2

Remote Web Penetration Tester Jobs (NOW HIRING)

Be Seen First

Penetration Tester

Knoxville, TN · Remote

$120K - $145K/yr

This role requires proven hands-on capability in both network and web application/API penetration ... What We Offer · Remote work environment · Unlimited paid time off (Policy Guided) · Continuing ...

Be Seen First

Penetration Tester

Knoxville, TN · Remote

$120K - $145K/yr

This role requires proven hands-on capability in both network and web application/API penetration ... What We Offer · Remote work environment · Unlimited paid time off (Policy Guided) · Continuing ...

Penetration Tester

Plano, TX · Remote

$60 - $70/hr

This is a remote, 6+ month contract-to-hire position. COMP : Up to $70/HR depending on candidate ... Conduct internal/external penetration testing, web application, API, and cloud security assessments ...

Web Application Testing: * Conduct security assessments of agency web applications using OWASP Top ... Penetration Testing & Exploitation Validation: * Perform controlled penetration testing (internal ...

... Remote (US) As a penetration tester on BreachLock's US Strategic delivery team, you'll execute manual, methodology-driven engagements across web applications, APIs, and internal networks - including ...

Summary: The Senior Penetration Tester will independently perform penetration testing of ... Knowledge of databases, applications, and Web server design and implementation * Possess oral and ...

Summary: The Senior Penetration Tester will independently perform penetration testing of ... Knowledge of databases, applications, and Web server design and implementation * Possess oral and ...

Cleared Penetration Tester

Herndon, VA · Remote

$130K - $160K/yr

Key Responsibilities This role will be responsible for conducting network, application (API, mobile, and web), and Social Engineering penetration testing. Specifically, you would: * Work closely with ...

Responsibilities : • Execute scoped penetration testing tasks under supervision across: • External and internal network assessments • Web application and API testing • Entry-level cloud ...

Summary: The Senior Penetration Tester will independently perform penetration testing of ... Knowledge of databases, applications, and Web server design and implementation * Possess oral and ...

next page

Showing results 1-20

Remote Web Penetration Tester information

See salary details

$22.5K

$119.9K

$168.5K

How much do remote web penetration tester jobs pay per year?

As of Aug 22, 2026, the average yearly pay for remote web penetration tester in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What is a remote web penetration tester?

A remote web penetration tester is a cybersecurity professional who evaluates the security of web applications and websites from a remote location. Their primary role is to identify vulnerabilities, such as coding errors or misconfigurations, that could be exploited by malicious hackers. They use a variety of tools and techniques to simulate attacks, report findings, and recommend solutions, all without being physically present at the client's site. This position often requires strong technical skills, analytical thinking, and up-to-date knowledge of the latest web threats and defenses.

What are the key skills and qualifications needed to thrive as a remote web penetration tester?

To thrive as a Remote Web Penetration Tester, you need a deep understanding of web application security, networking protocols, and vulnerability assessment, often supported by certifications like OSCP or CEH. Familiarity with tools such as Burp Suite, Metasploit, and automated scanners is essential for performing thorough security evaluations. Strong analytical thinking, attention to detail, and clear written communication are critical soft skills for effectively identifying vulnerabilities and reporting findings to clients. These skills ensure comprehensive assessments, actionable reporting, and contribute to the overall security posture of organizations.

How does a remote web penetration tester typically coordinate with development and security teams during an assessment?

As a Remote Web Penetration Tester, you will regularly collaborate with development and security teams through virtual meetings, secure communication channels, and detailed reporting. You'll often present your findings in real time or via structured reports, clarifying vulnerabilities and recommending mitigation steps. Strong communication skills are key, as you may need to explain complex technical issues to non-technical stakeholders and sometimes assist in prioritizing remediation efforts. This collaborative approach ensures that security improvements are effectively understood and implemented, even when working remotely.

What is the difference between Remote Web Penetration Tester vs Remote Network Security Analyst?

AspectRemote Web Penetration TesterRemote Network Security Analyst
CertificationsOSCP, CEH, GPENCompTIA Security+, CISSP, CEH
Work EnvironmentConducts simulated attacks on web applications remotelyMonitors and analyzes network security remotely
Industry UsageCybersecurity firms, tech companies, consultingFinancial institutions, government agencies, enterprises

The Remote Web Penetration Tester focuses on identifying vulnerabilities in web applications through simulated attacks, requiring certifications like OSCP or CEH. In contrast, the Remote Network Security Analyst monitors and analyzes network traffic to detect threats, often holding certifications like Security+ or CISSP. Both roles are essential in cybersecurity but differ in their focus areas and daily tasks.

More about Remote Web Penetration Tester jobs

What cities are hiring for Remote Web Penetration Tester jobs?

Cities with the most Remote Web Penetration Tester job openings:

What are the most commonly searched types of Web Penetration Tester jobs?

The most popular types of Web Penetration Tester jobs are:

What states have the most Remote Web Penetration Tester jobs?

States with the most job openings for Remote Web Penetration Tester jobs include:

Infographic showing various Remote Web Penetration Tester job openings in the United States as of August 2026, with employment types broken down into 82% Full Time, 10% Part Time, 1% Temporary, and 7% Contract. Highlights an 82% Physical, 4% Hybrid, and 14% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

Penetration Tester

Zelvin Security LLC

Knoxville, TN • Remote

$120K - $145K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 8 days ago

Be Seen First

After you apply to this job, you can share why you’re interested to jump to the top of the candidate list.


Job description

Zelvin Security is seeking an experienced Penetration Tester to join our Ethical Hacking Team and conduct hands-on ethical hacking engagements across networks, web applications, APIs, cloud platforms, and hybrid environments.

This role requires proven hands-on capability in both network and web application/API penetration testing. You’ll combine manual analysis with appropriate tooling, identify and pursue viable attack paths, validate exploitability, demonstrate real-world impact, and turn technical evidence into a clear, compelling narrative that helps clients understand their risk and take meaningful action.

At Zelvin, penetration testing is not about generating a list of vulnerabilities. Our testers think like attackers, follow the evidence, challenge assumptions, and determine which weaknesses create meaningful risk. They then help clients understand what matters, why it matters, and what they can do about it.

We are looking for someone who wants their work to make a meaningful impact serving clients, contributing to our team, their own professional growth, and the broader offensive security community.

Skills & Qualifications

· Minimum of three years of professional penetration testing or offensive security experience.

· Demonstrated hands-on experience conducting both network and web application/API penetration testing.

· Strong knowledge of Active Directory and Windows enterprise environments, including authentication, privilege escalation, lateral movement, and common attack paths.

· Working knowledge of cloud and hybrid environments, including identity, networking, permissions, and exposed services.

· Strong understanding of networking, operating systems, web technologies, authentication, exploitation techniques, and offensive security methodologies.

· Ability to analyze attack paths, adapt testing approaches, troubleshoot unsuccessful techniques, and distinguish demonstrated risk from assumptions or theoretical exposure.

· Strong critical-thinking, technical-curiosity, attention-to-detail, and problem-solving skills.

· Excellent written and verbal communication skills, including the ability to translate technical evidence and security risk for technical and non-technical audiences.

· Demonstrated professionalism, integrity, accountability, and sound judgment.

· Ability to work independently while collaborating effectively, sharing knowledge, respecting different perspectives, and contributing to team success.

· Bachelor’s degree in information security, computer science, a related field, or equivalent professional experience.

Professional Requirements:

At least one recognized hands-on offensive security certification such as OSCP, OSWE, or an equivalent. Other certifications such as CPTS, BSCP, GPEN, GWAPT, or equivalents will be considered.

Strong desire to make a meaningful impact through client service, team contribution, continued professional growth, and active engagement with the broader offensive security community. Uphold professional and technical standards, especially when doing so is challenging.

Responsibilities

As a Penetration Tester:

· Conduct all aspects of hands-on, manual and tool-assisted penetration testing of internal and external networks, web applications, APIs, cloud platforms, and hybrid environments.

· Identify, investigate, validate, safely exploit, and document vulnerabilities and attack paths to demonstrate actual security risk and real-world impact.

· Turn technical evidence into clear, defensible findings and practical remediation guidance that helps clients understand their risk and take meaningful action.

· Take ownership of assigned engagements through completion, while producing technically accurate, well-supported deliverables that uphold Zelvin’s quality standards.

As a Teammate:

· Participate in peer reviews and give and receive constructive feedback that improves the quality and accuracy of our work.

· Develop or adapt scripts, tools, payloads, and exploitation techniques when existing approaches are insufficient

· Research emerging technologies, vulnerabilities, and attack techniques, and contribute improvements to Zelvin’s methodologies, tools, and technical capabilities to support continuous innovation.


· Combine technical excellence with curiosity, professional judgment, and accountability. Communicate concerns, share in finding solutions to barriers, and act with integrity.

Technical excellence has its greatest impact when it strengthens our clients, improves our work, and develops the people around us.

What We Offer

· Remote work environment

· Unlimited paid time off (Policy Guided)

· Continuing education and professional development opportunities

· Competitive base salary and performance-based bonus

· Medical, dental, and vision insurance

· 401(k) with company match

· Opportunities to contribute directly to Zelvin’s testing methodologies, tools, processes, and technical capabilities

· Process improvement is guided by the team and everyone’s suggestions are considered


Position Details

This is a full-time remote position with less than 5% of required travel annually.

Zelvin Security is an equal opportunity employer. Employment is contingent upon successful completion of applicable background screening, drug screening, and E-Verify requirements. This position is not eligible for visa sponsorship. Applicants must have permanent authorization to work in the U. S. at the time of hire.

Base salary is determined by experience, technical capability, certifications, and overall qualifications. Performance bonuses are awarded according to defined company standards.

Company Description

Zelvin Security is a cybersecurity firm specializing in Ethical Hacking. We work with businesses and organizations to help them secure applications, networks, architecture and other sensitive assets to reduce cybersecurity risks. Our experienced Ethical Hacking testers perform penetration tests: application, mobile, cloud, network testing and other red and purple team exercises. We are a privately owned business with strong values and a team environment.