1

Security Testing Jobs (NOW HIRING)

Experience with security testing tools such as Proxy tools, Black box security testing tools, and ... Static Security Code analysis tools. * Knowledge of application security vulnerabilities like OWASP ...

Responsibilities : • Perform authorized security testing on complex, large-scale, and critical applications. • Work independently and in a team-oriented environment. • Present findings to ...

National Security Programs * Professional, Administrative, and Management Support * Mission and ... Penetration Testing Team Lead Location: National Capital Region Clearance: Secret Duties and ...

Security Engineer Primarily focused on manual penetration testing and cache fraud and places of vulnerabilities, specifically vulnerabilities in authorization, permissions, and MFA. Candidates who ...

Role: Penetration Testing / Security Test Engineer Location: Santa Clara, CA Role Summary The Application Security & Penetration Testing Specialist will be responsible for conducting security ...

next page

Showing results 1-20

Security Testing information

See salary details

$17

$51

$83

How much do security testing jobs pay per hour?

As of Jun 25, 2026, the average hourly pay for security testing in the United States is $51.09, according to ZipRecruiter salary data. Most workers in this role earn between $43.75 and $61.30 per hour, depending on experience, location, and employer.

What is the difference between Security Testing vs Penetration Testing?

AspectSecurity TestingPenetration Testing
PurposeIdentify security flaws and vulnerabilities in systems and applicationsSimulate cyberattacks to exploit vulnerabilities and assess security defenses
ScopeBroad, including security policies, configurations, and overall security postureFocused on exploiting specific vulnerabilities to test defenses
CertificationsSecurity+ (CompTIA), CEH, CISSP (common but not exclusive)OSCP, CEH, GPEN
Work EnvironmentSecurity teams, testing labs, development environmentsSecurity consultants, ethical hackers, penetration testers

Security Testing and Penetration Testing are related but distinct roles. Security Testing provides a comprehensive assessment of security weaknesses, while Penetration Testing focuses on actively exploiting vulnerabilities to evaluate defenses. Both are essential for maintaining robust security but serve different purposes within cybersecurity strategies.

What does a security tester do?

A security tester, also known as a penetration tester or ethical hacker, evaluates computer systems, networks, and applications for vulnerabilities by simulating cyberattacks. They use tools like vulnerability scanners and follow security standards to identify weaknesses and recommend improvements to protect against malicious threats.

What is security testing?

Security testing is a process used to identify vulnerabilities, threats, and risks in software applications or IT systems, ensuring that data and resources are protected from possible intruders. It involves evaluating the security features of a system to determine if its data is protected and to ensure the system behaves as expected when faced with malicious input or attacks. Security testing helps organizations protect sensitive information, comply with regulations, and maintain trust with users.

How does a security testing professional typically collaborate with development and IT teams during a project?

Security testing professionals often work closely with both development and IT teams to identify and mitigate vulnerabilities throughout the software development lifecycle. They participate in code reviews, conduct penetration tests, and provide actionable feedback to developers to help resolve security issues. Regular communication and collaboration are essential, as security testers often create detailed reports and recommendations, and may also lead training sessions to raise security awareness among team members. This collaborative approach ensures that security is integrated seamlessly into both the development process and ongoing IT operations.

Is security testing in demand?

Security testing is in high demand as organizations prioritize protecting their systems from cyber threats. Skilled security testers with knowledge of tools like penetration testing and vulnerability assessment are sought after across various industries, often requiring certifications such as CISSP or CEH. The field is expected to grow as cybersecurity remains a top priority for businesses worldwide.

Is 40 too old for cyber security?

Security testing is a field that values skills and experience over age, and many professionals successfully enter or continue in cybersecurity at age 40 and beyond. Relevant skills such as knowledge of security tools, certifications like CISSP, and continuous learning are more important than age when pursuing a career in cybersecurity.

What are the key skills and qualifications needed to thrive as a Security Tester, and why are they important?

To thrive as a Security Tester, you need expertise in cybersecurity principles, vulnerability assessment, and penetration testing, usually supported by a degree in computer science or related field and relevant certifications. Familiarity with tools like Metasploit, Burp Suite, and Wireshark, as well as knowledge of scripting languages, is typically required. Strong analytical thinking, problem-solving skills, and clear communication help Security Testers effectively identify and report risks. These skills are essential to safeguard organizational assets by proactively detecting and mitigating security threats.

Can you make $500,000 a year in cyber security?

Security testing roles, such as penetration testers or security consultants, can reach high salaries, especially with extensive experience, advanced certifications, and specialized skills. Senior professionals in cybersecurity can earn over $200,000 annually, but reaching $500,000 typically requires leadership positions, consulting, or working in high-demand industries with significant responsibilities.
More about Security Testing jobs
What cities are hiring for Security Testing jobs? Cities with the most Security Testing job openings:
What states have the most Security Testing jobs? States with the most job openings for Security Testing jobs include:
Infographic showing various Security Testing job openings in the United States as of June 2026, with employment types broken down into 76% Full Time, 21% Part Time, and 3% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $106,258 per year, or $51.1 per hour.
Web Application Security Testing Team Lead

Web Application Security Testing Team Lead

gTANGIBLE

Arlington, VA

Full-time

Posted 2 days ago


Job description

gTANGIBLE Corporation (gTC), www.gtangible.com, is a C corporation and a registered Government contractor that provides services and solutions in:

  • National Security Programs
  • Professional, Administrative, and Management Support
  • Mission and Warfighter Support

We are a Service Disabled Veteran Owned Small Business (SDVOSB) and the founder has years of successful experience in the Government contracting arena. Our leadership team is an exceptional group of Government contracting professionals. gTANGIBLE is in the process of identifying candidates for the following position.

Requisition Type: Full Time

Position Status: Contingent

Position Title: Web Application Security Testing Team Lead

Location: National Capital Region

Security Clearance: Secret

Duties and Responsibilities

The Web Application Security Testing Team Lead supports this Transportation Security Administration Information Technology (TSA IT) Task Order (TO) by web application testing that require testing both via automated tools and with manual testing techniques. Application testing will require authenticated and non-authenticated testing to ensure full evaluation of the cybersecurity controls for the applications. Off hours testing conducted on a as needed basis. Periodic travel required.

Team duties include the following:

  • Become, and remain, familiar with TSA and DHS security policies and Technical Standards relating to web applications and web application development to facilitate effective security assessments. Make recommendations for updates, additions, and modifications to TSA security policy as gaps or deficiencies in security policy are identified.
  • Engage with testing engagement stakeholders to gather all required information needed to create detailed test plans.
  • Conduct security testing of web applications and services (and other web-related assets) using both Information Assurance and Cybersecurity Division (IAD)-provided automated testing tools and manual testing techniques.
  • Troubleshoot any technical issues preventing successful completion of testing engagements within the scheduled time allotted for the engagement (i.e. insufficient credentials, proxy blocking, accounts blocked/expired, etc.).
  • Participate in findings meetings to review and provide input on the validity of application stakeholder responses to IAD findings.
  • Recommend adjustments of finding validity (valid or false positive) and severity (high, medium, low) to Governance, Risk, and Compliance (GRC) Portfolio Managers and Primary Assessors based on stakeholder responses.
  • Review application stakeholder mitigation or remediation actions to address valid findings to assist IAD with determining the applicability and effectiveness of those actions.
  • Provide Subject Matter Expertise for a variety of topics concerning web applications in a variety of formats (verbal or written). Includes common and emerging web and mobile technologies, languages, and frameworks to discuss the benefits and security detriments of those technologies.
  • Provide support for external security audits conducted of the TSA. Such support would include items such as: providing technical insight into data calls required by external Federal entities, offering technical information to facilitate external auditors work, or validating findings identified in external audit reports.

Knowledge and Qualifications

  • At least eight (8) years of technical IT security experience. Such experience can come from system or network administration, security analysis, security testing and evaluation, security incident response, security monitoring, IT project implementation, or other similar technical activities.
  • At least five (5) years of experience performing security control assessments (i.e. security testing such as security auditing, primary assessor for Security Control Assessments, etc.).
  • At least three (3) years of experience performing web application security testing.
  • At least one (1) year of experience performing security testing of Federal IT systems.
  • Experience with NIST and FIPS security controls, DISA STIGs, and CIS standards.
  • Experience working in groups acting as the sole security practitioner, as well as experience working in team(s) of various sizes of security personnel reviewing the same system.
  • Experience with HP WebInspect, IBM/HCL AppScan, Portswigger BurpSuite, SmartBear SoapUI, Nessus Professional, HP Fortify, Apple Developers Toolkit, Eclipse, and Wireshark.
  • Excellent communication skills to be able to understand concepts being verbally presented, participate in group discussions, and to present recommendations.
  • Strong organizational, analytical, and technical writing skills to be able to document findings in reports.

gTANGIBLE Corporation is an equal opportunity employer and does not discriminate against any employee or applicant because of race, age, sex, color, physical or mental disability, religion, sexual orientation, marital status, national origin, or political affiliation.

Employment Type: Full-Time