1

Web Application Penetration Tester Jobs in Raleigh, NC

Application Penetration Testing (Web-app, API,Thick Client) * Network Penetration Testing (Internal, External) * Cloud Service penetration testing tradecraft and methodologies across multiple service ...

Application Penetration Testing (Web-app, API,Thick Client) * Network Penetration Testing (Internal, External) * Cloud Service penetration testing tradecraft and methodologies across multiple service ...

Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web ... Experience with Java application technologies, deployment frameworks, and associated security best ...

New

Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web ... Experience with Java application technologies, deployment frameworks, and associated security best ...

New

Strong web application or network penetration testing experience * Familiarity with AI-assisted security tooling, AI agents, or emerging AI-driven approaches to vulnerability discovery and triage.

New

Knowledge of Test Driven Development, Continuous Integration and unit testing frameworks such as ... web site / application development required. Preferred Experience: MS / BS or equivalent ...

next page

Showing results 1-20

Web Application Penetration Tester information

See Raleigh, NC salary details

$93.8K

$128.6K

$155K

How much do web application penetration tester jobs pay per year?

As of Aug 6, 2026, the average yearly pay for web application penetration tester in Raleigh, NC is $128,606.00, according to ZipRecruiter salary data. Most workers in this role earn between $118,100.00 and $142,400.00 per year, depending on experience, location, and employer.

What is the difference between Web Application Penetration Tester vs Security Analyst?

AspectWeb Application Penetration TesterSecurity Analyst
CertificationsOSCP, CEH, GPENCISSP, Security+
Work EnvironmentHands-on testing, vulnerability assessmentsMonitoring, incident response, policy development
Industry UsageCybersecurity firms, tech companies, consultingCorporate security teams, government agencies

While both roles focus on cybersecurity, a Web Application Penetration Tester specializes in identifying vulnerabilities in web applications through active testing. In contrast, a Security Analyst monitors security systems, analyzes threats, and manages security policies. The roles often overlap in certifications and industry usage but differ in daily tasks and focus areas.

What types of challenges might a web application penetration tester encounter when working with diverse client environments?

Web Application Penetration Testers often face the challenge of adapting to a wide range of application architectures, technology stacks, and security maturity levels across different clients. Each environment may have unique configurations, legacy systems, or undocumented features that require creative problem-solving and thorough reconnaissance. Additionally, testers must communicate complex technical findings to both technical and non-technical stakeholders, ensuring recommendations are clear and actionable. Effective time management and staying updated on emerging threats are essential for success in this dynamic role.

What is a web application penetration tester?

Web Application Penetration Testers are cybersecurity professionals who assess the security of web applications by simulating real-world attacks. Their goal is to identify vulnerabilities, such as SQL injection or cross-site scripting, that could be exploited by malicious actors. They use a mix of automated tools and manual testing techniques to uncover and report weaknesses, helping organizations improve the security of their web-based systems. These testers often provide recommendations for remediation and may work in-house or as external consultants.

What are the key skills and qualifications needed to thrive as a web application penetration tester, and why are they important?

To thrive as a Web Application Penetration Tester, you need a solid understanding of web technologies, common vulnerabilities (such as those in the OWASP Top 10), and relevant security concepts, often backed by degrees in computer science or related fields and certifications like OSCP or CEH. Familiarity with penetration testing tools like Burp Suite, Metasploit, and Nmap, as well as scripting languages such as Python or Bash, is typically required. Attention to detail, analytical thinking, and effective written and verbal communication are crucial soft skills for reporting findings and collaborating with clients or development teams. These skills ensure accurate vulnerability identification, clear documentation, and actionable recommendations, all vital for improving web application security.
What are popular job titles related to Web Application Penetration Tester jobs in Raleigh, NC? For Web Application Penetration Tester jobs in Raleigh, NC, the most frequently searched job titles are:
What job categories do people searching Web Application Penetration Tester jobs in Raleigh, NC look for? The top searched job categories for Web Application Penetration Tester jobs in Raleigh, NC are:
What cities near Raleigh, NC are hiring for Web Application Penetration Tester jobs? Cities near Raleigh, NC with the most Web Application Penetration Tester job openings:
Infographic showing various Web Application Penetration Tester job openings in Raleigh, NC as of August 2026, with employment types broken down into 60% Full Time, and 40% Contract. Highlights an 100% In-person job distribution, with an average salary of $128,606 per year, or $61.8 per hour.

Application Penetration Testing Specialist (Remote)

First Citizens Bank

Raleigh, NC • On-site, Remote

$114K - $150K/yr

Full-time

Re-posted 18 days ago


First Citizens Bank rating

7.4

Company rating: 7.4 out of 10

Based on 106 frontline employees who took The Breakroom Quiz

108th of 170 rated banks


Job description

Overview

This position ensures the technological and digital security of the Bank. The tester will identify exposure to cyber threats, security risks, and unauthorized access and assist with mitigation guidance. The tester will assess organizational networks, applications, or systems for potential vulnerabilities. The tester will maintain knowledge of industry practices, technology, and evolving threats to enhance defenses for the Bank's information systems and resources.

The Pentester must be able to plan, coordinate, communicate, track, and conduct penetration testing assessments on the organization’s applications, aid in the coordination of additional testing through third-party vendors, and may lead other associates in the work group acting as lead tester. The selected candidate is welcome to work remotely and/or from a corporate office location.

Remote eligible.


Responsibilities
  • Plan and conduct application penetration tests of complex computer systems from a remote testing location
  • Coordinate third-party vendor testing
  • Analyze and document test results in the format and level of detail dictated by current procedures
  • Can convey highly technical information in a manner that can be understood and appreciated by Application Owners and other stakeholders
  • Track vulnerabilities and metrics
  • Coordinate multiple projects/assignments simultaneously and accurately, and deliver results in a timely manner
  • Stay current on new tools, TTPs, vulnerabilities, and emerging threats
  • Aid in defining and documenting Pentest Processes

#LI-IK1 


Qualifications

Bachelor's Degree and 4 years of experience in Systems Engineering, Network, or Information Security OR High School Diploma or GED and 8 years of experience in Systems Engineering, Network, or Information Security

Preferred Qualifications:

  • Bachelor's Degree and 4 or more years of experience in systems engineering, network security, or information security OR High School Diploma or GED and 6 years of experience in application penetration testing, systems engineering, network security, or information security
  • Expertise in application penetration testing techniques with and without scanners
  • Demonstrated expertise in:
    • Testing web applications and databases
    • System development life cycle
    • Network administration
    • Cloud penetration testing
    • Linux and Windows
    • Kali Linux tools, Burp Suite, and other pentest tools
    • Experience with pentesting frameworks such as OWASP and PTES
    • Jira and Confluence
    • Analysis and development of professional reports
    • Knowledge of the Secure System Development Lifecycle
  • Demonstrated ability to effectively balance and manage multiple priorities
  • Proficiency in Microsoft Word, Excel, PowerPoint and Outlook
  • Preferred but not required: OSWE, GPEN, GWAPT, or other equal certifications

This job posting is expected to remain active for 30 days from the initial posting date listed above. If it is necessary to extend this deadline, the posting will remain active as appropriate. Job postings may come down early due to business need or a high volume of applicants.

The base pay for this position is generally between $114,000 and $150,000. Actual starting base pay will be determined based on skills, experience, location, and other non-discriminatory factors permitted by law. For some roles, total compensation may also include variable incentives, bonuses, benefits, and/or other awards as outlined in the offer of employment.

Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at https://jobs.firstcitizens.com/benefits.

Qualifications:

Bachelor's Degree and 4 years of experience in Systems Engineering, Network, or Information Security OR High School Diploma or GED and 8 years of experience in Systems Engineering, Network, or Information Security

Preferred Qualifications:

  • Bachelor's Degree and 4 or more years of experience in systems engineering, network security, or information security OR High School Diploma or GED and 6 years of experience in application penetration testing, systems engineering, network security, or information security
  • Expertise in application penetration testing techniques with and without scanners
  • Demonstrated expertise in:
    • Testing web applications and databases
    • System development life cycle
    • Network administration
    • Cloud penetration testing
    • Linux and Windows
    • Kali Linux tools, Burp Suite, and other pentest tools
    • Experience with pentesting frameworks such as OWASP and PTES
    • Jira and Confluence
    • Analysis and development of professional reports
    • Knowledge of the Secure System Development Lifecycle
  • Demonstrated ability to effectively balance and manage multiple priorities
  • Proficiency in Microsoft Word, Excel, PowerPoint and Outlook
  • Preferred but not required: OSWE, GPEN, GWAPT, or other equal certifications

This job posting is expected to remain active for 30 days from the initial posting date listed above. If it is necessary to extend this deadline, the posting will remain active as appropriate. Job postings may come down early due to business need or a high volume of applicants.

The base pay for this position is generally between $114,000 and $150,000. Actual starting base pay will be determined based on skills, experience, location, and other non-discriminatory factors permitted by law. For some roles, total compensation may also include variable incentives, bonuses, benefits, and/or other awards as outlined in the offer of employment.

Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at https://jobs.firstcitizens.com/benefits.

Education:UNAVAILABLEEmployment Type: FULL_TIME

What First Citizens Bank employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom