1

Security Testing Jobs in Maryland (NOW HIRING)

Lead Security Engineer

Suitland, MD · On-site

$120K - $190K/yr

Direct Static and Dynamic Application Security Testing (SAST/DAST), vulnerability assessments, and penetration testing to identify, triage, and remediate security weaknesses * Lead threat modeling ...

Direct Static and Dynamic Application Security Testing (SAST/DAST), vulnerability assessments, and penetration testing to identify, triage, and remediate security weaknesses * Lead threat modeling ...

Lead Security Engineer

Suitland, MD · On-site

$120K - $190K/yr

Direct Static and Dynamic Application Security Testing (SAST/DAST), vulnerability assessments, and penetration testing to identify, triage, and remediate security weaknesses * Lead threat modeling ...

Direct Static and Dynamic Application Security Testing (SAST/DAST) , vulnerability assessments, and penetration testing to identify, triage, and remediate security weaknesses * Lead threat modeling ...

Direct Static and Dynamic Application Security Testing (SAST/DAST) , vulnerability assessments, and penetration testing to identify, triage, and remediate security weaknesses * Lead threat modeling ...

next page

Showing results 1-20

Security Testing information

See Maryland salary details

$16

$49

$81

How much do security testing jobs pay per hour?

As of Aug 20, 2026, the average hourly pay for security testing in Maryland is $49.58, according to ZipRecruiter salary data. Most workers in this role earn between $42.45 and $59.47 per hour, depending on experience, location, and employer.

What is security testing?

Security testing is a process used to identify vulnerabilities, threats, and risks in software applications or IT systems, ensuring that data and resources are protected from possible intruders. It involves evaluating the security features of a system to determine if its data is protected and to ensure the system behaves as expected when faced with malicious input or attacks. Security testing helps organizations protect sensitive information, comply with regulations, and maintain trust with users.

What are the key skills and qualifications needed to thrive as a security tester?

To thrive as a Security Tester, you need expertise in cybersecurity principles, vulnerability assessment, and penetration testing, usually supported by a degree in computer science or related field and relevant certifications. Familiarity with tools like Metasploit, Burp Suite, and Wireshark, as well as knowledge of scripting languages, is typically required. Strong analytical thinking, problem-solving skills, and clear communication help Security Testers effectively identify and report risks. These skills are essential to safeguard organizational assets by proactively detecting and mitigating security threats.

How does a security testing professional typically collaborate with development and IT teams during a project?

Security testing professionals often work closely with both development and IT teams to identify and mitigate vulnerabilities throughout the software development lifecycle. They participate in code reviews, conduct penetration tests, and provide actionable feedback to developers to help resolve security issues. Regular communication and collaboration are essential, as security testers often create detailed reports and recommendations, and may also lead training sessions to raise security awareness among team members. This collaborative approach ensures that security is integrated seamlessly into both the development process and ongoing IT operations.

What is the difference between Security Testing vs Penetration Testing?

AspectSecurity TestingPenetration Testing
PurposeIdentify security flaws and vulnerabilities in systems and applicationsSimulate cyberattacks to exploit vulnerabilities and assess security defenses
ScopeBroad, including security policies, configurations, and overall security postureFocused on exploiting specific vulnerabilities to test defenses
CertificationsSecurity+ (CompTIA), CEH, CISSP (common but not exclusive)OSCP, CEH, GPEN
Work EnvironmentSecurity teams, testing labs, development environmentsSecurity consultants, ethical hackers, penetration testers

Security Testing and Penetration Testing are related but distinct roles. Security Testing provides a comprehensive assessment of security weaknesses, while Penetration Testing focuses on actively exploiting vulnerabilities to evaluate defenses. Both are essential for maintaining robust security but serve different purposes within cybersecurity strategies.

How do you do security testing?

Security testing involves identifying vulnerabilities in systems, applications, or networks through techniques like penetration testing, vulnerability scanning, and code review. Security testers use tools such as scanners and testing frameworks, and often hold certifications like OSCP or CISSP to ensure thorough assessments. The process includes planning, executing tests, analyzing results, and reporting findings to improve security posture.

What skills are needed for security testing?

Security testing requires strong knowledge of networking, operating systems, and security protocols, along with skills in vulnerability assessment, penetration testing, and familiarity with tools like Metasploit, Burp Suite, or Wireshark. Analytical thinking, attention to detail, and understanding of coding or scripting languages such as Python or Bash are also important. Certifications like CEH or OSCP can enhance a security tester's qualifications.

What type of security testing job pays the most?

Senior security testing roles such as Security Architect, Penetration Tester, or Security Consultant typically offer the highest salaries in security testing, especially when combined with advanced certifications like CISSP or OSCP. These positions often require extensive experience, specialized skills, and knowledge of tools like Burp Suite, Metasploit, or Kali Linux, and may involve leading complex security assessments or designing security frameworks.
Infographic showing various Security Testing job openings in Maryland as of August 2026, with employment types broken down into 81% Full Time, 16% Part Time, and 3% Contract. Highlights an 91% In-person, and 9% Remote job distribution, with an average salary of $103,127 per year, or $49.6 per hour.

Senior Security Code Reviewer

Ashburn Consulting

Camp Springs, MD

$120K - $164K/yr

Full-time

Re-posted 23 days ago


Job description

Company Description

Ashburn Consulting, LLC, based in the Washington, DC metropolitan area, specializes in providing network and network security solutions in complex environments to a select set of government and business clients. The company, an established leader in its field, is composed of an elite team of engineers and business consultants, each of whom is recognized, and highly regarded, within the network and security communities. 

Job Description

Ashburn is seeking a Senior Security Code Reviewer to support a federal cybersecurity architecture opportunity. This Key Personnel role will lead application security testing, secure code review, DevSecOps pipeline integration, secure development guidance, risk assessments, and cloud/network security evaluation for a proposal opportunity.

Primary Responsibilities

  • Conduct security code reviews and risk assessments for applications and enterprise systems.
  • Use application security testing tools to identify vulnerabilities and provide remediation guidance.
  • Integrate security testing into DevSecOps and CI/CD pipelines.
  • Review application architecture, source code, dependencies, infrastructure-as-code, and deployment practices.
  • Support secure coding standards, developer security training, and technical remediation guidance.
  • Evaluate and improve cloud, network, and enterprise system security.
  • Provide technical writing, reporting, and mentoring to engineering and development teams.
  • Support federal cybersecurity compliance objectives and secure development lifecycle requirements.
Qualifications

Required Qualifications

  • Candidates must be U.S. citizens.
  • Candidates must be willing and able to work as Ashburn W-2 employees. 1099 and corp-to-corp arrangements are not permitted for these roles.
  • DHS EOD / suitability is required.
  • 10+ years of experience automating application security scanning processes, Zero Trust integration, and data sanitization for Government or similarly complex enterprise systems.
  • Experience deploying and using Application Security Testing platforms such as Checkmarx.
  • Experience automating or supporting Zero Trust Network Access (ZTNA) and Secure Web Gateway (SWG) solutions.
  • Advanced security engineering experience across on-premises and cloud environments.
  • Experience implementing AWS security best practices, including VPC Flow Logs, Security Lake, and audit monitoring.
  • Experience building EKS clusters using Terraform and Kubernetes.
  • Experience creating custom hardened AMI builds.
  • Experience integrating network security tools such as Palo Alto, AlgoSec, Gigamon, and Corelight.
  • Experience reviewing, evaluating, and improving security of complex systems and networks.
  • Experience with vulnerability management, SIEM integrations, certificate management, single sign-on implementations, and federal regulatory compliance.
  • Demonstrated ability to lead security code reviews and conduct risk assessments.
  • Experience developing OS hardening strategies, evaluating firewall policies, and implementing enterprise infrastructure monitoring solutions.
  • Strong technical writing, training, and mentoring skills.
  • Ability to mentor development teams in secure coding practices and align technical solutions to Government cybersecurity objectives.

Preferred / Strongly Desired Qualifications

  • Experience with Burp Suite, Checkmarx One, PortSwigger, SonarQube, Fortify, SAST, DAST, SCA, API security testing, or IaC scanning.
  • Experience integrating application security testing into CI/CD pipelines.
  • Experience with secure coding practices in Java, Python, JavaScript, C#, Ruby, SQL, React, Node.js, PowerShell, Go, or similar languages.
  • Experience applying OWASP, NIST, DHS, DevSecOps, and secure software lifecycle practices.
  • Secure software certification preferred, such as CSSLP, GIAC secure software credential, EC-Council secure programmer certification, or comparable experience.
  • Prior DHS, DOD / DOW or federal application security experience.

Additional Information

PHYSICAL REQUIREMENTS:
Work is equally performed in the field as well as in a normal office environment. Lifting (up to 50lbs) may be required. Ladder climbing may be required. Driving is required. All duties performed with or without reasonable accommodations.

Additional Information

Equal Opportunity Employer/Veterans/Disabled. An Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status

Ashburn Consulting is an Equal Opportunity Affirmative Action Employer.
In compliance with the American with Disabilities Act Amendments Act (ADAAA), if you have a disability and would like to request and accommodation in order to apply for a position with Ashburn Consulting, please e-mail hr@ashburnconsulting.com.

Ashburn Consulting is an Equal Opportunity Affirmative Action Employer.
In compliance with the American with Disabilities Act Amendments Act (ADAAA), if you have a disability and would like to request and accommodation in order to apply for a position with Ashburn Consulting, please e-mail hr@ashburnconsulting.com.