... penetration testing of modern Windows and Linux operating systems, IP-based networks and protocols, 802.11 networks, and/or web applications, hardware hacking, software defined networks/RF * 10+ ...
... penetration testing of modern Windows and Linux operating systems, IP-based networks and protocols, 802.11 networks, and/or web applications, hardware hacking, software defined networks/RF * 10+ ...
Automation Engineer
Tampa, FL · On-site
$90K - $115K/yr
... web app teams) to understand: • Application workflows • UI components • Business logic for ... testing and automation using Python libraries to validate REST services and backend processes • ...
Automation Engineer
Tampa, FL · On-site
$90K - $115K/yr
... web app teams) to understand: • Application workflows • UI components • Business logic for ... testing and automation using Python libraries to validate REST services and backend processes • ...
... penetration testing of modern Windows and Linux operating systems, IP-based networks and protocols, 802.11 networks, and/or web applications, hardware hacking, software defined networks/RF • 10+ ...
... penetration testing of modern Windows and Linux operating systems, IP-based networks and protocols, 802.11 networks, and/or web applications, hardware hacking, software defined networks/RF • 10+ ...
... Project Web App • Analyze WCS Software Resources within Project Web App to identify risk ... Testing, and Go Live Qualifications : Required : • Bachelor's degree in Software Engineering ...
... Project Web App • Analyze WCS Software Resources within Project Web App to identify risk ... Testing, and Go Live Qualifications : Required : • Bachelor's degree in Software Engineering ...
Hands-on experience designing and running A/B and multivariate tests with a testing platform (e.g., Optimizely, VWO, or similar) * Strong working knowledge of web/app analytics (GA4 strongly ...
Hands-on experience designing and running A/B and multivariate tests with a testing platform (e.g., Optimizely, VWO, or similar) * Strong working knowledge of web/app analytics (GA4 strongly ...
Hands-on experience designing and running A/B and multivariate tests with a testing platform (e.g., Optimizely, VWO, or similar) * Strong working knowledge of web/app analytics (GA4 strongly ...
Hands-on experience designing and running A/B and multivariate tests with a testing platform (e.g., Optimizely, VWO, or similar) * Strong working knowledge of web/app analytics (GA4 strongly ...
Software Project Manager II
Clearwater, FL · On-site
... testing lifecycles (Internal QA, Conference Room Pilot, Factory Acceptance Testing, On Site ... Analyze WCS Software Resources within Project Web App to identify risk, modifications, and ...
Software Project Manager II
Clearwater, FL · On-site
... testing lifecycles (Internal QA, Conference Room Pilot, Factory Acceptance Testing, On Site ... Analyze WCS Software Resources within Project Web App to identify risk, modifications, and ...
Software Project Manager II
Clearwater, FL · On-site
... testing lifecycles (Internal QA, Conference Room Pilot, Factory Acceptance Testing, On Site ... Analyze WCS Software Resources within Project Web App to identify risk, modifications, and ...
Software Project Manager II
Clearwater, FL · On-site
... testing lifecycles (Internal QA, Conference Room Pilot, Factory Acceptance Testing, On Site ... Analyze WCS Software Resources within Project Web App to identify risk, modifications, and ...
Software Project Manager II
Clearwater, FL · On-site
... testing lifecycles (Internal QA, Conference Room Pilot, Factory Acceptance Testing, On Site ... Analyze WCS Software Resources within Project Web App to identify risk, modifications, and ...
Software Project Manager II
Clearwater, FL · On-site
... testing lifecycles (Internal QA, Conference Room Pilot, Factory Acceptance Testing, On Site ... Analyze WCS Software Resources within Project Web App to identify risk, modifications, and ...
Conversion Rate Optimization (CRO) Specialist
Miami Gardens, FL · On-site
$85 - $110/hr
Hands‑on experience designing and running A/B and multivariate tests with a testing platform (e.g., Optimizely, VWO, or similar). * Strong working knowledge of web/app analytics (GA4 strongly ...
Conversion Rate Optimization (CRO) Specialist
Miami Gardens, FL · On-site
$85 - $110/hr
Hands‑on experience designing and running A/B and multivariate tests with a testing platform (e.g., Optimizely, VWO, or similar). * Strong working knowledge of web/app analytics (GA4 strongly ...
Software Project Manager III
Clearwater, FL · On-site
... testing lifecycles (Internal QA, Conference Room Pilot, Factory Acceptance Testing, On Site ... Analyze WCS Software Resources within Project Web App to identify risk, modifications, and ...
Software Project Manager III
Clearwater, FL · On-site
... testing lifecycles (Internal QA, Conference Room Pilot, Factory Acceptance Testing, On Site ... Analyze WCS Software Resources within Project Web App to identify risk, modifications, and ...
Software Project Manager II
Clearwater, FL · On-site
... testing lifecycles (Internal QA, Conference Room Pilot, Factory Acceptance Testing, On Site ... Analyze WCS Software Resources within Project Web App to identify risk, modifications, and ...
Software Project Manager II
Clearwater, FL · On-site
... testing lifecycles (Internal QA, Conference Room Pilot, Factory Acceptance Testing, On Site ... Analyze WCS Software Resources within Project Web App to identify risk, modifications, and ...
... testing lifecycles (Internal QA, Conference Room Pilot, Factory Acceptance Testing, On Site ... Analyze WCS Software Resources within Project Web App to identify risk, modifications, and ...
... testing lifecycles (Internal QA, Conference Room Pilot, Factory Acceptance Testing, On Site ... Analyze WCS Software Resources within Project Web App to identify risk, modifications, and ...
... testing lifecycles (Internal QA, Conference Room Pilot, Factory Acceptance Testing, On Site ... Analyze WCS Software Resources within Project Web App to identify risk, modifications, and ...
... testing lifecycles (Internal QA, Conference Room Pilot, Factory Acceptance Testing, On Site ... Analyze WCS Software Resources within Project Web App to identify risk, modifications, and ...
... testing lifecycles (Internal QA, Conference Room Pilot, Factory Acceptance Testing, On Site ... Analyze WCS Software Resources within Project Web App to identify risk, modifications, and ...
... testing lifecycles (Internal QA, Conference Room Pilot, Factory Acceptance Testing, On Site ... Analyze WCS Software Resources within Project Web App to identify risk, modifications, and ...
Any time you swipe your credit card, pay through a mobile app, or withdraw money from the bank, w ... security and penetration testing findings. * Assess whether existing compensating controls ...
Any time you swipe your credit card, pay through a mobile app, or withdraw money from the bank, w ... security and penetration testing findings. * Assess whether existing compensating controls ...
Senior Engineer, Offensive Security
Miami, FL · On-site
$109K - $150K/yr
Run penetration tests. Network, web-application, cloud, and infrastructure testing, recon through exploitation, privilege escalation, and lateral movement, accelerated by the tooling you build, with ...
Senior Engineer, Offensive Security
Miami, FL · On-site
$109K - $150K/yr
Run penetration tests. Network, web-application, cloud, and infrastructure testing, recon through exploitation, privilege escalation, and lateral movement, accelerated by the tooling you build, with ...
Senior Engineer, Offensive Security
Tampa, FL · On-site
$108K - $148K/yr
Run penetration tests. Network, web-application, cloud, and infrastructure testing, recon through exploitation, privilege escalation, and lateral movement, accelerated by the tooling you build, with ...
Senior Engineer, Offensive Security
Tampa, FL · On-site
$108K - $148K/yr
Run penetration tests. Network, web-application, cloud, and infrastructure testing, recon through exploitation, privilege escalation, and lateral movement, accelerated by the tooling you build, with ...
Senior Engineer, Offensive Security
$108K - $148K/yr
Run penetration tests. Network, web-application, cloud, and infrastructure testing, recon through exploitation, privilege escalation, and lateral movement, accelerated by the tooling you build, with ...
Senior Engineer, Offensive Security
$108K - $148K/yr
Run penetration tests. Network, web-application, cloud, and infrastructure testing, recon through exploitation, privilege escalation, and lateral movement, accelerated by the tooling you build, with ...
Senior Engineer, Offensive Security
Miami, FL · On-site
$109K - $150K/yr
Run penetration tests. Network, web-application, cloud, and infrastructure testing, recon through exploitation, privilege escalation, and lateral movement, accelerated by the tooling you build, with ...
Senior Engineer, Offensive Security
Miami, FL · On-site
$109K - $150K/yr
Run penetration tests. Network, web-application, cloud, and infrastructure testing, recon through exploitation, privilege escalation, and lateral movement, accelerated by the tooling you build, with ...
Web App Penetration Testing information
See Florida salary details
$8.62 - $13.72
4% of jobs
$13.72 - $18.81
0% of jobs
$18.81 - $23.91
0% of jobs
$23.91 - $29
6% of jobs
$29 - $34.10
5% of jobs
$38.03 is the 25th percentile. Wages below this are outliers.
$34.10 - $39.19
12% of jobs
The median wage is $44.17 / hr.
$39.19 - $44.29
23% of jobs
$49.13 is the 75th percentile. Wages above this are outliers.
