1

Web Pentester Jobs (NOW HIRING)

... Set - Red team pentester * Network penetration testing and experience working with network ... Experience conducting web application security assessments * Experience working with a range of ...

Senior pentester

Naples, NC · On-site +1

$94K - $111K/yr

Web Application Security Analysis and Intrusion Testing * Vulnerability Management WHAT DO WE OFFER? * Join our team and culture GMV by entering into technological and innovative projects within ...

Senior Manual Ethical Hacker

Denver, CO · On-site

$109K - $148K/yr

... Web APIs, Cloud environments, LLM security, Mobile application analysis • Able to manually ... Pentester Academy] • Strong programming/scripting skills • Frida • Binary analysis ...

Senior Manual Ethical Hacker

Charlotte, NC

$97K - $126K/yr

Web APIs * Cloud environments * LLM security * Mobile application analysis * Able to manually ... Pentester Academy] * Strong programming/scripting skills * Frida * Binary analysis (disassembly ...

Senior Manual Ethical Hacker

Chicago, IL · On-site

$103K - $132K/yr

Web APIs * Cloud environments * LLM security * Mobile application analysis * Able to manually ... Pentester Academy] * Strong programming/scripting skills * Frida * Binary analysis (disassembly ...

Senior Manual Ethical Hacker

Boston, MA · On-site

$108K - $140K/yr

Web APIs * Cloud environments * LLM security * Mobile application analysis * Able to manually ... Pentester Academy] * Strong programming/scripting skills * Frida * Binary analysis (disassembly ...

Senior Manual Ethical Hacker

Chicago, IL

$103K - $132K/yr

Web APIs * Cloud environments * LLM security * Mobile application analysis * Able to manually ... Pentester Academy] * Strong programming/scripting skills * Frida * Binary analysis (disassembly ...

Senior Manual Ethical Hacker

Jacksonville, FL · On-site

$92K - $119K/yr

Web APIs * Cloud environments * LLM security * Mobile application analysis * Able to manually ... Pentester Academy] * Strong programming/scripting skills * Frida * Binary analysis (disassembly ...

next page

Showing results 1-20

Web Pentester information

See salary details

$39K

$80.9K

$144K

How much do web pentester jobs pay per year?

As of Jul 22, 2026, the average yearly pay for web pentester in the United States is $80,851.00, according to ZipRecruiter salary data. Most workers in this role earn between $55,000.00 and $94,500.00 per year, depending on experience, location, and employer.

What is the difference between Web Pentester vs Penetration Tester?

AspectWeb PentesterPenetration Tester
CertificationsCEH, OSCP, GPENCEH, OSCP, GPEN
Work EnvironmentFocus on web applications and APIsBroader scope including networks, systems, and applications
Industry UsagePrimarily in cybersecurity firms, tech companies, and consultingIn various sectors including finance, government, and tech
Search & Comparison IntentSpecific to web security testingGeneral security testing across multiple domains

Web Pentesters specialize in testing the security of web applications and APIs, often requiring certifications like CEH or OSCP. Penetration Testers have a broader scope, assessing networks, systems, and applications. While Web Pentesters focus on web-specific vulnerabilities, Penetration Testers perform comprehensive security assessments across various environments.

What are the key skills and qualifications needed to thrive as a Web Pentester, and why are they important?

To thrive as a Web Pentester, you need strong knowledge of web application security principles, programming languages (such as JavaScript, Python, or PHP), and common vulnerabilities like OWASP Top 10, often supported by certifications like OSCP or CEH. Familiarity with penetration testing tools such as Burp Suite, OWASP ZAP, and Metasploit is typically required. Analytical thinking, attention to detail, and effective communication are essential soft skills to report findings and collaborate with development teams. These skills and qualifications are crucial for identifying, documenting, and mitigating web security risks to protect organizations from cyber threats.

What are some common challenges Web Pentesters face when conducting assessments for large organizations?

Web Pentesters working with large organizations often encounter challenges such as complex web application architectures, diverse technology stacks, and strict security protocols that limit testing methods. Coordinating with multiple teams, ensuring minimal disruption to business operations, and navigating change management procedures can also add complexity to the assessment process. Additionally, staying updated with the latest vulnerabilities and tools is crucial due to the rapidly evolving security landscape. Clear communication and thorough documentation are essential to ensure findings are well understood and remediation steps are actionable.

What are web pentesters?

Web pentesters, or web penetration testers, are cybersecurity professionals who assess the security of web applications by simulating cyberattacks. Their main goal is to identify vulnerabilities that malicious hackers could exploit and provide recommendations to strengthen the application's defenses. They use a combination of automated tools and manual testing techniques to evaluate issues like SQL injection, cross-site scripting, and authentication flaws. Web pentesters play a crucial role in helping organizations protect sensitive data and maintain the trust of their users.
More about Web Pentester jobs
Infographic showing various Web Pentester job openings in the United States as of July 2026, with employment types broken down into 53% Internship, 10% As Needed, 2% Full Time, 25% Temporary, 9% Nights, and 1% Summer. Highlights an 73% Physical, 2% Hybrid, and 25% Remote job distribution, with an average salary of $80,851 per year, or $38.9 per hour.
Continuous Opening: Senior Application Security Pentester REMOTE

Continuous Opening: Senior Application Security Pentester REMOTE

Independent Security Evaluators

Baltimore, MD • On-site, Remote

$115K - $165K/yr

Full-time

Medical, Life, PTO

Re-posted 14 days ago


Job description

Independent Security Evaluators (ISE) is continuously looking for Senior level Application Security Pentester/Analyst candidates.  We are not currently hiring for this role, but we would still love to connect with you!

Do you enjoy working with wicked smart people, like to hack into things, solve puzzles, and work on cool projects? ISE is the place for you! 

What you’ll do at ISE:

  • Interface directly as a project lead, senior analyst, or in a scoping capacity
  • Mentor junior analysts throughout client assessments, research projects, findings reviews, and general professional and technical development
  • Perform hands-on security assessments and reviews on various pieces of technology including but not limited to:
    • Web apps and APIs
    • Mobile apps
    • Networks
    • Cloud architecture and configuration
    • Source code analysis
    • Hardware and firmware
  • Create comprehensive assessment reports that clearly identify vulnerabilities, how they impact our client’s digital assets, and remediation strategies
  • Provide consultative advice to ISE’s clients regarding best practices, design guidance, new threats, policies and processes, etc. Basically: be their genius friend who helps solve problems.
  • Perform research and develop whitepapers/presentations/etc. regarding relevant research, security topics, tools and techniques driven by your areas of interest and expertise
  • Opportunity to participate in IoT Village

What you won't do at ISE:

  • Use scanners - we might use a scanning tool on occasion but our assessments are designed to find what scanners miss
  • Write policy or compliance rules or assess tools for regulatory purposes
  • Only hack with your head down - we are looking for folks who will talk with our clients, mentor others, and collaborate on projects, talks, and research

What you bring to the table:

  • 6+ years in security consulting with a focus on application/software
  • Experience with programming and developing exploits
  • Familiarity with Unix command line tools and working in CLI environments
  • Skillset in the following:
    • Web and desktop application security (Advanced)
    • Cloud security and architecture (Advanced)
    • Mobile application security (Basic)
  • Background in the following: 
    • Software vulnerability analysis, code analysis, and fuzzing
    • Reverse engineering through static and dynamic analysis
    • Analyzing cryptographic workflows
    • Analyzing network traffic
    • Experience interacting with clients in a consultative environment
  • Strong technical writing and oral communication skills
  • Public speaking experience
  • Desire to make things better: help our clients secure their products, help your colleagues grow and learn, self-motivated and always seeking improvement

Nice to have (but we can teach you!):

  • Skillset in the following:
    • IoT hardware security
    • Network security
    • Red Teaming
    • AI security
  • Experience with digital rights management and digital watermarking
  • Experience with secure software development
  • Familiarity with industry standard security policies (SOC2, OWASP ASVA, GDPR, ISO 27001, PCI, NIST CSF, etc) and their practical applications
  • Experience assessing generative AI technologies and applications

Salary:

$115K-$165K, according to experience

If you don't think you meet all of the criteria above but are still interested in the job, please apply. Nobody checks every box, and we're looking for someone excited to join the team.

What we bring to the table:  

  • Check out joinise.io for full details
  • Work that matters; projects that impact people’s everyday life and wellbeing
  • Quality, integrity, dedication, and education: our core values
  • Life balance: flexible schedule, work from home options, unlimited vacation
  • $0 health premium plan option, including spouse and family
  • Opportunities to research and publish, speak at major security events and conferences  
  • Leadership and peers that support and mentor you: your growth is our growth, your success is our success  
  • Relaxed and fun environment: ditch the suit and tie, sit or stand at your desk or find a sofa 
       

About ISE:  

ISE is an independent security consulting and software firm headquartered in Baltimore, Maryland, dedicated to securing high value assets for global enterprises and performing groundbreaking security research. Using an adversary-centric perspective driven by our elite team of analysts and developers, we improve our clients’ overall security posture, protect digital assets, harden existing technologies, secure infrastructures, and work with development teams to ensure product security prior to deployment.Our team enjoys working in a creative, educational, and comfortable environment where they can thrive professionally.  

Building a Better Community:

We value different viewpoints and fresh perspectives. We embrace people who challenge our thinking and question the status quo. We are opposed to narrow minded, exclusionary, and discriminatory viewpoints or practices that inherently undermine our creative process, hinder growth, and impede innovation.

Need more info?  

Be sure you spend some time at www.ise.io. Make sure you look through all the perks on the Careers page, then check out our Research and Blog, our events page for the IoT Village, and About page. Follow us on Twitter @ISEsecurity and @IoTvillage

Employment Type: FULL_TIME