... testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client ... app testing tools such as Netsparker and Checkmarx • Ability to travel as required • Must be ...
... testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client ... app testing tools such as Netsparker and Checkmarx • Ability to travel as required • Must be ...
... testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client ... app testing tools such as Netsparker and Checkmarx • Ability to travel as required • Must be ...
... testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client ... app testing tools such as Netsparker and Checkmarx • Ability to travel as required • Must be ...
... testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client ... app testing tools such as Netsparker and Checkmarx • Ability to travel as required • Must be ...
... testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client ... app testing tools such as Netsparker and Checkmarx • Ability to travel as required • Must be ...
... testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client ... app testing tools such as Netsparker and Checkmarx • Ability to travel as required • Must be ...
... testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client ... app testing tools such as Netsparker and Checkmarx • Ability to travel as required • Must be ...
Senior Penetration
Dallas, TX · On-site
Typical security testing activities: o Software/Web Application/Web Services penetration testing o network Penetration Testing o Mobile Application Penetration Testing o Thick Client Penetration ...
New
Senior Penetration
Dallas, TX · On-site
Typical security testing activities: o Software/Web Application/Web Services penetration testing o network Penetration Testing o Mobile Application Penetration Testing o Thick Client Penetration ...
New
Penetration Testing Manager , Vice President
Austin, TX · On-site
$120K - $217K/yr
Who We Are Looking For We are seeking a Manager to lead State Street's Penetration Testing Team ... OSCP/OSEP/OSCE, GPEN/GXPN, GWAPT, GCPN, PNPT, CREST (CRT, CCT INF, CCT APP, CCRTS, CCRTM) or ...
Penetration Testing Manager , Vice President
Austin, TX · On-site
$120K - $217K/yr
Who We Are Looking For We are seeking a Manager to lead State Street's Penetration Testing Team ... OSCP/OSEP/OSCE, GPEN/GXPN, GWAPT, GCPN, PNPT, CREST (CRT, CCT INF, CCT APP, CCRTS, CCRTM) or ...
Conduct tactical penetration testing assessments of web, mobile, and API applications against OWASP Top 10 threats and emerging risks, and collaborate with Application Security teams to provide ...
Conduct tactical penetration testing assessments of web, mobile, and API applications against OWASP Top 10 threats and emerging risks, and collaborate with Application Security teams to provide ...
Consulting Expert Penetration Tester Professional Multiple Cities
Dallas, TX · On-site
$120 - $224/hr
Penetration Testing experience with operating systems, web applications and network infrastructure; use of tools such as NMap, Nessus, Metasploit, BurpSuite, Nikto, Tcpdump; required certification:
Consulting Expert Penetration Tester Professional Multiple Cities
Dallas, TX · On-site
$120 - $224/hr
Penetration Testing experience with operating systems, web applications and network infrastructure; use of tools such as NMap, Nessus, Metasploit, BurpSuite, Nikto, Tcpdump; required certification:
Perform manual and automated penetration testing of web applications, APIs, and supporting infrastructure. * Identify, validate, and document security vulnerabilities such as those in the OWASP Top ...
Perform manual and automated penetration testing of web applications, APIs, and supporting infrastructure. * Identify, validate, and document security vulnerabilities such as those in the OWASP Top ...
Perform manual and automated penetration testing of web applications, APIs, and supporting infrastructure. * Identify, validate, and document security vulnerabilities such as those in the OWASP Top ...
Perform manual and automated penetration testing of web applications, APIs, and supporting infrastructure. * Identify, validate, and document security vulnerabilities such as those in the OWASP Top ...
Penetration Tester
$126K - $243K/yr
Penetration testing experience across at least two of the following domains: network, cloud, web application, identity, or containerized environments. * Experience operating within defined Rules of ...
Penetration Tester
$126K - $243K/yr
Penetration testing experience across at least two of the following domains: network, cloud, web application, identity, or containerized environments. * Experience operating within defined Rules of ...
Staff Security Engineer
Dallas, TX · On-site
Demonstrated ability to perform manual penetration testing (network and web app). Proficiency in scripting (Python/Bash) to automate security tasks. Preferred : • Experience securing on-device ...
Staff Security Engineer
Dallas, TX · On-site
Demonstrated ability to perform manual penetration testing (network and web app). Proficiency in scripting (Python/Bash) to automate security tasks. Preferred : • Experience securing on-device ...
Lead Penetration Test Engineer
Houston, TX · Hybrid
$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
Lead Penetration Test Engineer
Houston, TX · Hybrid
$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
Lead Penetration Test Engineer
Houston, TX · Hybrid
$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
Lead Penetration Test Engineer
Houston, TX · Hybrid
$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
Lead Penetration Test Engineer
Dallas, TX · Hybrid
$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
Lead Penetration Test Engineer
Dallas, TX · Hybrid
$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
Lead Penetration Test Engineer
Dallas, TX · Hybrid
$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
Lead Penetration Test Engineer
Dallas, TX · Hybrid
$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
Web Application Security Test Engineer
Addison, TX · On-site
$56.75 - $76/hr
Seattle, WA/ Addison , TX- relocation open W2 Candidates with 12-month validity JD: • This is a Web Application Security Testing role, not a penetration testing position. The focus is on candidates ...
Posted today
Web Application Security Test Engineer
Addison, TX · On-site
$56.75 - $76/hr
Seattle, WA/ Addison , TX- relocation open W2 Candidates with 12-month validity JD: • This is a Web Application Security Testing role, not a penetration testing position. The focus is on candidates ...
Posted today
Freelance Full-Stack Web App Developer
Austin, TX · Remote
$60/hr
Mindrift is looking for skilled Full-Stack Web App Developers (JavaScript/TypeScript + Python or ... Comfortable with version control (Git) and basic testing practices. Additional requirements
Freelance Full-Stack Web App Developer
Austin, TX · Remote
$60/hr
Mindrift is looking for skilled Full-Stack Web App Developers (JavaScript/TypeScript + Python or ... Comfortable with version control (Git) and basic testing practices. Additional requirements
Web Application Security Test Engineer
Addison, TX · On-site
$56.75 - $76/hr
Seattle, WA/ Addison , TX- relocation open W2 Candidates with 12-month validity JD: • This is a Web Application Security Testing role, not a penetration testing position. The focus is on candidates ...
Posted today
Web Application Security Test Engineer
Addison, TX · On-site
$56.75 - $76/hr
Seattle, WA/ Addison , TX- relocation open W2 Candidates with 12-month validity JD: • This is a Web Application Security Testing role, not a penetration testing position. The focus is on candidates ...
Posted today
Freelance Full-Stack Web App Developer
Houston, TX · Remote
$60/hr
Mindrift is looking for skilled Full-Stack Web App Developers (JavaScript/TypeScript + Python or ... Comfortable with version control (Git) and basic testing practices. Additional requirements
Freelance Full-Stack Web App Developer
Houston, TX · Remote
$60/hr
Mindrift is looking for skilled Full-Stack Web App Developers (JavaScript/TypeScript + Python or ... Comfortable with version control (Git) and basic testing practices. Additional requirements
Web App Penetration Testing information
See Texas salary details
$10.75 - $17.10
4% of jobs
$17.10 - $23.45
0% of jobs
$23.45 - $29.81
0% of jobs
$29.81 - $36.16
6% of jobs
$36.16 - $42.51
5% of jobs
$47.41 is the 25th percentile. Wages below this are outliers.
$42.51 - $48.86
12% of jobs
The median wage is $55.07 / hr.
$48.86 - $55.22
23% of jobs
$61.25 is the 75th percentile. Wages above this are outliers.
$55.22 - $61.57
26% of jobs
$61.57 - $67.92
13% of jobs
$67.92 - $74.27
3% of jobs
$74.27 - $80.62
7% of jobs
$10
$54
$80
How much do web app penetration testing jobs pay per hour?
Is a web app penetration tester a good career?
What is a web app penetration testing?
A Web App Penetration Testing job involves assessing the security of web applications by simulating real-world attacks. Security professionals use various techniques to identify vulnerabilities like SQL injection, cross-site scripting (XSS), or authentication flaws. The goal is to help organizations strengthen their web applications by providing recommendations for fixing security weaknesses. Testers use tools like Burp Suite, OWASP ZAP, and manual testing techniques to ensure comprehensive coverage. This job requires knowledge of ethical hacking, web technologies, and cybersecurity best practices.
What does a typical workday look like for someone in web app penetration testing?
A typical day in Web App Penetration Testing involves actively assessing web applications for security weaknesses using both automated tools and manual testing techniques, reviewing code when necessary, and documenting findings comprehensively. You may also participate in meetings with developers and stakeholders to discuss vulnerabilities, advise on remediation steps, and help prioritize risk mitigation tasks. Many roles offer a mix of independent analysis and team collaboration, with frequent opportunities to learn about new technologies and threats. This environment encourages continuous learning and offers clear pathways for career growth, such as advancing to a senior tester, security consultant, or application security architect.
What are the key skills and qualifications needed to thrive in web app penetration testing, and why are they important?
To thrive as a Web App Penetration Tester, you need a strong understanding of web application security, common vulnerabilities (such as OWASP Top 10), and solid programming/scripting skills, usually underpinned by a degree in computer science or a related field. Familiarity with tools like Burp Suite, OWASP ZAP, Metasploit, and certifications such as OSCP or CEH are highly valued. Attention to detail, analytical thinking, effective communication, and problem-solving are crucial soft skills for this role. These competencies help ensure that vulnerabilities are thoroughly identified, clearly reported, and resolved in collaboration with development teams, ultimately supporting organizational security.

Full-time
Re-posted 12 days ago
Job description
KPMG is a leading advisory firm that offers excellent opportunities for career advancement. They are currently seeking a Senior Specialist, MAST Application Penetration Tester to conduct manual penetration testing and evaluate application security, while working independently and collaborating with both internal and external audiences.
Responsibilities:
• Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications
• Perform objective based on abstract penetration testing engagements
• Execute threat modeling, evaluate application business logic, and perform application architecture reviews
• Demonstrate application testing experience in real time via demos to both internal and external audiences
• Function independently in penetration testing engagements, with minimal oversight and guidance
• Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
Qualifications:
Required:
• Minimum three years of recent experience in application penetration testing of Application Programming Interface (API's), web applications, or mobile applications
• Bachelor's degree from an accredited college/university or equivalent industry experience
• Ability to communicate reporting results with technical and non-technical audiences and lead remediation conversations
• Experience with burp suite pro, and other app testing tools such as Netsparker and Checkmarx
• Ability to travel as required
• Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future.
Preferred:
• One or more major ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert (OSWE), Offensive Security Web Assessor (OSWA)
Company:
KPMG is one of the world’s leading professional services firms and the fastest growing Big Four accounting firm in the United States. Founded in 2010, the company is headquartered in New York, USA, with a team of 10001+ employees. The company is currently Late Stage.