$44.29 - $49.38
26% of jobs
$49.38 - $54.48
13% of jobs
$54.48 - $59.57
3% of jobs
$59.57 - $64.67
7% of jobs
$8
$44
$64
How much do web app penetration testing jobs pay per hour?
What is a web app penetration testing?
A Web App Penetration Testing job involves assessing the security of web applications by simulating real-world attacks. Security professionals use various techniques to identify vulnerabilities like SQL injection, cross-site scripting (XSS), or authentication flaws. The goal is to help organizations strengthen their web applications by providing recommendations for fixing security weaknesses. Testers use tools like Burp Suite, OWASP ZAP, and manual testing techniques to ensure comprehensive coverage. This job requires knowledge of ethical hacking, web technologies, and cybersecurity best practices.
What does a typical workday look like for someone in web app penetration testing?
A typical day in Web App Penetration Testing involves actively assessing web applications for security weaknesses using both automated tools and manual testing techniques, reviewing code when necessary, and documenting findings comprehensively. You may also participate in meetings with developers and stakeholders to discuss vulnerabilities, advise on remediation steps, and help prioritize risk mitigation tasks. Many roles offer a mix of independent analysis and team collaboration, with frequent opportunities to learn about new technologies and threats. This environment encourages continuous learning and offers clear pathways for career growth, such as advancing to a senior tester, security consultant, or application security architect.
What are the key skills and qualifications needed to thrive in web app penetration testing, and why are they important?
To thrive as a Web App Penetration Tester, you need a strong understanding of web application security, common vulnerabilities (such as OWASP Top 10), and solid programming/scripting skills, usually underpinned by a degree in computer science or a related field. Familiarity with tools like Burp Suite, OWASP ZAP, Metasploit, and certifications such as OSCP or CEH are highly valued. Attention to detail, analytical thinking, effective communication, and problem-solving are crucial soft skills for this role. These competencies help ensure that vulnerabilities are thoroughly identified, clearly reported, and resolved in collaboration with development teams, ultimately supporting organizational security.
What are the most commonly searched types of Web App Penetration Testing jobs in Florida?
The most popular types of Web App Penetration Testing jobs in Florida are:
What are popular job titles related to Web App Penetration Testing jobs in Florida?
For Web App Penetration Testing jobs in Florida, the most frequently searched job titles are:
What job categories do people searching Web App Penetration Testing jobs in Florida look for?
The top searched job categories for Web App Penetration Testing jobs in Florida are:

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Re-posted 12 days ago
Job description
- Supporting offensive security/red team/adversarial emulation testing
- Executing Red Team engagements in a variety of networks using real-world adversarial Tactics, Techniques, and Procedures (TTPs) from conception to report delivery
- Developing comprehensive security testing strategies and programs across NCRC-U to provide assurance that security controls are designed and operating effectively
- Developing innovative accelerators, tools, mechanisms, and processes to enhance the security team's velocity and scale to customer needs
- Facilitating multiple stakeholders to agree on appropriate solutions and verifying that risks are mitigated appropriately
- Demonstrating creativity, insight, intellectual flexibility, and sound business judgment throughout the process
- Working independently but collaborate with cross-functional to provide security engineering consulting and control design recommendations to reduce risk
- Conducting open-source intelligence gathering, network vulnerability scanning, exploitation of vulnerable services, lateral movement, install persistence in a target network(s), and manage C2 infrastructure
- Systematically analyzing each component of an application with the intent of locating programming flaws that could be leveraged to compromise the software through source code review or reverse engineering
- Developing payloads, scripts and tools that weaponize new proof-of-concepts for exploitation, evasion, and lateral movement
- Safely utilize attacker tools, tactics, and procedures when in sensitive environments/devices
- Evading EDR devices such as Windows Defender and Carbon Black to avoid detection by Defenders/behavioral based alerting in order to further the engagement objectives
- Demonstrating expertise in one of the following: Active Directory, Software Development, Incident Response, or Cloud Infrastructure
- Carefully document and log all exploitation activities
- Continually exercise situational awareness in order quickly identify any instances of cohabitation
- Documenting identified vulnerabilities and researching corrective/remediation actions in order to recommend a risk mitigation technique(s)
- Demonstrating new vulnerabilities and assist Network Defenders (Blue Team) with the refinement of detection capabilities
- Maintaining knowledge of applicable Red Team policies, Standing Ground Rules, regulations, and compliance documents
- Communicating effectively with team members and during an engagement
- Ability to think unconventionally in order to develop adversarial TTPs
- Keeping current with TTPs and the latest offensive security techniques
[#LI-DH1]
Requirements- Bachelor's degree with a focus in computer science, computer information systems, engineering, mathematics, management information systems, cybersecurity, cyber operations, or a related discipline with corresponding experience and demonstrated mastery of relevant computer science topics
- 5+ years of cyber adversarial emulation experience, to include penetration testing of modern Windows and Linux operating systems, IP-based networks and protocols, 802.11 networks, and/or web applications, hardware hacking, software defined networks/RF
- 10+ years of experience in leading complex and technically diverse teams of cyber professionals (software developers, system administrators, penetration testers, incident responders, etc.)
- Intermediate knowledge of known Advanced Persistent Threat (APT) actor Techniques, Tactics, and Procedures (TTPs), to include familiarity with terminology from Mitre ATT&CK used to describe TTPs used in cyber attacks
- Intermediate knowledge of techniques and tools used for exploit development of common operating systems, software debugging, and application fuzzing
- Intermediate knowledge of tools and techniques used for incident response, reverse engineering, and digital forensics
- Superior oral communication skills, including the ability to project confidence and enthusiasm, in the following core areas: formal presentations; soliciting goals and requirements from range users; explaining adversarial emulation in the context of testing and training events; effectively communicating event and environment requirements to CSET members; explaining cost estimates based on estimated levels of CSET effort; managing expectations as relevant to CSET TTPs; and explaining technical nuances and significant attributes of advanced cyber attacks to non-cyber-savvy audiences
- Superior technical writing skills, including the ability to author, review, and provide input and feedback to documents drafted by CSET personnel, as well as the ability to create persuasive and impactful technical briefing materials as relevant to range training and test events
- Ability to work independently and to collaborate with range and event leadership, CSET team members, users, and other event stakeholders
- Required/Maintain IAT Level III or IAM Level III 8570 certifications include one or more of the following:
- CASP+ CE
- CCNP Security
- CISA
- GIAC Incident Handler (GCIH)
- GIAC Certified Enterprise Defender (GCED)
- CISM
- GSLC
- CCISO
- Certified Information Systems Security Professional (CISSP)
- In addition to meeting the applicable cyber security workforce (CSWF) requirements for Computer Network Defenders (CND) Auditors (DoD 8570) or Vulnerability Assessment Analysts (SECNAV 5239.2), CSET members must obtain one or more of the following vendor certifications within 6 months of being hired:
- Offensive Security Certified Engineer (OSCE)
- Offensive Security Certified Professional (OSCP)
- GIAC Certified Exploit Researcher and Advanced Penetration Testers (GXPN)
- Offensive Security Certified Engineer (OSCE3)
- Master's degree with a focus in computer science or cybersecurity
- 10+ years of experience supporting the execution of Department of Defense (DoD) offensive cyber operations (OCO) or defensive cyber operations (DCO) as a civilian, contractor, or uniformed personnel
- Experience with operational training programs and qualification standards
- Red Team, Computer Operator or Exploitation Analyst experience with Threat Systems Management Office (TSMO), US Air Force, US Navy or National Security Agency (NSA) / Cyber Mission Force teams
- Experience with OT, IoT, XIoT is a plus
SRC IS A CONTRACTOR FOR THE U.S. GOVERNMENT, THIS POSITION WILL REQUIRE U.S. CITIZENSHIP AS WELL AS, A U.S. GOVERNMENT SECURITY CLEARANCE AT THE TOP SECRET / SCI LEVEL
Travel Requirementsn/a
About UsScientific Research Corporation is an advanced information technology and engineering company that provides innovative products and services to government and private industry, as well as independent institutions. At the core of our capabilities is a seasoned team of highly skilled engineers and scientists with multidisciplinary backgrounds. This team is challenged daily to provide cutting edge technology solutions to our clients.
SRC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with a company match, life insurance, vacation and sick paid time off accruals with amounts increasing based on role and years of service, 11 paid holidays, tuition reimbursement, and a work environment that encourages excellence and more. For positions requiring a security clearance, selected applicants will be subject to a government security investigation and must meet eligibility requirements for access to classified information.
EEOScientific Research Corporation is an equal opportunity employer that does not discriminate in employment.
All qualified applicants will receive consideration for employment without regard to their race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other protected characteristic under federal, state or local law.
Scientific Research Corporation endeavors to make www.scires.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact jobs@scires.com for assistance. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.
Employment Type: FULL_TIMEAbout Scientific Research
Sourced by ZipRecruiter
Industry
Guided missile and space vehicle manufacturing
Company size
1,001 - 5,000 Employees
Headquarters location
Atlanta, GA, US
Year founded
1988