1

Web Penetration Testing Jobs in Chicago, IL (NOW HIRING)

Perform hands-on penetration testing with a primary focus on web applications and web APIs across homegrown and vendor systems, support testing of cloud, mobile, and internal systems. * Conduct ...

The Senior Cyber Security Penetration Tester performs offensive security testing for BDO clients ... Performs and reviews web and API security testing using Burp Suite and related techniques, focusing ...

The Senior Cyber Security Penetration Tester performs offensive security testing for BDO clients ... Performs and reviews web and API security testing using Burp Suite and related techniques, focusing ...

Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.

Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.

Conduct web application penetration testing (covering OWASP Top 10, API security, authentication/authorization flaws, business logic vulnerabilities, and modern web frameworks). * Perform mobile ...

Senior Penetration Tester

Northbrook, IL · Hybrid

$110K - $140K/yr

As a Senior Penetration Tester, you will lead technical engagements responsible for evaluating and ... testing the security of embedded systems, cloud environments, web applications and mobile ...

Senior Penetration Tester

Northbrook, IL · Hybrid

$110K - $140K/yr

As a Senior Penetration Tester, you will lead technical engagements responsible for evaluating and ... testing the security of embedded systems, cloud environments, web applications and mobile ...

Senior Offensive Security Engineer

Naperville, IL · On-site

$114K - $156K/yr

One practical offensive security certification such as OSCP, GPEN, GWAPT, GWEB, PNPT, or similar hands-on application, web, cloud, or penetration testing certification. * Experience testing ...

Senior Offensive Security Engineer

Naperville, IL · On-site

$114K - $156K/yr

One practical offensive security certification such as OSCP, GPEN, GWAPT, GWEB, PNPT, or similar hands-on application, web, cloud, or penetration testing certification. * Experience testing ...

Practical offensive security certifications such as OSCP, GPEN, GWAPT, GWEB, PNPT, or similar hands-on application, web, cloud, or penetration testing certifications. * Experience testing commercial ...

Practical offensive security certifications such as OSCP, GPEN, GWAPT, GWEB, PNPT, or similar hands-on application, web, cloud, or penetration testing certifications. * Experience testing commercial ...

Tempus is seeking a Senior Application Security Engineer with deep expertise in penetration testing to lead efforts in identifying and remediating vulnerabilities across web, mobile, and medical ...

next page

Showing results 1-20

Web Penetration Testing information

See Chicago, IL salary details

$11

$60

$89

How much do web penetration testing jobs pay per hour?

As of Sep 1, 2026, the average hourly pay for web penetration testing in Chicago, IL is $60.83, according to ZipRecruiter salary data. Most workers in this role earn between $52.79 and $68.89 per hour, depending on experience, location, and employer.

What is web penetration testing?

Web penetration testing is a security assessment process where ethical hackers simulate cyberattacks on a website or web application to identify vulnerabilities and weaknesses. The goal is to find and fix security flaws before malicious hackers can exploit them. This process involves testing for issues such as SQL injection, cross-site scripting (XSS), authentication problems, and insecure configurations. The results help organizations strengthen their web security and protect sensitive data from breaches.

What are the key skills and qualifications needed to thrive as a web penetration tester?

To excel as a Web Penetration Tester, you need a solid understanding of web application security, networking protocols, and common vulnerabilities, often supported by a degree in computer science or a related field. Familiarity with tools like Burp Suite, OWASP ZAP, Metasploit, and relevant certifications such as OSCP or CEH is typically required. Strong analytical thinking, attention to detail, and effective communication skills help testers identify risks and clearly report findings to technical and non-technical stakeholders. These competencies are crucial for uncovering security flaws, ensuring robust defenses, and helping organizations mitigate potential cyber threats.

What are some common challenges faced by web penetration testers during assessments, and how can they be addressed?

Web penetration testers often encounter challenges such as limited access to required testing environments, incomplete or outdated documentation, and rapidly evolving web technologies that demand continuous learning. Additionally, testers must balance thoroughness with time constraints and ensure clear communication with development and security teams. Addressing these challenges involves proactive coordination with stakeholders, staying updated with industry tools and vulnerabilities, and maintaining detailed, well-structured reporting to facilitate remediation and collaboration.

What is the difference between Web Penetration Testing vs Web Security Analyst?

AspectWeb Penetration TestingWeb Security Analyst
CertificationsOSCP, CEH, GPENCISSP, CISA, GIAC
Work EnvironmentHands-on testing, simulated attacksMonitoring, policy development, incident response
Employer & Industry UsageCybersecurity firms, tech companies, consultingCorporate IT, financial institutions, government agencies

Web Penetration Testing focuses on actively identifying vulnerabilities through simulated attacks, while Web Security Analysts monitor and improve security measures, analyze threats, and respond to incidents. Both roles require cybersecurity certifications but differ in their approach and daily tasks.

What are popular job titles related to Web Penetration Testing jobs in Chicago, IL?

For Web Penetration Testing jobs in Chicago, IL, the most frequently searched job titles are:

What job categories do people searching Web Penetration Testing jobs in Chicago, IL look for?

The top searched job categories for Web Penetration Testing jobs in Chicago, IL are:

Infographic showing various Web Penetration Testing job openings in Chicago, IL as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 11% Part Time, 3% Contract, and 1% Nights. Highlights an 88% Physical, 3% Hybrid, and 9% Remote job distribution, with an average salary of $126,535 per year, or $60.8 per hour.

Senior Specialist, MAST Application Penetration Tester

Chicago, IL • On-site

Full-time

Re-posted 2 days ago


Job description

Job Summary:
KPMG is a leading advisory firm that offers excellent opportunities for career advancement. They are currently seeking a Senior Specialist, MAST Application Penetration Tester to conduct manual penetration testing and evaluate application security across various platforms.
Responsibilities:
• Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications
• Perform objective based on abstract penetration testing engagements
• Execute threat modeling, evaluate application business logic, and perform application architecture reviews
• Demonstrate application testing experience in real time via demos to both internal and external audiences
• Function independently in penetration testing engagements, with minimal oversight and guidance
• Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
Qualifications:
Required:
• Minimum three years of recent experience in application penetration testing of Application Programming Interface (API's), web applications, or mobile applications
• Bachelor's degree from an accredited college/university or equivalent industry experience
• Ability to communicate reporting results with technical and non-technical audiences and lead remediation conversations
• Experience with burp suite pro, and other app testing tools such as Netsparker and Checkmarx
• Ability to travel as required
• Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa)
Preferred:
• One or more major ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert (OSWE), Offensive Security Web Assessor (OSWA)
Company:
KPMG is one of the world’s leading professional services firms and the fastest growing Big Four accounting firm in the United States. Founded in 2010, the company is headquartered in New York, USA, with a team of 10001+ employees. The company is currently Late Stage.