1

Web Application Penetration Tester Jobs in Raleigh, NC

Furthermore, we build web products and offer services such as web designing, layouts, responsive designing, graphic designing, web application development using frameworks based on model view ...

java developer

Raleigh, NC

$49.50 - $64.25/hr

To be successful in this role you need to: - Be familiar with all aspects of software design, development, testing and deployment on a client-facing web application stack - Demonstrate expertise in ...

Our company provides application analysis, design, development and programming, software ... testing, integration, and implementation, and management consulting services to various clients ...

... Application Deadline 09/25/2026 Open Until Filled No Position Type Permanent Staff (EHRA NF ... They will perform data analytics and multi-platform site testing as necessary to ensure optimal ...

New

Foster a DevOps culture around automation of builds, testing, deployments, and scaling * Contribute ... Extensive web application development experience for high-scale applications * Advanced skills in ...

Showing results 21-40

Web Application Penetration Tester information

See Raleigh, NC salary details

$93.8K

$128.6K

$155K

How much do web application penetration tester jobs pay per year?

As of Sep 5, 2026, the average yearly pay for web application penetration tester in Raleigh, NC is $128,606.00, according to ZipRecruiter salary data. Most workers in this role earn between $118,100.00 and $142,400.00 per year, depending on experience, location, and employer.

What is a web application penetration tester?

Web Application Penetration Testers are cybersecurity professionals who assess the security of web applications by simulating real-world attacks. Their goal is to identify vulnerabilities, such as SQL injection or cross-site scripting, that could be exploited by malicious actors. They use a mix of automated tools and manual testing techniques to uncover and report weaknesses, helping organizations improve the security of their web-based systems. These testers often provide recommendations for remediation and may work in-house or as external consultants.

What are the key skills and qualifications needed to thrive as a web application penetration tester, and why are they important?

To thrive as a Web Application Penetration Tester, you need a solid understanding of web technologies, common vulnerabilities (such as those in the OWASP Top 10), and relevant security concepts, often backed by degrees in computer science or related fields and certifications like OSCP or CEH. Familiarity with penetration testing tools like Burp Suite, Metasploit, and Nmap, as well as scripting languages such as Python or Bash, is typically required. Attention to detail, analytical thinking, and effective written and verbal communication are crucial soft skills for reporting findings and collaborating with clients or development teams. These skills ensure accurate vulnerability identification, clear documentation, and actionable recommendations, all vital for improving web application security.

What types of challenges might a web application penetration tester encounter when working with diverse client environments?

Web Application Penetration Testers often face the challenge of adapting to a wide range of application architectures, technology stacks, and security maturity levels across different clients. Each environment may have unique configurations, legacy systems, or undocumented features that require creative problem-solving and thorough reconnaissance. Additionally, testers must communicate complex technical findings to both technical and non-technical stakeholders, ensuring recommendations are clear and actionable. Effective time management and staying updated on emerging threats are essential for success in this dynamic role.

What is the difference between Web Application Penetration Tester vs Security Analyst?

AspectWeb Application Penetration TesterSecurity Analyst
CertificationsOSCP, CEH, GPENCISSP, Security+
Work EnvironmentHands-on testing, vulnerability assessmentsMonitoring, incident response, policy development
Industry UsageCybersecurity firms, tech companies, consultingCorporate security teams, government agencies

While both roles focus on cybersecurity, a Web Application Penetration Tester specializes in identifying vulnerabilities in web applications through active testing. In contrast, a Security Analyst monitors security systems, analyzes threats, and manages security policies. The roles often overlap in certifications and industry usage but differ in daily tasks and focus areas.

What are popular job titles related to Web Application Penetration Tester jobs in Raleigh, NC?

For Web Application Penetration Tester jobs in Raleigh, NC, the most frequently searched job titles are:

What job categories do people searching Web Application Penetration Tester jobs in Raleigh, NC look for?

The top searched job categories for Web Application Penetration Tester jobs in Raleigh, NC are:

What cities near Raleigh, NC are hiring for Web Application Penetration Tester jobs?

Cities near Raleigh, NC with the most Web Application Penetration Tester job openings:

Infographic showing various Web Application Penetration Tester job openings in Raleigh, NC as of August 2026, with employment types broken down into 80% Full Time, 15% Part Time, and 5% Contract. Highlights an 88% Physical, 3% Hybrid, and 9% Remote job distribution, with an average salary of $128,606 per year, or $61.8 per hour.

Spring & Summer 2027 Intern - Security & GRC

Workiva

Raleigh, NC • On-site, Remote

$40/hr

Full-time

Retirement

Posted 7 days ago


Workiva rating

9.9

Company rating: 9.9 out of 10

Based on 7 frontline employees who took The Breakroom Quiz

1st of 247 rated software companies


Job description

The Security Intern is an integral part of the Information Security team at Workiva. You will help solve security issues, develop tools to assist with security threats, and assist with vulnerability testing of web applications. This role may involve making recommendations on security controls and collaborating with internal stakeholders.

What You'll Do

  • Provide Incident Response support when an actionable incident is confirmed
  • Document, investigate, and report on information security issues and emerging trends
  • Manage and configure tools and devices to expand our security monitoring infrastructure
  • Develop tools to assist with security and compliance tasks
  • Assist with continual vulnerability testing of web applications to identify weaknesses
  • Research and identify potential security controls to fix active vulnerabilities
  • Collaborate with other teams to create remediation strategies and timelines for vulnerabilities
  • Develop queries and visualizations to assist with security and compliance tasks
  • Help solve security issues identified in the production application
  • Provide analysis and trending of security log data from a large number of various security devices
  • Collaborate with other teams to gather information regarding security problems, issues, and ideas

What You'll Need

Minimum Qualifications

  • Currently enrolled in a degree-seeking program, preferably in Computer Engineering, Computer Science, Management Information Systems, or a similar degree

Preferred Qualifications

  • Strong ethical and discretionary ability to handle sensitive information and data
  • Strong communication and networking skills (written, verbal, listening)
  • Basic competency in one or more programming languages (Python, Java, SQL, Go, and/or Dart)
  • Familiarity with vulnerability scanning tools and/or penetration testing techniques
  • Familiarity with Amazon Web Services (AWS) and/or Google App Engine (GAE)
  • Working knowledge of Linux/Unix operating systems
  • If Security Engineering focused: Ability to analyze problems and devise creative solutions within business constraints; good understanding of HTTP and common web application vulnerabilities
  • If Security Operations focused: Self-motivation and initiative skills to search for and resolve security issues; initiative and social skills to network with technical individuals to gather information on projects

Travel Requirements & Working Conditions

  • Minimal travel
  • Reliable internet access for any period of time working remotely and not in a Workiva office

Location: This internship is primarily a remote opportunity. However, if you are located near one of our office hubs, you are welcome to work in a hybrid capacity and utilize our office spaces. Check out our article on Workplace Flexibility to learn more.

When can you expect to hear back?

We are committed to attending all career fairs and recruitment events before closing our positions. That means, this position might be open without updates for a few weeks to give us time to connect with all potential candidates before wrapping up the recruitment season. Check out our tentative timeline below to see when you can expect to hear from us!

Postings close: September 27, 2026

Engineering postings close: October 2, 2026

Interviews: Early to mid October

Offers: Late October

2027 Start Dates:

This position has opportunities to start in the Spring or Summer. Please see our start dates below and let us know your availability in your application.

  • Spring 2027 Internships: Monday, January 4, 2027 (15-20 hours per week max)
  • Summer 2027 Internships: Monday, May 17, 2027 (40/hours per week max)

How You’ll Be Rewarded

Salary range in the US: $40.00 - $40.00 401(k) participation and match Paid sick leave A unique opportunity to further your learning experience through additional internship seasons

Why Join Workiva

Workiva is the platform designed to bring confidence, control, and a competitive edge to the world’s most complex organizations. Our AI-powered platform unifies finance, risk, and sustainability on a single, secure foundation-ensuring data is trusted, traceable, and ready to act on. With an unbroken path from source to output, leaders gain confidence in their numbers, visibility into current and emerging risks, and the ability to move with speed and precision in a constantly changing world.

At Workiva, you’ll bring technology to market that executives, boards, and regulators depend on. The work you do here helps organizations navigate uncertainty, maintain trust, and make decisions that stand up to scrutiny. If you’re energized by meaningful challenges, inspired by collaborative teams, and motivated to help organizations turn uncertainty into advantage, we’d love to meet you.

Employment decisions are made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other protected characteristic.

Workiva is committed to working with and providing reasonable accommodations to applicants with disabilities. To request assistance with the application process, please email earlycareer@workiva.com.

Workiva employees are required to undergo comprehensive security and privacy training tailored to their roles, ensuring adherence to company policies and regulatory standards.

Workiva supports employees in working where they work best - either from an office or remotely from any location within their country of employment.


What Workiva employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom