1

Penetration Testing Jobs (NOW HIRING)

Senior Penetration Tester

Washington, DC · On-site

$124K - $180K/yr

Lead, plan, and oversee penetration testing operations for systems, networks, cloud resources, and web‑based applications in a TS/SCI environment * Execute comprehensive vulnerability assessments ...

This role is responsible for conducting penetration testing and red team activities, assessing security posture across enterprise environments, and supporting identification, validation, and ...

Penetration Testers - Senior (Lead)

Washington, DC · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

This individual will serve as the technical lead for SBA's penetration testing program, providing expert guidance on adversary simulation, vulnerability exploitation, and security control validation ...

Penetration Tester

Quantico, VA · On-site

$130K - $147K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Experience with a variety of penetration testing tools and techniques (e.g., Rapid7 Nexpose, Appspider Pro, Metasploit, Cobalt Strike and/or Burp Suite). * Active Top-Secret Clearance REQUIRED ...

Senior Penetration Tester

Washington, DC · On-site

$124K - $180K/yr

Lead, plan, and oversee penetration testing operations for systems, networks, cloud resources, and web-based applications in a TS/SCI environment * Execute comprehensive vulnerability assessments and ...

Penetration Tester

Rensselaer, NY · On-site

$90K - $105K/yr

Key Responsibilities Penetration Testing and Vulnerability Assessment * Conduct penetration tests and vulnerability assessments for Java applications and infrastructure. * Identify security flaws in ...

Experience with a variety of penetration testing tools and techniques (e.g., Rapid7 Nexpose, Appspider Pro, Metasploit, Cobalt Strike and/or Burp Suite). * Active Top-Secret Clearance REQUIRED ...

This role is responsible for conducting penetration testing and red team activities, assessing security posture across enterprise environments, and supporting identification, validation, and ...

Tharros is seeking a Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer to support a DHS Intelligence and Analysis cybersecurity program in the National Capital ...

Penetration Tester

Leesburg, VA · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Document all testing activities, findings, and exploitation paths in Penetration Test Reports (PTRs). * Perform regression penetration tests to validate remediation of previously identified ...

Penetration Tester

Arlington, VA · On-site

$86K - $138K/yr

Minimum of 2 years with penetration testing experience. * Possess one of the following certifications, OR be able to obtain before start date: * CCNA Cyber Ops, CCNA-Security, CEH, CFR, Cloud+, CySA ...

Security Penetration Testing Engineer

Eagan, MN · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Security Penetration Testing Engineer Location: Eagan, MN Duration: 6 Months Major Areas of Accountability: Conduct formal both automated and manual penetration tests using approved standard ...

Perform web application, infrastructure, and application-level penetration testing. Conduct security design reviews to ensure compliance with NATO security policies and directives. Provide ...

Showing results 41-60

Penetration Testing information

See salary details

$22.5K

$119.9K

$168.5K

How much do penetration testing jobs pay per year?

As of Aug 17, 2026, the average yearly pay for penetration testing in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What is penetration testing?

Penetration testing, also known as ethical hacking, is a security practice where professionals simulate cyberattacks on a computer system, network, or application to identify vulnerabilities before malicious hackers can exploit them. The goal is to find and safely exploit weaknesses, assess the impact of potential attacks, and provide recommendations to improve security. Penetration testers use a variety of tools and techniques, often mirroring real-world attack methods, to thoroughly evaluate an organization’s defenses. It is a proactive approach to improving an organization's cybersecurity posture.

What are some common challenges faced by penetration testers during client engagements?

Penetration testers often encounter challenges such as limited access to information, time constraints, and complex network environments that can hinder thorough assessments. Additionally, balancing the need to simulate real-world attacks while ensuring no disruption to client operations requires careful planning and communication. Collaborating effectively with IT teams and clearly documenting findings are crucial for ensuring that vulnerabilities are properly understood and addressed.

What is the difference between Penetration Testing vs Vulnerability Assessment?

AspectPenetration TestingVulnerability Assessment
PurposeSimulate cyberattacks to identify exploitable vulnerabilitiesIdentify and prioritize security weaknesses
DepthIn-depth, targeted testingBroad, comprehensive scanning
CertificationsOSCP, CEH, GPENOSCP, CEH, Security+
Work EnvironmentHands-on testing, simulated attacksAutomated scans, reports

While both roles focus on security weaknesses, Penetration Testing involves actively exploiting vulnerabilities to assess real-world impact, whereas Vulnerability Assessment identifies potential issues for prioritization. Penetration Testing provides a deeper, more targeted security evaluation, making it essential for comprehensive security testing.

What cities are hiring for Penetration Testing jobs?

Cities with the most Penetration Testing job openings:

What are the most commonly searched types of Penetration Testing jobs?

The most popular types of Penetration Testing jobs are:

What states have the most Penetration Testing jobs?

States with the most job openings for Penetration Testing jobs include:

Infographic showing various Penetration Testing job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 85% Full Time, 9% Part Time, 4% Contract, and 1% Nights. Highlights an 89% Physical, 2% Hybrid, and 9% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

Senior Penetration Tester

Govcio LLC

Washington, DC • On-site

$124K - $180K/yr

Other

Posted 20 days ago


GovCIO rating

7.5

Company rating: 7.5 out of 10

Based on 9 frontline employees who took The Breakroom Quiz

109th of 224 rated it services


Job description

Overview:

GovCIO is currently hiring for a Senior Pentration Tester with an active TS/SCI clearance to support DHS onsite in Washington, DC.

Responsibilities:

The Senior Penetration Tester serves as Key Personnel responsible for leading advanced penetration testing and vulnerability assessment activities within a TS/SCI environment. This role ensures mission‑critical security assurance across enterprise systems, applications, and cloud infrastructures by applying deep technical expertise, zero‑trust principles, and attacker‑focused methodologies. The Senior Penetration Tester guides technical direction, ensures rigorous execution, and provides authoritative recommendations to strengthen security posture across sensitive environments.

  • Lead, plan, and oversee penetration testing operations for systems, networks, cloud resources, and web‑based applications in a TS/SCI environment

  • Execute comprehensive vulnerability assessments and software assurance evaluations; authoritatively document findings and drive remediation strategies

  • Conduct deep technical analysis of vulnerabilities including buffer overflows, SQL injection, CSRF, XSS, race conditions (TOCTOU), XXE, encryption weaknesses, authentication bypass, and similar issues

  • Assess and advise on security considerations during software acceptance activities, including criteria definition, risk acceptance evaluation, documentation review, and independent validation approaches

  • Apply advanced security defense functions (encryption, access control, identity management) to reduce exploitation risks, including those related to supply chain considerations

  • Provide threat intelligence insights and vulnerability research aligned with frameworks such as NIST 800‑53 and MITRE ATT&CK to inform cloud security architecture decisions

  • Develop new or enhanced penetration testing methodologies to identify emerging vulnerabilities and expand organizational capability

  • Serve as a senior technical advisor and mentor to penetration testing staff; ensure consistency, quality, and rigor in testing execution

  • Represent the penetration testing function in discussions with leadership, engineering teams, and mission stakeholders as required for Key Personnel roles

Qualifications:
  • Bachelor's with 12+ years of penetration testing experience (or commensurate experience)
  • Minimum of 8 years of experience supporting enterprise security architectures and cloud platforms (AWS, Azure, Google Cloud)

  • Proven, extensive experience as a Penetration Tester in complex or classified environments

  • Advanced knowledge of penetration testing methodologies, offensive security techniques, and industry tools

  • Experience with AWS, Azure, RHEL, Linux, and Tenable

  • Hands-on experience with tools including Kali Linux, Burp Suite Pro, and Metasploit

  • Strong analytical and problem‑solving skills with an ability to think like an attacker

  • Excellent communication skills to deliver clear, actionable findings to both technical and executive stakeholders

  • Preferred certifications: CEH, OSCP, or equivalent offensive security certifications

  • Clearance Required: Active TS/SCI clearance
Posted Salary Range: USD $124,540.00 - USD $180,000.00 /Yr.

What GovCIO employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom