1

Web Application Penetration Tester Jobs in Reston, VA

Senior Penetration Tester

Herndon, VA · On-site

$120 - $150/hr

Web Application Security * Network Security * Scripting Languages * Top Secret Clearance ATS Optimization Keywords Hard Skills * Penetration Testing Methodologies * Social Engineering Techniques

Web Application Testing: * Conduct security assessments of agency web applications using OWASP Top ... Penetration Testing & Exploitation Validation: * Perform controlled penetration testing (internal ...

New

Experience with web application testing following OWASP methodology. Security Clearance Requirement ... Experience with cloud penetration testing (AWS, Azure). * Familiarity with aircraft systems ...

Penetration Tester

Washington, DC · On-site

$130K - $145K/yr

Conducting web application security assessments, focusing on OWASP Top Ten vulnerabilities and API ... Engaging in wireless and RF security testing, including penetration testing on Wi-Fi, Bluetooth ...

Penetration Tester

Washington, DC · Hybrid

$130K - $145K/yr

Conducting web application security assessments, focusing on OWASP Top Ten vulnerabilities and API ... Engaging in wireless and RF security testing, including penetration testing on Wi-Fi, Bluetooth ...

Penetration Tester

Gaithersburg, MD · On-site

$100K - $130K/yr

Web Application Testing: * Conduct security assessments of agency web applications using OWASP Top ... Penetration Testing & Exploitation Validation: * Perform controlled penetration testing (internal ...

New

Penetration Tester

Gaithersburg, MD · On-site

$100K - $130K/yr

Web Application Testing: Conduct security assessments of agency web applications using OWASP Top 10 ... Penetration Testing & Exploitation Validation: Perform controlled penetration testing (internal and ...

New

Penetration Tester

Arlington, VA · On-site

$86K - $138K/yr

Responsibilities Peraton is seeking an experienced Cyber Penetration Tester to become part of ... Common web application vulnerabilities and exploits such as XSS, SQLi, LFI, file uploads, broken ...

Demonstrated experience with web application and API penetration testing, including identifying and exploiting attack chains across complex application logic, authentication, and authorization flows.

Penetration Tester

Herndon, VA · Hybrid

$130K - $145K/yr

Conducting web application security assessments, focusing on OWASP Top Ten vulnerabilities and API ... Engaging in wireless and RF security testing, including penetration testing on Wi-Fi, Bluetooth ...

Demonstrated experience with web application and API penetration testing, including identifying and exploiting attack chains across complex application logic, authentication, and authorization flows.

SkyePoint Decisions is seeking a Penetration Tester to support the Diplomatic Security Cyber ... Common web application vulnerabilities and exploits such as XSS, SQLi, LFI, file uploads, broken ...

Penetration Tester

Arlington, VA · On-site

$86K - $138K/yr

Responsibilities Peraton is seeking an experienced Cyber Penetration Tester to become part of ... Common web application vulnerabilities and exploits such as XSS, SQLi, LFI, file uploads, broken ...

Demonstrated experience with web application and API penetration testing, including identifying and exploiting attack chains across complex application logic, authentication, and authorization flows.

Penetration Tester

Arlington, VA · On-site

$86K - $138K/yr

Responsibilities Peraton is seeking an experienced Cyber Penetration Tester to become part of ... Common web application vulnerabilities and exploits such as XSS, SQLi, LFI, file uploads, broken ...

... Penetration Tester to perform computer network evaluations and penetration security assessments ... common web application vulnerabilities like XSS, CSRF, Command Injection, SQLi, single sign-on ...

Showing results 21-40

Web Application Penetration Tester information

See Reston, VA salary details

$100.4K

$137.6K

$165.9K

How much do web application penetration tester jobs pay per year?

As of Aug 9, 2026, the average yearly pay for web application penetration tester in Reston, VA is $137,647.00, according to ZipRecruiter salary data. Most workers in this role earn between $126,400.00 and $152,400.00 per year, depending on experience, location, and employer.

What is the difference between Web Application Penetration Tester vs Security Analyst?

AspectWeb Application Penetration TesterSecurity Analyst
CertificationsOSCP, CEH, GPENCISSP, Security+
Work EnvironmentHands-on testing, vulnerability assessmentsMonitoring, incident response, policy development
Industry UsageCybersecurity firms, tech companies, consultingCorporate security teams, government agencies

While both roles focus on cybersecurity, a Web Application Penetration Tester specializes in identifying vulnerabilities in web applications through active testing. In contrast, a Security Analyst monitors security systems, analyzes threats, and manages security policies. The roles often overlap in certifications and industry usage but differ in daily tasks and focus areas.

What types of challenges might a web application penetration tester encounter when working with diverse client environments?

Web Application Penetration Testers often face the challenge of adapting to a wide range of application architectures, technology stacks, and security maturity levels across different clients. Each environment may have unique configurations, legacy systems, or undocumented features that require creative problem-solving and thorough reconnaissance. Additionally, testers must communicate complex technical findings to both technical and non-technical stakeholders, ensuring recommendations are clear and actionable. Effective time management and staying updated on emerging threats are essential for success in this dynamic role.

What is a web application penetration tester?

Web Application Penetration Testers are cybersecurity professionals who assess the security of web applications by simulating real-world attacks. Their goal is to identify vulnerabilities, such as SQL injection or cross-site scripting, that could be exploited by malicious actors. They use a mix of automated tools and manual testing techniques to uncover and report weaknesses, helping organizations improve the security of their web-based systems. These testers often provide recommendations for remediation and may work in-house or as external consultants.

What are the key skills and qualifications needed to thrive as a web application penetration tester, and why are they important?

To thrive as a Web Application Penetration Tester, you need a solid understanding of web technologies, common vulnerabilities (such as those in the OWASP Top 10), and relevant security concepts, often backed by degrees in computer science or related fields and certifications like OSCP or CEH. Familiarity with penetration testing tools like Burp Suite, Metasploit, and Nmap, as well as scripting languages such as Python or Bash, is typically required. Attention to detail, analytical thinking, and effective written and verbal communication are crucial soft skills for reporting findings and collaborating with clients or development teams. These skills ensure accurate vulnerability identification, clear documentation, and actionable recommendations, all vital for improving web application security.
What are popular job titles related to Web Application Penetration Tester jobs in Reston, VA? For Web Application Penetration Tester jobs in Reston, VA, the most frequently searched job titles are:
What job categories do people searching Web Application Penetration Tester jobs in Reston, VA look for? The top searched job categories for Web Application Penetration Tester jobs in Reston, VA are:
What cities near Reston, VA are hiring for Web Application Penetration Tester jobs? Cities near Reston, VA with the most Web Application Penetration Tester job openings:

Penetration Testers - Senior (Lead) with Security Clearance

Koniag Government Services

Washington, DC • On-site

Other

Medical, Dental, Vision, Retirement, PTO

Posted 24 days ago


Koniag Government Services rating

8.6

Company rating: 8.6 out of 10

Based on 6 frontline employees who took The Breakroom Quiz

53rd of 485 rated business services


Job description

Koniag Data Solutions, LLC, a Koniag Government Services company, is seeking a Penetration Testers - Senior (Lead) to support KDS and our government customer in Washington, DC. This position requires the candidate to be able to obtain a Public Trust. We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more. Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced Senior Lead Penetration Tester to support the U.S. Small Business Administration (SBA). The ideal candidate is a highly skilled offensive security professional with extensive experience planning, leading, and executing advanced penetration testing and red team operations across complex federal IT environments. This individual will serve as the technical lead for SBA's penetration testing program, providing expert guidance on adversary simulation, vulnerability exploitation, and security control validation to help the agency identify and remediate security weaknesses before they can be exploited by real-world adversaries. The Senior Lead Penetration Tester will serve as the primary technical lead for all penetration testing and offensive security activities supporting SBA's cybersecurity program, overseeing the full lifecycle of penetration testing engagements, red team operations, and adversary simulation exercises across SBA's enterprise environment. This individual will bring deep technical expertise, strong leadership capabilities, and a comprehensive understanding of adversary TTPs to drive a high-quality, mission-focused penetration testing program that meaningfully strengthens SBA's security posture. Principal responsibilities will include but are not limited to: * Lead the end-to-end planning, scoping, coordination, execution, and reporting of advanced penetration testing engagements across all components of SBA's enterprise IT environment, including network infrastructure, web applications, mobile applications, APIs, cloud environments, and supporting systems and services. * Design and execute sophisticated red team operations and adversary simulation exercises that realistically emulate the tactics, techniques, and procedures (TTPs) of advanced persistent threat (APT) actors, nation-state adversaries, and other sophisticated threat actors known to target federal civilian agencies. * Conduct advanced exploitation of vulnerabilities identified during penetration testing engagements, including privilege escalation, lateral movement, persistence establishment, credential harvesting, and data exfiltration, to accurately demonstrate the real-world impact and exploitability of identified security weaknesses. * Develop and maintain a comprehensive, documented penetration testing methodology, program charter, and rules of engagement (ROE) for SBA's penetration testing program, ensuring alignment with industry best practices and federal security requirements including NIST SP 800-115 and applicable CISA guidance. * Produce detailed, high-quality penetration test reports and executive-level briefings documenting engagement scope, methodologies, technical findings, exploitation evidence, risk ratings, attack narratives, and prioritized, actionable remediation recommendations tailored to both technical and non-technical SBA audiences. * Collaborate with SBA security leadership, the Cybersecurity Architect, SOC teams, and system owners to communicate penetration testing findings, validate remediation efforts through retesting activities, and provide expert guidance on the prioritization and resolution of identified vulnerabilities and security control gaps. * Conduct web application penetration testing in accordance with industry frameworks and standards including the OWASP Testing Guide and OWASP API Security Top 10, identifying and exploiting vulnerabilities including injection flaws, broken authentication, cross-site scripting (XSS), insecure direct object references (IDOR), business logic flaws, and other advanced application security vulnerabilities. * Perform cloud penetration testing and security configuration assessments across AWS, Azure, and/or GCP environments, evaluating the security of cloud service configurations, IAM policies, storage services, network controls, serverless functions, and container environments. * Develop and utilize custom exploitation tools, offensive scripts, and proof-of-concept (PoC) code to demonstrate the exploitability of identified vulnerabilities and support penetration testing operations in scenarios where commercial tools are insufficient or inappropriate. * Lead social engineering assessments, including phishing and spear-phishing campaigns, vishing exercises, and physical penetration testing activities, to evaluate SBA's human and physical security controls and the effectiveness of the agency's security awareness program. * Support and validate vulnerability management activities by providing expert-level analysis of vulnerability scan results, assessing real-world exploitability and risk in the context of SBA's environment, and advising on remediation prioritization strategies based on actual exploitation risk. * Stay current with the latest offensive security research, vulnerability disclosures, exploit development techniques, and adversary TTPs, continuously applying new knowledge to improve the quality, realism, and effectiveness of SBA's penetration testing program. * Mentor and provide senior technical leadership to junior and mid-level penetration testers, fostering professional growth, knowledge transfer, and the continuous development of the offensive security team's technical capabilities. * Ensure all penetration testing and offensive security activities are conducted in strict compliance with SBA's approved rules of engagement, applicable federal laws and regulations, and the ethical standards governing offensive security research and testing. * Coordinate and lead purple team exercises in collaboration with SBA's blue team, SOC, and incident response teams, designing realistic attack scenarios to validate detection and response capabilities and drive measurable improvements in SBA's defensive posture. Education and Experience: Required: * Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field from an accredited college or university. * 8+ years of progressive experience in offensive security, with at least 4 years of dedicated experience leading and executing advanced penetration testing and red team operations in a senior or lead capacity. * Demonstrated experience conducting advanced penetration testing and red team operations within a federal government or large enterprise IT environment. * One or more of the following certifications: * Offensive Security Certified Professional (OSCP) * Offensive Security Experienced Penetration Tester (OSEP) * Offensive Security Web Expert (OSWE) * GIAC Penetration Tester (GPEN) * GIAC Web Application Penetration Tester (GWAPT) * GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) * Certified Penetration Testing Engineer (CPTE) * Certified Red Team Professional (CRTP) Desired: * Master's degree in Cybersecurity, Computer Science, or a related field. * 10+ years of offensive security experience, with a strong background supporting federal government or defense contracting penetration testing and red team programs. Required Skills and Competencies: * Exceptional communication skills in English - both written and oral - with the ability to clearly articulate complex offensive security findings, exploitation narratives, and remediation recommendations to both technical and non-technical audiences, including senior SBA leadership and government contracting officials. * Advanced expertise in penetration testing methodologies and industry frameworks, including PTES, OWASP, NIST SP 800-115, and MITRE ATT&CK, with demonstrated ability to apply these frameworks across diverse target environments, assessment types, and engagement scopes. * Deep proficiency in network penetration testing, including all phases of the engagement lifecycle: reconnaissance, scanning and enumeration, exploitation, privilege escalation, lateral movement, persistence, and post-exploitation techniques across both Windows and Linux environments. * Advanced experience in web application and API penetration testing, including the identification and exploitation of OWASP Top 10 and beyond vulnerabilities in modern web application architectures, RESTful and SOAP APIs, and web services. * Strong hands-on experience with industry-standard penetration testing tools and offensive security platforms, including Metasploit Framework, Burp Suite Professional, Cobalt Strike, BloodHound, Mimikatz, Impacket, Nmap, Nessus, Nikto, SQLMap, Responder, and equivalent utilities. * Proficiency in scripting and programming languages, including Python, PowerShell, Bash, and/or Ruby, for the development of custom exploitation tools, offensive automation scripts, and proof-of-concept code tailored to specific penetration testing objectives. * Experience planning, designing, and executing full-scope red team operations and adversary simulation exercises, including the realistic emulation of APT TTPs using the MITRE ATT&CK framework to comprehensively assess the effectiveness of SBA's defensive controls and detection capabilities. * Demonstrated expertise in cloud penetration testing across AWS, Azure, and/or GCP environments, including the assessment of cloud-native services, IAM misconfigurations, storage security, network controls, serverless functions, and container and Kubernetes environments. * Experience planning and conducting social engineering assessments, including phishing campaign design and execution, vishing exercises, and physical penetration testing activities,

What Koniag Government Services employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom