1

Web Penetration Testing Jobs (NOW HIRING)

Penetration Tester

Leesburg, VA · On-site

$125 - $155/hr

Work closely with all members of the team to conduct penetration testing of customer networks, applications (API, web, and mobile), and/or social engineering activities to achieve the customer ...

Be Seen First

Penetration Tester

Knoxville, TN · Remote

$120K - $145K/yr

This role requires proven hands-on capability in both network and web application/API penetration testing. You'll combine manual analysis with appropriate tooling, identify and pursue viable attack ...

Lead Penetration Tester

Kansas City, MO · On-site

$110 - $150K/hr

Yes - travel to agency sites required Project Description This position leads operational security assessments and penetration testing across a portfolio of federal agencies and web applications.

Proven experience conducting penetration tests of web applications, networks, and other systems. * Experience with a variety of penetration testing tools and techniques (e.g., Rapid7 Nexpose ...

NJ · On-site

$125 - $170/hr

Practical experience delivering penetration testing or related security services. * Proficiency in web application, network/infrastructure, API, mobile, thick client, AI, and cloud penetration ...

New

Penetration Tester

Quantico, VA · On-site

$130K - $147K/yr

Penetration Testing: * Conduct penetration tests of web applications, mobile applications, networks, cloud environments, and other systems. * Utilize a variety of tools and techniques to identify ...

Web Application Testing: * Conduct security assessments of agency web applications using OWASP Top ... Penetration Testing & Exploitation Validation: * Perform controlled penetration testing (internal ...

Network penetration testing and experience working with network infrastructure * An understanding ... Experience conducting web application security assessments * Experience working with a range of ...

Be Seen First

Penetration Tester

Knoxville, TN · Remote

$120K - $145K/yr

This role requires proven hands-on capability in both network and web application/API penetration testing. You'll combine manual analysis with appropriate tooling, identify and pursue viable attack ...

Lead Penetration Tester

Washington, DC · On-site

$110 - $150K/hr

Yes - travel to agency sites required Project Description This position leads operational security assessments and penetration testing across a portfolio of federal agencies and web applications.

Penetration Tester

Rensselaer, NY · On-site

$90 - $105/hr

Key Responsibilities Penetration Testing and Vulnerability Assessment * Conduct penetration tests ... Proficiency in web application security principles, including OWASP. * Knowledge of common web ...

New

MD · On-site

Lead penetration testing engagements for web applications, external and internal networks, cloud environments, mobile applications, wireless networks, containers, and emerging technologies. * Conduct ...

$90 - $105/hr

Key Responsibilities Penetration Testing and Vulnerability Assessment * Conduct penetration tests ... Proficiency in web application security principles, including OWASP. * Knowledge of common web ...

New

Showing results 41-60

Web Penetration Testing information

See salary details

$11

$59

$86

How much do web penetration testing jobs pay per hour?

As of Aug 21, 2026, the average hourly pay for web penetration testing in the United States is $59.01, according to ZipRecruiter salary data. Most workers in this role earn between $51.20 and $66.83 per hour, depending on experience, location, and employer.

What is web penetration testing?

Web penetration testing is a security assessment process where ethical hackers simulate cyberattacks on a website or web application to identify vulnerabilities and weaknesses. The goal is to find and fix security flaws before malicious hackers can exploit them. This process involves testing for issues such as SQL injection, cross-site scripting (XSS), authentication problems, and insecure configurations. The results help organizations strengthen their web security and protect sensitive data from breaches.

What are the key skills and qualifications needed to thrive as a web penetration tester?

To excel as a Web Penetration Tester, you need a solid understanding of web application security, networking protocols, and common vulnerabilities, often supported by a degree in computer science or a related field. Familiarity with tools like Burp Suite, OWASP ZAP, Metasploit, and relevant certifications such as OSCP or CEH is typically required. Strong analytical thinking, attention to detail, and effective communication skills help testers identify risks and clearly report findings to technical and non-technical stakeholders. These competencies are crucial for uncovering security flaws, ensuring robust defenses, and helping organizations mitigate potential cyber threats.

What are some common challenges faced by web penetration testers during assessments, and how can they be addressed?

Web penetration testers often encounter challenges such as limited access to required testing environments, incomplete or outdated documentation, and rapidly evolving web technologies that demand continuous learning. Additionally, testers must balance thoroughness with time constraints and ensure clear communication with development and security teams. Addressing these challenges involves proactive coordination with stakeholders, staying updated with industry tools and vulnerabilities, and maintaining detailed, well-structured reporting to facilitate remediation and collaboration.

What is the difference between Web Penetration Testing vs Web Security Analyst?

AspectWeb Penetration TestingWeb Security Analyst
CertificationsOSCP, CEH, GPENCISSP, CISA, GIAC
Work EnvironmentHands-on testing, simulated attacksMonitoring, policy development, incident response
Employer & Industry UsageCybersecurity firms, tech companies, consultingCorporate IT, financial institutions, government agencies

Web Penetration Testing focuses on actively identifying vulnerabilities through simulated attacks, while Web Security Analysts monitor and improve security measures, analyze threats, and respond to incidents. Both roles require cybersecurity certifications but differ in their approach and daily tasks.

More about Web Penetration Testing jobs

What cities are hiring for Web Penetration Testing jobs?

