1

Web Penetration Testing Jobs in Ohio (NOW HIRING)

Senior Cybersecurity Engineer

Columbus, OH · On-site

$110K - $151K/yr

Run automated penetration testing and attack path analysis (NodeZero); validate findings and drive remediation across web apps, APIs, cloud, and internal/external infrastructure * Administer Zscaler ...

New

Web Penetration Testing information

See Ohio salary details

$10

$56

$82

How much do web penetration testing jobs pay per hour?

As of Aug 1, 2026, the average hourly pay for web penetration testing in Ohio is $56.10, according to ZipRecruiter salary data. Most workers in this role earn between $48.65 and $63.51 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Web Penetration Tester, and why are they important?

To excel as a Web Penetration Tester, you need a solid understanding of web application security, networking protocols, and common vulnerabilities, often supported by a degree in computer science or a related field. Familiarity with tools like Burp Suite, OWASP ZAP, Metasploit, and relevant certifications such as OSCP or CEH is typically required. Strong analytical thinking, attention to detail, and effective communication skills help testers identify risks and clearly report findings to technical and non-technical stakeholders. These competencies are crucial for uncovering security flaws, ensuring robust defenses, and helping organizations mitigate potential cyber threats.

What is web penetration testing?

Web penetration testing is a security assessment process where ethical hackers simulate cyberattacks on a website or web application to identify vulnerabilities and weaknesses. The goal is to find and fix security flaws before malicious hackers can exploit them. This process involves testing for issues such as SQL injection, cross-site scripting (XSS), authentication problems, and insecure configurations. The results help organizations strengthen their web security and protect sensitive data from breaches.

What are some common challenges faced by web penetration testers during assessments, and how can they be addressed?

Web penetration testers often encounter challenges such as limited access to required testing environments, incomplete or outdated documentation, and rapidly evolving web technologies that demand continuous learning. Additionally, testers must balance thoroughness with time constraints and ensure clear communication with development and security teams. Addressing these challenges involves proactive coordination with stakeholders, staying updated with industry tools and vulnerabilities, and maintaining detailed, well-structured reporting to facilitate remediation and collaboration.

What is the difference between Web Penetration Testing vs Web Security Analyst?

AspectWeb Penetration TestingWeb Security Analyst
CertificationsOSCP, CEH, GPENCISSP, CISA, GIAC
Work EnvironmentHands-on testing, simulated attacksMonitoring, policy development, incident response
Employer & Industry UsageCybersecurity firms, tech companies, consultingCorporate IT, financial institutions, government agencies

Web Penetration Testing focuses on actively identifying vulnerabilities through simulated attacks, while Web Security Analysts monitor and improve security measures, analyze threats, and respond to incidents. Both roles require cybersecurity certifications but differ in their approach and daily tasks.

What cities in Ohio are hiring for Web Penetration Testing jobs? Cities in Ohio with the most Web Penetration Testing job openings:
Infographic showing various Web Penetration Testing job openings in Ohio as of July 2026, with employment types broken down into 1% Locum Tenens, 91% Full Time, 5% Part Time, 2% Contract, and 1% Summer. Highlights an 86% Physical, 3% Hybrid, and 11% Remote job distribution, with an average salary of $116,684 per year, or $56.1 per hour.

Application & Cloud Security Specialist

Keybank

Brooklyn, OH • Remote

$69K - $105K/yr

Full-time

This job post has expired today. Applications are no longer accepted.


KeyBank rating

8.2

Company rating: 8.2 out of 10

Based on 99 frontline employees who took The Breakroom Quiz

52nd of 170 rated banks


Job description

Location:

4910 Tiedeman Road, Brooklyn Ohio

Our Cyber Application & Cloud Defense team operates within Key's broader Cyber Defense function in Corporate Information Security. Our mission is to enable secure software delivery and resilient cloud environments by proactively identifying, assessing, and reducing application and cloud security risks.

The Application & Cloud Security Specialist is responsible for performing application security assessments and cloud security reviews across modern development and cloud-native environments. This role combines hands-on manual penetration testing with the use of SAST, SCA, and DAST tools, as well as cloud security posture evaluation through CSPM capabilities.

