1

Physical Penetration Tester Jobs (NOW HIRING)

The Cybersecurity Penetration Tester is a hands-on technical role responsible for conducting ... Work Environment and Physical Demands: * This is primarily a Telework position with a requirement ...

Penetration Tester

Quantico, VA · On-site

$130K - $147K/yr

The Cybersecurity Penetration Tester is a hands-on technical role responsible for conducting ... Work Environment and Physical Demands: * This is primarily a Telework position with a requirement ...

ASRC Federal Technology Solutions is seeking an experienced Penetration Tester to lead advanced ... Ensure compliance with business continuity, operations security, insider threat detection, physical ...

ASRC Federal Technology Solutions is seeking an experienced Penetration Tester to lead advanced ... Ensure compliance with business continuity, operations security, insider threat detection, physical ...

The Cybersecurity Penetration Tester is a hands-on technical role responsible for conducting ... Work Environment and Physical Demands: * This is primarily a Telework position with a requirement ...

Penetration Tester Location: Arlington, VA Security Clearance:Secret Duties and Responsibilities ... physical or mental disability, religion, sexual orientation, marital status, national origin, or ...

Description Tharros has an immediate opportunity for a Penetration Tester to support the US Navy ... Testing may be against physical, virtualized, or cloud-based systems. This position shall leverage ...

The Penetration Tester will assist in the development of cyber test plans, execute cyber tests, and ... Testing may be against physical, virtualized, or cloud-based systems. This position shall leverage ...

... systems, physical security technology, command and control integration, operational technology ... Responsibilities As a Penetration Tester, the selected individual will support the research ...

Overview Amyx is seeking a Sr. Penetration Tester for our DOD client to work remotely ... Physical Demands Employee needs to be able to sit at a workstation for extended periods; use hand(s ...

About the Role The Penetration Tester works to execute department activities and deliver high ... Execute social engineering tests, including phishing, vishing, and physical * Execute vulnerability ...

next page

Showing results 1-20

Physical Penetration Tester information

See salary details

$22.5K

$119.9K

$168.5K

How much do physical penetration tester jobs pay per year?

As of Sep 1, 2026, the average yearly pay for physical penetration tester in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What is a physical penetration tester?

A Physical Penetration Tester is a security professional who assesses the physical security of buildings and facilities by attempting to gain unauthorized access. They use techniques such as lock picking, tailgating, and bypassing security controls to identify vulnerabilities in physical security systems. Their goal is to help organizations strengthen their defenses by exposing weaknesses before malicious actors can exploit them. Physical Penetration Testers report their findings and provide recommendations for improving security measures.

What are some common challenges faced by physical penetration testers during onsite assessments?

Physical penetration testers often encounter challenges such as navigating strict access controls, adapting to unpredictable security personnel responses, and maintaining professionalism while simulating real-world intrusions. They must balance creativity with legal and ethical boundaries, ensuring they do not cause unintended disruptions. Additionally, testers frequently need to think quickly on their feet, document findings thoroughly, and communicate results clearly to both technical and non-technical stakeholders.

What are the key skills and qualifications needed to thrive as a physical penetration tester, and why are they important?

To thrive as a Physical Penetration Tester, you need a solid understanding of security systems, physical access controls, and security protocols, often supported by certifications like OSCP or GPEN. Familiarity with lock picking tools, RFID cloning devices, and surveillance evasion technologies is typically required. Strong problem-solving, discretion, and effective communication are standout soft skills for this role. These skills ensure accurate risk assessment, successful simulation of real-world threats, and clear reporting to improve organizational security.

What is the difference between Physical Penetration Tester vs Network Security Analyst?

AspectPhysical Penetration TesterNetwork Security Analyst
CertificationsOSCP, CEH, OSWPCompTIA Security+, CISSP, CEH
Work EnvironmentOn-site, physical security testingOffice, network monitoring, and analysis
Employer & IndustrySecurity firms, corporate security teamsIT departments, cybersecurity firms

The Physical Penetration Tester focuses on testing physical security measures like access controls and vulnerabilities in physical infrastructure. In contrast, the Network Security Analyst monitors and protects digital networks. Both roles require security certifications and work within security-focused environments, but their core responsibilities differ—one targets physical security, the other digital security.

Are physical penetration testers in demand?

Physical penetration testers are in increasing demand as organizations seek to identify vulnerabilities in their physical security measures. The role often requires skills in security assessments, access control, and sometimes certifications like OSCP or CEH. Growing concerns over security breaches have led to more opportunities in this specialized field.
More about Physical Penetration Tester jobs

What cities are hiring for Physical Penetration Tester jobs?

Cities with the most Physical Penetration Tester job openings:

What states have the most Physical Penetration Tester jobs?

