1

Security Testing Jobs (NOW HIRING)

$112K - $228K/yr

As a Security Testing Specialist Sr within PNC's Technology Security organization, you will be based in Denver, CO; Phoenix, AZ; Birmingham, AL; Dallas, TX; Pittsburgh, PA or Cleveland, OH. This role ...

As part of BMO's Security Testing Team, you'll play a key role in building and advancing our AI Security Testing capability, assessing cutting-edge AI technologies, large language models (LLMs), AI ...

Showing results 41-60

Security Testing information

See salary details

$17

$51

$83

How much do security testing jobs pay per hour?

As of Aug 20, 2026, the average hourly pay for security testing in the United States is $51.09, according to ZipRecruiter salary data. Most workers in this role earn between $43.75 and $61.30 per hour, depending on experience, location, and employer.

What is security testing?

Security testing is a process used to identify vulnerabilities, threats, and risks in software applications or IT systems, ensuring that data and resources are protected from possible intruders. It involves evaluating the security features of a system to determine if its data is protected and to ensure the system behaves as expected when faced with malicious input or attacks. Security testing helps organizations protect sensitive information, comply with regulations, and maintain trust with users.

What are the key skills and qualifications needed to thrive as a security tester?

To thrive as a Security Tester, you need expertise in cybersecurity principles, vulnerability assessment, and penetration testing, usually supported by a degree in computer science or related field and relevant certifications. Familiarity with tools like Metasploit, Burp Suite, and Wireshark, as well as knowledge of scripting languages, is typically required. Strong analytical thinking, problem-solving skills, and clear communication help Security Testers effectively identify and report risks. These skills are essential to safeguard organizational assets by proactively detecting and mitigating security threats.

How does a security testing professional typically collaborate with development and IT teams during a project?

Security testing professionals often work closely with both development and IT teams to identify and mitigate vulnerabilities throughout the software development lifecycle. They participate in code reviews, conduct penetration tests, and provide actionable feedback to developers to help resolve security issues. Regular communication and collaboration are essential, as security testers often create detailed reports and recommendations, and may also lead training sessions to raise security awareness among team members. This collaborative approach ensures that security is integrated seamlessly into both the development process and ongoing IT operations.

What is the difference between Security Testing vs Penetration Testing?

AspectSecurity TestingPenetration Testing
PurposeIdentify security flaws and vulnerabilities in systems and applicationsSimulate cyberattacks to exploit vulnerabilities and assess security defenses
ScopeBroad, including security policies, configurations, and overall security postureFocused on exploiting specific vulnerabilities to test defenses
CertificationsSecurity+ (CompTIA), CEH, CISSP (common but not exclusive)OSCP, CEH, GPEN
Work EnvironmentSecurity teams, testing labs, development environmentsSecurity consultants, ethical hackers, penetration testers

Security Testing and Penetration Testing are related but distinct roles. Security Testing provides a comprehensive assessment of security weaknesses, while Penetration Testing focuses on actively exploiting vulnerabilities to evaluate defenses. Both are essential for maintaining robust security but serve different purposes within cybersecurity strategies.

How do you do security testing?

Security testing involves identifying vulnerabilities in systems, applications, or networks through techniques like penetration testing, vulnerability scanning, and code review. Security testers use tools such as scanners and testing frameworks, and often hold certifications like OSCP or CISSP to ensure thorough assessments. The process includes planning, executing tests, analyzing results, and reporting findings to improve security posture.

What skills are needed for security testing?

Security testing requires strong knowledge of networking, operating systems, and security protocols, along with skills in vulnerability assessment, penetration testing, and familiarity with tools like Metasploit, Burp Suite, or Wireshark. Analytical thinking, attention to detail, and understanding of coding or scripting languages such as Python or Bash are also important. Certifications like CEH or OSCP can enhance a security tester's qualifications.

What type of security testing job pays the most?

Senior security testing roles such as Security Architect, Penetration Tester, or Security Consultant typically offer the highest salaries in security testing, especially when combined with advanced certifications like CISSP or OSCP. These positions often require extensive experience, specialized skills, and knowledge of tools like Burp Suite, Metasploit, or Kali Linux, and may involve leading complex security assessments or designing security frameworks.
More about Security Testing jobs

What cities are hiring for Security Testing jobs?

Cities with the most Security Testing job openings:

What states have the most Security Testing jobs?

States with the most job openings for Security Testing jobs include:

Infographic showing various Security Testing job openings in the United States as of August 2026, with employment types broken down into 87% Full Time, 11% Part Time, and 2% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $106,258 per year, or $51.1 per hour.

Senior Security Test & Evaluation Analyst

PB consulting

Barre, VT โ€ข Hybrid

Full-time

Posted 6 days ago


Job description

Seeking a Senior Security Test & Evaluation Analyst with strong experience in security testing, vulnerability assessment, ethical hacking, and AI-enabled security testing. The ideal candidate will combine traditional security assessment expertise with hands-on experience applying AI technologies to static/dynamic testing, control assessments, vulnerability analysis, and security validation across on-premises and cloud environments.

Key Responsibilities

* Conduct comprehensive security testing across reconnaissance, scanning, exploitation, and post-exploitation phases.
* Perform static/dynamic code reviews, architecture reviews, control assessments, and vulnerability testing.
* Implement and integrate AI-enabled solutions into security test and evaluation processes.
* Conduct authenticated and unauthenticated security testing across applications, infrastructure, and cloud environments.
* Analyze AI-generated security findings and identify vulnerabilities, exploitability, and remediation strategies.
* Support security testing across AWS, Azure, ServiceNow, and hybrid environments.
* Develop security metrics, technical reports, and analytic products demonstrating testing effectiveness.
* Collaborate with stakeholders to assess vulnerabilities, prioritize risks, and develop remediation plans.
* Ensure security testing and AI implementations comply with applicable governance, security, and regulatory standards.

Required Qualifications

* 5+ years of hands-on security test and evaluation experience.
* Experience with tools such as Tenable Nessus, GitLab, Fortify, Invicti, Mandiant, Kali Linux, and Wiz.
* 3+ years of experience testing cloud environments, including AWS and Azure.
* Strong hands-on experience with ethical hacking and penetration testing methodologies.
* Experience implementing AI solutions for security testing and evaluation.
* Experience identifying, validating, and analyzing security vulnerabilities and attack vectors.
* Strong stakeholder collaboration, analytical, problem-solving, and documentation skills.

Preferred Qualifications

* Experience applying AI-enabled capabilities to security testing in hybrid environments.
* Strong knowledge of network, operating system, database, web application, and cloud security.
* Knowledge of common vulnerabilities including SQL injection, XSS, CSRF, and API security.
* Experience with Windows, Linux, macOS, network devices, and security technologies.
* Experience working with NIST, FISMA, FedRAMP, and OMB security requirements.
* Strong technical communication and reporting skills.