Conduct tactical penetration testing assessments of web, mobile, and API applications against OWASP Top 10 threats and emerging risks, and collaborate with Application Security teams to provide ...
Conduct tactical penetration testing assessments of web, mobile, and API applications against OWASP Top 10 threats and emerging risks, and collaborate with Application Security teams to provide ...
Depth over volume Focus on deep, manual penetration testing (web, mobile, APIs)--not automated, scanner-driven assessments. * Accelerated technical growth Work in complex, enterprise-scale ...
Depth over volume Focus on deep, manual penetration testing (web, mobile, APIs)--not automated, scanner-driven assessments. * Accelerated technical growth Work in complex, enterprise-scale ...
Perform manual and automated penetration testing of web applications, APIs, and supporting infrastructure. * Identify, validate, and document security vulnerabilities such as those in the OWASP Top ...
Perform manual and automated penetration testing of web applications, APIs, and supporting infrastructure. * Identify, validate, and document security vulnerabilities such as those in the OWASP Top ...
Perform manual and automated penetration testing of web applications, APIs, and supporting infrastructure. * Identify, validate, and document security vulnerabilities such as those in the OWASP Top ...
Perform manual and automated penetration testing of web applications, APIs, and supporting infrastructure. * Identify, validate, and document security vulnerabilities such as those in the OWASP Top ...
Penetration Tester
$126K - $243K/yr
Penetration testing experience across at least two of the following domains: network, cloud, web application, identity, or containerized environments. * Experience operating within defined Rules of ...
Penetration Tester
$126K - $243K/yr
Penetration testing experience across at least two of the following domains: network, cloud, web application, identity, or containerized environments. * Experience operating within defined Rules of ...
Perform penetration testing of mobile (Android and iOS), API, and web applications using manual and toolassisted techniques. * Identify security vulnerabilities and, where appropriate, demonstrate ...
Perform penetration testing of mobile (Android and iOS), API, and web applications using manual and toolassisted techniques. * Identify security vulnerabilities and, where appropriate, demonstrate ...
Perform penetration testing of mobile (Android and iOS), API, and web applications using manual and tool-assisted techniques. * Identify security vulnerabilities and, where appropriate, demonstrate ...
Perform penetration testing of mobile (Android and iOS), API, and web applications using manual and tool-assisted techniques. * Identify security vulnerabilities and, where appropriate, demonstrate ...
$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
Lead Penetration Test Engineer
Dallas, TX · Hybrid
$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
Lead Penetration Test Engineer
Dallas, TX · Hybrid
$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
Lead Penetration Test Engineer
Dallas, TX · Hybrid
$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
Lead Penetration Test Engineer
Dallas, TX · Hybrid
$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
Lead Penetration Test Engineer
Houston, TX · Hybrid
$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
Lead Penetration Test Engineer
Houston, TX · Hybrid
$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
Lead Penetration Test Engineer
Houston, TX · Hybrid
$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
Lead Penetration Test Engineer
Houston, TX · Hybrid
$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
Qualifications -Min 3 years of experience penetration/vulnerability testing for web and applications in an enterprise environment -Automated and manual testing experience -Strong understanding of web ...
Qualifications -Min 3 years of experience penetration/vulnerability testing for web and applications in an enterprise environment -Automated and manual testing experience -Strong understanding of web ...
Leads and executes penetration tests across a variety of technologies, including web applications, APIs, and AI-enabled systems. Performs manual and automated testing to identify, exploit, and ...
Leads and executes penetration tests across a variety of technologies, including web applications, APIs, and AI-enabled systems. Performs manual and automated testing to identify, exploit, and ...
Application Security Testing Engineer- onsite
$58.25 - $77.75/hr
Key Responsibilities Perform hands-on web application testing and security assessments (DAST, penetration testing, WAF review) Manage vulnerability tooling and provide remediation guidance and ...
Application Security Testing Engineer- onsite
$58.25 - $77.75/hr
Key Responsibilities Perform hands-on web application testing and security assessments (DAST, penetration testing, WAF review) Manage vulnerability tooling and provide remediation guidance and ...
Associate Principal, Application Security
Dallas, TX · On-site
$58.25 - $77.75/hr
Candidate would perform Network/Application and Web Application penetration testing. Also create custom scripts and perform automation while also perform security assessments on both legacy on prem ...
Associate Principal, Application Security
Dallas, TX · On-site
$58.25 - $77.75/hr
Candidate would perform Network/Application and Web Application penetration testing. Also create custom scripts and perform automation while also perform security assessments on both legacy on prem ...
Lead Application Security Engineer
Irving, TX · On-site
$56.50 - $75.50/hr
Demonstrate proficiency in commonly used Penetration Testing Tools * Demonstrate proficiency in Web Application scanning tools * Demonstrate experience and proficiency in a Static Code Analysis Tool ...
Quick apply
Lead Application Security Engineer
Irving, TX · On-site
$56.50 - $75.50/hr
Demonstrate proficiency in commonly used Penetration Testing Tools * Demonstrate proficiency in Web Application scanning tools * Demonstrate experience and proficiency in a Static Code Analysis Tool ...
