Understanding of Pen Test methods such as Open Source Security Testing Methodology Manual (OSSTMM), Open Web Application Security Project (OWASP), Penetration Testing Execution Standard (PTES ...
Quick apply
Understanding of Pen Test methods such as Open Source Security Testing Methodology Manual (OSSTMM), Open Web Application Security Project (OWASP), Penetration Testing Execution Standard (PTES ...
Quick apply
Understanding of Pen Test methods such as Open Source Security Testing Methodology Manual (OSSTMM), Open Web Application Security Project (OWASP), Penetration Testing Execution Standard (PTES ...
Carolina, RI · On-site +1
$114K - $150K/yr
Testing web applications and databases * System development life cycle * Network administration * Cloud penetration testing * Linux and Windows * Kali Linux tools, Burp Suite, and other pentest tools
Carolina, RI · On-site +1
$114K - $150K/yr
Testing web applications and databases * System development life cycle * Network administration * Cloud penetration testing * Linux and Windows * Kali Linux tools, Burp Suite, and other pentest tools
Quantico, VA · Hybrid
Proven experience conducting penetration tests of web applications, networks, and other systems. * Experience with a variety of penetration testing tools and techniques (e.g., Rapid7 Nexpose ...
Quantico, VA · Hybrid
Proven experience conducting penetration tests of web applications, networks, and other systems. * Experience with a variety of penetration testing tools and techniques (e.g., Rapid7 Nexpose ...
Conduct web application penetration testing in accordance with industry frameworks and standards including the OWASP Testing Guide and OWASP API Security Top 10, identifying and exploiting ...
Conduct web application penetration testing in accordance with industry frameworks and standards including the OWASP Testing Guide and OWASP API Security Top 10, identifying and exploiting ...
Washington, DC · On-site
$150 - $190/hr
Conduct web application penetration testing in accordance with industry frameworks and standards including the OWASP Testing Guide and OWASP API Security Top 10, identifying and exploiting ...
Washington, DC · On-site
$150 - $190/hr
Conduct web application penetration testing in accordance with industry frameworks and standards including the OWASP Testing Guide and OWASP API Security Top 10, identifying and exploiting ...
$110 - $150K/hr
Yes - travel to agency sites required Project Description This position leads operational security assessments and penetration testing across a portfolio of federal agencies and web applications.
Quick apply
$110 - $150K/hr
Yes - travel to agency sites required Project Description This position leads operational security assessments and penetration testing across a portfolio of federal agencies and web applications.
Carolina, RI · On-site +1
$114K - $150K/yr
Testing web applications and databases * System development life cycle * Network administration * Cloud penetration testing * Linux and Windows * Kali Linux tools, Burp Suite, and other pentest tools
Carolina, RI · On-site +1
$114K - $150K/yr
Testing web applications and databases * System development life cycle * Network administration * Cloud penetration testing * Linux and Windows * Kali Linux tools, Burp Suite, and other pentest tools
Quantico, VA · On-site
$130K - $147K/yr
Penetration Testing: * Conduct penetration tests of web applications, mobile applications, networks, cloud environments, and other systems. * Utilize a variety of tools and techniques to identify ...
Quantico, VA · On-site
$130K - $147K/yr
Penetration Testing: * Conduct penetration tests of web applications, mobile applications, networks, cloud environments, and other systems. * Utilize a variety of tools and techniques to identify ...
OWASP Web Security Testing Guide * NIST penetration testing guidance * PTES (Penetration Testing Execution Standard) * Plan and execute all phases of penetration testing, including: * Pre-engagement ...
OWASP Web Security Testing Guide * NIST penetration testing guidance * PTES (Penetration Testing Execution Standard) * Plan and execute all phases of penetration testing, including: * Pre-engagement ...
Sterling, VA · On-site +1
$50 - $85/hr
Understanding of Pen Test methods such as Open Source Security Testing Methodology Manual (OSSTMM), Open Web Application Security Project (OWASP), Penetration Testing Execution Standard (PTES ...