You will work closely with development, DevOps, and cloud engineering teams to integrate security into CI/CD pipelines and improve secure coding practices. This role requires strong technical depth, development experience, and proficiency with command-line tools.

The ideal candidate is hands-on, execution-focused, and comfortable leveraging modern tooling-including AI-powered development and security assistants-to improve productivity, testing depth, and vulnerability detection.

Key Responsibilities
  • Perform manual application security testing and penetration testing of web applications, APIs, and services.
  • Review and validate findings from SAST, SCA, and DAST tools, including triage and false positive reduction.
  • Conduct API security and dynamic testing to identify vulnerabilities and misconfigurations.
  • Assess open-source dependencies and third-party libraries for vulnerabilities and supply chain risk.
  • Evaluate cloud environments (GCP, Azure, AWS) for misconfigurations, excessive permissions, and exposure risks in support of the CSPM program.
  • Implement and maintain CI/CD security integrations, including scanning tools and automation workflows.
  • Develop scripts and CLI-based tooling to support scalable security testing and validation activities.
  • Partner with development teams to remediate vulnerabilities and improve secure coding practices.
  • Participate in architecture and design reviews, providing actionable security recommendations.
  • Utilize AI tools and coding assistants to enhance productivity, automate analysis, and improve testing efficiency while maintaining secure and responsible usage practices.
  • Track and report vulnerabilities, remediation progress, and security metrics.
Required Qualifications
  • Bachelor of Computer Science, Cybersecurity, or related field-or equivalent experience.
  • 4+ years of experience in application security, penetration testing, or secure software development.
  • Hands-on experience with:
    • Manual application security testing (web/API)
    • SAST, SCA, DAST tools
    • Common vulnerabilities (OWASP Top 10, API risks)
  • Experience with at least one cloud platform (Google Cloud, Microsoft Azure, or AWS).
  • Strong programming/scripting experience (Python, Java, JavaScript, Bash, PowerShell, or similar).
  • Proficiency working in command-line environments (Linux/Unix).
  • Familiarity with CI/CD pipelines and DevSecOps practices.
  • Experience or comfort using AI-enabled tools and coding assistants (e.g., for code analysis, automation, or testing support).
Preferred Qualifications / Certifications
  • Experience with AppSec tools (e.g., Snyk, Burp Suite, API security tools).
  • Familiarity with containers, Kubernetes, and cloud-native architectures.
  • Exposure to IaC security practices.
  • Certifications such as:
    • GIAC Web Application Penetration Tester (GWAPT)
    • Offensive Security Web Expert (OSWE)
    • Cloud security certifications (AWS/Azure/GCP)

COMPENSATION AND BENEFITS

This position is eligible to earn a base salary in the range of $69,000.00 - $105,000.00 annually. Placement within the pay range may differ based upon various factors, including but not limited to skills, experience and geographic location. Compensation for this role also includes eligibility for incentive compensation which may include production, commission, and/or discretionary incentives.

Please click here for a list of benefits for which this position is eligible.

Key has implemented an approach to employee workspaces which prioritizes in-office presence, while providing flexible options in circumstances where roles can be performed effectively in a mobile environment.

Job Posting Expiration Date: 08/21/2026 KeyCorp is an Equal Opportunity Employer committed to sustaining an inclusive culture. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, genetic information, pregnancy, disability, veteran status or any other characteristic protected by law.

Qualified individuals with disabilities or disabled veterans who are unable or limited in their ability to apply on this site may request reasonable accommodations by emailing HR_Compliance@keybank.com.

#LI-Remote

What KeyBank employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


KeyBank logo

About KeyBank

Sourced by ZipRecruiter

Key is one of the nation's largest bank-based financial services companies. Key provides deposit, lending, cash management, insurance, and investment services to individuals and businesses in 15 states under the name KeyBank National Association through a network of more than 1,200 branches and more than 1,500 ATMs. Key also provides a broad range of sophisticated corporate and investment banking products, such as merger and acquisition advice, public and private debt and equity, syndications, and derivatives to middle market companies in selected industries throughout the United States under the KeyBanc Capital Markets trade name.

Industry

Banking and credit intermediation

Company size

10,000+ Employees

Headquarters location

Cleveland, OH, US

Year founded

1849