Staff Security Engineer
Dallas, TX · On-site
Demonstrated ability to perform manual penetration testing (network and web app). Proficiency in scripting (Python/Bash) to automate security tasks. Preferred : • Experience securing on-device ...
Staff Security Engineer
Dallas, TX · On-site
Demonstrated ability to perform manual penetration testing (network and web app). Proficiency in scripting (Python/Bash) to automate security tasks. Preferred : • Experience securing on-device ...
Broad expertise across Network/Application, Web Application, and Mobile Application Penetration Testing, Command and Control (C2) Infrastructure Development, Cyber Defense Evasion techniques, Social ...
Broad expertise across Network/Application, Web Application, and Mobile Application Penetration Testing, Command and Control (C2) Infrastructure Development, Cyber Defense Evasion techniques, Social ...
Web Penetration Testing information
See Texas salary details
$10.75 - $17.10
4% of jobs
$17.10 - $23.45
0% of jobs
$23.45 - $29.81
0% of jobs
$29.81 - $36.16
6% of jobs
$36.16 - $42.51
5% of jobs
$47.41 is the 25th percentile. Wages below this are outliers.
$42.51 - $48.86
12% of jobs
The median wage is $55.07 / hr.
$48.86 - $55.22
23% of jobs
$61.25 is the 75th percentile. Wages above this are outliers.
$55.22 - $61.57
26% of jobs
$61.57 - $67.92
13% of jobs
$67.92 - $74.27
3% of jobs
$74.27 - $80.62
7% of jobs
$10
$54
$80
How much do web penetration testing jobs pay per hour?
What are the key skills and qualifications needed to thrive as a Web Penetration Tester, and why are they important?
What is web penetration testing?
What are some common challenges faced by web penetration testers during assessments, and how can they be addressed?
What is the difference between Web Penetration Testing vs Web Security Analyst?
| Aspect | Web Penetration Testing | Web Security Analyst |
|---|---|---|
| Certifications | OSCP, CEH, GPEN | CISSP, CISA, GIAC |
| Work Environment | Hands-on testing, simulated attacks | Monitoring, policy development, incident response |
| Employer & Industry Usage | Cybersecurity firms, tech companies, consulting | Corporate IT, financial institutions, government agencies |
Web Penetration Testing focuses on actively identifying vulnerabilities through simulated attacks, while Web Security Analysts monitor and improve security measures, analyze threats, and respond to incidents. Both roles require cybersecurity certifications but differ in their approach and daily tasks.
- Temporary Vulnerability Assessment Penetration Testing
- Internship Web Penetration Tester
- Associate Application Penetration Tester
- Junior Vulnerability Assessment Penetration Testing
- Full Time Vulnerability Analyst
- Seasonal Cloud Penetration Tester
- Web Penetration Tester
- Att Cybersecurity
- Junior Penetration Tester
- Penetration Tester Part Time

Full-time
Medical, Retirement, PTO
Re-posted 23 days ago
LPL Financial rating
7.5
Based on 69 frontline employees who took The Breakroom Quiz
116th of 150 rated financial services
Job description
Where Ambition Meets Innovation
Build a career that matches all your initiative with an impressive dose of innovation. From cutting-edge resources and a collaborative environment to the freedom to make an impact and more, you'll find the ingredients you need at LPL Financial to shape your success while helping clients pursue their financial goals.
At LPL Financial, protecting our clients, advisors, and employees is foundational to everything we do. Offensive Security is a top area of investment within Information Security, and this role offers the opportunity to directly influence the security posture of a large, complex enterprise. If you enjoy handson technical work, collaborating across teams, and creatively testing the limits of modern systems, this is an exciting opportunity to help evolve LPL's offensive security capabilities.
Job Overview
As a member of the Cyber Security team, the Senior Penetration Tester, Offensive Security, is responsible for the scheduling, scoping, and execution of internal penetration testing, with a primary focus on web, mobile, cloud, API, and AIenabled applications.
This individual contributor role performs advanced manual penetration testing to validate the security of company resources. The position serves as the primary point of contact for assigned testing initiatives and partners closely with stakeholders across the organization to identify security weaknesses, recommend mitigation strategies, and validate remediation efforts across LPL applications and platforms.
