1

Penetration Testing Jobs in Chicago, IL (NOW HIRING)

Perform hands-on penetration testing with a primary focus on web applications and web APIs across homegrown and vendor systems, support testing of cloud, mobile, and internal systems. * Conduct ...

Participates in client penetration testing and vulnerability assessment engagements across external and internal networks, Active Directory, web applications, APIs, cloud platforms, and Microsoft 365 ...

Participates in client penetration testing and vulnerability assessment engagements across external and internal networks, Active Directory, web applications, APIs, cloud platforms, and Microsoft 365 ...

Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.

Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.

Conduct web application penetration testing (covering OWASP Top 10, API security, authentication/authorization flaws, business logic vulnerabilities, and modern web frameworks). * Perform mobile ...

Senior Penetration Tester

Northbrook, IL · Hybrid

$110K - $140K/yr

As a Senior Penetration Tester, you will lead technical engagements responsible for evaluating and ... UL Solutions delivers testing, inspection and certification services, together with software ...

next page

Showing results 1-20

Penetration Testing information

See Chicago, IL salary details

$23.2K

$123.6K

$173.7K

How much do penetration testing jobs pay per year?

As of Sep 7, 2026, the average yearly pay for penetration testing in Chicago, IL is $123,606.00, according to ZipRecruiter salary data. Most workers in this role earn between $99,000.00 and $145,400.00 per year, depending on experience, location, and employer.

What is penetration testing?

Penetration testing, also known as ethical hacking, is a security practice where professionals simulate cyberattacks on a computer system, network, or application to identify vulnerabilities before malicious hackers can exploit them. The goal is to find and safely exploit weaknesses, assess the impact of potential attacks, and provide recommendations to improve security. Penetration testers use a variety of tools and techniques, often mirroring real-world attack methods, to thoroughly evaluate an organization’s defenses. It is a proactive approach to improving an organization's cybersecurity posture.

What are some common challenges faced by penetration testers during client engagements?

Penetration testers often encounter challenges such as limited access to information, time constraints, and complex network environments that can hinder thorough assessments. Additionally, balancing the need to simulate real-world attacks while ensuring no disruption to client operations requires careful planning and communication. Collaborating effectively with IT teams and clearly documenting findings are crucial for ensuring that vulnerabilities are properly understood and addressed.

What is the difference between Penetration Testing vs Vulnerability Assessment?

AspectPenetration TestingVulnerability Assessment
PurposeSimulate cyberattacks to identify exploitable vulnerabilitiesIdentify and prioritize security weaknesses
DepthIn-depth, targeted testingBroad, comprehensive scanning
CertificationsOSCP, CEH, GPENOSCP, CEH, Security+
Work EnvironmentHands-on testing, simulated attacksAutomated scans, reports

While both roles focus on security weaknesses, Penetration Testing involves actively exploiting vulnerabilities to assess real-world impact, whereas Vulnerability Assessment identifies potential issues for prioritization. Penetration Testing provides a deeper, more targeted security evaluation, making it essential for comprehensive security testing.

Are penetration testers high in demand?

Penetration testers are in high demand due to increasing cybersecurity threats and the need for organizations to identify vulnerabilities. The role often requires skills in tools like Kali Linux and certifications such as OSCP, with job growth expected to remain strong in the cybersecurity field.

Is penetration testing a good career?

Penetration testing is a growing cybersecurity field that involves identifying vulnerabilities in computer systems and networks. It requires technical skills, knowledge of security tools, and often certifications like OSCP or CEH. The role offers high demand, competitive salaries, and opportunities for continuous learning, making it a viable career choice for those interested in cybersecurity.

What are the most commonly searched types of Penetration Testing jobs in Chicago, IL?

The most popular types of Penetration Testing jobs in Chicago, IL are:

Infographic showing various Penetration Testing job openings in Chicago, IL as of August 2026, with employment types broken down into 67% Full Time, and 33% Part Time. Highlights an 67% In-person, and 33% Hybrid job distribution, with an average salary of $123,606 per year, or $59.4 per hour.

Senior Specialist, MAST Application Penetration Tester

KPMG US

Chicago, IL • On-site

Full-time

Re-posted 8 days ago


Job description

Job Summary:
KPMG is a leading advisory firm that offers excellent opportunities for career advancement. They are currently seeking a Senior Specialist, MAST Application Penetration Tester to conduct manual penetration testing and evaluate application security across various platforms.
Responsibilities:
• Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications
• Perform objective based on abstract penetration testing engagements
• Execute threat modeling, evaluate application business logic, and perform application architecture reviews
• Demonstrate application testing experience in real time via demos to both internal and external audiences
• Function independently in penetration testing engagements, with minimal oversight and guidance
• Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
Qualifications:
Required:
• Minimum three years of recent experience in application penetration testing of Application Programming Interface (API's), web applications, or mobile applications
• Bachelor's degree from an accredited college/university or equivalent industry experience
• Ability to communicate reporting results with technical and non-technical audiences and lead remediation conversations
• Experience with burp suite pro, and other app testing tools such as Netsparker and Checkmarx
• Ability to travel as required
• Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa)
Preferred:
• One or more major ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert (OSWE), Offensive Security Web Assessor (OSWA)
Company:
KPMG is one of the world’s leading professional services firms and the fastest growing Big Four accounting firm in the United States. Founded in 2010, the company is headquartered in New York, USA, with a team of 10001+ employees. The company is currently Late Stage.