2

Remote Penetration Testing Jobs in Colorado (NOW HIRING)

Cybersecurity Engineer

Boulder, CO · On-site +1

$85K - $125K/yr

Analyze application and infrastructure security utilizing penetration testing * Investigate ... Partial Remote Work Options * 4-day workweek Proof of current COVID-19 vaccination status is a ...

Remote Penetration Testing information

See Colorado salary details

$23.7K

$126.1K

$177.2K

How much do remote penetration testing jobs pay per year?

As of Jul 25, 2026, the average yearly pay for remote penetration testing in Colorado is $126,071.00, according to ZipRecruiter salary data. Most workers in this role earn between $100,900.00 and $148,300.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Remote Penetration Tester, and why are they important?

To thrive as a Remote Penetration Tester, you need a solid understanding of computer networks, cybersecurity principles, and common vulnerabilities, often supported by a degree in computer science or related certifications like OSCP or CEH. Familiarity with penetration testing tools such as Metasploit, Burp Suite, Nmap, and various operating systems is essential. Strong analytical thinking, attention to detail, and clear written communication skills help you effectively discover, document, and explain security findings to clients. These competencies are crucial for accurately identifying risks and helping organizations strengthen their security posture.

Is there a demand for penetration testing?

There is strong demand for penetration testers, including those in remote roles, as organizations prioritize cybersecurity and vulnerability assessments. Skilled professionals with knowledge of tools like Kali Linux, Metasploit, and certifications such as OSCP are especially sought after in the industry.

Will pentesters be replaced by AI?

Remote penetration testers perform manual and creative security assessments that AI currently cannot fully replicate. While AI tools can assist with vulnerability scanning and data analysis, human expertise is essential for identifying complex threats, interpreting results, and developing effective security strategies. The role of pentesters is expected to evolve with technology, but not be entirely replaced by AI.

What is the difference between Remote Penetration Testing vs Vulnerability Assessment Specialist?

AspectRemote Penetration TestingVulnerability Assessment Specialist
CertificationsOSCP, CEH, GPENOSCP, CEH, CISSP
Work EnvironmentHands-on testing, simulated attacksScanning, identifying vulnerabilities
Industry UsageCybersecurity firms, IT departmentsSecurity teams, consulting firms

Remote Penetration Testing involves actively exploiting vulnerabilities to assess security defenses, while Vulnerability Assessment Specialists focus on identifying and prioritizing security weaknesses without exploiting them. Both roles require similar certifications and often work in overlapping environments, but penetration testers perform more in-depth, simulated attack scenarios to evaluate security robustness.

What are some common challenges faced by remote penetration testers, and how can they be addressed?

Remote penetration testers often encounter challenges such as limited access to physical infrastructure, varying levels of client preparedness, and potential communication barriers with on-site teams. To address these issues, it's important to establish clear communication channels, use secure remote access tools, and maintain detailed documentation of testing activities. Building strong relationships with client IT staff and staying up-to-date with remote testing best practices can also help ensure effective and successful engagements.

How much do remote penetration testers make?

Remote penetration testers typically earn between $70,000 and $130,000 annually, depending on experience, certifications, and the complexity of the projects. Senior professionals with advanced skills and certifications like OSCP or CISSP can earn higher salaries, especially when working for specialized firms or as freelancers.

Do penetration testers work remotely?

Many penetration testers work remotely, especially those in freelance or consulting roles, utilizing tools like VPNs, remote access software, and security testing platforms. Remote work allows flexibility, but some employers may require on-site presence for certain assessments or client interactions.

What is remote penetration testing?

Remote penetration testing is a security assessment process where cybersecurity professionals, also known as ethical hackers, attempt to find and exploit vulnerabilities in an organization’s systems, networks, or applications from an offsite location. This simulates a real-world cyberattack to help organizations identify and fix security weaknesses before malicious actors can exploit them. Remote penetration testing is often conducted over the internet, making it a flexible and efficient option for businesses to assess their security posture without requiring onsite visits.
What are the most commonly searched types of Penetration Testing jobs in Colorado? The most popular types of Penetration Testing jobs in Colorado are:
What are popular job titles related to Remote Penetration Testing jobs in Colorado? For Remote Penetration Testing jobs in Colorado, the most frequently searched job titles are:
What cities in Colorado are hiring for Remote Penetration Testing jobs? Cities in Colorado with the most Remote Penetration Testing job openings:
Infographic showing various Remote Penetration Testing job openings in Colorado as of July 2026, with employment types broken down into 74% Full Time, 19% Part Time, and 7% Contract. Highlights an 100% Remote job distribution, with an average salary of $126,071 per year, or $60.6 per hour.
Application Security Engineer (REMOTE)

Application Security Engineer (REMOTE)

EnerSys

Longmont, CO • Remote

$117K - $146K/yr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 24 days ago


EnerSys rating

7.5

Company rating: 7.5 out of 10

Based on 53 frontline employees who took The Breakroom Quiz

259th of 535 rated manufacturers


Job description

EnerSys is a global leader in stored energy solutions for industrial applications. We have over thirty manufacturing and assembly plants worldwide servicing over 10,000 customers in more than 100 countries. Worldwide headquarters are located in Reading, PA, USA with regional headquarters in Europe and Asia. We complement our extensive line of Motive Power and Energy Systems with a full range of integrated services and systems. With sales and service locations throughout the world, and over 100 years of battery experience, EnerSys is the power/full solution for stored DC power products. 

