2

Remote Penetration Tester Jobs in Reston, VA (NOW HIRING)

IT & Cyber Security Engineer

Washington, DC · On-site +1

$125K - $188K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Location: Remote - This position may be performed remotely in states where the company is ... Experience with penetration testing and security assessments * Experience implementing and ...

IT & Cyber Security Engineer

Washington, DC · On-site +1

$125K - $188K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Location: Remote - This position may be performed remotely in states where the company is ... Experience with penetration testing and security assessments * Experience implementing and ...

IT & Cyber Security Engineer

Washington, DC · On-site +1

$125K - $188K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Location: Remote - This position may be performed remotely in states where the company is ... Experience with penetration testing and security assessments * Experience implementing and ...

IT & Cyber Security Engineer

Washington, DC · On-site +1

$125K - $188K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Location: Remote - This position may be performed remotely in states where the company is ... Experience with penetration testing and security assessments * Experience implementing and ...

Senior Systems Architect

Washington, DC · On-site +1

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Remote work requires a high level of trust in our employees, and we strictly adhere to the details ... penetration testing, DevSecOps, Identity and Access Management, and AWS GovCloud systems.

... a remote setting, you will be supporting teams of professionals working to evaluate and secure a ... Certified Penetration Testing Engineer (CPTE) * Cybersecurity Analyst+ (CySA+) * Federal IT Securit ...

... a remote setting, you will be supporting teams of professionals working to evaluate and secure a ... Certified Penetration Testing Engineer (CPTE) * Cybersecurity Analyst+ (CySA+) * Federal IT Securit ...

AWS Cloud Security Engineer

Mclean, VA · Remote

$57 - $76.25/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer ... scanning, and penetration testing practices. * Support alignment with security and compliance ...

AWS Cloud Security Engineer

Mclean, VA · Remote

$57 - $76.25/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer ... scanning, and penetration testing practices. * Support alignment with security and compliance ...

AWS Cloud Security Engineer

Mclean, VA · Remote

$57 - $76.25/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer ... scanning, and penetration testing practices. * Support alignment with security and compliance ...

AWS Cloud Security Engineer

Mclean, VA · Remote

$57 - $76.25/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer ... scanning, and penetration testing practices. * Support alignment with security and compliance ...

AWS Cloud Security Engineer

Mclean, VA · Remote

$57 - $76.25/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer ... scanning, and penetration testing practices. * Support alignment with security and compliance ...

AWS Cloud Security Engineer

Mclean, VA · Remote

$57 - $76.25/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer ... scanning, and penetration testing practices. * Support alignment with security and compliance ...

AWS Cloud Security Engineer

Mclean, VA · Remote

$57 - $76.25/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer ... scanning, and penetration testing practices. * Support alignment with security and compliance ...

AWS Cloud Security Engineer

Mclean, VA · Remote

$57 - $76.25/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer ... scanning, and penetration testing practices. * Support alignment with security and compliance ...

AWS Cloud Security Engineer

Mclean, VA · Remote

$57 - $76.25/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer ... scanning, and penetration testing practices. * Support alignment with security and compliance ...

Showing results 41-60

Remote Penetration Tester information

See Reston, VA salary details

$23.4K

$124.7K

$175.3K

How much do remote penetration tester jobs pay per year?

As of Aug 14, 2026, the average yearly pay for remote penetration tester in Reston, VA is $124,733.00, according to ZipRecruiter salary data. Most workers in this role earn between $99,900.00 and $146,700.00 per year, depending on experience, location, and employer.

How does a remote penetration tester typically collaborate with in-house IT and security teams during an engagement?

Remote penetration testers often work closely with in-house IT and security teams through virtual meetings, secure communication platforms, and shared documentation. They coordinate to define testing scopes, clarify network boundaries, and discuss any findings in real time. Regular check-ins and status updates ensure transparency and alignment throughout the engagement. This collaborative approach helps address vulnerabilities promptly and fosters knowledge sharing between the remote tester and the organization’s internal teams.

Are remote penetration testers in demand?

Remote penetration testers are in high demand due to increasing cybersecurity threats and the need for organizations to identify vulnerabilities remotely. The role often requires skills in tools like Kali Linux and certifications such as OSCP, with many companies offering flexible remote work arrangements.

What is the difference between Remote Penetration Tester vs Remote Security Analyst?

AspectRemote Penetration TesterRemote Security Analyst
CertificationsOSCP, CEH, GPENCISSP, Security+
Work EnvironmentConducts simulated attacks, often independently or in teamsMonitors security systems, analyzes threats, and implements defenses
Employer & Industry UsageCybersecurity firms, consulting companies, large enterprisesCorporate IT departments, government agencies, financial institutions

Remote Penetration Testers focus on identifying vulnerabilities through simulated attacks, requiring offensive skills and certifications like OSCP or CEH. Remote Security Analysts monitor and defend networks, emphasizing defensive skills and certifications like CISSP. While both roles work remotely in cybersecurity, their core responsibilities and skill sets differ significantly.

What are the key skills and qualifications needed to thrive as a remote penetration tester, and why are they important?

To thrive as a Remote Penetration Tester, you need strong knowledge of cybersecurity principles, network protocols, and operating systems, often supported by certifications like OSCP, CEH, or CISSP. Familiarity with penetration testing tools such as Metasploit, Burp Suite, and Nmap, as well as secure remote collaboration platforms, is essential. Analytical thinking, attention to detail, and clear written communication skills help you document findings and collaborate with clients and teams remotely. These competencies ensure you can effectively identify vulnerabilities, communicate risks, and help organizations strengthen their security posture from any location.

What does a remote penetration tester do?

Remote penetration testers attempt to hack into an application, network, or computer to assess its security. Instead of working in the office, remote penetration testers complete their tasks from home or another location outside of the office with internet connectivity. As a remote penetration tester, you discuss the security concerns your client may have about their current computer system and develop ways to infiltrate the security of a network or computer hardware using the internet as a pathway. Other job duties may include documenting how you broke through a company's network security and providing recommendations for augmenting the protection of company files. Because of their hacking expertise, some remote penetration testers may be called in to help investigate cyber crimes in criminal cases.

What is a remote penetration tester?

A Remote Penetration Tester is a cybersecurity professional who evaluates the security of computer systems, networks, and applications by simulating cyberattacks from a remote location. Their goal is to identify vulnerabilities that malicious hackers could exploit and to provide recommendations for strengthening security. Working remotely, they use specialized tools and techniques to conduct assessments without being physically present at the client’s site. This role often involves preparing detailed reports and collaborating with IT teams to remediate identified risks.

What are the most commonly searched types of Penetration Tester jobs in Reston, VA?

The most popular types of Penetration Tester jobs in Reston, VA are:

What are popular job titles related to Remote Penetration Tester jobs in Reston, VA?

For Remote Penetration Tester jobs in Reston, VA, the most frequently searched job titles are:

What job categories do people searching Remote Penetration Tester jobs in Reston, VA look for?

The top searched job categories for Remote Penetration Tester jobs in Reston, VA are:

What cities near Reston, VA are hiring for Remote Penetration Tester jobs?

Cities near Reston, VA with the most Remote Penetration Tester job openings:

Infographic showing various Remote Penetration Tester job openings in Reston, VA as of August 2026, with employment types broken down into 73% Full Time, and 27% Part Time. Highlights an 100% Remote job distribution, with an average salary of $124,733 per year, or $60 per hour.

$66.50 - $89/hr

Full-time

Medical, Dental, Vision, Life, Retirement

This job post has expired today. Applications are no longer accepted.


Job description

Job Description:   

Application Security Engineer II 

(Remote Candidates will be considered)   

Our Story and Our Purpose   

National Digital Trust Company (In Organization) has received conditional approval from the Office of the Comptroller of the Currency to open as a federally chartered trust bank to provide a broad range of digital asset services. 

 We are building a specialized financial institution addressing the growing demand for digital asset services. Our primary business will focus on digital asset custody, providing secure, efficient custodial and fiduciary services for a variety of digital assets.  

You will work with foundational systems and processes to help shape our operating model and influence how a new category of financial infrastructure comes to market. 

We are looking for builders who handle complexity with confidence and tackle ambitious opportunities while keeping pace with this rapidly evolving industry.  

Our Principles  

Greatness is a mindset, not an accomplishment. Mediocrity is unacceptable. Excellence is contagious. We hire people because we believe in their greatness. Now is the time to prove us right. 

Responsibility comes with the territory. Everyone is an owner, which means we share a common vision and mutual accountability. We act in line with our strategic objectives and the trust our customers place in us. We believe there is no such thing as "not my problem." Taking this level of ownership not only drives our collective success but also offers the potential for significant reward. 

Innovation and adaptation are in our DNA. We are in a period of the most dramatic and rapid period of technological change in the history of humankind. Those that stay ahead will thrive, those that don\'t, won\'t. We innovate intelligently and thrive on overcoming challenges, to get (at least) a little better every day and ensure our continued growth and success. 

Team first. We are reliable teammates working together toward extraordinary success through honesty and accountability. We believe collaboration knows no hierarchy, and we focus on what matters.  We work toward consensus, but when necessary, we disagree and commit. We know that winners win. 

