Senior Web Application Penetration Tester Job Type: Full-time Location: Remote Clearance Requirements: Must be able to obtain a Secret Clearance Travel Requirements: Up to 10% Experience: 5+ years ...
Senior Web Application Penetration Tester Job Type: Full-time Location: Remote Clearance Requirements: Must be able to obtain a Secret Clearance Travel Requirements: Up to 10% Experience: 5+ years ...
Application Penetration Tester
$62K - $141K/yr
Perform web application security testing, network penetration testing, and cloud penetration testing. Develop comprehensive and accurate reports, and presentations for both technical and executive ...
Application Penetration Tester
$62K - $141K/yr
Perform web application security testing, network penetration testing, and cloud penetration testing. Develop comprehensive and accurate reports, and presentations for both technical and executive ...
Application Penetration Tester
Chantilly, VA · On-site
$62K - $141K/yr
Perform web application security testing, network penetration testing, and cloud penetration testing. Develop comprehensive and accurate reports, and presentations for both technical and executive ...
Application Penetration Tester
Chantilly, VA · On-site
$62K - $141K/yr
Perform web application security testing, network penetration testing, and cloud penetration testing. Develop comprehensive and accurate reports, and presentations for both technical and executive ...
Application Penetration Tester
Chantilly, VA · On-site +1
$62K - $141K/yr
Perform web application security testing, network penetration testing, and cloud penetration testing. Develop comprehensive and accurate reports, and presentations for both technical and executive ...
Application Penetration Tester
Chantilly, VA · On-site +1
$62K - $141K/yr
Perform web application security testing, network penetration testing, and cloud penetration testing. Develop comprehensive and accurate reports, and presentations for both technical and executive ...
Penetration Tester
Charlotte, NC · On-site
... web application vulnerabilities to various level of personnel within a large organization ... application penetration testing. Minimum of 5 years of demonstrated experience with automated ...
Penetration Tester
Charlotte, NC · On-site
... web application vulnerabilities to various level of personnel within a large organization ... application penetration testing. Minimum of 5 years of demonstrated experience with automated ...
Penetration Tester
Springfield, VA · On-site
$100K - $140K/yr
GIAC Web Application Penetration Tester (GWAP) Company Description Total Cyber Solutions is a premier provider of Government Contracting, managed IT Services, and Cybersecurity Training. We help ...
Quick apply
Penetration Tester
Springfield, VA · On-site
$100K - $140K/yr
GIAC Web Application Penetration Tester (GWAP) Company Description Total Cyber Solutions is a premier provider of Government Contracting, managed IT Services, and Cybersecurity Training. We help ...
Penetration Tester III
Chandler, AZ · On-site
The role involves conducting penetration testing, managing projects, and leading Red Team ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...
Penetration Tester III
Chandler, AZ · On-site
The role involves conducting penetration testing, managing projects, and leading Red Team ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...
Penetration Tester II
Chandler, AZ · On-site
They are seeking a Penetration Tester II to support a government contract and conduct various types ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...
Penetration Tester II
Chandler, AZ · On-site
They are seeking a Penetration Tester II to support a government contract and conduct various types ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...
Penetration Tester
Springfield, VA · On-site
$100K - $140K/yr
GIAC Web Application Penetration Tester (GWAP) Company Description Total Cyber Solutions is a premier provider of Government Contracting, managed IT Services, and Cybersecurity Training. We help ...
Quick apply
Penetration Tester
Springfield, VA · On-site
$100K - $140K/yr
GIAC Web Application Penetration Tester (GWAP) Company Description Total Cyber Solutions is a premier provider of Government Contracting, managed IT Services, and Cybersecurity Training. We help ...
As a Penetration Tester supporting web applications, you will work closely with clients to deliver ... Minimum of 2-3 years of work experience in application penetration testing * Familiarity with ...
Quick apply
As a Penetration Tester supporting web applications, you will work closely with clients to deliver ... Minimum of 2-3 years of work experience in application penetration testing * Familiarity with ...
