1

Web Application Penetration Tester Jobs (NOW HIRING)

We are seeking an experienced and results-driven Penetration Tester to perform comprehensive web application security assessments. The role involves conducting penetration tests, evaluating security ...

... web application vulnerabilities to various level of personnel within a large organization ... application penetration testing. Minimum of 5 years of demonstrated experience with automated ...

... Web Application/Web Services penetration testing • network Penetration Testing • Mobile Application Penetration Testing • Thick Client Penetration Testing • Knows scripting language. • ...

Senior Penetration Tester

Washington, DC · On-site

$145K - $180K/yr

... web application security, and emerging offensive security techniques. Essential Functions of the Job * Plan, create, and execute advanced penetration methods, scripts, and tests for the team, with a ...

... web application vulnerabilities to various level of personnel within a large organization ... with application penetration testing. • Minimum of 5 years of demonstrated experience with ...

Showing results 21-40

Web Application Penetration Tester information

See salary details

$96.5K

$132.3K

$159.5K

How much do web application penetration tester jobs pay per year?

As of Sep 5, 2026, the average yearly pay for web application penetration tester in the United States is $132,307.00, according to ZipRecruiter salary data. Most workers in this role earn between $121,500.00 and $146,500.00 per year, depending on experience, location, and employer.

What is a web application penetration tester?

Web Application Penetration Testers are cybersecurity professionals who assess the security of web applications by simulating real-world attacks. Their goal is to identify vulnerabilities, such as SQL injection or cross-site scripting, that could be exploited by malicious actors. They use a mix of automated tools and manual testing techniques to uncover and report weaknesses, helping organizations improve the security of their web-based systems. These testers often provide recommendations for remediation and may work in-house or as external consultants.

What are the key skills and qualifications needed to thrive as a web application penetration tester, and why are they important?

To thrive as a Web Application Penetration Tester, you need a solid understanding of web technologies, common vulnerabilities (such as those in the OWASP Top 10), and relevant security concepts, often backed by degrees in computer science or related fields and certifications like OSCP or CEH. Familiarity with penetration testing tools like Burp Suite, Metasploit, and Nmap, as well as scripting languages such as Python or Bash, is typically required. Attention to detail, analytical thinking, and effective written and verbal communication are crucial soft skills for reporting findings and collaborating with clients or development teams. These skills ensure accurate vulnerability identification, clear documentation, and actionable recommendations, all vital for improving web application security.

What types of challenges might a web application penetration tester encounter when working with diverse client environments?

Web Application Penetration Testers often face the challenge of adapting to a wide range of application architectures, technology stacks, and security maturity levels across different clients. Each environment may have unique configurations, legacy systems, or undocumented features that require creative problem-solving and thorough reconnaissance. Additionally, testers must communicate complex technical findings to both technical and non-technical stakeholders, ensuring recommendations are clear and actionable. Effective time management and staying updated on emerging threats are essential for success in this dynamic role.

What is the difference between Web Application Penetration Tester vs Security Analyst?

AspectWeb Application Penetration TesterSecurity Analyst
CertificationsOSCP, CEH, GPENCISSP, Security+
Work EnvironmentHands-on testing, vulnerability assessmentsMonitoring, incident response, policy development
Industry UsageCybersecurity firms, tech companies, consultingCorporate security teams, government agencies

While both roles focus on cybersecurity, a Web Application Penetration Tester specializes in identifying vulnerabilities in web applications through active testing. In contrast, a Security Analyst monitors security systems, analyzes threats, and manages security policies. The roles often overlap in certifications and industry usage but differ in daily tasks and focus areas.

More about Web Application Penetration Tester jobs

What cities are hiring for Web Application Penetration Tester jobs?

Cities with the most Web Application Penetration Tester job openings:

What states have the most Web Application Penetration Tester jobs?

States with the most job openings for Web Application Penetration Tester jobs include:

What job categories do people searching Web Application Penetration Tester jobs look for?

The top searched job categories for Web Application Penetration Tester jobs are:

Infographic showing various Web Application Penetration Tester job openings in the United States as of August 2026, with employment types broken down into 76% Full Time, 19% Part Time, and 5% Contract. Highlights an 90% Physical, 2% Hybrid, and 8% Remote job distribution, with an average salary of $132,307 per year, or $63.6 per hour.

Senior Specialist, MAST Application Penetration Tester

KPMG US

Fort Worth, TX • On-site

Full-time

Re-posted 6 days ago


Job description

Job Summary:
KPMG is a leading firm in the Advisory practice, offering opportunities for career advancement. They are seeking a Senior Specialist, MAST Application Penetration Tester to conduct manual penetration testing and execute threat modeling while working independently in various engagements.
Responsibilities:
• Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications
• Perform objective based on abstract penetration testing engagements
• Execute threat modeling, evaluate application business logic, and perform application architecture reviews
• Demonstrate application testing experience in real time via demos to both internal and external audiences
• Function independently in penetration testing engagements, with minimal oversight and guidance
• Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
Qualifications:
Required:
• Minimum three years of recent experience in application penetration testing of Application Programming Interface (API's), web applications, or mobile applications
• Bachelor's degree from an accredited college/university or equivalent industry experience
• Ability to communicate reporting results with technical and non-technical audiences and lead remediation conversations
• Experience with burp suite pro, and other app testing tools such as Netsparker and Checkmarx
• Ability to travel as required
• Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa)
Preferred:
• One or more major ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert (OSWE), Offensive Security Web Assessor (OSWA)
Company:
KPMG is one of the world’s leading professional services firms and the fastest growing Big Four accounting firm in the United States. Founded in 2010, the company is headquartered in New York, USA, with a team of 10001+ employees. The company is currently Late Stage.