States with the most job openings for Physical Penetration Tester jobs include:

What job categories do people searching Physical Penetration Tester jobs look for?

The top searched job categories for Physical Penetration Tester jobs are:

Infographic showing various Physical Penetration Tester job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 74% Full Time, 20% Part Time, 1% Temporary, 3% Contract, and 1% Nights. Highlights an 97% Physical, 1% Hybrid, and 2% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

Penetration Tester

Quantico, VA • Hybrid


asrcfh

7.8

Company rating: 7.8 out of 10

Based on 28 frontline employees who took The Breakroom Quiz

243rd of 450 rated engineering

People enjoy working here

Good employer

Paid breaks


Full-time

Re-posted 11 days ago


Job description

ASRC Federal is actively hiring a Penetration Tester in support of our Defense Counterintelligence Security Agency (DCSA) program based out of Quantico VA.

Remote flexibility available! Telework offered with a requirement to be onsite up to two (2) days a week at Quantico Marine Corps Base VA.

Position Description:

The Cybersecurity Penetration Tester is a hands-on technical role responsible for conducting simulated attacks on systems and networks to identify vulnerabilities and weaknesses that could be exploited by malicious actors. This role requires a deep understanding of security principles, hacking techniques, and attack methodologies. The Penetration Tester will plan, execute, and document penetration tests, provide recommendations for remediation, and contribute to the overall improvement of the organization's security posture.

Minimum Requirements: 

  • Minimum of 5 – 7 years of experience in security principles such as attack frameworks, threat landscapes, and attacker tactics, techniques and procedures. 
  • Proven experience conducting penetration tests of web applications, networks, and other systems.
  • Experience with a variety of penetration testing tools and techniques (e.g., Rapid7 Nexpose, Appspider Pro, Metasploit, Cobalt Strike and/or Burp Suite).
  • Active Top-Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI
  • Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent experience.
  • Must meet 8570 certification requirements at the time of hire.  IAT II Information Assurance Baseline (e.g., CASP+ CE, CCMP Security, CISA, CISSP, GCED, GCIH, Security+ CE or CCSP) In addition to the IA baseline, a CSSP Auditor cert is preferred (e.g., CEH, CySA+, CISA, GSNA, CFR or PenTest) 

 

Responsibilities:

  • Penetration Testing:
    • Conduct penetration tests of web applications, mobile applications, networks, cloud environments, and other systems.
    • Utilize a variety of tools and techniques to identify vulnerabilities, including SQL injection, cross-site scripting (XSS), buffer overflows, and other common attack vectors.
    • Perform reconnaissance to gather information about target systems and networks.
    • Develop and execute exploit code to demonstrate the impact of identified vulnerabilities.
    • Bypass security controls and evade detection.
  • Vulnerability Assessment:
    • Perform vulnerability assessments using automated scanning tools and manual techniques.
    • Analyze scan results to identify false positives and prioritize vulnerabilities.
    • Develop custom scripts and tools to automate vulnerability assessment tasks.
  • Reporting and Documentation:
    • Document all findings in detailed and comprehensive reports, including descriptions of vulnerabilities, methods used to exploit them, and recommendations for remediation.
    • Present findings to stakeholders, including technical teams and management.
    • Create and maintain documentation on penetration testing methodologies, tools, and techniques.
  • Remediation Support:
    • Provide guidance and technical assistance to system owners and developers on vulnerability remediation.
    • Validate remediation efforts to ensure that vulnerabilities have been properly addressed.
    • Conduct retests to verify the effectiveness of implemented security controls.
  • Research and Development:
    • Stay up-to-date on the latest security threats, vulnerabilities, and attack techniques.
    • Research and evaluate new penetration testing tools and methodologies.
    • Develop custom tools and scripts to enhance penetration testing capabilities.
    • Contribute to the development of security policies and procedures.
  • Collaboration:
    • Collaborate with other cybersecurity professionals, including security architects, incident responders, and security engineers.
    • Share knowledge and expertise with team members.
    • Participate in security training and awareness programs.
  • Ethical Hacking:
    • Conduct all penetration testing activities in a legal and ethical manner, adhering to established rules of engagement.
    • Protect the confidentiality and integrity of sensitive data.
    • Respect the privacy of users and systems.

Work Environment and Physical Demands: 

  • This is primarily a Telework position with a requirement to be onsite up to two (2) days a week
  • If alternate worksite is other than DCSA facilities or corporate office space, must have the reliable ability to communicate over voice (cell phone preferred) and stable, capable internet connection
  • Must be able to communicate complex technical ideas to a diverse customer base both verbally and in written form

What ASRC Federal employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom