1

Web Application Penetration Tester Jobs in Raleigh, NC

Application Penetration Testing (Web-app, API,Thick Client) * Network Penetration Testing (Internal, External) * Cloud Service penetration testing tradecraft and methodologies across multiple service ...

Application Penetration Testing (Web-app, API,Thick Client) * Network Penetration Testing (Internal, External) * Cloud Service penetration testing tradecraft and methodologies across multiple service ...

Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web ... Experience with Java application technologies, deployment frameworks, and associated security best ...

Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web ... Experience with Java application technologies, deployment frameworks, and associated security best ...

.Net Web Developer

Raleigh, NC · On-site

$47 - $62/hr

Coordinate Web application software installation and provide engineering support. • Testing the patches in test environment. Applying the patches to Web Servers, DR Servers, NAP Servers and branch ...

Strong web application or network penetration testing experience * Familiarity with AI-assisted security tooling, AI agents, or emerging AI-driven approaches to vulnerability discovery and triage.

What You'll Build This isn't a role where you'll be maintaining a single application or working ... testing Education • Bachelor's Degree in Computer Science, Software Engineering, or a related ...

Knowledge of Test Driven Development, Continuous Integration and unit testing frameworks such as ... web site / application development required. Preferred Experience: MS / BS or equivalent ...

next page

Showing results 1-20

Web Application Penetration Tester information

See Raleigh, NC salary details

$93.8K

$128.6K

$155K

How much do web application penetration tester jobs pay per year?

As of Sep 5, 2026, the average yearly pay for web application penetration tester in Raleigh, NC is $128,606.00, according to ZipRecruiter salary data. Most workers in this role earn between $118,100.00 and $142,400.00 per year, depending on experience, location, and employer.

What is a web application penetration tester?

Web Application Penetration Testers are cybersecurity professionals who assess the security of web applications by simulating real-world attacks. Their goal is to identify vulnerabilities, such as SQL injection or cross-site scripting, that could be exploited by malicious actors. They use a mix of automated tools and manual testing techniques to uncover and report weaknesses, helping organizations improve the security of their web-based systems. These testers often provide recommendations for remediation and may work in-house or as external consultants.

What are the key skills and qualifications needed to thrive as a web application penetration tester, and why are they important?

To thrive as a Web Application Penetration Tester, you need a solid understanding of web technologies, common vulnerabilities (such as those in the OWASP Top 10), and relevant security concepts, often backed by degrees in computer science or related fields and certifications like OSCP or CEH. Familiarity with penetration testing tools like Burp Suite, Metasploit, and Nmap, as well as scripting languages such as Python or Bash, is typically required. Attention to detail, analytical thinking, and effective written and verbal communication are crucial soft skills for reporting findings and collaborating with clients or development teams. These skills ensure accurate vulnerability identification, clear documentation, and actionable recommendations, all vital for improving web application security.

What types of challenges might a web application penetration tester encounter when working with diverse client environments?

Web Application Penetration Testers often face the challenge of adapting to a wide range of application architectures, technology stacks, and security maturity levels across different clients. Each environment may have unique configurations, legacy systems, or undocumented features that require creative problem-solving and thorough reconnaissance. Additionally, testers must communicate complex technical findings to both technical and non-technical stakeholders, ensuring recommendations are clear and actionable. Effective time management and staying updated on emerging threats are essential for success in this dynamic role.

What is the difference between Web Application Penetration Tester vs Security Analyst?

AspectWeb Application Penetration TesterSecurity Analyst
CertificationsOSCP, CEH, GPENCISSP, Security+
Work EnvironmentHands-on testing, vulnerability assessmentsMonitoring, incident response, policy development
Industry UsageCybersecurity firms, tech companies, consultingCorporate security teams, government agencies

While both roles focus on cybersecurity, a Web Application Penetration Tester specializes in identifying vulnerabilities in web applications through active testing. In contrast, a Security Analyst monitors security systems, analyzes threats, and manages security policies. The roles often overlap in certifications and industry usage but differ in daily tasks and focus areas.

What are popular job titles related to Web Application Penetration Tester jobs in Raleigh, NC?

For Web Application Penetration Tester jobs in Raleigh, NC, the most frequently searched job titles are:

What job categories do people searching Web Application Penetration Tester jobs in Raleigh, NC look for?

The top searched job categories for Web Application Penetration Tester jobs in Raleigh, NC are:

What cities near Raleigh, NC are hiring for Web Application Penetration Tester jobs?

Cities near Raleigh, NC with the most Web Application Penetration Tester job openings:

Infographic showing various Web Application Penetration Tester job openings in Raleigh, NC as of August 2026, with employment types broken down into 80% Full Time, 15% Part Time, and 5% Contract. Highlights an 88% Physical, 3% Hybrid, and 9% Remote job distribution, with an average salary of $128,606 per year, or $61.8 per hour.

Senior Specialist, MAST Application Penetration Tester

KPMG US

Raleigh, NC • On-site

Full-time

Re-posted 6 days ago


Job description

Job Summary:
KPMG is a leading advisory firm that offers transformative opportunities for career advancement. They are seeking a Senior Specialist, MAST Application Penetration Tester to conduct application penetration testing and ensure security measures are effectively implemented.
Responsibilities:
• Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications
• Perform objective based on abstract penetration testing engagements
• Execute threat modeling, evaluate application business logic, and perform application architecture reviews
• Demonstrate application testing experience in real time via demos to both internal and external audiences
• Function independently in penetration testing engagements, with minimal oversight and guidance
• Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
Qualifications:
Required:
• Minimum three years of recent experience in application penetration testing of Application Programming Interface (API's), web applications, or mobile applications
• Bachelor's degree from an accredited college/university or equivalent industry experience
• Ability to communicate reporting results with technical and non-technical audiences and lead remediation conversations
• Experience with burp suite pro, and other app testing tools such as Netsparker and Checkmarx
• Ability to travel as required
• Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future.
Preferred:
• One or more major ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert (OSWE), Offensive Security Web Assessor (OSWA)
Company:
KPMG is one of the world’s leading professional services firms and the fastest growing Big Four accounting firm in the United States. Founded in 2010, the company is headquartered in New York, USA, with a team of 10001+ employees. The company is currently Late Stage.