Responsibilities : • Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications • Perform objective based on ...
Responsibilities : • Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications • Perform objective based on ...
Responsibilities : • Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications • Perform objective based on ...
Responsibilities : • Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications • Perform objective based on ...
Responsibilities : • Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications • Perform objective based on ...
Responsibilities : • Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications • Perform objective based on ...
Responsibilities : • Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications • Perform objective based on ...
Responsibilities : • Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications • Perform objective based on ...
Responsibilities : • Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications • Perform objective based on ...
Responsibilities : • Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications • Perform objective based on ...
Responsibilities : • Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications • Perform objective based on ...
Responsibilities : • Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications • Perform objective based on ...
Jnr. Penetration Tester - Cloud, Mobile & Web Application
California, MO · On-site
$80 - $132/hr
Cloud, Mobile and Web Application Penetration Tester in Orange County, CA. This is an onsite position (hybrid is possible) for US Citizens and Green Card holders. If you need visa sponsorship now or ...
Jnr. Penetration Tester - Cloud, Mobile & Web Application
California, MO · On-site
$80 - $132/hr
Cloud, Mobile and Web Application Penetration Tester in Orange County, CA. This is an onsite position (hybrid is possible) for US Citizens and Green Card holders. If you need visa sponsorship now or ...
GIAC Penetration Tester (GPEN) * Offensive Security Web Expert (OSWE) * eLearnSecurity Web Application Penetration Tester (eWPT) * Certified Red Team Operator (CRTO) * Other relevant offensive ...
GIAC Penetration Tester (GPEN) * Offensive Security Web Expert (OSWE) * eLearnSecurity Web Application Penetration Tester (eWPT) * Certified Red Team Operator (CRTO) * Other relevant offensive ...
We are seeking an experienced and results-driven Penetration Tester to perform comprehensive web application security assessments. The role involves conducting penetration tests, evaluating security ...
We are seeking an experienced and results-driven Penetration Tester to perform comprehensive web application security assessments. The role involves conducting penetration tests, evaluating security ...
... web application vulnerabilities to various level of personnel within a large organization ... application penetration testing. Minimum of 5 years of demonstrated experience with automated ...
... web application vulnerabilities to various level of personnel within a large organization ... application penetration testing. Minimum of 5 years of demonstrated experience with automated ...
Penetration tester
Dallas, TX · On-site
... Web Application/Web Services penetration testing • network Penetration Testing • Mobile Application Penetration Testing • Thick Client Penetration Testing • Knows scripting language. • ...
Penetration tester
Dallas, TX · On-site
... Web Application/Web Services penetration testing • network Penetration Testing • Mobile Application Penetration Testing • Thick Client Penetration Testing • Knows scripting language. • ...
Senior Penetration Tester
Washington, DC · On-site
$145K - $180K/yr
... web application security, and emerging offensive security techniques. Essential Functions of the Job * Plan, create, and execute advanced penetration methods, scripts, and tests for the team, with a ...
Quick apply
Senior Penetration Tester
Washington, DC · On-site
$145K - $180K/yr
... web application security, and emerging offensive security techniques. Essential Functions of the Job * Plan, create, and execute advanced penetration methods, scripts, and tests for the team, with a ...
As a Penetration Tester supporting web applications, you will work closely with clients to deliver ... Minimum of 2-3 years of work experience in application penetration testing * Familiarity with ...
Quick apply
As a Penetration Tester supporting web applications, you will work closely with clients to deliver ... Minimum of 2-3 years of work experience in application penetration testing * Familiarity with ...
Penetration Tester
Charlotte, NC · On-site
... web application vulnerabilities to various level of personnel within a large organization ... with application penetration testing. • Minimum of 5 years of demonstrated experience with ...
Penetration Tester
Charlotte, NC · On-site
... web application vulnerabilities to various level of personnel within a large organization ... with application penetration testing. • Minimum of 5 years of demonstrated experience with ...
Senior Specialist, MAST Application Penetration Tester
Atlanta, GA · On-site
$95K - $208K/yr
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Senior Specialist, MAST Application Penetration Tester
Atlanta, GA · On-site
$95K - $208K/yr
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Penetration Tester
Hillsboro, OR · On-site
... penetration testing or application security background * Strong understanding of a variety of ... Strong Web Application development, security flaw and remediation technical understanding.
Penetration Tester
Hillsboro, OR · On-site
... penetration testing or application security background * Strong understanding of a variety of ... Strong Web Application development, security flaw and remediation technical understanding.
As a Penetration Tester supporting web applications, you will work closely with clients to deliver ... Minimum of 2-3 years of work experience in application penetration testing * Familiarity with ...
As a Penetration Tester supporting web applications, you will work closely with clients to deliver ... Minimum of 2-3 years of work experience in application penetration testing * Familiarity with ...
... Web Application Penetration Tester). Location: Hybrid to Alexandria, VA Clearance: Public Trust
New
... Web Application Penetration Tester). Location: Hybrid to Alexandria, VA Clearance: Public Trust
New
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications * Perform objective based on abstract penetration ...
Web Application Penetration Tester information
See salary details
$96.5K - $102.2K
4% of jobs
$102.2K - $108K
8% of jobs
$108K - $113.7K
4% of jobs
$113.7K - $119.4K
2% of jobs
$121.8K is the 25th percentile. Wages below this are outliers.
$119.4K - $125.1K
16% of jobs
$125.1K - $130.9K
15% of jobs
The median wage is $131.2K / yr.
$130.9K - $136.6K
11% of jobs
$136.6K - $142.3K
10% of jobs
$145.3K is the 75th percentile. Wages above this are outliers.
$142.3K - $148K
10% of jobs
$148K - $153.8K
11% of jobs
$153.8K - $159.5K
10% of jobs
$96.5K
$132.3K
$159.5K
How much do web application penetration tester jobs pay per year?
What is a web application penetration tester?
What are the key skills and qualifications needed to thrive as a web application penetration tester, and why are they important?
What types of challenges might a web application penetration tester encounter when working with diverse client environments?
What is the difference between Web Application Penetration Tester vs Security Analyst?
| Aspect | Web Application Penetration Tester | Security Analyst |
|---|---|---|
| Certifications | OSCP, CEH, GPEN | CISSP, Security+ |
| Work Environment | Hands-on testing, vulnerability assessments | Monitoring, incident response, policy development |
| Industry Usage | Cybersecurity firms, tech companies, consulting | Corporate security teams, government agencies |
While both roles focus on cybersecurity, a Web Application Penetration Tester specializes in identifying vulnerabilities in web applications through active testing. In contrast, a Security Analyst monitors security systems, analyzes threats, and manages security policies. The roles often overlap in certifications and industry usage but differ in daily tasks and focus areas.
What cities are hiring for Web Application Penetration Tester jobs?
Cities with the most Web Application Penetration Tester job openings:
What states have the most Web Application Penetration Tester jobs?
States with the most job openings for Web Application Penetration Tester jobs include:
What job categories do people searching Web Application Penetration Tester jobs look for?
The top searched job categories for Web Application Penetration Tester jobs are:

Full-time
Re-posted 6 days ago
Job description
KPMG is a leading firm in the Advisory practice, offering opportunities for career advancement. They are seeking a Senior Specialist, MAST Application Penetration Tester to conduct manual penetration testing and execute threat modeling while working independently in various engagements.
Responsibilities:
• Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications
• Perform objective based on abstract penetration testing engagements
• Execute threat modeling, evaluate application business logic, and perform application architecture reviews
• Demonstrate application testing experience in real time via demos to both internal and external audiences
• Function independently in penetration testing engagements, with minimal oversight and guidance
• Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
Qualifications:
Required:
• Minimum three years of recent experience in application penetration testing of Application Programming Interface (API's), web applications, or mobile applications
• Bachelor's degree from an accredited college/university or equivalent industry experience
• Ability to communicate reporting results with technical and non-technical audiences and lead remediation conversations
• Experience with burp suite pro, and other app testing tools such as Netsparker and Checkmarx
• Ability to travel as required
• Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa)
Preferred:
• One or more major ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert (OSWE), Offensive Security Web Assessor (OSWA)
Company:
KPMG is one of the world’s leading professional services firms and the fastest growing Big Four accounting firm in the United States. Founded in 2010, the company is headquartered in New York, USA, with a team of 10001+ employees. The company is currently Late Stage.