About the Role 

Application Security (AppSec) Engineers are responsible for designing, implementing, and managing security practices that protect NDTC’s applications and services. 

As an Application Security Engineer II, you will work closely with software engineers to perform secure code reviews, conduct automated and manual testing, and integrate security throughout the software development lifecycle (SDLC). You will support and approve engineering projects from a security perspective, ensuring applications meet both internal standards and industry best practices. 

This is a critical role in safeguarding systems used by our customers. Success requires strong technical depth, critical thinking, adaptability, and a passion for application security in a fast-evolving environment. 

Key Responsibilities 

Application Security Assessments 

  • Perform automated and manual vulnerability assessments for APIs and web applications 

  • Conduct static (SAST), dynamic (DAST), software composition analysis (SCA), and interactive (IAST) testing 

  • Review findings for exploitability and provide actionable remediation guidance 

  • Perform manual testing to validate vulnerabilities and ensure secure implementations 

Secure Development & Engineering Support 

  • Partner with developers to embed security into the SDLC 

  • Participate in and help manage the secure code review approval process 

  • Perform product threat modeling and develop threat-focused validation checks 

  • Ensure new projects are designed, scoped, and deployed securely 

Security Tools & Operations 

  • Implement, manage, and optimize application security tools across the organization  

  • Support the operational management of AppSec programs and workflows 

  • Manage cloud security for both internally developed and third-party applications 

  • Contribute to internal security documentation, playbooks, and best practices 

Offensive Security & Testing 

  • Support Red Team exercises and external penetration testing engagements 

  • Assist in triaging and responding to bug bounty submissions 

  • Perform validation testing to ensure applications meet internal and industry security standards 

Incident Response & Monitoring 

  • Investigate security incidents through research and log analysis 

  • Contribute to incident response processes, documentation, and continuous improvement 

Automation & Tool Development 

  • Build or enhance internal tooling to automate security testing, compliance checks, and evidence collection 

  • Write scripts and utilities to improve efficiency and scalability 

  • Evaluate and experiment with new tools to improve application security outcomes 

Collaboration & Culture 

  • Serve as a security subject matter expert for engineering and business teams 

  • Promote a strong, approachable security culture across the organization 

  • Operate flexibly across multiple responsibilities in a fast-growing environment 

Required Qualifications 

  • 3–5+ years of experience in Information Technology, including security tooling 

  • 3–5+ years of experience as an Application Security Engineer 

  • 1–3+ years of experience in regulated environments (e.g., financial services, fintech) 

  • Strong understanding of web application security principles and architecture 

  • Experience with container technologies and container security 

  • Proficiency in at least one programming language, with willingness to learn additional languages (e.g., Rust, TypeScript) 

  • Experience with CI/CD pipelines and source control tools (Git, GitHub) 

  • Experience evaluating Infrastructure-as-Code (IaC) security across cloud environments 

  • Familiarity with bug bounty programs (participation or triage) 

  • Understanding of OWASP Top 10 and application security best practices across web, DevOps, and emerging AI systems 

  • Strong problem-solving, analytical thinking, and ability to adapt quickly 

Preferred Experience, Skills & Knowledge 

Security & Compliance 

  • Experience implementing security controls within DevOps / DevSecOps environments 

  • Knowledge of application security risks and mitigation strategies 

  • Familiarity with frameworks and standards such as:  

  • NIST 800-53 / CSF 2.0 

  • NIST SSDF (800-218) 

  • SOC 2, PCI-DSS, PA-DSS 

  • Understanding of Content Security Policy (CSP) 

  • Ability to identify and explain vulnerabilities such as:  

  • XSS, CSRF, injection attacks 

  • MITM attacks 

  • Brute-force and credential attacks 

  • Interest in financial services, digital assets, and custodial security 

AI & Emerging Technologies 

  • Experience working with AI tools and understanding of security considerations for generative AI 

  • Familiarity with AI-assisted development workflows, agent-based systems, or MCP-based tools 

  • Willingness to learn and adapt to AI-driven SDLC environments 

What Sets You Apart 

  • Curiosity and a continuous improvement mindset 

  • Ability to balance security rigor with engineering velocity 

  • Strong communication skills and ability to influence across teams 

  • Passion for building scalable, practical security solutions 

We promote diversity of thought, culture, background, and experience. We are an equal opportunity employer, and employment at our company is based solely on one\'s merit and qualifications directly related to professional competence. We do not discriminate based on race, creed, color, ancestry, religion, gender, sexual orientation, gender identity, national origin, age, disability, genetic information, military or veteran status, or any other characteristics protected by law. 

Featured benefits 

  • Employer-provided: Medical, Dental, and Vision insurance, 401(k), life and disability insurance.