1

Web App Penetration Testing Jobs (NOW HIRING)

Proven experience conducting penetration tests of web applications, networks, and other systems. * Experience with a variety of penetration testing tools and techniques (e.g., Rapid7 Nexpose ...

Penetration Tester

Quantico, VA · On-site

$130K - $147K/yr

Penetration Testing: * Conduct penetration tests of web applications, mobile applications, networks, cloud environments, and other systems. * Utilize a variety of tools and techniques to identify ...

Network penetration testing and experience working with network infrastructure * An understanding ... Experience conducting web application security assessments * Experience working with a range of ...

... penetration testing and security assessments for government clients, requiring an active Secret ... Company : M9 Solutions is a national staffing firm focused on cloud, cyber security, web ...

Web Application Testing: * Conduct security assessments of agency web applications using OWASP Top ... Penetration Testing & Exploitation Validation: * Perform controlled penetration testing (internal ...

Penetration Tester

Leesburg, VA · On-site

$125K - $155K/yr

Work closely with all members of the team to conduct penetration testing of customer networks, applications (API, web, and mobile), and/or social engineering activities to achieve the customer ...

Showing results 41-60

Web APP Penetration Testing information

See salary details

$11

$59

$86

How much do web app penetration testing jobs pay per hour?

As of Aug 12, 2026, the average hourly pay for web app penetration testing in the United States is $59.01, according to ZipRecruiter salary data. Most workers in this role earn between $51.20 and $66.83 per hour, depending on experience, location, and employer.

Is a web app penetration tester a good career?

A web app penetration tester is a specialized cybersecurity professional who assesses web applications for vulnerabilities using tools like Burp Suite and knowledge of security protocols. The role offers high demand, competitive salaries, and opportunities for certification such as OSCP or CEH, making it a valuable career path for those interested in cybersecurity and ethical hacking.

What is a web app penetration testing?

A Web App Penetration Testing job involves assessing the security of web applications by simulating real-world attacks. Security professionals use various techniques to identify vulnerabilities like SQL injection, cross-site scripting (XSS), or authentication flaws. The goal is to help organizations strengthen their web applications by providing recommendations for fixing security weaknesses. Testers use tools like Burp Suite, OWASP ZAP, and manual testing techniques to ensure comprehensive coverage. This job requires knowledge of ethical hacking, web technologies, and cybersecurity best practices.

What does a typical workday look like for someone in web app penetration testing?

A typical day in Web App Penetration Testing involves actively assessing web applications for security weaknesses using both automated tools and manual testing techniques, reviewing code when necessary, and documenting findings comprehensively. You may also participate in meetings with developers and stakeholders to discuss vulnerabilities, advise on remediation steps, and help prioritize risk mitigation tasks. Many roles offer a mix of independent analysis and team collaboration, with frequent opportunities to learn about new technologies and threats. This environment encourages continuous learning and offers clear pathways for career growth, such as advancing to a senior tester, security consultant, or application security architect.

What are the key skills and qualifications needed to thrive in web app penetration testing, and why are they important?

To thrive as a Web App Penetration Tester, you need a strong understanding of web application security, common vulnerabilities (such as OWASP Top 10), and solid programming/scripting skills, usually underpinned by a degree in computer science or a related field. Familiarity with tools like Burp Suite, OWASP ZAP, Metasploit, and certifications such as OSCP or CEH are highly valued. Attention to detail, analytical thinking, effective communication, and problem-solving are crucial soft skills for this role. These competencies help ensure that vulnerabilities are thoroughly identified, clearly reported, and resolved in collaboration with development teams, ultimately supporting organizational security.

More about Web APP Penetration Testing jobs
What are the most commonly searched types of Web App Penetration Testing jobs? The most popular types of Web App Penetration Testing jobs are:
What states have the most Web App Penetration Testing jobs? States with the most job openings for Web App Penetration Testing jobs include:
What job categories do people searching Web App Penetration Testing jobs look for? The top searched job categories for Web App Penetration Testing jobs are:
Infographic showing various Web App Penetration Testing job openings in the United States as of August 2026, with employment types broken down into 25% Full Time, 25% Part Time, and 50% Contract. Highlights an 100% In-person job distribution, with an average salary of $122,736 per year, or $59 per hour.

Penetration Tester (Part Time & Remote)

TestPros

Sterling, VA • Remote

Part-time

Re-posted 23 days ago


Job description

TestPros delivers innovative independent IT assessment solutions to critical challenges facing the nation and the world.  We support the U.S. Federal Government and Commercial clients within the continental USA. TestPros is dedicated to making lives better, safer and more secure.
TestPros is looking for an experienced Penetration Testers to support our IT Security consulting work for various Commercial and Federal consulting services projects.  
Start: Future projects late 2026 or 2027 (not an immediate job opening) 
Type: Part-time consulting
Overview
This role is responsible for the successful delivery of penetration testing in both classic hosted and also in cloud hosted environments.  In this role, the selected candidate will work with our client’s product development teams to plan for, execute, and report on the results of penetration testing. You must be delivery and efficiency focused, with the ability to manage all aspects of a consulting project to include requirements analysis, bid and proposal development, resource planning, process improvement, and customer relationship management.  The ideal candidate will thrive in a fast-paced environment where personal responsibility and open, direct, respectful communications are highly valued. 
Responsibilities: ​​​

  • Conduct complete penetration tests, report on results, and provide improvement recommendations
  • Ensure customer satisfaction through the delivery of high-quality consulting services across a portfolio of commercial and federal government projects
  • Ability to elicit and understand customer requirements and covert those requirements into a technical services solution
  • Ability to accurately estimate time and cost for each project
  • Foster an environment of continuous learning, innovation and excellence 
  • Work closely with development teams, product managers, and customer success teams to ensure successful delivery of consulting services or product implementation projects and remove roadblocks 
  • Develop, review and approve formal statements of work, change requests, and proposals 
  • Formulate timely reports and documentation to track progress 
  • Effectively collaborate with peers and company leadership to accomplish team, corporate and client objectives 
  • Answer developer, designer, and content contributor questions about IT Security requirements.  
Experience Requirements: 
  • Minimum of 5 years of experience in penetration testing
  • Desired certifications – Security+, CEH, GPEN, OSCP, AWS, or equivalent
  • Understanding of OWASP Top 10 and “industry best practices” for penetration testing
  • Understanding of all aspects of Penetration Testing with an emphasis on white box testing, black box testing, internal networks, external networks, web applications, and application/code review
  • Understanding of Pen Test methods such as Open Source Security Testing Methodology Manual (OSSTMM), Open Web Application Security Project (OWASP), Penetration Testing Execution Standard (PTES), FedRAMP Penetration Test Guide, NIST, etc.
  • Proficient with the command line interface of multiple operating systems – Windows, macOS, Linux, etc.
  • Solid understanding of manual scripting and scripting languages- ex. Python, Bash, PowerShell, C/C++, etc.
  • Proficient with using commercial and open source penetration testing tools – ex. Metasploit, Nikto, SQLMAP, Responder, Nessus, Netcat, Burp Suite, etc.
  • Conduct and document vulnerability scans and penetration testing on web-based applications and their underlying hosts
  • Proven ability to perform computer network vulnerability assessment and penetration testing
  • Understanding of risk planning and mitigation strategies
  • Ability to prepare and present documents and briefing materials
  • Advise on new threats to the technologies and environment and provide mitigation steps when applicable
  • Provide security guidance on design, deployment, and architecture of web-based and cloud hosted applications.
  • Participate in technical discussions and collaborate with team members
  • Exceptional communication skills - both orally and written
  • Strong customer service skills
  • Strong organizational and time-management skills with the ability to handle multiple tasks at once, while still paying attention to detail 
  • A strong work ethic and self-starter attitude, with the ability to thrive in a fast-paced environment 
  • Bachelor’s degree in a related field or equivalent work experience and advance

Rate: $50-85/hr (1099 or Corp. To Corp.). This range represents a good-faith estimate and is not a guarantee; final compensation is determined by factors such as experience, qualifications, and government contract labor rate requirements and may fall outside the stated range. 
Equal Opportunity Employer
TestPros is an equal-opportunity employer and does not discriminate in employment based on race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, retaliation, parental status, military service, or any other non-merit factor.
Offer Considerations
TestPros considers several factors when extending an offer, including but not limited to, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, geographic location, education, and certifications.
Federal Compliance
As a federal contractor, TestPros is subject to all federal and state mandates and/or other customer requirements.

Powered by JazzHR

YyqqwR9LpU