Penetration Tester
Charlotte, NC · On-site
... web application vulnerabilities to various level of personnel within a large organization ... with application penetration testing. • Minimum of 5 years of demonstrated experience with ...
Penetration Tester
Charlotte, NC · On-site
... web application vulnerabilities to various level of personnel within a large organization ... with application penetration testing. • Minimum of 5 years of demonstrated experience with ...
Penetration Tester II
Washington, DC · On-site
They are seeking a Penetration Tester II to work on-site in support of a government contract ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...
Penetration Tester II
Washington, DC · On-site
They are seeking a Penetration Tester II to work on-site in support of a government contract ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...
Senior Specialist, MAST Application Penetration Tester
Atlanta, GA · On-site
$95K - $208K/yr
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Senior Specialist, MAST Application Penetration Tester
Atlanta, GA · On-site
$95K - $208K/yr
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Penetration Tester
Hillsboro, OR · On-site
... penetration testing or application security background * Strong understanding of a variety of ... Strong Web Application development, security flaw and remediation technical understanding.
Penetration Tester
Hillsboro, OR · On-site
... penetration testing or application security background * Strong understanding of a variety of ... Strong Web Application development, security flaw and remediation technical understanding.
As a Penetration Tester supporting web applications, you will work closely with clients to deliver ... Minimum of 2-3 years of work experience in application penetration testing * Familiarity with ...
As a Penetration Tester supporting web applications, you will work closely with clients to deliver ... Minimum of 2-3 years of work experience in application penetration testing * Familiarity with ...
Penetration Tester II
Chandler, AZ · On-site
They are seeking a Penetration Tester II to support a government contract, requiring an active ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...
Penetration Tester II
Chandler, AZ · On-site
They are seeking a Penetration Tester II to support a government contract, requiring an active ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Web Application Penetration Tester information
See salary details
$96.5K - $102.2K
4% of jobs
$102.2K - $108K
8% of jobs
$108K - $113.7K
4% of jobs
$113.7K - $119.4K
2% of jobs
$121.8K is the 25th percentile. Wages below this are outliers.
$119.4K - $125.1K
16% of jobs
$125.1K - $130.9K
15% of jobs
The median wage is $131.2K / yr.
$130.9K - $136.6K
11% of jobs
$136.6K - $142.3K
10% of jobs
$145.3K is the 75th percentile. Wages above this are outliers.
$142.3K - $148K
10% of jobs
$148K - $153.8K
11% of jobs
$153.8K - $159.5K
10% of jobs
$96.5K
$132.3K
$159.5K
How much do web application penetration tester jobs pay per year?
What is the difference between Web Application Penetration Tester vs Security Analyst?
| Aspect | Web Application Penetration Tester | Security Analyst |
|---|---|---|
| Certifications | OSCP, CEH, GPEN | CISSP, Security+ |
| Work Environment | Hands-on testing, vulnerability assessments | Monitoring, incident response, policy development |
| Industry Usage | Cybersecurity firms, tech companies, consulting | Corporate security teams, government agencies |
While both roles focus on cybersecurity, a Web Application Penetration Tester specializes in identifying vulnerabilities in web applications through active testing. In contrast, a Security Analyst monitors security systems, analyzes threats, and manages security policies. The roles often overlap in certifications and industry usage but differ in daily tasks and focus areas.
What types of challenges might a web application penetration tester encounter when working with diverse client environments?
What is a web application penetration tester?
What are the key skills and qualifications needed to thrive as a web application penetration tester, and why are they important?

Other
Medical, Dental, Vision, Life, Retirement, PTO
Re-posted 24 days ago
Job description
SIXGEN's mission is to deliver agile, mission-ready cybersecurity solutions that empower government and critical infrastructure organizations to stay ahead of advanced cyber threats. We combine innovation, deep expertise, and cutting-edge capabilities to uncover vulnerabilities, protect vital systems, and ensure operational superiority in an ever-evolving digital landscape.
