1

Web Application Penetration Tester Jobs (NOW HIRING)

They are seeking a Penetration Tester II to conduct penetration testing and support government ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...

They are seeking a Penetration Tester II to conduct penetration testing and support government ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...

They are seeking a Penetration Tester III to conduct penetration testing and security assessments ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...

They are seeking a Penetration Tester III to conduct penetration testing and security assessments ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...

Lead Penetration Tester

Kansas City, MO · On-site

$110 - $150K/hr

Lead Penetration Tester Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (project ... Web application security assessments (approximately 3-4 applications per year) * Test plan and ...

Key Responsibilities Penetration Testing and Vulnerability Assessment * Conduct penetration tests ... Proficiency in web application security principles, including OWASP. * Knowledge of common web ...

New

Senior Penetration Tester

Washington, DC · On-site

$145K - $180K/yr

... Web Applications * Assess and test the security of internal networks and underlying application infrastructure. * Conduct penetration testing and vulnerability assessments on Azure cloud ...

Proficiency in web application security principles (e.g., OWASP). * Knowledge of common web vulnerabilities (e.g., SQL injection, XSS) and exploit techniques. * Experience with penetration testing ...

GIAC Web Application Penetration Tester (GWAPT) * GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) * GIAC Assessing and Auditing Wireless Networks (GAWN) Blue Teaming Certifications:

GIAC Web Application Penetration Tester (GWAPT) * GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) * GIAC Assessing and Auditing Wireless Networks (GAWN) Blue Teaming Certifications:

Showing results 21-40

Web Application Penetration Tester information

See salary details

$96.5K

$132.3K

$159.5K

How much do web application penetration tester jobs pay per year?

As of Aug 7, 2026, the average yearly pay for web application penetration tester in the United States is $132,307.00, according to ZipRecruiter salary data. Most workers in this role earn between $121,500.00 and $146,500.00 per year, depending on experience, location, and employer.

What is the difference between Web Application Penetration Tester vs Security Analyst?

AspectWeb Application Penetration TesterSecurity Analyst
CertificationsOSCP, CEH, GPENCISSP, Security+
Work EnvironmentHands-on testing, vulnerability assessmentsMonitoring, incident response, policy development
Industry UsageCybersecurity firms, tech companies, consultingCorporate security teams, government agencies

While both roles focus on cybersecurity, a Web Application Penetration Tester specializes in identifying vulnerabilities in web applications through active testing. In contrast, a Security Analyst monitors security systems, analyzes threats, and manages security policies. The roles often overlap in certifications and industry usage but differ in daily tasks and focus areas.

What types of challenges might a web application penetration tester encounter when working with diverse client environments?

Web Application Penetration Testers often face the challenge of adapting to a wide range of application architectures, technology stacks, and security maturity levels across different clients. Each environment may have unique configurations, legacy systems, or undocumented features that require creative problem-solving and thorough reconnaissance. Additionally, testers must communicate complex technical findings to both technical and non-technical stakeholders, ensuring recommendations are clear and actionable. Effective time management and staying updated on emerging threats are essential for success in this dynamic role.

What is a web application penetration tester?

Web Application Penetration Testers are cybersecurity professionals who assess the security of web applications by simulating real-world attacks. Their goal is to identify vulnerabilities, such as SQL injection or cross-site scripting, that could be exploited by malicious actors. They use a mix of automated tools and manual testing techniques to uncover and report weaknesses, helping organizations improve the security of their web-based systems. These testers often provide recommendations for remediation and may work in-house or as external consultants.

What are the key skills and qualifications needed to thrive as a web application penetration tester, and why are they important?

To thrive as a Web Application Penetration Tester, you need a solid understanding of web technologies, common vulnerabilities (such as those in the OWASP Top 10), and relevant security concepts, often backed by degrees in computer science or related fields and certifications like OSCP or CEH. Familiarity with penetration testing tools like Burp Suite, Metasploit, and Nmap, as well as scripting languages such as Python or Bash, is typically required. Attention to detail, analytical thinking, and effective written and verbal communication are crucial soft skills for reporting findings and collaborating with clients or development teams. These skills ensure accurate vulnerability identification, clear documentation, and actionable recommendations, all vital for improving web application security.
More about Web Application Penetration Tester jobs
What cities are hiring for Web Application Penetration Tester jobs? Cities with the most Web Application Penetration Tester job openings:
What states have the most Web Application Penetration Tester jobs? States with the most job openings for Web Application Penetration Tester jobs include:
What job categories do people searching Web Application Penetration Tester jobs look for? The top searched job categories for Web Application Penetration Tester jobs are:
Infographic showing various Web Application Penetration Tester job openings in the United States as of August 2026, with employment types broken down into 60% Full Time, and 40% Contract. Highlights an 100% In-person job distribution, with an average salary of $132,307 per year, or $63.6 per hour.

Senior Specialist, MAST Application Penetration Tester

KPMG

Chicago, IL

$95K - $208K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 6 days ago


Job description

The KPMG Advisory practice is at the forefront of transformation, offering excellent opportunities for individuals to advance their careers and expertise with KPMG. Looking ahead, we anticipate continued evolution and success within the practice, fostering both personal and professional development, thereby creating new pathways for growth. In this ever-changing market environment, our professionals must be adaptable and thrive in a collaborative, team-driven culture. At KPMG, our people are our number one priority. With a wealth of learning and career development opportunities, a world-class training facility, and leading market tools, we help our people continue to grow both professionally and personally. If you're looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have the flexibility and access to constantly find new areas of inspiration and expand your capabilities, then consider a career in Advisory.

KPMG is currently seeking a Senior Specialist, MAST Application Penetration Tester to join our Managed Services practice.

Responsibilities:
  • Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications
  • Perform objective based on abstract penetration testing engagements
  • Execute threat modeling, evaluate application business logic, and perform application architecture reviews
  • Demonstrate application testing experience in real time via demos to both internal and external audiences
  • Function independently in penetration testing engagements, with minimal oversight and guidance
  • Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
Qualifications:
  • Minimum three years of recent experience in application penetration testing of Application Programming Interface (API's), web applications, or mobile applications
  • Bachelor's  degree from an accredited college/university or equivalent industry experience
  • Ability to communicate reporting results with technical and non-technical audiences and lead remediation conversations
  • Experience with burp suite pro, and other app testing tools such as Netsparker and Checkmarx
  • One or more major ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST),  Offensive Security Web Expert (OSWE),  Offensive Security Web Assessor (OSWA)
  • Ability to travel as required
  • Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa)
KPMG LLP and its affiliates and subsidiaries (“KPMG”) complies with all local/state regulations regarding displaying salary ranges. If required, the ranges displayed below or via the URL below are specifically for those potential hires who will work in the location(s) listed. Any offered salary is determined based on relevant factors such as applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications and market considerations. In addition, KPMG is proud to offer a comprehensive, competitive benefits package, with options designed to help you make the best decisions for yourself, your family, and your lifestyle. Available benefits are based on eligibility. Our Total Rewards package includes a variety of medical and dental plans, vision coverage, disability and life insurance, 401(k) plans, and a robust suite of personal well-being benefits to support your mental health. Depending on job classification, standard work hours, and years of service, KPMG provides Personal Time Off per fiscal year. Additionally, each year KPMG publishes a calendar of holidays to be observed during the year and provides eligible employees two breaks each year where employees will not be required to use Personal Time Off; one is at year end and the other is around the July 4th holiday. Additional details about our benefits can be found towards the bottom of our KPMG US Careers site at Benefits & How We Work.

Follow this link to obtain salary ranges by city outside of CA:
https://kpmg.com/us/en/how-we-work/pay-transparency.html/?id=M105ADV_4_26 California Salary Range: $95855 - $208265

KPMG offers a comprehensive compensation and benefits package. KPMG is an equal opportunity employer. KPMG complies with all applicable federal, state and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by applicable federal, state, or local laws. The attached link contains further information regarding KPMG's compliance with federal, state and local recruitment and hiring laws. No phone calls or agencies please.

KPMG recruits on a rolling basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) for which they are qualified that is also of interest to them.

Los Angeles County applicants: Material job duties for this position are listed above. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation. Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.