Conduct web application penetration testing in accordance with industry frameworks and standards including the OWASP Testing Guide and OWASP API Security Top 10, identifying and exploiting ...
New
Conduct web application penetration testing in accordance with industry frameworks and standards including the OWASP Testing Guide and OWASP API Security Top 10, identifying and exploiting ...
New
Conduct web application penetration testing in accordance with industry frameworks and standards including the OWASP Testing Guide and OWASP API Security Top 10, identifying and exploiting ...
New
Reston, VA · On-site
Network penetration testing and experience working with network infrastructure * An understanding ... Experience conducting web application security assessments * Experience working with a range of ...
Reston, VA · On-site
Network penetration testing and experience working with network infrastructure * An understanding ... Experience conducting web application security assessments * Experience working with a range of ...
$110 - $150K/hr
Yes - travel to agency sites required Project Description This position leads operational security assessments and penetration testing across a portfolio of federal agencies and web applications.
New
Quick apply
$110 - $150K/hr
Yes - travel to agency sites required Project Description This position leads operational security assessments and penetration testing across a portfolio of federal agencies and web applications.
New
Albany, NY · On-site
Knowledge of common web vulnerabilities (e.g., SQL injection, XSS) and exploit techniques. * Experience with penetration testing tools like Burp Suite, Metasploit. * Familiarity with Fortify on ...
Albany, NY · On-site
Knowledge of common web vulnerabilities (e.g., SQL injection, XSS) and exploit techniques. * Experience with penetration testing tools like Burp Suite, Metasploit. * Familiarity with Fortify on ...
Los Angeles, CA · On-site
Perform offensive engagements including red teaming and penetration testing * Perform penetration tests against external networks, internal networks, web applications, mobile applications, social ...
Los Angeles, CA · On-site
Perform offensive engagements including red teaming and penetration testing * Perform penetration tests against external networks, internal networks, web applications, mobile applications, social ...
Carolina, RI · On-site +1
$114K - $150K/yr
Testing web applications and databases * System development life cycle * Network administration * Cloud penetration testing * Linux and Windows * Kali Linux tools, Burp Suite, and other pentest tools
Carolina, RI · On-site +1
$114K - $150K/yr
Testing web applications and databases * System development life cycle * Network administration * Cloud penetration testing * Linux and Windows * Kali Linux tools, Burp Suite, and other pentest tools
NetSPI ® pioneered Penetration Testing as a Service (PTaaS) and leads the industry in modern ... As a Penetration Tester supporting web applications, you will work closely with clients to deliver ...
Quick apply
NetSPI ® pioneered Penetration Testing as a Service (PTaaS) and leads the industry in modern ... As a Penetration Tester supporting web applications, you will work closely with clients to deliver ...
NetSPI ® pioneered Penetration Testing as a Service (PTaaS) and leads the industry in modern ... As a Penetration Tester supporting web applications, you will work closely with clients to deliver ...
NetSPI ® pioneered Penetration Testing as a Service (PTaaS) and leads the industry in modern ... As a Penetration Tester supporting web applications, you will work closely with clients to deliver ...
Sterling, VA · On-site +1
$50 - $85/hr
Understanding of Pen Test methods such as Open Source Security Testing Methodology Manual (OSSTMM), Open Web Application Security Project (OWASP), Penetration Testing Execution Standard (PTES ...
Sterling, VA · On-site +1
$50 - $85/hr
Understanding of Pen Test methods such as Open Source Security Testing Methodology Manual (OSSTMM), Open Web Application Security Project (OWASP), Penetration Testing Execution Standard (PTES ...
$110 - $150K/hr
Yes - travel to agency sites required Project Description This position leads operational security assessments and penetration testing across a portfolio of federal agencies and web applications.
New
Quick apply
$110 - $150K/hr
Yes - travel to agency sites required Project Description This position leads operational security assessments and penetration testing across a portfolio of federal agencies and web applications.
New
NetSPI ® is an award-winning pioneer of Penetration Testing as a Service (PTaaS) with its AI ... Conduct engagements on web applications and underlying APIs independently and provide technical ...
Quick apply
NetSPI ® is an award-winning pioneer of Penetration Testing as a Service (PTaaS) with its AI ... Conduct engagements on web applications and underlying APIs independently and provide technical ...
Conduct web, mobile, API, and microservices security testing using industrystandard tools and manual exploitation techniques. * Execute AWS cloud penetration testing within approved boundaries (IAM ...
Fairfax, VA · On-site
$170K - $190K/yr
Plan, coordinate, and lead Red Team and penetration testing engagements across federal systems, including network infrastructure, web applications, APIs, and cloud environments. * Oversee all aspects ...
Fairfax, VA · On-site
$170K - $190K/yr
Plan, coordinate, and lead Red Team and penetration testing engagements across federal systems, including network infrastructure, web applications, APIs, and cloud environments. * Oversee all aspects ...
$110 - $150K/hr
Yes - travel to agency sites required Project Description This position leads operational security assessments and penetration testing across a portfolio of federal agencies and web applications.
New
Quick apply
$110 - $150K/hr
Yes - travel to agency sites required Project Description This position leads operational security assessments and penetration testing across a portfolio of federal agencies and web applications.
New
Charlotte, NC · On-site +1
$50 - $65/hr
Utilizing various penetration testing tools and methodologies to simulate cyber attacks. * Analyzing web applications for weaknesses and vulnerabilities using manual and automated methods.
Charlotte, NC · On-site +1
$50 - $65/hr
Utilizing various penetration testing tools and methodologies to simulate cyber attacks. * Analyzing web applications for weaknesses and vulnerabilities using manual and automated methods.
