetration testers actively exploit vulnerabilities, while vulnerability analysts identify and assess them. Both roles are vital in cybersecurity and often overlap in skills and certifications.

Is a penetration tester a good job?

A penetration tester is a cybersecurity professional who assesses computer systems for vulnerabilities using tools like Kali Linux and exploits. The role offers high demand, competitive salaries, and opportunities for certification such as OSCP or CEH. It requires strong technical skills, problem-solving ability, and often involves working in a fast-paced environment.

What is the average salary for a penetration tester?

The average salary for a penetration tester varies depending on experience, location, and industry. In the United States, entry-level penetration testers typically earn between $60,000 and $85,000 per year, while more experienced professionals can make $100,000 to $130,000 or more. Senior-level penetration testers and those with specialized certifications may command even higher salaries. Factors such as certifications, technical skills, and the size of the employer also play a significant role in compensation.

What are some common career advancement paths for professionals in penetration testing?

Professionals in penetration testing often advance by specializing in areas such as application security, red teaming, or cloud security, or by moving into leadership roles like security consultant, security architect, or team lead. Many also pursue certifications (such as OSCP or CISSP) to open up higher-level positions. Additionally, experienced penetration testers may transition into roles focused on security strategy, incident response, or even training and mentoring new testers. Career progression typically depends on a mix of technical expertise, hands-on experience, and ongoing learning.
More about Penetration Testing Salary jobs

What cities are hiring for Penetration Testing Salary jobs?

Cities with the most Penetration Testing Salary job openings:

What states have the most Penetration Testing Salary jobs?

States with the most job openings for Penetration Testing Salary jobs include:

Infographic showing various Penetration Testing Salary job openings in the United States as of August 2026, with employment types broken down into 88% Full Time, 10% Part Time, and 2% Contract. Highlights an 91% Physical, 3% Hybrid, and 6% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

Lead Penetration Tester

Revolutional, LLC

Washington, DC

$110 - $150K/hr

Full-time

Re-posted 2 days ago


Job description

Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes.

We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy.

Lead Penetration Tester

Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (project-based; onsite)

Terms: Full-time

Salary Range: $110-$150k DOE

Clearance: Active Secret required

Travel: Yes – travel to agency sites required

Project Description

This position leads operational security assessments and penetration testing across a portfolio of federal agencies and web applications. Assessments are conducted in accordance with the ISC Security Assessment Methodology and applicable federal rules of engagement, producing findings that reach agency CIO and CISO-level leadership. The program also requires FedRAMP-qualified penetration testing support for cloud service authorization activities.

The core challenge: leading a high-tempo assessment program across multiple agencies per year — each with distinct environments, rules of engagement, and stakeholder expectations — while producing deliverables that meet the evidentiary and presentation standards of senior federal leadership.

Position Description

As a Lead Penetration Tester at Revolutional, you own the end-to-end execution of operational security assessments and web application penetration tests across a federal agency portfolio. You develop test plans, lead technical execution, produce security assessment reports and criticality matrices, and deliver out-brief presentations directly to agency CIO and CISO-level audiences. You are the senior technical authority on every engagement you lead.

You bring deep experience with federal assessment methodologies — ISC Security Assessment Methodology, OWASP, NIST SP 800 series, and DISA STIG — and hold or are actively pursuing CISA AES certification. You are equally comfortable executing a technically complex assessment and standing in front of agency leadership to explain what you found and what it means.

