2

Remote Penetration Testing Jobs in California (NOW HIRING)

Remote Role Responsibilities * Review and evaluate AI-generated outputs related to threat analysis ... Background in areas such as SOC analysis, incident response (DFIR), penetration testing, threat ...

Contract Compensation: $20-$22/hour Location: Remote Role Responsibilities * Red team ... Background in Cybersecurity : penetration testing, exploit development, reverse engineering.

Contract Compensation: $48-$62/hour Location: Remote Role Responsibilities * Red team ... Background in Cybersecurity , such as penetration testing and exploit development. * Expertise in ...

Conduct application security assessments, code reviews, API testing, threat modeling, and penetration testing to identify vulnerabilities. Define, maintain, and enforce secure coding standards ...

This is a remote first role. You will partner closely with teams across the company and focus on ... Help run penetration testing and offensive security exercises against Figma's AI infrastructure ...

Senior Cyber Security Engineer

Milpitas, CA · On-site +1

$130K - $179K/yr

Conduct and oversee penetration testing activities, coordinating third parties and providing ... Assess and secure third-party access (vendors, OEMs, remote maintenance channels) * Evaluate risks ...

Senior Cyber Security Engineer

Milpitas, CA · On-site +1

$130K - $179K/yr

Conduct and oversee penetration testing activities, coordinating third parties and providing ... Assess and secure third-party access (vendors, OEMs, remote maintenance channels) * Evaluate risks ...

Senior Cyber Security Engineer

Milpitas, CA · On-site +1

$130K - $179K/yr

Conduct and oversee penetration testing activities, coordinating third parties and providing ... Assess and secure third-party access (vendors, OEMs, remote maintenance channels) * Evaluate risks ...

If you're located beyond that distance, the role is fully remote. For location-specific details ... Strong software engineering background is more important here than classic penetration testing ...

Network Security Engineer

San Francisco, CA · On-site +1

$123K - $168K/yr

Oversee vulnerability assessments, penetration testing, and security reviews. * Prioritize and ... Architect secure, low-latency remote access and mesh VPN solutions for intra-fleet communication ...

Lead Engineer, AI Attack Simulation

San Francisco, CA · On-site +1

$120K - $159K/yr

... penetration testing, or control validation. * Strong proficiency in Go and experience with at least ... Fully Remote: We are a completely remote global team. Though we're distributed, we are intentional ...

next page

Showing results 1-20

Remote Penetration Testing information

See California salary details

$22.2K

$118.3K

$166.3K

How much do remote penetration testing jobs pay per year?

As of Aug 11, 2026, the average yearly pay for remote penetration testing in California is $118,325.00, according to ZipRecruiter salary data. Most workers in this role earn between $94,700.00 and $139,200.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a remote penetration tester?

To thrive as a Remote Penetration Tester, you need a solid understanding of computer networks, cybersecurity principles, and common vulnerabilities, often supported by a degree in computer science or related certifications like OSCP or CEH. Familiarity with penetration testing tools such as Metasploit, Burp Suite, Nmap, and various operating systems is essential. Strong analytical thinking, attention to detail, and clear written communication skills help you effectively discover, document, and explain security findings to clients. These competencies are crucial for accurately identifying risks and helping organizations strengthen their security posture.

Is there a demand for remote penetration testing?

Remote penetration testing is in high demand as organizations seek cybersecurity professionals to identify vulnerabilities remotely. Skills in network security, ethical hacking, and familiarity with tools like Kali Linux and Metasploit are essential, and many companies prefer candidates with industry certifications such as OSCP or CEH.

What is the difference between Remote Penetration Testing vs Vulnerability Assessment Specialist?

AspectRemote Penetration TestingVulnerability Assessment Specialist
CertificationsOSCP, CEH, GPENOSCP, CEH, CISSP
Work EnvironmentHands-on testing, simulated attacksScanning, identifying vulnerabilities
Industry UsageCybersecurity firms, IT departmentsSecurity teams, consulting firms

Remote Penetration Testing involves actively exploiting vulnerabilities to assess security defenses, while Vulnerability Assessment Specialists focus on identifying and prioritizing security weaknesses without exploiting them. Both roles require similar certifications and often work in overlapping environments, but penetration testers perform more in-depth, simulated attack scenarios to evaluate security robustness.

What are some common challenges faced by remote penetration testers, and how can they be addressed?

Remote penetration testers often encounter challenges such as limited access to physical infrastructure, varying levels of client preparedness, and potential communication barriers with on-site teams. To address these issues, it's important to establish clear communication channels, use secure remote access tools, and maintain detailed documentation of testing activities. Building strong relationships with client IT staff and staying up-to-date with remote testing best practices can also help ensure effective and successful engagements.

Can remote penetration testers work remotely?

Yes, remote penetration testers can work remotely, as the role primarily involves using specialized tools and techniques to assess cybersecurity defenses from any location. Many companies hire remote testers to perform assessments, provided they have the necessary skills, secure access, and appropriate certifications such as OSCP or CEH. Effective communication and familiarity with remote collaboration tools are also important for success in remote roles.

What is remote penetration testing?

Remote penetration testing is a security assessment process where cybersecurity professionals, also known as ethical hackers, attempt to find and exploit vulnerabilities in an organization’s systems, networks, or applications from an offsite location. This simulates a real-world cyberattack to help organizations identify and fix security weaknesses before malicious actors can exploit them. Remote penetration testing is often conducted over the internet, making it a flexible and efficient option for businesses to assess their security posture without requiring onsite visits.
What are the most commonly searched types of Penetration Testing jobs in California? The most popular types of Penetration Testing jobs in California are:
What cities in California are hiring for Remote Penetration Testing jobs? Cities in California with the most Remote Penetration Testing job openings:
Infographic showing various Remote Penetration Testing job openings in California as of August 2026, with employment types broken down into 68% Full Time, and 32% Part Time. Highlights an 100% Remote job distribution, with an average salary of $118,325 per year, or $56.9 per hour.

Security Analyst - Fully Remote

Mercor

San Francisco, CA • Remote

$1.7K - $2.1K/wk

Full-time

This job post has expired today. Applications are no longer accepted.


Job description

About the job

Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey.

Position: Cybersecurity Expert
Type: Contract
Compensation: $1,750–$2,150 per completed task
Location: Remote

Role Responsibilities

  • Review and evaluate AI-generated outputs related to threat analysis, vulnerability assessment, and security architecture recommendations.
  • Create realistic scenarios based on cybersecurity workflows such as incident response runbooks, threat hunting queries, and penetration testing reports.
  • Annotate, label, and validate data across cybersecurity use cases like CVE classification accuracy and SIEM alert triage.
  • Provide structured feedback on AI accuracy in areas such as cybersecurity frameworks (NIST CSF, MITRE ATT&CK) and threat intelligence standards (STIX/TAXII).
  • Collaborate asynchronously with research teams to refine evaluation frameworks for cybersecurity AI.

Qualifications

Must-Have

  • 3+ years of professional experience in cybersecurity at an enterprise organization, MSSP, consultancy, or government/defense environment.
  • Background in areas such as SOC analysis, incident response (DFIR), penetration testing, threat intelligence, or security architecture.
  • Strong analytical thinking and ability to translate security operations into structured evaluation tasks.
  • Clear written communication and attention to detail.

Preferred

  • Professional certifications like CISSP, CISM, CEH, OSCP, GIAC certifications, Security+.

Compensation & Legal

  • Task Completion Pay: Competitive and based on task quality.
  • Performance Bonus: Weekly bonus incentive for top performers.
  • Hourly Opportunity: Transition to hourly compensation for sustained quality.

Application Process (Takes 20–30 mins to complete)

  • Upload resume
  • AI interview based on your resume
  • Submit form

Resources & Support

  • For details about the interview process and platform information, please check: https://talent.docs.mercor.com/welcome
  • For any help or support, reach out to: support@mercor.com

PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.