1

Web Penetration Testing Jobs in Massachusetts (NOW HIRING)

Hands-on experience performing penetration testing of web applications, systems, networks, cloud environments, or APIs. * Familiarity with common offensive security tools, techniques, and ...

Senior Security Engineer

Boston, MA

$124K - $170K/yr

Hands-on experience performing penetration testing of web applications, systems, networks, cloud environments, or APIs. * Familiarity with common offensive security tools, techniques, and ...

... networks, web applications, and infrastructure, LLM-driven planning loops that reason through ... This is the emerging class of LLM-driven penetration-testing agents, built for production use by a ...

... networks, web applications, and infrastructure, LLM-driven planning loops that reason through ... This is the emerging class of LLM-driven penetration-testing agents, built for production use by a ...

... networks, web applications, and infrastructure, LLM-driven planning loops that reason through ... This is the emerging class of LLM-driven penetration-testing agents, built for production use by a ...

Offensive Security Manager

Boston, MA

$120K - $163K/yr

Web application penetration testing * Wireless penetration testing * Social engineering (phishing, telephone, onsite) * Red teaming/Threat emulation * Purple teaming * Evaluate and test IT controls, ...

New

... penetration testing, product assessments, vulnerability research, reverse engineering, and related pursuits. • 3+ years of software development experience. • Deep understanding of web browsers (i ...

Perform regular security assessments, dependency audits, and penetration testing. * Support ... Hands-on experience securing production web applications, preferably in Node.js/Next.js ...

Run penetration tests. Network, web-application, cloud, and infrastructure testing, recon through exploitation, privilege escalation, and lateral movement, accelerated by the tooling you build, with ...

next page

Showing results 1-20

Web Penetration Testing information

See Massachusetts salary details

$12

$64

$94

How much do web penetration testing jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for web penetration testing in Massachusetts is $64.44, according to ZipRecruiter salary data. Most workers in this role earn between $55.91 and $72.98 per hour, depending on experience, location, and employer.

What is web penetration testing?

Web penetration testing is a security assessment process where ethical hackers simulate cyberattacks on a website or web application to identify vulnerabilities and weaknesses. The goal is to find and fix security flaws before malicious hackers can exploit them. This process involves testing for issues such as SQL injection, cross-site scripting (XSS), authentication problems, and insecure configurations. The results help organizations strengthen their web security and protect sensitive data from breaches.

What are the key skills and qualifications needed to thrive as a web penetration tester?

To excel as a Web Penetration Tester, you need a solid understanding of web application security, networking protocols, and common vulnerabilities, often supported by a degree in computer science or a related field. Familiarity with tools like Burp Suite, OWASP ZAP, Metasploit, and relevant certifications such as OSCP or CEH is typically required. Strong analytical thinking, attention to detail, and effective communication skills help testers identify risks and clearly report findings to technical and non-technical stakeholders. These competencies are crucial for uncovering security flaws, ensuring robust defenses, and helping organizations mitigate potential cyber threats.

What are some common challenges faced by web penetration testers during assessments, and how can they be addressed?

Web penetration testers often encounter challenges such as limited access to required testing environments, incomplete or outdated documentation, and rapidly evolving web technologies that demand continuous learning. Additionally, testers must balance thoroughness with time constraints and ensure clear communication with development and security teams. Addressing these challenges involves proactive coordination with stakeholders, staying updated with industry tools and vulnerabilities, and maintaining detailed, well-structured reporting to facilitate remediation and collaboration.

What is the difference between Web Penetration Testing vs Web Security Analyst?

AspectWeb Penetration TestingWeb Security Analyst
CertificationsOSCP, CEH, GPENCISSP, CISA, GIAC
Work EnvironmentHands-on testing, simulated attacksMonitoring, policy development, incident response
Employer & Industry UsageCybersecurity firms, tech companies, consultingCorporate IT, financial institutions, government agencies

Web Penetration Testing focuses on actively identifying vulnerabilities through simulated attacks, while Web Security Analysts monitor and improve security measures, analyze threats, and respond to incidents. Both roles require cybersecurity certifications but differ in their approach and daily tasks.

What job categories do people searching Web Penetration Testing jobs in Massachusetts look for?

The top searched job categories for Web Penetration Testing jobs in Massachusetts are:

What cities in Massachusetts are hiring for Web Penetration Testing jobs?

Cities in Massachusetts with the most Web Penetration Testing job openings:

Infographic showing various Web Penetration Testing job openings in Massachusetts as of August 2026, with employment types broken down into 1% As Needed, 88% Full Time, 8% Part Time, 2% Contract, and 1% Nights. Highlights an 87% Physical, 3% Hybrid, and 10% Remote job distribution, with an average salary of $134,042 per year, or $64.4 per hour.

Senior Security Engineer

Harvard University

Boston, MA • On-site

$59/hr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 24 days ago


Harvard University rating

8.5

Company rating: 8.5 out of 10

Based on 12 frontline employees who took The Breakroom Quiz

81st of 620 rated colleges and universities


Job description

Company Description
By working at Harvard University, you join a vibrant community that advances Harvard's world-changing mission in meaningful ways, inspires innovation and collaboration, and builds skills and expertise. We are dedicated to creating a diverse and welcoming environment where everyone can thrive.
Why join Harvard Medical School?
Harvard Medical School's mission is to nurture a diverse, inclusive community dedicated to alleviating suffering and improving health and well-being for all through excellence in teaching and learning, discovery and scholarship, and service and leadership.
You'll be at the heart of biomedical discovery, education, and innovation, working alongside world-renowned faculty and a community dedicated to improving human health. This is more than a job - it's an opportunity to shape the future of medicine.
Job Description
The Senior Security Engineer will have responsibility for supporting and advancing Harvard Medical School's application security, Secure SDLC, and penetration testing programs. This role will partner closely with others across HMS IT and Security to enable the HMS mission by implementing Secure SDLC practices, operating application security testing platforms, identifying security weaknesses through penetration testing, and collaborating with development teams to improve security throughout the software lifecycle. On a daily basis, this role will perform penetration testing of applications, systems, and emerging technologies; support the administration of application security platforms; conduct threat research; identify security risks and remediation opportunities; and help mature the organization's application security capabilities. This role will partner with SecOps when required during security incidents and investigations. The Senior Security Engineer, as part of the IT Security team, will partner with others across Security and IT to establish strategic and tactical roadmaps and help mature application and offensive security capabilities.
Principal duties and responsibilities:
  • Perform penetration testing of applications, systems, infrastructure, cloud environments, and emerging technologies.
  • Identify security weaknesses and provide remediation recommendations through technical testing.
  • Support Secure SDLC initiatives and collaborate with development teams to improve application security.
  • Administer and support application security platforms and testing tools.
  • Assist with implementation and operation of SAST, SCA, DAST, API Security, Secrets Detection, and related application security capabilities.
  • Conduct threat research and stay current on emerging attack techniques, vulnerabilities, adversary activity, and security trends.
  • Inform the organization of emerging threats, attack techniques, vulnerabilities, and risks.
  • Serve as an information security subject matter expert in penetration testing and application security.
  • Research, evaluate, and recommend new security tools, technologies, and processes that improve HMS security capabilities.
  • Abide by and follow Harvard University IT technical standards, policies, and Code of Conduct.

Qualifications
Basic Qualifications:
  • Minimum of seven years' post-secondary education or relevant work experience.

Additional Qualifications and Skills:
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field; or equivalent combination of education and relevant experience.
  • Experience using common security testing and analysis tools.
  • Ability to communicate technical security findings and remediation recommendations to both technical and non-technical audiences.
  • Hands-on experience performing penetration testing of web applications, systems, networks, cloud environments, or APIs.
  • Familiarity with common offensive security tools, techniques, and methodologies.
  • Experience identifying, validating, and helping remediate common web application vulnerabilities (OWASP Top 10).
  • Experience with Secure SDLC concepts and application security testing tools such as Checkmarx, Burp Suite, Veracode, GitHub Advanced Security, or similar platforms.
  • Experience administering or supporting application security platforms preferred.
  • Familiarity with software development practices and modern application architectures.
  • Experience conducting threat research and analyzing emerging threats, vulnerabilities, attack techniques, and adversary activity.
  • Experience creating technical reports and communicating security findings and remediation recommendations.
  • Participation in cyber competitions (CTFs), cyber ranges, security research projects, bug bounty programs, red team exercises, or similar activities is highly desirable.
  • Demonstrated analytical, problem-solving, and technical investigation skills.
  • Demonstrated team performance skills, service-oriented mindset, and ability to collaborate effectively with technical and non-technical stakeholders.
  • Strong desire to continuously learn and develop expertise in offensive security, application security, and emerging technologies.

Certificates and Licenses:
  • Completion of Harvard IT Academy Information Security Foundations course (or external equivalent) preferred.
  • IT Security Certification preferred; e.g., OSCP, CSSLP, GIAC GWAPT, CISSP, PenTest+

Additional Information
  • Standard Hours/Schedule: 35 hours per week
  • Visa Sponsorship Information: Harvard University is unable to provide visa sponsorship for this position.
  • Pre-Employment Screening: Identity, Criminal
  • Staying Informed About Your Application: Due to the high volume of applications, we may not always be able to reach out right away, but you can track your status anytime through the Careers@Harvard portal.

#LI-DK1
Work Format Details
This position has been determined by school or unit leaders that some of the duties and responsibilities can be effectively performed at a non-Harvard location. The work schedule and location will be set by the department at its discretion and based upon operational needs. When not working at a Harvard or Harvard-designated location, employees in hybrid positions must work in a Harvard registered state in compliance with the University's Policy on Employment Outside of Massachusetts. Additional details will be discussed during the interview process. Certain visa types and funding sources may limit work location. Individuals must meet work location sponsorship requirements prior to employment.
Salary Grade and Ranges
This position is salary grade level 059. Please visit Harvard's Salary Ranges to view the corresponding salary range and related information.
Benefits
Harvard offers a comprehensive benefits package that is designed to support a healthy work-life balance and your physical, mental and financial wellbeing. Because here, you are what matters. Our benefits include, but are not limited to:
  • Generous paid time off including parental leave
  • Medical, dental, and vision health insurance coverage starting on day one
  • Retirement plans with university contributions
  • Wellbeing and mental health resources
  • Support for families and caregivers
  • Professional development opportunities including tuition assistance and reimbursement
  • Commuter benefits, discounts and campus perks

Learn more about these and additional benefits on our Benefits & Wellbeing Page.
EEO/Non-Discrimination Commitment Statement
Harvard University is committed to equal opportunity and non-discrimination. We seek talent from all parts of society and the world, and we strive to ensure everyone at Harvard thrives. Our differences help our community advance Harvard's academic purposes.
Harvard has an equal employment opportunity policy that outlines our commitment to prohibiting discrimination on the basis of race, ethnicity, color, national origin, sex, sexual orientation, gender identity, veteran status, religion, disability, or any other characteristic protected by law or identified in the university's non-discrimination policy. Harvard's equal employment opportunity policy and non-discrimination policy help all community members participate fully in work and campus life free from harassment and discrimination.

What Harvard University employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom