1

Web Penetration Tester Jobs (NOW HIRING)

Penetration Tester

Virginia, MN · On-site

$120 - $180/hr

* Work closely with all members of the team to conduct penetration testing of customer networks, applications (API, web, and mobile), and/or social engineering activities to achieve the customer ...

... web application vulnerabilities to various level of personnel within a large organization ... application penetration testing. Minimum of 5 years of demonstrated experience with automated ...

Penetration Tester

Reston, VA · On-site

$110 - $170/hr

Perform web application, network, API and AI penetration testing. * Conduct red teaming engagements and emulate attacker techniques to surface vulnerabilities. * Develop actionable recommendations to ...

Penetration Tester

Arlington, VA · On-site

$86K - $138K/yr

Responsibilities Peraton is seeking an experienced Cyber Penetration Tester to become part of ... Common web application vulnerabilities and exploits such as XSS, SQLi, LFI, file uploads, broken ...

Penetration Tester

Washington, DC · On-site

$120 - $180/hr

Identify and exploit vulnerabilities in network infrastructure, operating systems, web applications ... Document all testing activities, findings, and exploitation paths in Penetration Test Reports (PTRs)

... web application vulnerabilities to various level of personnel within a large organization ... with application penetration testing. • Minimum of 5 years of demonstrated experience with ...

Penetration Tester

Arlington, VA · On-site

$95K - $112K/yr

SkyePoint Decisions is seeking a Penetration Tester to support the Diplomatic Security Cyber ... Common web application vulnerabilities and exploits such as XSS, SQLi, LFI, file uploads, broken ...

Penetration Tester

Rensselaer, NY · On-site

$90K - $105K/yr

Key Responsibilities Penetration Testing and Vulnerability Assessment * Conduct penetration tests ... Proficiency in web application security principles, including OWASP. * Knowledge of common web ...

Penetration Tester

Chantilly, VA · On-site

$90K - $130K/yr

CDT is looking for a Penetration Tester to This will be supporting a government customer onsite in ... System methodologies including: client/server, web hosting, web content servers, policy servers ...

Responsibilities Peraton is seeking an experienced Cyber Penetration Tester to become part of ... Common web application vulnerabilities and exploits such as XSS, SQLi, LFI, file uploads, broken ...

Identify and exploit vulnerabilities in network infrastructure, operating systems, web applications ... Document all testing activities, findings, and exploitation paths in Penetration Test Reports (PTRs)

Penetration Tester

Beltsville, MD · On-site

$60 - $70/hr

Network & Web Application Testing: * Ability to identify and exploit vulnerabilities in networks ... GPEN (GIAC Penetration Tester) * CPT (Certified Penetration Tester) Soft Skills * Strong report ...

Proven experience conducting penetration tests of web applications, networks, and other systems. * Experience with a variety of penetration testing tools and techniques (e.g., Rapid7 Nexpose ...

Looking for an experienced Penetration Tester with strong skills in VAPT for Web, API, and Thick-Client applications , along with SAST/DAST expertise. The role involves performing manual and ...

Penetration Tester

Colorado Springs, CO · Hybrid

$130K - $145K/yr

Conducting web application security assessments, focusing on OWASP Top Ten vulnerabilities and API ... Engaging in wireless and RF security testing, including penetration testing on Wi-Fi, Bluetooth ...

Penetration Tester

Leesburg, VA · On-site

$125 - $155/hr

Key Responsibilities This role will be responsible for conducting network, application (API, mobile, and web), and Social Engineering penetration testing. Specifically, you would: * Work closely with ...

Penetration Tester

Colorado Springs, CO · Hybrid

$130K - $145K/yr

Conducting web application security assessments, focusing on OWASP Top Ten vulnerabilities and API ... Engaging in wireless and RF security testing, including penetration testing on Wi-Fi, Bluetooth ...

Penetration Tester

Colorado Springs, CO · On-site

$130K - $145K/yr

Conducting web application security assessments, focusing on OWASP Top Ten vulnerabilities and API ... Engaging in wireless and RF security testing, including penetration testing on Wi-Fi, Bluetooth ...

next page

Showing results 1-20

Web Penetration Tester information

See salary details

$22.5K

$119.9K

$168.5K

How much do web penetration tester jobs pay per year?

As of Aug 22, 2026, the average yearly pay for web penetration tester in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What is a web penetration tester?

A Web Penetration Tester is a cybersecurity professional who evaluates the security of web applications by simulating cyberattacks. They identify vulnerabilities, exploit weaknesses, and provide recommendations to improve security. Their goal is to protect web systems from threats like SQL injection, cross-site scripting (XSS), and authentication flaws. This role requires expertise in ethical hacking, scripting, and security tools such as Burp Suite and OWASP ZAP.

What are the key skills and qualifications needed to thrive as a web penetration tester?

To thrive as a Web Penetration Tester, you need a solid background in cybersecurity principles, web application architecture, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools like Burp Suite, OWASP ZAP, Metasploit, and relevant certifications such as OSCP or CEH are highly valued. Strong analytical thinking, effective communication, and meticulous attention to detail set candidates apart in this profession. These skills ensure that testers can identify critical security flaws while clearly conveying technical risks to both technical teams and non-technical stakeholders, effectively strengthening organizational cybersecurity.

What are some of the main challenges faced by web penetration testers in their daily work?

Web Penetration Testers often face the challenge of keeping up with rapidly evolving web technologies and an ever-changing threat landscape. They must carefully balance thorough testing with tight project deadlines, ensuring their work uncovers both common and obscure security vulnerabilities. Collaborating with development and operations teams can require clear communication to explain findings and foster a security-oriented culture. The role can also involve continual learning and adapting to new tools, methodologies, and compliance requirements.

More about Web Penetration Tester jobs

What are the most commonly searched types of Web Penetration Tester jobs?

The most popular types of Web Penetration Tester jobs are:

What states have the most Web Penetration Tester jobs?

States with the most job openings for Web Penetration Tester jobs include:

Infographic showing various Web Penetration Tester job openings in the United States as of August 2026, with employment types broken down into 1% Internship, 80% Full Time, 11% Part Time, 1% Temporary, and 7% Contract. Highlights an 82% Physical, 4% Hybrid, and 14% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

Penetration Tester

Jobtailor

Virginia, MN • On-site

$120 - $180/hr

Other

Posted 4 days ago


Job description


  • Work closely with all members of the team to conduct penetration testing of customer networks, applications (API, web, and mobile), and/or social engineering activities to achieve the customer’s objectives of the engagement.

  • Advise customers on details of vulnerabilities, remediation strategies, and compliance requirements

  • Prepare final deliverables for delivery to customers within established timelines

  • Establish and maintain positive relationships with customers and stakeholders

  • Coordinate project readiness with internal teams and customers

  • Pursue continuous professional development in by achieving industry specific certifications (must be willing to meet FedRAMP certification requirements as outlined by A2LA)

  • Perform project readouts with customers to notify them of the outcome of their penetration test

  • Train and mentor junior team members

  • Interface with customers and other internal delivery team members through entire engagement, interacting will all levels of customer organizations


Requirements

  • Bachelor’s Degree or 4 years of equivalent job experience

  • 2+ years of professional services experience

  • 3+ years of web application and network penetration testing experience

  • Proficient in at least one or more scripting languages (i.e., bash, python, PowerShell, ruby, etc.)

  • Strong technical acumen with regards to penetration testing methodologies

  • Familiarity with best practices frameworks such as OWASP, MITRE ATT&CK, OSSTMM, and/or PTES

  • Ability to work in a SCIF in Northern Virginia or Seattle, Washington

  • Active Top Secret clearance or ability to get a Top Secret clearance


Core Competencies

Demonstrates expertise in penetration testing methodologies, including web application and network testing, while effectively advising clients on vulnerabilities and compliance. Strong ability to mentor junior team members and maintain positive customer relationships throughout engagements.


Highest-signal resume keywords

  • Penetration Testing

  • Web Application Testing

  • Network Penetration Testing

  • Scripting Languages (Bash, Python, PowerShell, Ruby)

  • Top Secret Clearance


ATS Optimization Keywords
Hard Skills

  • Penetration Testing Methodologies

  • Vulnerability Assessment

  • Remediation Strategies

  • Compliance Requirements

  • Project Management


Soft Skills

  • Customer Relationship Management

  • Team Collaboration

  • Mentoring


Certifications & Qualifications

  • FedRAMP Certification


Industry Keywords

  • Professional Services

  • SCIF

  • Security Clearance


Tools & Technologies

  • OWASP

  • MITRE ATT&CK

  • OSSTMM

  • PTES

#J-18808-Ljbffr