What You Will Own
  • Operational security assessment leadership across a portfolio of federal agencies (approximately 6–7 per year)
  • Web application security assessments (approximately 3–4 applications per year)
  • Test plan and rules of engagement development for each assessment
  • Criticality matrix development and risk prioritization
  • Security assessment report authorship and quality
  • Out-brief presentations to agency CIO and CISO-level leadership
  • FedRAMP penetration testing support for cloud service authorization
Responsibilities
  • Lead operational security assessments across federal agencies in accordance with the ISC Security Assessment Methodology and applicable rules of engagement; manage approximately 6–7 agency assessments per year
  • Conduct web application security assessments using OWASP methodology; assess approximately 3–4 applications per year across a range of agency environments
  • Develop comprehensive test plans for each engagement: scope definition, assessment objectives, methodology selection, rules of engagement, and timeline
  • Build criticality matrices that prioritize findings by risk, asset value, and mission impact to support agency remediation planning
  • Author detailed security assessment reports documenting findings, evidence, risk ratings, and actionable remediation guidance meeting federal evidentiary and reporting standards
  • Develop and deliver out-brief presentations to agency CIO, CISO, and senior leadership audiences; communicate complex technical findings with clarity and executive-level credibility
  • Conduct FedRAMP-qualified penetration testing in support of cloud service authorization activities; apply FedRAMP pen testing requirements and documentation standards
  • Apply NIST SP 800 series guidance and DISA STIG methodology throughout assessment planning, execution, and reporting
  • Coordinate with agency stakeholders before, during, and after assessments to manage expectations, address questions, and ensure findings are understood and acted upon
  • Stay current on vulnerability research, offensive techniques, and emerging attack surfaces relevant to federal civilian agency environments
What You Bring (Requirements)Baseline Requirements
  • Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience)
  • 5 or more years of hands-on penetration testing experience, with demonstrated experience leading assessments in federal environments
  • CISA AES (Authorized External Security) certification required, or actively in process of obtaining
  • FedRAMP penetration testing experience required
  • Active Secret clearance
  • Ability and willingness to travel to agency sites as required
Technical & Domain Capabilities
  • Deep experience conducting operational security assessments in accordance with the ISC Security Assessment Methodology and federal rules of engagement
  • Proficiency with OWASP methodology applied to web application security assessments across federal environments
  • Working knowledge of NIST SP 800 series guidance as applied to security assessment planning, execution, and reporting
  • Experience applying DISA STIG methodology to assessment scope and findings documentation
  • Experience developing test plans, criticality matrices, and security assessment reports that meet federal evidentiary and leadership reporting standards
  • Demonstrated experience presenting technical security findings to CIO, CISO, and senior agency leadership audiences
  • FedRAMP-qualified penetration testing experience, including familiarity with FedRAMP pen test requirements, documentation, and cloud authorization processes
  • Proficiency with industry-standard penetration testing toolsets for network, application, and infrastructure assessments
Core Strengths
  • Senior assessment lead: you own engagements end-to-end and your findings are technically sound, clearly documented, and risk-rated with precision
  • Executive-ready communicator — you develop and deliver out-brief presentations that land with CIO and CISO audiences, not just technical teams
  • Methodologically disciplined: you work within rules of engagement, document everything, and produce deliverables that hold up under agency and regulatory scrutiny
  • High-tempo operator who manages multiple concurrent engagements across different agency environments without loss of quality or attention to detail
Certifications

The following certifications are required or strongly preferred:

Required
  • CISA AES (Authorized External Security) Assessment Lead or Technical Lead certification (or actively in process)
Strongly Preferred
  • GPEN (GIAC Penetration Tester), GXPN (GIAC Exploit Researcher and Advanced Penetration Tester), OSCP (Offensive Security Certified Professional), or equivalent offensive security credential
  • GWAPT (GIAC Web Application Penetration Tester) or equivalent web application security certification
Nice to Have (Differentiators)
  • Experience conducting CISA AES assessments as Assessment Lead across multiple federal civilian agencies
  • Familiarity with FedRAMP High, Moderate, and Low authorization boundaries and their penetration testing implications
  • Background in Red Team operations or adversary emulation in addition to structured assessment methodology
  • Experience with cloud-native application security assessments (AWS, Azure, GCP, or GovCloud)
  • Active TS/SCI clearance

#DICE #LinkedIn

___________________________________________________________________________________________________________

Here at Revolutional we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day. Some of these recognitions include:

  • Recognized as a Top 20 "Best Place to Work in Virginia"
  • Recipient of Department of Labor's HireVets Gold Medallion
  • Great Place to Work Certification for five years running
  • A Virginia Chamber of Commerce Fantastic 50 company
  • A Northern Virginia Technology Council Tech 100 company
  • Inc. 5000 list of fastest growing companies for eleven years
  • Two-time SBA SBIR Tibbett's Award winner
  • Virginia Values Veterans (V3) Certification

We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Revolutional family! In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to

  • Traditional and HSA- eligible medical insurance plans
  • 100% employer-paid dental and vision insurance options
  • 100% employer-sponsored STD, LTD, and life insurance
  • 5% 401(k) company matching
  • Flexible-schedules and teleworking options
  • Paid holidays and PTO Accrual Plans
  • Paid Parental Leave
  • Professional development and career growth opportunities
  • Team and company-wide events, recognition, and appreciation-- and so much more!

Check out our Revolutional | LinkedIn to find out a little more about who we are and if we are the right next step for your career!

Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Revolutional does and will take affirmative action to employ and advance in employment individuals with disabilities and protected veterans. To perform the above job successfully, an individual must possess the knowledge, skills, and abilities listed; meet the education and work experience required; and must be able to perform each essential duty and responsibility satisfactorily. Other duties in addition to those listed may be assigned as necessary to meet business needs. Reasonable accommodation will be made to enable an applicant with a disability to successfully apply for and/or perform the essential duties of the job. If you are in need of an accommodation, please contact HR@revolutional.com.