1

Web Application Penetration Tester Jobs in Silver Spring, MD

They are seeking a Penetration Tester II to work on-site in support of a government contract ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...

They are seeking a Penetration Tester II to conduct penetration testing and support government ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...

They are seeking a Penetration Tester III to conduct penetration testing and security assessments ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...

Senior Penetration Tester

Washington, DC · On-site

$145K - $180K/yr

... Web Applications * Assess and test the security of internal networks and underlying application infrastructure. * Conduct penetration testing and vulnerability assessments on Azure cloud ...

GIAC Web Application Penetration Tester (GWAPT) * GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) * GIAC Assessing and Auditing Wireless Networks (GAWN) Blue Teaming Certifications:

GIAC Web Application Penetration Tester (GWAPT) * GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) * GIAC Assessing and Auditing Wireless Networks (GAWN) Blue Teaming Certifications:

GIAC Web Application Penetration Tester (GWAPT) * GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) * GIAC Assessing and Auditing Wireless Networks (GAWN) Blue Teaming Certifications:

Penetration Tester Location: Reston, VA Work Mode - Hybrid role, 2 days' Work from Office ... Experience conducting web application security assessments * Experience working with a range of ...

next page

Showing results 1-20

Web Application Penetration Tester information

See Silver Spring, MD salary details

$99.5K

$136.4K

$164.4K

How much do web application penetration tester jobs pay per year?

As of Aug 8, 2026, the average yearly pay for web application penetration tester in Silver Spring, MD is $136,358.00, according to ZipRecruiter salary data. Most workers in this role earn between $125,200.00 and $151,000.00 per year, depending on experience, location, and employer.

What is the difference between Web Application Penetration Tester vs Security Analyst?

AspectWeb Application Penetration TesterSecurity Analyst
CertificationsOSCP, CEH, GPENCISSP, Security+
Work EnvironmentHands-on testing, vulnerability assessmentsMonitoring, incident response, policy development
Industry UsageCybersecurity firms, tech companies, consultingCorporate security teams, government agencies

While both roles focus on cybersecurity, a Web Application Penetration Tester specializes in identifying vulnerabilities in web applications through active testing. In contrast, a Security Analyst monitors security systems, analyzes threats, and manages security policies. The roles often overlap in certifications and industry usage but differ in daily tasks and focus areas.

What types of challenges might a web application penetration tester encounter when working with diverse client environments?

Web Application Penetration Testers often face the challenge of adapting to a wide range of application architectures, technology stacks, and security maturity levels across different clients. Each environment may have unique configurations, legacy systems, or undocumented features that require creative problem-solving and thorough reconnaissance. Additionally, testers must communicate complex technical findings to both technical and non-technical stakeholders, ensuring recommendations are clear and actionable. Effective time management and staying updated on emerging threats are essential for success in this dynamic role.

What is a web application penetration tester?

Web Application Penetration Testers are cybersecurity professionals who assess the security of web applications by simulating real-world attacks. Their goal is to identify vulnerabilities, such as SQL injection or cross-site scripting, that could be exploited by malicious actors. They use a mix of automated tools and manual testing techniques to uncover and report weaknesses, helping organizations improve the security of their web-based systems. These testers often provide recommendations for remediation and may work in-house or as external consultants.

What are the key skills and qualifications needed to thrive as a web application penetration tester, and why are they important?

To thrive as a Web Application Penetration Tester, you need a solid understanding of web technologies, common vulnerabilities (such as those in the OWASP Top 10), and relevant security concepts, often backed by degrees in computer science or related fields and certifications like OSCP or CEH. Familiarity with penetration testing tools like Burp Suite, Metasploit, and Nmap, as well as scripting languages such as Python or Bash, is typically required. Attention to detail, analytical thinking, and effective written and verbal communication are crucial soft skills for reporting findings and collaborating with clients or development teams. These skills ensure accurate vulnerability identification, clear documentation, and actionable recommendations, all vital for improving web application security.
What are popular job titles related to Web Application Penetration Tester jobs in Silver Spring, MD? For Web Application Penetration Tester jobs in Silver Spring, MD, the most frequently searched job titles are:
What job categories do people searching Web Application Penetration Tester jobs in Silver Spring, MD look for? The top searched job categories for Web Application Penetration Tester jobs in Silver Spring, MD are:
What cities near Silver Spring, MD are hiring for Web Application Penetration Tester jobs? Cities near Silver Spring, MD with the most Web Application Penetration Tester job openings:
Infographic showing various Web Application Penetration Tester job openings in Silver Spring, MD as of August 2026, with employment types broken down into 60% Full Time, and 40% Contract. Highlights an 100% In-person job distribution, with an average salary of $136,358 per year, or $65.6 per hour.

Application Penetration Tester

Booz Allen Hamilton

Chantilly, VA • On-site

$62K - $141K/yr

Full-time

Medical, Life, Retirement, PTO

Posted 19 days ago


Booz Allen Hamilton rating

8.9

Company rating: 8.9 out of 10

Based on 49 frontline employees who took The Breakroom Quiz

9th of 72 rated business consultants


Job description

Application Penetration Tester

The Opportunity:

Work with a wide variety of clients, including Fortune 100 companies, to validate security controls and incident response through offensive security operations, including application penetration testing. Perform web application security testing, network penetration testing, and cloud penetration testing. Develop comprehensive and accurate reports, and presentations for both technical and executive audiences. Conduct security testing lifecycles in Windows and *nix environments. Communicate findings and strategy to client stakeholders, including technical staff, executive leadership, and legal counsel. Perform innovative research and promote an environment of innovation and knowledge sharing. Apply security testing and penetration testing techniques and mindset to a wide range of projects, become part of a team of security enthusiasts that perform cutting-edge research, and promote an environment of innovation and knowledge sharing. Due to the nature of work performed within this facility, U.S. citizenship is required.

You Have:

  • 1+ years of experience conducting application penetration testing
  • Experience with scripting or coding in Python, Go, or Bash
  • Experience working in a Windows environment and with Active Directory attack path enumeration
  • Experience with C2 frameworks, including Cobalt Strike, Mythic, or Havoc
  • Knowledge of network vulnerability assessments, web application security testing, network penetration testing, or red teaming
  • HS diploma or GED

Nice If You Have:

  • Experience working in a commercial environment, and with Burp Suite Professional
  • Experience deploying infrastructure in cloud environments
  • Bachelor's degree in CS or a related field
  • BSCP, OSWA, OSWE, OSCP, CRTO, GPEN, GXPN, OSCE, or GWAPT Certification

Compensation

At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.

Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $62,000.00 to $141,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date.

Identity Statement

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Candidate AI Usage Policy

AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided.

Work Model
Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.

  • Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.

  • Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.

  • Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.


What Booz Allen Hamilton employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Booz Allen Hamilton logo

About Booz Allen Hamilton

Sourced by ZipRecruiter

Booz Allen Hamilton is a leading provider of management and technology consulting services to the US government in defense, intelligence, and civil markets. Headquartered in McLean, Virginia, the firm also serves major corporations, institutions, and not-for-profit organizations. Founded in 1914 by Edwin G. Booz, the company has a long-standing tradition of helping clients achieve success by delivering a wide range of consulting services that include strategic planning, human capital and learning, communication, systems development, and others. The company's mission is to empower people to change the world, and it has a reputation for maintaining the highest standards of integrity and-excellence.

Industry

It services

Company size

10,000+ Employees

Headquarters location

McLean, VA, US

Year founded

1914