2

Remote Application Penetration Tester Jobs in Raleigh, NC

Field Application Engineer '27

Raleigh, NC ยท On-site +1

$53K - $80K/yr

Provide on-call, on-site and remote technical support, training, and troubleshooting * Travel ... Conduct product testing and create detailed proposal reports to aid our sales team. * Work in ...

Sales, Marketing & Product Management Job Schedule: Full time Remote: No The opportunity Hitachi ... Background in commissioning, site testing, and routine or type testing of main components * Strong ...

AppSec Sales Engineer - East

Raleigh, NC ยท Remote

$57 - $76.25/hr

Deliver world-class platform presentations and demos focused on Application Security Testing and ... Work Location * Remote role, strong preference for Raleigh area What You Will Have At Harness

Citrix Engineer (Remote)

Cary, NC ยท On-site +1

$73K - $114K/yr

Cary, NC, Remote Organization: WCG Job Type: Full Time - Regular Description and Requirements ABOUT ... Build, deliver and maintain desktop OS and application images. Participate in testing, provisioning ...

next page

Showing results 1-20

Remote Application Penetration Tester information

See Raleigh, NC salary details

$93.8K

$128.6K

$155K

How much do remote application penetration tester jobs pay per year?

As of Aug 26, 2026, the average yearly pay for remote application penetration tester in Raleigh, NC is $128,613.00, according to ZipRecruiter salary data. Most workers in this role earn between $118,100.00 and $142,400.00 per year, depending on experience, location, and employer.

What is a remote application penetration tester?

A Remote Application Penetration Tester is a cybersecurity professional who evaluates the security of software applications from a remote location. They simulate cyberattacks on web, mobile, or cloud applications to identify vulnerabilities that could be exploited by malicious actors. Their work involves using specialized tools and techniques to test the application's defenses, report findings, and recommend solutions to improve security. By working remotely, they can assess applications from anywhere, providing flexibility and broad coverage for organizations.

What are the key skills and qualifications needed to thrive as a remote application penetration tester, and why are they important?

To thrive as a Remote Application Penetration Tester, you need in-depth knowledge of web and mobile application security, strong understanding of networking, and experience with common programming languages and security frameworks, often backed by certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Metasploit, Nmap, and vulnerability scanners is expected. Outstanding analytical thinking, attention to detail, and clear written communication set top performers apart. These skills are essential to identify vulnerabilities, provide actionable recommendations, and ensure robust application security in diverse, remote environments.

How does a remote application penetration tester typically collaborate with development teams to address identified vulnerabilities?

Remote application penetration testers often work closely with development teams by providing detailed reports on vulnerabilities discovered during assessments, including risk ratings and remediation recommendations. Communication usually takes place via secure collaboration tools, video calls, and ticketing systems to track progress on fixing issues. Testers may also participate in follow-up meetings or retesting efforts to verify that vulnerabilities have been properly addressed. Building effective working relationships and clear communication are key to ensuring that security improvements are implemented efficiently in distributed, remote environments.

What is the difference between Remote Application Penetration Tester vs Remote Security Analyst?

AspectRemote Application Penetration TesterRemote Security Analyst
CertificationsOSCP, CEH, GPENCISSP, Security+
Work EnvironmentHands-on testing, vulnerability assessmentsMonitoring, incident response, policy development
Industry UsageCybersecurity firms, tech companies, consultingFinancial, healthcare, government sectors

The Remote Application Penetration Tester focuses on identifying vulnerabilities in applications through active testing, while the Remote Security Analyst monitors security systems and responds to threats. Both roles require cybersecurity certifications and are vital in protecting organizational assets, but they differ in daily tasks and focus areas.

What are the most commonly searched types of Application Penetration Tester jobs in Raleigh, NC?

The most popular types of Application Penetration Tester jobs in Raleigh, NC are:

What are popular job titles related to Remote Application Penetration Tester jobs in Raleigh, NC?

For Remote Application Penetration Tester jobs in Raleigh, NC, the most frequently searched job titles are:

What job categories do people searching Remote Application Penetration Tester jobs in Raleigh, NC look for?

The top searched job categories for Remote Application Penetration Tester jobs in Raleigh, NC are:

What cities near Raleigh, NC are hiring for Remote Application Penetration Tester jobs?

Cities near Raleigh, NC with the most Remote Application Penetration Tester job openings:

AWS Security Engineer (DevSecOps)

Meta Force Technology Staffing LLC

Raleigh, NC โ€ข Remote

Contractor

Re-posted 24 days ago


Job description

AWS Security Engineer (DevSecOps)
Location: Remote
Duration: 12 Months
Important Notes:
* Location: Remote – anywhere in the US and need to support during EST/CST hours.
* Early submissions will receive priority consideration.
 
Key Responsibilities:
* Design and implement secure AWS architectures following the AWS Well-Architected Framework (Security Pillar).
* Manage and govern IAM, SSO, KMS, CloudTrail, Config, and Security Hub.
 
Configure & Maintain AWS Native Security Services:
* GuardDuty, Macie, Inspector, Detective, WAF, Shield, and Firewall Manager.
* Build automated security policies and compliance frameworks (CIS, NIST, ISO 27001, PCI DSS).
* Implement encryption at rest and in transit, enforce TLS, and key rotation via KMS.
* Develop and run incident detection, alerting, and response workflows using EventBridge, Lambda, and SNS.
* Integrate AWS Security Hub and GuardDuty findings into SIEM platforms (Splunk, Elastic, etc.).
 
Systems & Infrastructure Engineering:
* Manage and secure Linux/Windows systems running on EC2, EKS, and ECS.
* Build, automate, and maintain infrastructure with Terraform, CloudFormation, or AWS CDK.
* Configure VPCs, subnets, NAT gateways, Transit Gateway, and PrivateLink for secure network segmentation.
* Implement system patching, configuration management, and OS-level hardening (CIS benchmarks).
* Design and manage backups, disaster recovery, and multi-region high availability setups.
* Automate system monitoring, logging, and remediation with CloudWatch, SSM, and Config Rules.
 
DevSecOps:
* Integrate security scanning and compliance checks into CI/CD pipelines (GitHub Actions, Jenkins, CodePipeline).
* Automate vulnerability management (ECR image scanning, Inspector, Trivy, or Twistlock).
* Develop infrastructure automation for identity provisioning, logging, and access control.
* Create reusable Terraform modules and templates for AWS accounts and VPCs.
* Implement infrastructure drift detection and self-healing automation.
 
Monitoring, Audit & Compliance:
* Implement centralized log aggregation with CloudWatch Logs, OpenSearch, or SIEM tools.
* Monitor security posture continuously via Security Hub, Config, and GuardDuty dashboards.
* Conduct regular vulnerability scans, penetration testing coordination, and security posture reviews.
* Manage audit readiness and evidence collection for compliance frameworks (SOC2, ISO27001, HIPAA).
* Develop runbooks and playbooks for incident response and operational processes.
 
Preferred Qualifications:
* AWS Certified Security – Specialty (strongly preferred).
* Experience with multi-account AWS Organizations, Control Tower, and Service Control Policies (SCPs).
* Knowledge of container security (EKS, ECS, Bottlerocket, Karpenter).
* Experience with SIEM/SOAR integrations and automated incident response.
* Exposure to Zero Trust and Network Segmentation design principles.