2

Remote Penetration Testing Jobs in Oregon (NOW HIRING)

Conduct advanced penetration testing and vulnerability assessments on our products and ... All full-time positions are hybrid, with many eligible to be completely remote * Fully Paid by ...

As leaders in continuous offensive security and penetration testing, we deliver world-class ... We're seeking remote, US or Mexico-based hacking professionals focused on red teaming to join our ...

As leaders in continuous offensive security and penetration testing, we deliver world-class ... We're seeking remote, US or Mexico-based hacking professionals focused on red teaming to join our ...

Application Security Engineer (REMOTE)

Portland, OR · Remote

$117.20K - $146.60K/yr

Conduct application security assessments, code reviews, API testing, threat modeling, and penetration testing to identify vulnerabilities. Define, maintain, and enforce secure coding standards ...

AI Red Teamer

OR · On-site +1

Conduct end to end penetration testing on AI systems, with a focus on predictive and generative AI ... Fully Remote: We are a completely remote global team. Though we're distributed, we are intentional ...

Perform entry level penetration testing activities against external assets, as assigned by the Red ... Remote About Rapid7 At Rapid7, our vision is to create a secure digital world for our customers ...

Principal Application Security Engineer

OR · Remote

$58.75 - $78.50/hr

This role can be fully remote and must reside in US. In this role, you will help us drive our ... Drive our security assessment, penetration testing and bug bounty programs * Participate in ...

This position may be remote from any location within the United States. Responsibilities * Build ... Handson leadership of risk assessments, audits, and penetration testing efforts. * Practical ...

Sr. Cybersecurity Engineer

OR · On-site +1

$121.57K - $153.99K/yr

This position may be remote from any location within the United States. Responsibilities * Build ... Hands-on leadership of risk assessments, audits, and penetration testing efforts. * Practical ...

... penetration testing). * Excellent written and verbal communication skills, with the ability to ... Wellness program incentives Onboarding & Travel This is a remote role, with an in-person onboarding ...

Application Security Engineer

OR · Remote

$58.75 - $78.50/hr

Take part in our security assessment, penetration testing and bug bounty programs * Participate in ... Ability to work extended hours as required #LI-JC1 #LI-REMOTE

... penetration testing program, and help the broader organization navigate increasingly complex security challenges, including the emerging frontier of AI and agentic systems. This is a remote position ...

This position is anticipated to be majority remote, but with the ability to travel and visit the ... Conduct security risk assessments and oversee vulnerability scanning and penetration testing ...

next page

Showing results 1-20

Remote Penetration Testing information

See Oregon salary details

$23.8K

$126.8K

$178.2K

How much do remote penetration testing jobs pay per year?

As of May 31, 2026, the average yearly pay for remote penetration testing in Oregon is $126,763.00, according to ZipRecruiter salary data. Most workers in this role earn between $101,500.00 and $149,100.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Remote Penetration Tester, and why are they important?

To thrive as a Remote Penetration Tester, you need a solid understanding of computer networks, cybersecurity principles, and common vulnerabilities, often supported by a degree in computer science or related certifications like OSCP or CEH. Familiarity with penetration testing tools such as Metasploit, Burp Suite, Nmap, and various operating systems is essential. Strong analytical thinking, attention to detail, and clear written communication skills help you effectively discover, document, and explain security findings to clients. These competencies are crucial for accurately identifying risks and helping organizations strengthen their security posture.

What are some common challenges faced by remote penetration testers, and how can they be addressed?

Remote penetration testers often encounter challenges such as limited access to physical infrastructure, varying levels of client preparedness, and potential communication barriers with on-site teams. To address these issues, it's important to establish clear communication channels, use secure remote access tools, and maintain detailed documentation of testing activities. Building strong relationships with client IT staff and staying up-to-date with remote testing best practices can also help ensure effective and successful engagements.

What is remote penetration testing?

Remote penetration testing is a security assessment process where cybersecurity professionals, also known as ethical hackers, attempt to find and exploit vulnerabilities in an organization’s systems, networks, or applications from an offsite location. This simulates a real-world cyberattack to help organizations identify and fix security weaknesses before malicious actors can exploit them. Remote penetration testing is often conducted over the internet, making it a flexible and efficient option for businesses to assess their security posture without requiring onsite visits.

What is the difference between Remote Penetration Testing vs Vulnerability Assessment Specialist?

AspectRemote Penetration TestingVulnerability Assessment Specialist
CertificationsOSCP, CEH, GPENOSCP, CEH, CISSP
Work EnvironmentHands-on testing, simulated attacksScanning, identifying vulnerabilities
Industry UsageCybersecurity firms, IT departmentsSecurity teams, consulting firms

Remote Penetration Testing involves actively exploiting vulnerabilities to assess security defenses, while Vulnerability Assessment Specialists focus on identifying and prioritizing security weaknesses without exploiting them. Both roles require similar certifications and often work in overlapping environments, but penetration testers perform more in-depth, simulated attack scenarios to evaluate security robustness.

What are the most commonly searched types of Penetration Testing jobs in Oregon? The most popular types of Penetration Testing jobs in Oregon are:
What are popular job titles related to Remote Penetration Testing jobs in Oregon? For Remote Penetration Testing jobs in Oregon, the most frequently searched job titles are:
What cities in Oregon are hiring for Remote Penetration Testing jobs? Cities in Oregon with the most Remote Penetration Testing job openings:
Senior Penetration Tester (59660)

Full-time

Medical, Dental, Vision, Retirement

Posted 17 days ago


Job description

BMA is seeking a Senior Penetration Tester to support our Cybersecurity Assessment Program (CAP) Program. This position is fully remote and contingent on contract award. 

Job Summary 

Key elements of this work consist of but are not limited to:

  • Independently performs penetration testing of applications, systems, and enclaves; identifies security flaws in computing platforms and applications and devises strategies and techniques to mitigate identified cybersecurity risks
  • Performs application, network, and wireless penetration testing and security assessments
  • Applies offensive cybersecurity testing techniques and coordinates testing projects with internal and external system owners
  • Reports on identified cybersecurity risks and recommends mitigation measures to improve the overall cybersecurity posture of the enterprise
  • Applies in-depth knowledge of network protocols, operating systems, web application security, reverse engineering, and scripting languages to identify and mitigate vulnerabilities before they can be exploited by threat actors
  • Continuously refines and improves cybersecurity defenses and incident response plans
  • Supports the development of Assessment Final Reports, Mitigation Effectiveness Reports, and Rules of Engagement
  • Supports daily hotwash events, briefings and presentations, and scoping meetings

Clearance Requirements 

An active Secret security clearance is required at the time of proposal submission.

Required Skills & Certifications 

  • 6+ years of proven proficiency performing extensive vulnerability assessments and penetration testing
  • 3+ years of experience using testing tools including NESSUS, Metasploit, CANVAS, Nmap, Burp Suite, and Kismet
  • 3+ years of experience performing network vulnerability assessments and applying penetration testing methodologies
  • 3+ years of experience writing penetration testing and assessment reports
  • 2+ years of experience administering, using, and troubleshooting Windows Server and IIS
  • 2+ years of experience administering, using, and troubleshooting a major Linux distribution
  • 2+ years of experience performing PCI DSS testing
  • Possession of one or more penetration testing certifications such as Licensed Penetration Tester (LPT), Certified Expert Penetration Tester (CEPT), Certified Ethical Hacker (CEH), or GIAC Penetration Tester (GPEN)
  • Knowledge of TCP/IP protocols and networking architectures
  • Knowledge of open security testing standards and projects, including OWASP
  • Knowledge of database, application, and web server design and implementation
  • Experience scripting in Perl, Python, Ruby, Bash, or Java
  • Experience with wireless LAN security testing
  • Excellent oral communication, written documentation, and presentation skills

Desired Skills & Certifications

  • Experience supporting DLA contracts
  • Bachelor’s degree in a relevant technical field
  • Project Management Professional (PMP) certification
  • Familiarity with enterprise networks and systems, including servers, databases, APIs, and Active Directory
  • Familiarity with web application concepts such as session management, business logic, and input validation
  • Familiarity with AI and large language model (LLM) security concerns, including data poisoning and prompt injection exploitation
  • Familiarity with operational technology (OT) environments, including SCADA system security and PLC security
  • Familiarity with wireless networks, including Bluetooth security and wireless intrusion detection and prevention systems (WIDS/WIPS)
  • Familiarity with DevSecOps pipelines, including SAST, DAST, and SCA implementation and automated security testing
  • Familiarity with hybrid environments, including the interconnectivity and security of on-premises and cloud-based systems

Other Duties

This job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice. 

Overview

BMA is an employee-owned small business headquartered in Huntsville, AL that provides superior customer service by empowering all levels of our staff to make timely decisions to produce high-quality results. BMA fosters an environment of passion, precision, and dedication in order to fulfill our commitments to our partners, government, and country.

Benefits

We believe that our employees well-being is paramount to our success so our benefits package has been crafted with that in mind. We offer multiple healthcare coverage options to include low deductible, high deductible, and plans eligible for our Health Savings Account (HSA) option. Along with medical coverage, employees have dental, vision, accident & illness, short- and long-term disability all available to them. BMA proudly maintains a 401(k) plan with an industry leading 6% match that can include profit sharing based on company performance. Lastly, being an employee-owned company means that BMA offers a 100% Employee Stock Ownership Plan (ESOP), providing eligible employees the opportunity to earn stock in BMA, subject to plan eligibility and vesting requirements. 

AAP & EEO Statement
 Beshenich Muir & Associates, LLC (BMA) is an Equal opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regards to race, color, religion, religious creed, gender, sexual orientation, gender identity, gender expression, transgender, pregnancy, marital status, national origin, ancestry, citizenship status, age, disability, protected Veteran Status, genetics or any other characteristics protected by applicable Federal, State, or Local Law.Â