1

Security Engineer Penetration Tester Jobs (NOW HIRING)

Qualifications โ€ข Minimum of 5 years of Information Security Engineer/Consultant experience with ... penetration testing. โ€ข Minimum of 5 years of demonstrated experience with automated penetration ...

REQUIRED QUALIFICATIONS 5+ years of experience in security applications and systems Minimum of 5 years of Information Security Engineer/Consultant experience with application penetration testing.

Penetration Tester

Arlington, VA ยท On-site

$95K - $112K/yr

ISC2 Information Systems Security Engineering Professional (ISSEP) * One of the following certifications or an alternate, verifiable certification demonstrating practical penetration testing ...

... responders, and security engineers. * Share knowledge and expertise with team members ... Conduct all penetration testing activities in a legal and ethical manner, adhering to established ...

... responders, and security engineers. * Share knowledge and expertise with team members ... Conduct all penetration testing activities in a legal and ethical manner, adhering to established ...

Penetration Tester

Leesburg, VA ยท On-site

$125K - $155K/yr

Your expertise in cloud penetration testing (FedRAMP and other compliance frameworks) and security ... and Social Engineering penetration testing. Specifically, you would: * Work closely with all ...

Penetration Tester LOCATION Chantilly, VA 20151 CLEARANCE TS/SCI Full Poly (Please note this ... Experience with cloud security assessments (e.g., AWS, Azure) * Expertise in reverse engineering ...

Penetration Tester LOCATION Reston, VA 20190 CLEARANCE TS/SCI Full Poly (Please note this position ... Experience with cloud security assessments (e.g., AWS, Azure) * Expertise in reverse engineering ...

This is a client-facing role that requires the ability to independently deliver standard penetration testing engagements while collaborating with fellow Security Engineers and Analysts and providing ...

Penetration Tester LOCATION Reston, VA 20190 CLEARANCE TS/SCI Full Poly (Please note this position ... Experience with cloud security assessments (e.g., AWS, Azure) * Expertise in reverse engineering ...

next page

Showing results 1-20

Security Engineer Penetration Tester information

See salary details

$11K

$109.6K

$183.5K

How much do security engineer penetration tester jobs pay per year?

As of Sep 9, 2026, the average yearly pay for security engineer penetration tester in the United States is $109,565.00, according to ZipRecruiter salary data. Most workers in this role earn between $80,000.00 and $143,000.00 per year, depending on experience, location, and employer.

What is the difference between Security Engineer Penetration Tester vs Security Analyst?

AspectSecurity Engineer Penetration TesterSecurity Analyst
Primary FocusIdentifying vulnerabilities through simulated attacksMonitoring and analyzing security events
CertificationsOSCP, CEH, CISSP often preferredCISSP, Security+, CEH often preferred
Work EnvironmentHands-on testing, offensive security tasksDefensive security, monitoring, incident response
Employer UsageCybersecurity firms, IT departments, consultingCorporate security teams, government agencies

While both roles focus on cybersecurity, Security Engineer Penetration Testers proactively identify vulnerabilities by simulating attacks, whereas Security Analysts monitor and respond to security threats. Both require similar certifications but differ in daily tasks and work environment.

What cities are hiring for Security Engineer Penetration Tester jobs?

Cities with the most Security Engineer Penetration Tester job openings:

What states have the most Security Engineer Penetration Tester jobs?

States with the most job openings for Security Engineer Penetration Tester jobs include:

What are popular job titles related to Security Engineer Penetration Tester jobs?

For Security Engineer Penetration Tester jobs, the most frequently searched job titles are:

Security Engineer Penetration Testing

San Jose, CA โ€ข On-site

Hallmark Global Technologies
IT Servicesย โ€ขย 501 - 1,000 employees

Other

Posted 8 days ago


Job description

Job Title: Security Engineer Penetration Testing

Location: San Jose, CA Onsite

Contract

Role summary

We are seeking a highly skilled Security Engineer specializing in Penetration Testing to strengthen our o ensive security capabilities. This role is responsible for identifying vulnerabilities across applications, infrastructure, cloud environments, and emerging AI/ML systems, including Large Language Models (LLMs) and GenAI platforms. The ideal candidate combines deep technical pentesting expertise with hands-on experience in AI security, enabling proactive defense against sophisticated and evolving threats.

Key Responsibilities:

Application & API Security Testing

  • Perform black-box, gray-box, and white-box penetration testing of:
    • Web applications, APIs (REST/GraphQL), and mobile platforms

Identify vulnerabilities including:

  • Authentication/authorization flaws
  • Injection attacks
  • Business logic vulnerabilities
  • Session Management
  • Information Gathering
  • Data Validation, Governance and Transfer
  • Configuration Management

Conduct secure code reviews and validate SAST/DAST findings

Infrastructure & Network Penetration Testing

Execute penetration testing across:

  • Enterprise networks (internal/external)
  • Cloud platforms (AWS, Azure, Google Cloud Platform)
  • Hybrid environments

Perform:

  • Privilege escalation and lateral movement
  • Active Directory assessments (Kerberos, NTLM, etc.)

Identify misconfigurations and control weaknesses

AI/ML & GenAI Security Testing

Conduct security assessments on:

  • LLM-based applications and AI copilots
  • Machine learning models and pipelines

Perform:

  • Prompt injection and jailbreak testing
  • Data leakage and model abuse scenarios
  • Adversarial ML attacks (evasion, poisoning)

Assess:

  • RAG (Retrieval-Augmented Generation) pipelines
  • Model APIs, plugins, and agent frameworks
  • E ectiveness of AI guardrails and controls

Red Teaming & Adversary Simulation

Simulate real-world attack scenarios across:

  • Applications, infrastructure, and AI systems

Develop multi-stage attack chains combining:

  • Traditional and AI-specific techniques

Support purple team exercises with SOC and detection teams

Automation & AI-Driven Security Testing

Leverage AI tools to:

  • Automate vulnerability discovery
  • Generate test cases and attack payloads
    • Develop custom tools/scripts using:
  • Python, Bash, PowerShell, or Go

Enhance scalability and repeatability of pentesting processes

Reporting & Stakeholder Engagement

Deliver:

  • Executive-level summaries (CIO/CISO ready)
  • Detailed technical reports with reproduction steps

Provide:

  • Risk-based prioritization aligned to business impact
  • Actionable remediation guide

Collaborate with:

  • Engineering, Cloud, SOC, and DevOps teams

Required Qualifications

Experience

5+ years in penetration testing, red teaming, or o ensive security

Proven experience testing:

  • Web applications, APIs, and infrastructure

Hands-on exposure to cloud security and enterprise environments

Technical Skills

Strong knowledge of:

  • OWASP Top 10 / API Top 10
  • OWASP Top 10 LLM
  • Network and infrastructure pentesting
  • Identity and Active Directory exploitation

Experience with tools such as:

  • Burp Suite, Metasploit, Nmap
  • BloodHound, Mimikatz, Nessus

AI Security

Understanding of:

  • LLM architectures and GenAI use cases
  • RAG pipelines, embeddings, and vector databases

Experience with:

  • Prompt injection testing
  • AI red teaming or model security assessments

Exposure to:

  • LangChain, Semantic Kernel, or similar frameworks

Programming

Proficiency in:

  • Python (required)
  • Scripting (Bash/PowerShell)

Ability to develop:

  • Custom testing tools and exploit scripts