Cities with the most Web Penetration Testing job openings:

What states have the most Web Penetration Testing jobs?

States with the most job openings for Web Penetration Testing jobs include:

Infographic showing various Web Penetration Testing job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 85% Full Time, 10% Part Time, 3% Contract, and 1% Nights. Highlights an 87% Physical, 3% Hybrid, and 10% Remote job distribution, with an average salary of $122,736 per year, or $59 per hour.

Penetration Tester

Fortreum

Leesburg, VA • On-site

$125 - $155/hr

Other

Medical, Dental, Vision, Life, Retirement

Posted 20 days ago


Job description

Fortreum is a trusted leader in cloud and cybersecurity services, ranked among the Top 5 FedRAMP Third Party Assessment Organizations (3PAO). With the addition of Kovr.AI, we have expanded our capabilities to include advanced cyber risk quantification and analytics, enabling organizations to better understand, measure, and communicate risk. Together, we deliver independent, third-party, vendor-agnostic regulatory assessment and advisory services, alongside advanced cybersecurity offensive and compliance technical solutions. Our comprehensive service portfolio spans regulatory compliance frameworks including FedRAMP, CMMC, FISMA, SOC, PCI, ISO, and HIPAA.

Working with Fortune 500 companies and leading cloud service providers, we’ve built our reputation on service-delivery excellence and an unwavering commitment to client success. Our continued rapid growth creates exceptional opportunities for driven professionals to make their mark in the cybersecurity industry—guided by our core values: quality above all, a customer-driven mindset, autonomy, and personal accountability.

The Opportunity

On our team, you will have the opportunity to work with the best and brightest in the field. Fortreum team members have supported the biggest cloud providers in the world, and you will have the opportunity to learn from the best. We're seeking a seasoned Penetration Tester to join our team. Your expertise in cloud penetration testing (FedRAMP and other compliance frameworks) and security best practices will be essential in helping our customers.

Key Responsibilities

This role will be responsible for conducting network, application (API, mobile, and web), and Social Engineering penetration testing. Specifically, you would:

  • Work closely with all members of the team to conduct penetration testing of customer networks, applications (API, web, and mobile), and/or social engineering activities to achieve the customer’s objectives of the engagement

  • Advise customers on details of vulnerabilities, remediation strategies, and compliance requirements

  • Prepare final deliverables for delivery to customers within established timelines

  • Establish and maintain positive relationships with customers and stakeholders

  • Coordinate project readiness with internal teams and customers

  • Pursue continuous professional development in by achieving industry specific certifications (must be willing to meet FedRAMP certification requirements as outlined by A2LA)

  • Perform project readouts with customers to notify them of the outcome of their penetration test

  • Train and mentor junior team members

  • Interface with customers and other internal delivery team members through entire engagement, interacting will all levels of customer organizations

This is a customer facing role. Travel is expected to be limited in nature; however, you may be required to travel to client locations to deliver professional services periodically when needed.

Basic Qualifications
  • Bachelor’s Degree or 4 years of equivalent job experience

  • 2+ years of professional services experience

  • 3+ years of web application and network penetration testing experience

  • Proficient in at least one or more scripting languages (i.e., bash, python, PowerShell, ruby, etc.)

  • Strong technical acumen with regards to penetration testing methodologies

  • Familiarity with best practices frameworks such as OWASP, MITRE ATT&CK, OSSTMM, and/or PTES

Preferred Skills
  • eCPPT, OSCP, OSCE, OSWE, or GPEN certifications

  • Ability to quickly assess new and leading-edge technologies and concepts

  • Ability to manage multiple priorities simultaneously

  • Proven analytical and problem-solving skills

  • Ability to develop technical content for website updates, whitepapers, and blog posts that can be used both internally and by our clients to assist them in evaluating/building out their security programs

  • Ability to develop and maintain strong relationships with team members and clients

  • Familiarity with commonly used network architecture, network devices/services, development platforms, and software suites

  • Ability to work in a team environment with compliance specialists who conduct security control assessments in parallel

  • Comfortable supporting fast-paced team environments

  • Familiarity of penetration testing in cloud environments encompassing a variety of technology stacks

Posted Salary Range

$125,000 - $155,000 annual salary

What Fortreum Offers

We offer a competitive compensation package, where you will be rewarded based on your performance/outcomes and recognized for the value you bring to our business. Our benefits package includes medical insurance, dental insurance, vision insurance, 401K plan with a 4% match, company paid short-term disability, company paid long-term disability, company paid AD&D and life insurance, flex time off, annual bonuses, training stipends, certification reimbursements, access to over 30,000 free online training courses, personal cell phone allowance, new hire and annual home office stipend, spot awards and eleven paid holidays.

An Affiant and Equal Opportunity Employer

Fortreum is an Affiant and Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability. If you’d like to view a copy of the company’s affirmative action plan or policy statement, please email hr@fortreum.com. If you have a disability and you believe you need a reasonable accommodation in order to search for a job opening or to submit an online application, please e-mail hr@fortreum.com or call 703-594-1460. This email and phone number is created exclusively to assist disabled job seekers whose disability prevents them from being able to apply online. Only messages left for this purpose will be returned. Messages left for other purposes, such as following up on an application or technical issues not related to a disability, will not receive a response.

In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.

#J-18808-Ljbffr