POSITION OVERVIEWPosition: Senior Web Application Penetration Tester
Job Type: Full-time
Location: Remote
Clearance Requirements: Must be able to obtain a Secret Clearance
Travel Requirements: Up to 10%
Experience: 5+ years
We are seeking a skilled and motivated Senior Web Application Penetration Tester to join our growing cyber operations team. The ideal candidate will possess deep expertise in web application security testing, vulnerability research, and exploitation techniques, with the ability to identify complex attack paths and develop creative solutions to challenging security problems.
This role goes far beyond automated scanning. Successful candidates will conduct in-depth assessments of web applications, APIs, mobile applications, and supporting infrastructure while leveraging custom tooling, manual testing techniques, and advanced exploitation methodologies to uncover impactful security findings.
KEY RESPONSIBILITIESWeb Application Security Assessments- Conduct penetration testing of web applications, APIs, mobile applications, databases, and client-side technologies.
- Perform application enumeration, endpoint discovery, vulnerability research, and exploitation activities.
- Identify, validate, and assess vulnerabilities across complex environments.
- Analyze attack paths and security weaknesses to determine business and operational impact.
- Develop and utilize custom tools, scripts, and payloads to support testing activities.
- Perform network mapping, vulnerability analysis, and security assessments across applications and supporting infrastructure.
- Research emerging vulnerabilities, attack techniques, and exploitation methodologies.
- Support post-exploitation activities involving cloud and enterprise environments when applicable.
- Collaborate with clients and internal teams to define scope, review findings, and recommend remediation strategies.
- Communicate technical concepts and findings to both technical and non-technical stakeholders.
- Produce comprehensive reports, including detailed findings, exploitation procedures, risk analysis, and mitigation recommendations.
- Participate in client meetings and provide ongoing updates throughout assessment activities.
- 5+ years of experience in web application penetration testing or offensive cybersecurity.
- Demonstrated experience conducting manual web application security assessments.
- Knowledge of modern web application vulnerabilities, attack methodologies, and exploitation techniques.
- Experience with network mapping, vulnerability scanning, and penetration testing methodologies.
- Familiarity with NIST 800-series standards and cybersecurity best practices.
- Experience developing scripts, payloads, or custom testing tools.
- Strong analytical, problem-solving, and communication skills.
One or more of the following certifications is strongly preferred:
- CWES (preferred)
- CWEE (preferred)
- OSCP
- OSWA
- OSWE
- CRTO
- GWAPT
- Other relevant hands-on offensive security certifications
- Experience with cloud environments and post-exploitation activities.
- Experience with Active Directory security assessments.
- Familiarity with FISMA compliance requirements.
- Experience supporting government or regulated industry clients.
- Proficiency with common offensive security tools and frameworks.
At SIXGEN, we are committed to fair and equitable compensation practices. Compensation for this role will be based on experience, qualifications, technical expertise, and overall alignment with the position.
Additionally, SIXGEN offers top-tier benefits for full-time employees, including:
- Employer-paid health insurance premiums (medical, dental, vision) for you and your family
- Employer-paid short/long term disability insurance and basic life/AD&D insurance
- 401K with a 4% employer contribution
- Professional development reimbursement options available (training, certification, education, etc)
- Flexible and remote work policies for most positions
- Flexible PTO and holiday schedule
For more information, please reach out to our Director of Human Resources, Amy Maxwell at amy.maxwell@sixgen.io.
OUR COMMITMENTSIXGEN is an Equal Opportunity Employer. We ensure that all applicants are considered for employment without regard to race, color, religion, sexual orientation, gender identity, national origin, disability, age, marital status, ancestry, projected veteran status, or any other protected group or class.
We are committed to fostering an inclusive culture that values diversity in our people, reflecting the communities we serve and our customer base. We strive to attract and retain a diverse talent pool and create an environment where everyone is empowered to be their authentic selves at work.
About SixGen
Sourced by ZipRecruiter
Industry
Software development
Company size
51 - 200 Employees
Headquarters location
Annapolis, MD, US
Year founded
2014