What We're Offering

  • Paid time off plus paid holidays
  • Medical/dental/vision insurance plan
  • Life insurance, short/long term disability, tuition reimbursement, flex spending, and employee stock purchase plan
  • 401K plan
  • Culture: We value and strive for excellence in all that we do through innovative technology by creating long lasting relationships with our stakeholders, co-workers, and customers. We continually strive to foster teamwork, engagement and enhance our employee's skills and competence by providing appropriate training.

Compensation Range: $117,200 - $146,600 

Compensation may vary based on applicant's work experience, education level, skill set, and/or location.  

Job Purpose

The Application Security Engineer is responsible for strengthening the security of our applications, platforms, and development processes. This position partners with software engineers, DevOps teams, and security professionals to embed security into the full software development lifecycle. Collaborate within an expanding Cybersecurity team, and work closely with internal EnerSys teams to ensure new and continued compliance with cybersecurity frameworks and required programs and initiatives.

Essential Duties and Responsibilities

   Serve as a primary liaison between the Cybersecurity and development teams, ensuring security is integrated into design, development, deployment, and operations.
   Conduct application security assessments, code reviews, API testing, threat modeling, and penetration testing to identify vulnerabilities.
   Define, maintain, and enforce secure coding standards, patterns, and best practices.
   Integrate and manage security tooling within CI/CD pipelines, including SAST, DAST, SCA, IaC scanning, and container security solutions.
   Support secure architecture reviews for cloudnative applications, microservices, and containerized workloads.
   Support threat modeling, risk assessments, and security architecture reviews for applications.
   Ensure that all security practices meet regulatory and compliance requirements.
   Develop and deliver cybersecurity training programs for development teams to promote awareness and adherence to best practices.
   Ensure application security practices align with regulatory and compliance frameworks (e.g., NIST CSF, ISO 27001, IEC 62443).
   Keep up to date on emerging threats, incorporating threat intelligence into security practices and providing proactive defenses.
   Monitor and respond to application security threats, incidents and vulnerabilities.
   Stay up to date on regulatory developments and industry trends.
   Manage and maintain third-party vendor and consultant relationships .
   Perform other duties as assigned.

SUPERVISORY RESPONSIBILITIES: N/A

Qualifications

To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. 

Must have an active passport and be willing to travel internationally.

Required Qualifications

  • Bachelor's degree in a technical field (e.g., Computer Science, Information Systems, Cybersecurity).
  • 5+ years of experience in Information Security, with at least 3 years focused on application security, secure development, or DevSecOps.
  • Demonstrated experience building and scaling an application security program, either as the lead or a key contributor.
  • Strong knowledge of OWASP Top 10, OWASP ASVS, SANS Top 25, and secure SDLC methodologies.
  • Hands-on experience with application security testing tools such as Burp Suite, Fortify, Checkmarx, Veracode, and ZAP.
  • Experience conducting threat modeling, penetration testing, secure software development, and secure architecture reviews.
  • Practical experience securing cloud environments (AWS or Azure) and implementing cloud-native security controls.
  • Familiarity with Kubernetes security, container hardening, and runtime protection.
  • Strong communication skills with the ability to collaborate and influence across technical and non-technical teams.

Preferred Qualifications

  • Relevant certifications such as CISSP, CSSLP, OSCP, GWAPT, CEH, or GIAC Cloud Security.
  • Experience securing embedded systems and mobile applications.

Reasoning Ability
   Problem management / resolution skills; project management skills; generally accepted security principles.
   Ability to analyze data, resources, and schedules to make decisions that affect a project on a regular basis.
TRAVEL REQUIRED: Up to 15%

General Job Requirements
  • This position will work in an office setting, expect minimal physical demands.

EnerSys provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.  

Know Your Rights

Know Your Rights (Spanish)

We use artificial intelligence to screen, assess and select applicants for open positions, including for the purposes of reviewing and ranking application materials and scoring answers to application questions. Accordingly, decisions about your application and eligibility for employment with EnerSys may be made based exclusively on the automated processing of the personal information that you submit in your application materials.


What EnerSys employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom