2

Remote Penetration Test Jobs (NOW HIRING)

Lead the strategy for third party penetration tests * Reporting & Metrics: Deliver executive-level ... Whether you are working from our San Francisco or Phoenix offices or joining us as a fully remote ...

Lead the strategy for third party penetration tests * Reporting & Metrics: Deliver executive-level ... Whether you are working from our San Francisco or Phoenix offices or joining us as a fully remote ...

Senior Security Engineer

$117.20K - $160.70K/yr

This is an all-remote team and we are looking for someone located in the U.S. We do not offer visa ... Conduct internal penetration tests on systems and networks to determine realistic threat vectors

Senior Security Engineer

Santa Barbara, CA · Remote

$127.40K - $174.70K/yr

This is an all-remote team and we are looking for someone located in the U.S. We do not offer visa ... Conduct internal penetration tests on systems and networks to determine realistic threat vectors

This is a remote role . Product Security Engineers at Collibra are responsible for * Application ... IAST, DAST, and penetration tests. * Leverage AI and MCP to create intelligent, context-aware ...

... Remote Salary: $120,000 - $130,000 About Us: Capio Group is a California-based Information ... Provide testing expertise in usability, security (vulnerability and penetration), regression, user ...

Quality Assurance and Test Lead

Sacramento, CA · On-site +1

$120K - $130K/yr

... Remote Salary: $120,000 - $130,000 About Us: Capio Group is a California-based Information ... Provide testing expertise in usability, security (vulnerability and penetration), regression, user ...

next page

Showing results 1-20

Remote Penetration Test information

See salary details

$22.5K

$119.9K

$168.5K

How much do remote penetration test jobs pay per year?

As of May 31, 2026, the average yearly pay for remote penetration test in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What is the difference between Remote Penetration Test vs Vulnerability Analyst?

AspectRemote Penetration TestVulnerability Analyst
CertificationsOSCP, CEH, GPENCompTIA Security+, CISSP, CEH
Work EnvironmentHands-on testing, simulated attacksVulnerability scanning, risk assessment
Industry UsageCybersecurity firms, IT departmentsSecurity teams, consulting firms

Remote Penetration Testers focus on actively exploiting vulnerabilities to assess security defenses, while Vulnerability Analysts identify and prioritize security weaknesses through scanning and analysis. Both roles require similar certifications and often work within the same industry environments, but their core activities differ: penetration testing involves active exploitation, whereas vulnerability analysis emphasizes detection and reporting.

More about Remote Penetration Test jobs
What cities are hiring for Remote Penetration Test jobs? Cities with the most Remote Penetration Test job openings:
What are the most commonly searched types of Penetration Test jobs? The most popular types of Penetration Test jobs are:
What states have the most Remote Penetration Test jobs? States with the most job openings for Remote Penetration Test jobs include:
Infographic showing various Remote Penetration Test job openings in the United States as of May 2026, with employment types broken down into 83% Full Time, 13% Part Time, and 4% Contract. Highlights an 65% Physical, and 35% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

Sr/Staff Product Security Engineer

With Cherry, Inc

Remote

$117.20K - $160.70K/yr

Full-time

Medical, Dental, Vision, PTO

Posted yesterday


Job description

Staff Product Security Engineer
Remote • Full-Time • Engineering
About Cherry
Founded in 2019, Cherry is a fast-growing FinTech offering the simplest, fastest, and most inclusive BNPL solution for medical practices-including dental, medical aesthetics, and veterinary etc. We help practices treat more patients by making care financially accessible. Cherry is led by Stanford entrepreneurs with a previous successful exit and backed by top investors, including Kleiner Perkins and DCM.
About the Role
As Cherry scales its platform across thousands of medical practices and millions of patient transactions, security is foundational. We are looking for a Product Security Engineer to embed directly within our engineering organization, helping us build and ship secure products from the ground up. You will own security across our product surface area: from threat modeling new features to hardening our authentication systems, cloud infrastructure, and payment flows. This is a high-impact, high-ownership role at a meaningful inflection point for Cherry's growth.
What You'll Do:
  • Partner with product and engineering teams to perform security design reviews and threat modeling for new and existing features across Cherry's platform.
  • Own and evolve Cherry's product security program - including secure coding standards, vulnerability management, and security testing processes.
  • Lead security reviews for authentication and authorization systems, ensuring robust access control patterns across our web and mobile products.
  • Assess and improve the security posture of Cherry's cloud infrastructure including network controls, IAM policies, secrets management, and container security.
  • Champion security best practices for payment processing, financial and health data handling, in alignment with PCI DSS and relevant compliance frameworks.
  • Conduct or coordinate penetration tests, red team exercises, and bug bounty triage; drive remediation of identified vulnerabilities.
  • Build and maintain security tooling integrated into the SDLC - SAST, DAST, dependency scanning, and runtime protection.
  • Respond to security incidents, perform root cause analysis, and implement lasting fixes to prevent recurrence.
  • Educate and mentor engineers on security principles, fostering a culture of security ownership across the organization.
  • Monitor the threat landscape for emerging risks relevant to FinTech and healthcare-adjacent payment products.

What We're Looking For:
  • 5+ years of experience in product security, application security, or a related security engineering role.
  • Deep expertise in authentication and authorization - including OAuth 2.0, OIDC, JWT, SAML, RBAC/ABAC models, and session management.
  • Hands-on experience securing cloud environments (AWS preferred), including IAM, VPC, container orchestration (EKS/ECS), and infrastructure-as-code.
  • Strong understanding of secure software development practices - OWASP Top 10, threat modeling (STRIDE or similar), secure code review, and vulnerability remediation.
  • Experience integrating security tooling (SAST, DAST, SCA) into CI/CD pipelines.
  • Excellent communication skills - able to articulate security risk clearly to both technical and non-technical stakeholders.
  • Proven ability to work cross-functionally in a fast-paced, high-growth engineering environment.

Nice to Have:
  • Penetration testing experience, with the ability to conduct or lead internal red team exercises or external pentest engagements.
  • Familiarity with payment industry security - PCI DSS, tokenization, EMV, card transaction security.
  • Experience at a FinTech, healthcare technology, or other regulated-industry company.

Compensation & Benefits:
  • Competitive Base + Bonus
  • Generous equity grant
  • Medical, vision, and dental benefits
  • Fully remote company
  • Flexible PTO