Responsibilities
Partner with product and technology stakeholders to drive endtoend penetration testing activities, including collaboration with Security Architects throughout the SDLC to identify and address security issues prior to production deployment
Conduct tactical penetration testing assessments of web, mobile, and API applications against OWASP Top 10 threats and emerging risks, and collaborate with Application Security teams to provide actionable feedback and recommendations, including opportunities to expand automated and AIassisted testing capabilities
Perform security assessments of internal and external networks, infrastructure, cloud environments, and a wide range of internally developed and commercial products
Apply creative and analytical thinking to bypass security controls, identify vulnerabilities, and develop practical remediation guidance; stay informed on evolving tactics, techniques, and procedures (TTPs), zeroday vulnerabilities, and mitigation strategies
Develop or modify custom tools and scripts to support new penetration testing needs, automation, and AIassisted testing approaches
Document and formally report testing scope, methodology, findings, risk ratings, remediation recommendations, and validation results in a clear and concise manner
Present testing results to technology and business partners, clearly communicating risk, impact, and remediation guidance in an accessible and collaborative way
Lead execution of assigned penetration testing initiatives, including status communication to leadership and coordination with stakeholders
Oversee communication, tracking, and retesting of findings to validate successful closure of previously identified issues
Assist with validation and triage of submissions from the company's Vulnerability Disclosure Program and Bug Bounty programs
What are we looking for?
We are seeking collaborative professionals who enjoy handson technical work and take pride in delivering a highquality internal client experience. This role is well suited for individuals who thrive in a fastpaced environment, enjoy solving complex security challenges, and continuously look for ways to improve processes, tooling, and outcomes.
Requirements
8+ years of experience conducting application, API, and networkbased penetration testing engagements
6+ years of experience troubleshooting tools, manually identifying vulnerabilities in code, and rewriting code to remediate security issues
3+ years of experience leading penetration testing engagements from scoping through reporting and remediation validation
1+ year of experience testing AI, LLM, or Generative AIenabled applications
1+ year of experience using AI models (such as Claude or similar) to accelerate tool development or testing workflows + Advanced knowledge of security assessment tools and frameworks, such as Burp Suite, Kali Linux, Nessus, Accunetix, Metasploit, AutoSploit, Cobalt Strike, MITRE ATT&CK, MITRE ATLAS, OWASP Top 10 (including OWASP Top 10 for LLMs)
Preferences
Bachelor's degree or equivalent experience in Information Security, Engineering, Computer Science, or a related field
Advanced understanding of OWASP frameworks, MITRE ATT&CK and ATLAS, and secure software development lifecycle (SDLC) practices
At least one industryrecognized certification, such as OSCP, OSCE, OSWE, GPEN, GCIH, GWAPT, or GXPN
Advanced proficiency in one or more programming or scripting languages, such as .NET, JavaScript, Python, Java, PowerShell, Perl, Ruby, Bash, or similar
Advanced knowledge of Linux, macOS, and Windows operating systems, as well as AWS and Azure cloud environments and cloudnative services (e.g., containers, Kubernetes, microservices, serverless functions)
Experience performing reverse engineering on mobile applications, including those with obfuscation or antiemulation protections
Broad knowledge of operating system security, networking and protocols, firewalls, databases, middleware, forensics, and secure coding practices
Effective written and verbal communication skills, with the ability to collaborate with technical and nontechnical stakeholders
Organized approach to managing multiple testing efforts and deliverables
A natural curiosity for exploring, testing, and understanding security controls and how they can be improved
Pay Range:
$122,570.00 - $204,249.00Actual base salary varies based on factors, including but not limited to, relevant skill, prior experience, education, base salary of internal peers, demonstrated performance, and geographic location. Additionally, LPL Total Rewards package is highly competitive, designed to support your success at work, at home, and at play - such as 401K matching, health benefits, employee stock options, paid time off, volunteer time off, and more. Your recruiter will be happy to discuss all that LPL has to offer!
Company Overview:
LPL Financial Holdings Inc. (Nasdaq: LPLA) is among the fastest growing wealth management firms in the U.S. As a leader in the financial advisor-mediated marketplace(6) , LPL supports over 32,000 financial advisors and the wealth management practices of approximately 1,100 financial institutions, servicing and custodying approximately $2.3 trillion in brokerage and advisory assets on behalf of approximately 8 million Americans. The firm provides a wide range of advisor affiliation models, investment solutions, fintech tools and practice management services, ensuring that advisors and institutions have the flexibility to choose the business model, services, and technology resources they need to run thriving businesses. For further information about LPL, please visit www.lpl.com.
At LPL, independence means that advisors and institution leaders have the freedom they deserve to choose the business model, services, and technology resources that allow them to run a thriving business. They have the flexibility to do business their way. And they have the freedom to manage their client relationships, because they know their clients best. Simply put, we take care of our advisors and institutions, so they can take care of their clients.
For further information about LPL, please visit www.lpl.com.
Join the LPL team and help us make a difference by turning life's aspirations into financial realities. Please log in or create an account to apply to this position. Principals only. EOE.
Information on Interviews:
LPL will only communicate with a job applicant directly from an@lplfinancial.comemail address and will never conduct an interview online or in a chatroom forum. During an interview, LPL will not request any form of payment from the applicant, or information regarding an applicant's bank or credit card. Should you have any questions regarding the application process, please contact LPL's Human Resources Solutions Center at(855) 575-6947.
EAC 5.19.26
What LPL Financial employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About LPL Financial
Sourced by ZipRecruiter
Industry
Finance and insurance
Company size
1,001 - 5,000 Employees
Headquarters location
San Diego, CA, US
Year founded
1989