Charlotte, NC · On-site
$50 - $65/hr
Utilizing various penetration testing tools and methodologies to simulate cyber attacks. * Analyzing web applications for weaknesses and vulnerabilities using manual and automated methods.
Charlotte, NC · On-site
$50 - $65/hr
Utilizing various penetration testing tools and methodologies to simulate cyber attacks. * Analyzing web applications for weaknesses and vulnerabilities using manual and automated methods.
NetSPI ® is an award-winning pioneer of Penetration Testing as a Service (PTaaS) with its AI ... Conduct engagements on web applications and underlying APIs independently and provide technical ...
NetSPI ® is an award-winning pioneer of Penetration Testing as a Service (PTaaS) with its AI ... Conduct engagements on web applications and underlying APIs independently and provide technical ...
Raleigh, NC · On-site +1
$114K - $150K/yr
Testing web applications and databases * System development life cycle * Network administration * Cloud penetration testing * Linux and Windows * Kali Linux tools, Burp Suite, and other pentest tools
Raleigh, NC · On-site +1
$114K - $150K/yr
Testing web applications and databases * System development life cycle * Network administration * Cloud penetration testing * Linux and Windows * Kali Linux tools, Burp Suite, and other pentest tools
Raleigh, NC · On-site +1
$114K - $150K/yr
Testing web applications and databases * System development life cycle * Network administration * Cloud penetration testing * Linux and Windows * Kali Linux tools, Burp Suite, and other pentest tools
Raleigh, NC · On-site +1
$114K - $150K/yr
Testing web applications and databases * System development life cycle * Network administration * Cloud penetration testing * Linux and Windows * Kali Linux tools, Burp Suite, and other pentest tools
$90K - $150K/yr
Summary: The Senior Penetration Tester will independently perform penetration testing of ... testing standards and projects, including OWASP * Knowledge of databases, applications, and Web ...
$90K - $150K/yr
Summary: The Senior Penetration Tester will independently perform penetration testing of ... testing standards and projects, including OWASP * Knowledge of databases, applications, and Web ...
$11.54 - $18.36
4% of jobs
$18.36 - $25.17
0% of jobs
$25.17 - $31.99
0% of jobs
$31.99 - $38.81
6% of jobs
$38.81 - $45.63
5% of jobs
$50.89 is the 25th percentile. Wages below this are outliers.
$45.63 - $52.45
12% of jobs
The median wage is $59.11 / hr.
$52.45 - $59.27
23% of jobs
$65.74 is the 75th percentile. Wages above this are outliers.
$59.27 - $66.08
26% of jobs
$66.08 - $72.90
13% of jobs
$72.90 - $79.72
3% of jobs
$79.72 - $86.54
7% of jobs
$11
$59
$86
A Web App Penetration Testing job involves assessing the security of web applications by simulating real-world attacks. Security professionals use various techniques to identify vulnerabilities like SQL injection, cross-site scripting (XSS), or authentication flaws. The goal is to help organizations strengthen their web applications by providing recommendations for fixing security weaknesses. Testers use tools like Burp Suite, OWASP ZAP, and manual testing techniques to ensure comprehensive coverage. This job requires knowledge of ethical hacking, web technologies, and cybersecurity best practices.
A typical day in Web App Penetration Testing involves actively assessing web applications for security weaknesses using both automated tools and manual testing techniques, reviewing code when necessary, and documenting findings comprehensively. You may also participate in meetings with developers and stakeholders to discuss vulnerabilities, advise on remediation steps, and help prioritize risk mitigation tasks. Many roles offer a mix of independent analysis and team collaboration, with frequent opportunities to learn about new technologies and threats. This environment encourages continuous learning and offers clear pathways for career growth, such as advancing to a senior tester, security consultant, or application security architect.
To thrive as a Web App Penetration Tester, you need a strong understanding of web application security, common vulnerabilities (such as OWASP Top 10), and solid programming/scripting skills, usually underpinned by a degree in computer science or a related field. Familiarity with tools like Burp Suite, OWASP ZAP, Metasploit, and certifications such as OSCP or CEH are highly valued. Attention to detail, analytical thinking, effective communication, and problem-solving are crucial soft skills for this role. These competencies help ensure that vulnerabilities are thoroughly identified, clearly reported, and resolved in collaboration with development teams, ultimately supporting organizational security.

Other
Medical, Dental, Vision, Retirement, PTO
Posted 7 days ago
New
Koniag Data Solutions, LLC, a Koniag Government Services company, is seeking a Penetration Testers – Senior (Lead) to support KDS and our government customer in Washington, DC. This position requires the candidate to be able to obtain a Public Trust.
We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.
Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced Senior Lead Penetration Tester to support the U.S. Small Business Administration (SBA). The ideal candidate is a highly skilled offensive security professional with extensive experience planning, leading, and executing advanced penetration testing and red team operations across complex federal IT environments. This individual will serve as the technical lead for SBA's penetration testing program, providing expert guidance on adversary simulation, vulnerability exploitation, and security control validation to help the agency identify and remediate security weaknesses before they can be exploited by real-world adversaries.
The Senior Lead Penetration Tester will serve as the primary technical lead for all penetration testing and offensive security activities supporting SBA's cybersecurity program, overseeing the full lifecycle of penetration testing engagements, red team operations, and adversary simulation exercises across SBA's enterprise environment. This individual will bring deep technical expertise, strong leadership capabilities, and a comprehensive understanding of adversary TTPs to drive a high-quality, mission-focused penetration testing program that meaningfully strengthens SBA's security posture.
Principal responsibilities will include but are not limited to:
Education and Experience:
Required:
Desired:
Required Skills and Competencies:
Desired Skills and Competencies:
Our Equal Employment Opportunity Policy
The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.
<...