Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Penetration Tester II
Chandler, AZ · On-site
They are seeking a Penetration Tester II to conduct penetration testing and support government ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...
Penetration Tester II
Chandler, AZ · On-site
They are seeking a Penetration Tester II to conduct penetration testing and support government ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...
Conduct external network and web application penetration testing and vulnerability assessments per NIST SP 800-115 methodology. * Attempt to obtain ePHI, PII, financial data, and privileged ...
Quick apply
Conduct external network and web application penetration testing and vulnerability assessments per NIST SP 800-115 methodology. * Attempt to obtain ePHI, PII, financial data, and privileged ...
Senior Penetration Tester (WebApp and Network)
Charlotte, NC · On-site +1
$50 - $65/hr
Strong understanding of web application technologies and protocols (HTTP/HTTPS, HTML, JavaScript, etc.). * Proficiency in using penetration testing tools like Burp Suite, OWASP ZAP, Metasploit ...
Senior Penetration Tester (WebApp and Network)
Charlotte, NC · On-site +1
$50 - $65/hr
Strong understanding of web application technologies and protocols (HTTP/HTTPS, HTML, JavaScript, etc.). * Proficiency in using penetration testing tools like Burp Suite, OWASP ZAP, Metasploit ...
Senior Penetration Tester (WebApp and Network)
Charlotte, NC · On-site
$50 - $65/hr
Strong understanding of web application technologies and protocols (HTTP/HTTPS, HTML, JavaScript, etc.). * Proficiency in using penetration testing tools like Burp Suite, OWASP ZAP, Metasploit ...
Senior Penetration Tester (WebApp and Network)
Charlotte, NC · On-site
$50 - $65/hr
Strong understanding of web application technologies and protocols (HTTP/HTTPS, HTML, JavaScript, etc.). * Proficiency in using penetration testing tools like Burp Suite, OWASP ZAP, Metasploit ...
Penetration Tester II
Washington, DC · On-site
They are seeking a Penetration Tester II to conduct penetration testing and support government ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...
Penetration Tester II
Washington, DC · On-site
They are seeking a Penetration Tester II to conduct penetration testing and support government ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...
Key Responsibilities • Conduct external network and web application penetration testing and vulnerability assessments per NIST SP 800-115 methodology. • Attempt to obtain ePHI, PII, financial ...
Key Responsibilities • Conduct external network and web application penetration testing and vulnerability assessments per NIST SP 800-115 methodology. • Attempt to obtain ePHI, PII, financial ...
Penetration Tester III
Chandler, AZ · On-site
They are seeking a Penetration Tester III to conduct penetration testing and security assessments ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...
Penetration Tester III
Chandler, AZ · On-site
They are seeking a Penetration Tester III to conduct penetration testing and security assessments ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...
Penetration Tester III
Washington, DC · On-site
They are seeking a Penetration Tester III to conduct penetration testing and security assessments ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...
Penetration Tester III
Washington, DC · On-site
They are seeking a Penetration Tester III to conduct penetration testing and security assessments ... M9 Solutions is a national staffing firm focused on cloud, cyber security, web application services ...
As a Penetration Tester supporting web applications, you will work closely with clients to deliver clear, actionable reports and contribute to the development of security best practices.
Quick apply
As a Penetration Tester supporting web applications, you will work closely with clients to deliver clear, actionable reports and contribute to the development of security best practices.
Lead Penetration Tester
$110 - $150K/hr
Lead Penetration Tester Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (project ... Web application security assessments (approximately 3-4 applications per year) * Test plan and ...
Quick apply
Lead Penetration Tester
$110 - $150K/hr
Lead Penetration Tester Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (project ... Web application security assessments (approximately 3-4 applications per year) * Test plan and ...
Lead Penetration Tester
Kansas City, MO · On-site
$110 - $150K/hr
Lead Penetration Tester Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (project ... Web application security assessments (approximately 3-4 applications per year) * Test plan and ...
Quick apply
Lead Penetration Tester
Kansas City, MO · On-site
$110 - $150K/hr
Lead Penetration Tester Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (project ... Web application security assessments (approximately 3-4 applications per year) * Test plan and ...
Penetration Tester
$90K - $105K/yr
Key Responsibilities Penetration Testing and Vulnerability Assessment * Conduct penetration tests ... Proficiency in web application security principles, including OWASP. * Knowledge of common web ...
New
Quick apply
Penetration Tester
$90K - $105K/yr
Key Responsibilities Penetration Testing and Vulnerability Assessment * Conduct penetration tests ... Proficiency in web application security principles, including OWASP. * Knowledge of common web ...
New
As a Penetration Tester supporting web applications, you will work closely with clients to deliver clear, actionable reports and contribute to the development of security best practices.
As a Penetration Tester supporting web applications, you will work closely with clients to deliver clear, actionable reports and contribute to the development of security best practices.
Lead Penetration Tester
Fort Collins, CO · On-site
$110 - $150K/hr
Lead Penetration Tester Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (project ... Web application security assessments (approximately 3-4 applications per year) * Test plan and ...
Quick apply
Lead Penetration Tester
Fort Collins, CO · On-site
$110 - $150K/hr
Lead Penetration Tester Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (project ... Web application security assessments (approximately 3-4 applications per year) * Test plan and ...
Senior Penetration Tester
Washington, DC · On-site
$145K - $180K/yr
... Web Applications * Assess and test the security of internal networks and underlying application infrastructure. * Conduct penetration testing and vulnerability assessments on Azure cloud ...
Quick apply
Senior Penetration Tester
Washington, DC · On-site
$145K - $180K/yr
... Web Applications * Assess and test the security of internal networks and underlying application infrastructure. * Conduct penetration testing and vulnerability assessments on Azure cloud ...
Penetration Tester
Albany, NY · On-site
$60/hr
Proficiency in web application security principles (e.g., OWASP). * Knowledge of common web vulnerabilities (e.g., SQL injection, XSS) and exploit techniques. * Experience with penetration testing ...
Quick apply
Penetration Tester
Albany, NY · On-site
$60/hr
Proficiency in web application security principles (e.g., OWASP). * Knowledge of common web vulnerabilities (e.g., SQL injection, XSS) and exploit techniques. * Experience with penetration testing ...
Penetration Testing Lead
Leesburg, VA · On-site
GIAC Web Application Penetration Tester (GWAPT) * GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) * GIAC Assessing and Auditing Wireless Networks (GAWN) Blue Teaming Certifications:
Penetration Testing Lead
Leesburg, VA · On-site
GIAC Web Application Penetration Tester (GWAPT) * GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) * GIAC Assessing and Auditing Wireless Networks (GAWN) Blue Teaming Certifications:
Conduct web application and API database penetration testing efforts. * Analyze application workflows, API endpoints, authentication mechanisms, and authorization controls to identify security ...
Conduct web application and API database penetration testing efforts. * Analyze application workflows, API endpoints, authentication mechanisms, and authorization controls to identify security ...
Penetration Testing Lead
Leesburg, VA · On-site
GIAC Web Application Penetration Tester (GWAPT) * GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) * GIAC Assessing and Auditing Wireless Networks (GAWN) Blue Teaming Certifications:
Penetration Testing Lead
Leesburg, VA · On-site
GIAC Web Application Penetration Tester (GWAPT) * GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) * GIAC Assessing and Auditing Wireless Networks (GAWN) Blue Teaming Certifications:
Web Application Penetration Tester information
See salary details
$96.5K - $102.2K
4% of jobs
$102.2K - $108K
8% of jobs
$108K - $113.7K
4% of jobs
$113.7K - $119.4K
2% of jobs
$121.8K is the 25th percentile. Wages below this are outliers.
$119.4K - $125.1K
16% of jobs
$125.1K - $130.9K
15% of jobs
The median wage is $131.2K / yr.
$130.9K - $136.6K
11% of jobs
$136.6K - $142.3K
10% of jobs
$145.3K is the 75th percentile. Wages above this are outliers.
$142.3K - $148K
10% of jobs
$148K - $153.8K
11% of jobs
$153.8K - $159.5K
10% of jobs
$96.5K
$132.3K
$159.5K
How much do web application penetration tester jobs pay per year?
What is the difference between Web Application Penetration Tester vs Security Analyst?
| Aspect | Web Application Penetration Tester | Security Analyst |
|---|---|---|
| Certifications | OSCP, CEH, GPEN | CISSP, Security+ |
| Work Environment | Hands-on testing, vulnerability assessments | Monitoring, incident response, policy development |
| Industry Usage | Cybersecurity firms, tech companies, consulting | Corporate security teams, government agencies |
While both roles focus on cybersecurity, a Web Application Penetration Tester specializes in identifying vulnerabilities in web applications through active testing. In contrast, a Security Analyst monitors security systems, analyzes threats, and manages security policies. The roles often overlap in certifications and industry usage but differ in daily tasks and focus areas.
What types of challenges might a web application penetration tester encounter when working with diverse client environments?
What is a web application penetration tester?
What are the key skills and qualifications needed to thrive as a web application penetration tester, and why are they important?

$95K - $208K/yr
Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Re-posted 6 days ago
Job description
The KPMG Advisory practice is at the forefront of transformation, offering excellent opportunities for individuals to advance their careers and expertise with KPMG. Looking ahead, we anticipate continued evolution and success within the practice, fostering both personal and professional development, thereby creating new pathways for growth. In this ever-changing market environment, our professionals must be adaptable and thrive in a collaborative, team-driven culture. At KPMG, our people are our number one priority. With a wealth of learning and career development opportunities, a world-class training facility, and leading market tools, we help our people continue to grow both professionally and personally. If you're looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have the flexibility and access to constantly find new areas of inspiration and expand your capabilities, then consider a career in Advisory.
KPMG is currently seeking a Senior Specialist, MAST Application Penetration Tester to join our Managed Services practice.
Responsibilities:- Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications
- Perform objective based on abstract penetration testing engagements
- Execute threat modeling, evaluate application business logic, and perform application architecture reviews
- Demonstrate application testing experience in real time via demos to both internal and external audiences
- Function independently in penetration testing engagements, with minimal oversight and guidance
- Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
- Minimum three years of recent experience in application penetration testing of Application Programming Interface (API's), web applications, or mobile applications
- Bachelor's degree from an accredited college/university or equivalent industry experience
- Ability to communicate reporting results with technical and non-technical audiences and lead remediation conversations
- Experience with burp suite pro, and other app testing tools such as Netsparker and Checkmarx
- One or more major ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert (OSWE), Offensive Security Web Assessor (OSWA)
- Ability to travel as required
- Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa)
KPMG offers a comprehensive compensation and benefits package. KPMG is an equal opportunity employer. KPMG complies with all applicable federal, state and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by applicable federal, state, or local laws. The attached link contains further information regarding KPMG's compliance with federal, state and local recruitment and hiring laws. No phone calls or agencies please.
KPMG recruits on a rolling basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) for which they are qualified that is also of interest to them.
Los Angeles County applicants: Material job duties for this position are listed above. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation. Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.