Sterling, VA · On-site +1
$50 - $85/hr
Understanding of Pen Test methods such as Open Source Security Testing Methodology Manual (OSSTMM), Open Web Application Security Project (OWASP), Penetration Testing Execution Standard (PTES ...
Reston, VA · On-site
Network penetration testing and experience working with network infrastructure * An understanding ... Experience conducting web application security assessments * Experience working with a range of ...
Reston, VA · On-site
Network penetration testing and experience working with network infrastructure * An understanding ... Experience conducting web application security assessments * Experience working with a range of ...
Washington, DC · On-site
... penetration testing and security assessments for government clients, requiring an active Secret ... Company : M9 Solutions is a national staffing firm focused on cloud, cyber security, web ...
Washington, DC · On-site
... penetration testing and security assessments for government clients, requiring an active Secret ... Company : M9 Solutions is a national staffing firm focused on cloud, cyber security, web ...
$110 - $150K/hr
Yes - travel to agency sites required Project Description This position leads operational security assessments and penetration testing across a portfolio of federal agencies and web applications.
Quick apply
$110 - $150K/hr
Yes - travel to agency sites required Project Description This position leads operational security assessments and penetration testing across a portfolio of federal agencies and web applications.
NetSPI ® pioneered Penetration Testing as a Service (PTaaS) and leads the industry in modern ... As a Penetration Tester supporting web applications, you will work closely with clients to deliver ...
Quick apply
NetSPI ® pioneered Penetration Testing as a Service (PTaaS) and leads the industry in modern ... As a Penetration Tester supporting web applications, you will work closely with clients to deliver ...
NetSPI ® is an award-winning pioneer of Penetration Testing as a Service (PTaaS) with its AI ... Conduct engagements on web applications and underlying APIs independently and provide technical ...
Quick apply
NetSPI ® is an award-winning pioneer of Penetration Testing as a Service (PTaaS) with its AI ... Conduct engagements on web applications and underlying APIs independently and provide technical ...
NetSPI ® pioneered Penetration Testing as a Service (PTaaS) and leads the industry in modern ... As a Penetration Tester supporting web applications, you will work closely with clients to deliver ...
NetSPI ® pioneered Penetration Testing as a Service (PTaaS) and leads the industry in modern ... As a Penetration Tester supporting web applications, you will work closely with clients to deliver ...
Gaithersburg, MD · Remote
Web Application Testing: * Conduct security assessments of agency web applications using OWASP Top ... Penetration Testing & Exploitation Validation: * Perform controlled penetration testing (internal ...
Gaithersburg, MD · Remote
Web Application Testing: * Conduct security assessments of agency web applications using OWASP Top ... Penetration Testing & Exploitation Validation: * Perform controlled penetration testing (internal ...
Position Summary Performs blind and intelligent penetration testing against internet-facing assets -- web applications, firewalls, remote access (VPN/RDP), and internet postings -- for all 47 County ...
Quick apply
Position Summary Performs blind and intelligent penetration testing against internet-facing assets -- web applications, firewalls, remote access (VPN/RDP), and internet postings -- for all 47 County ...
$110 - $150K/hr
Yes - travel to agency sites required Project Description This position leads operational security assessments and penetration testing across a portfolio of federal agencies and web applications.
Quick apply
$110 - $150K/hr
Yes - travel to agency sites required Project Description This position leads operational security assessments and penetration testing across a portfolio of federal agencies and web applications.
Leesburg, VA · On-site
$125K - $155K/yr
Work closely with all members of the team to conduct penetration testing of customer networks, applications (API, web, and mobile), and/or social engineering activities to achieve the customer ...
Leesburg, VA · On-site
$125K - $155K/yr
Work closely with all members of the team to conduct penetration testing of customer networks, applications (API, web, and mobile), and/or social engineering activities to achieve the customer ...
$11.54 - $18.36
4% of jobs
$18.36 - $25.17
0% of jobs
$25.17 - $31.99
0% of jobs
$31.99 - $38.81
6% of jobs
$38.81 - $45.63
5% of jobs
$50.89 is the 25th percentile. Wages below this are outliers.
$45.63 - $52.45
12% of jobs
The median wage is $59.11 / hr.
$52.45 - $59.27
23% of jobs
$65.74 is the 75th percentile. Wages above this are outliers.
$59.27 - $66.08
26% of jobs
$66.08 - $72.90
13% of jobs
$72.90 - $79.72
3% of jobs
$79.72 - $86.54
7% of jobs
$11
$59
$86
A Web App Penetration Testing job involves assessing the security of web applications by simulating real-world attacks. Security professionals use various techniques to identify vulnerabilities like SQL injection, cross-site scripting (XSS), or authentication flaws. The goal is to help organizations strengthen their web applications by providing recommendations for fixing security weaknesses. Testers use tools like Burp Suite, OWASP ZAP, and manual testing techniques to ensure comprehensive coverage. This job requires knowledge of ethical hacking, web technologies, and cybersecurity best practices.
A typical day in Web App Penetration Testing involves actively assessing web applications for security weaknesses using both automated tools and manual testing techniques, reviewing code when necessary, and documenting findings comprehensively. You may also participate in meetings with developers and stakeholders to discuss vulnerabilities, advise on remediation steps, and help prioritize risk mitigation tasks. Many roles offer a mix of independent analysis and team collaboration, with frequent opportunities to learn about new technologies and threats. This environment encourages continuous learning and offers clear pathways for career growth, such as advancing to a senior tester, security consultant, or application security architect.
To thrive as a Web App Penetration Tester, you need a strong understanding of web application security, common vulnerabilities (such as OWASP Top 10), and solid programming/scripting skills, usually underpinned by a degree in computer science or a related field. Familiarity with tools like Burp Suite, OWASP ZAP, Metasploit, and certifications such as OSCP or CEH are highly valued. Attention to detail, analytical thinking, effective communication, and problem-solving are crucial soft skills for this role. These competencies help ensure that vulnerabilities are thoroughly identified, clearly reported, and resolved in collaboration with development teams, ultimately supporting organizational security.

TestPros delivers innovative independent IT assessment solutions to critical challenges facing the nation and the world. We support the U.S. Federal Government and Commercial clients within the continental USA. TestPros is dedicated to making lives better, safer and more secure.
TestPros is looking for an experienced Penetration Testers to support our IT Security consulting work for various Commercial and Federal consulting services projects.
Start: Future projects late 2026 or 2027 (not an immediate job opening)
Type: Part-time consulting
Overview
This role is responsible for the successful delivery of penetration testing in both classic hosted and also in cloud hosted environments. In this role, the selected candidate will work with our client’s product development teams to plan for, execute, and report on the results of penetration testing. You must be delivery and efficiency focused, with the ability to manage all aspects of a consulting project to include requirements analysis, bid and proposal development, resource planning, process improvement, and customer relationship management. The ideal candidate will thrive in a fast-paced environment where personal responsibility and open, direct, respectful communications are highly valued.
Responsibilities:
Rate: $50-85/hr (1099 or Corp. To Corp.). This range represents a good-faith estimate and is not a guarantee; final compensation is determined by factors such as experience, qualifications, and government contract labor rate requirements and may fall outside the stated range.
Equal Opportunity Employer
TestPros is an equal-opportunity employer and does not discriminate in employment based on race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, retaliation, parental status, military service, or any other non-merit factor.
Offer Considerations
TestPros considers several factors when extending an offer, including but not limited to, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, geographic location, education, and certifications.
Federal Compliance
As a federal contractor, TestPros is subject to all federal and state mandates and/or other customer requirements.
Powered by JazzHR
YyqqwR9LpU
Sourced by ZipRecruiter
It services
11 - 50 Employees
Sterling, VA, US
1988