382 penetration test jobs at 243 companies in United States

2w
Save
Mark Applied
Hide
Lead Penetration Test Engineer
Boston or Chicago or Dallas or Houston or Englewood or Raleigh or Princeton or New York or Southfield or Washington or Toronto or Calgary or Boulder
$135k-$200k/yr HybridFull Time
S&P Global
S&P GlobalNYSE: SPGI: Provides financial data, analytics, and credit ratings worldwide.
8+ YOEBachelor's degree or equivalent, minimum 8 years information security experience focused on penetration testing, expertise with offensive techniques, cloud/app security, scripting, and at least one offensive security certification.
Burp Suite, Nessus, Metasploit, Nmap, DAST, SAST, SCA, CI/CD, Bash, Python, Go, PowerShell, JavaScript, MITRE ATT&CK, OWASP Top 10, CVE, CVSS, CWE
2w
Save
Mark Applied
Hide
Lead Penetration Test Engineer
Princeton or Boston or Chicago or Dallas or Houston or Englewood or Raleigh or New York or Southfield or Washington or Toronto or Calgary
$135k-$200k/yr HybridFull Time
S&P Global
S&P GlobalNYSE: SPGI: Provides independent credit ratings, market benchmarks, and financial analytics.
8+ YOEBachelor's or equivalent, 8+ years in information security with penetration testing focus; hands-on with Burp Suite, Nessus, Metasploit, Nmap; scripting (Bash, Python, Go, PowerShell, JavaScript); offensive cert (OSCP or similar).
Burp Suite, Nessus, Metasploit, Nmap, MITRE ATT&CK, OWASP Top 10, DAST, SAST, SCA, CVE, CVSS, CWE, Bash, Python, Go, PowerShell, JavaScript, CI/CD
3w
Save
Mark Applied
Hide
Penetration Test Engineer
Aberdeen, Maryland, United States
$165k-$195k/yr HybridFull Time
Techximius: Provides specialized IT and engineering services for defense missions.
3+ YOEHands-on vulnerability scanning and analysis (Tenable/Qualys/NMAP), experience with vulnerability lifecycle tracking (ServiceNow/SharePoint/PowerBI), OSCP preferred, DoD Secret clearance, Bachelor's in related field or 2yrs experience, 3+ years cybersecurity experience.
Nessus, Security Center, Tenable.IO, Qualys WAS, NMAP, ServiceNow, SharePoint, Microsoft SQL, PowerBI, Azure, AWS, GCP, Python, PowerShell, SQL, DAX
2w
Save
Mark Applied
Hide
Penetration Tester
Washington or United States
$123k-$167k/yr RemoteFull Time
GDIT
GDITNYSE: GD: Delivers IT and mission services to government agencies.
8+ YOE8+ years penetration testing/application security experience; AWS cloud and federal security (NIST/RMF/FISMA) knowledge; familiarity with web, API, microservices, container, and cloud testing and reporting.
Burp Suite, OWASP ZAP, Metasploit, Nmap, Nessus, Nikto, K6 Security, Python, JavaScript, AWS CloudWatch, AWS CloudTrail, AWS GuardDuty, Datadog, ELK Stack, Prometheus, Grafana, Jenkins, GitLab CI/CD, GitHub Actions, SonarQube, Checkmarx, Fortify, Jira, Confluence, Microsoft SharePoint, Microsoft Teams, Microsoft Power BI
2mo
Save
Mark Applied
Hide
Penetration Tester
United States
RemoteFull Time
Aerstone
Aerstone: A cybersecurity services delivering risk assessments and penetration testing.
5+ YOE5+ years of penetration testing experience; Bachelor's degree; strong Linux knowledge; various security tool experience; cloud and network assessment skills; ability to lead testing and produce reports.
Kali Linux, Metasploit, Burp Suite, ZAP, Nessus, Linux, Windows, Unix, Cloud assessment tools
1w
Save
Mark Applied
Hide
Penetration Tester
United States
RemoteFull Time
SecureIT
SecureIT: Cybersecurity compliance advisory and assessment services firm.
Experience in web application, network, API and AI penetration testing and red teaming; client-facing experience and relevant offensive security credentials preferred.
3w
Save
Mark Applied
Hide
Penetration Tester
Fort Meade, Maryland, United States
$87k-$198k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
3+ YOESecret clearance required; 3+ years experience with MITRE ATT&CK, penetration testing, Linux/Windows environments, exploit development, network security analysis, and test planning; HS diploma or GED required.
MITRE ATT&CK, Atomic Red Team, Scythe, Mandiant ASV, AttackIQ, Java, Ruby, Python, JavaScript, Rust, C, Linux, Windows
1mo
Save
Mark Applied
Hide
Penetration Tester
New York or Washington or Chicago or Wilmington or Jersey City or Brooklyn or Tampa or Atlanta or McLean or Plano or Houston or Columbus
$152k-$260k/yr OnsiteFull Time
JPMorgan Chase
JPMorgan ChaseNYSE: JPM: Global financial services firm providing banking and investment solutions.
5+ YOE5+ years penetration testing experience across web, API, cloud, infrastructure, thick-client, and mobile; strong manual testing skills, reporting ability, and knowledge of OWASP/NIST frameworks; relevant offensive security certifications preferred.
Burp Suite, Nmap, Metasploit, AWS, Azure, GCP, OWASP Top Ten, NIST Cybersecurity Framework, Python, Java, Rust, Android, iOS, Windows, Unix
2d
Save
Mark Applied
Hide
Penetration Tester
Herndon, Virginia, United States
OnsiteFull Time
Bespoke Technologies
Bespoke Technologies: Provides technical engineering and data solutions for national security.
Active polygraph required. Experienced in penetration testing, adversarial tactics, network and system exploitation across Linux, Windows, and virtual platforms; risk analysis and mitigation; communicating technical results.
Linux, Windows, hypervisors
3w
Save
Mark Applied
Hide
Penetration Tester
Fort Meade, Maryland, United States
$87k-$198k/yr HybridFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
3+ YOE3+ years performing penetration testing, MITRE ATT&CK-based assessments, network/security analysis, and operating in Linux/Windows/virtual platforms; Secret clearance and HS diploma/GED required.
MITRE ATT&CK, Linux, Windows, Atomic Red Team, Scythe, Mandiant ASV, AttackIQ, Java, Ruby, Python, JavaScript, Rust, C
2w
Save
Mark Applied
Hide
Penetration Tester, AVP
Whippany, New Jersey, United States
$169k-$170k/yr HybridFull Time
Barclays
BarclaysLondon Stock Exchange: BARC: Global bank providing retail, corporate, and investment financial services.
Perform and lead penetration tests across web, mobile, infrastructure and cloud; analyze and report vulnerabilities; collaborate with stakeholders and develop testing methodologies.
3mo
Save
Mark Applied
Hide
Penetration Tester
Washington or San Antonio or Cleveland or California or Colorado or Hawaii or Illinois or Maine or Maryland or Massachusetts or Minnesota or New Jersey or New York or Vermont or Virginia or Washington
$126k-$243k/yr HybridFull Time
Accenture Federal Services
Accenture Federal ServicesNYSE: ACN: Provides technology and consulting services to U.S. federal agencies.
2+ YOE2+ years penetration-testing experience across at least two domains (network, cloud, web app, identity, containers); proficiency with offensive-security tools and producing technical reports; experience with Rules of Engagement.
Burp Suite, Cobalt Strike, Metasploit, BloodHound
2w
Save
Mark Applied
Hide
Penetration Tester
United States
RemoteFull Time
Schellman
Schellman: Provides IT compliance, cybersecurity, and attestation services.
Hands-on penetration testing and project execution, knowledge of security domains and professional standards, strong communication and time management, proficiency with Microsoft Office and service delivery applications, pursuing/maintaining security or audit certifications.
Microsoft Word, Microsoft Excel, Microsoft PowerPoint
2mo
Save
Mark Applied
Hide
Penetration Tester
Ogden, Utah, United States
OnsiteFull Time
Dark Wolf Solutions
Dark Wolf Solutions: Provides cybersecurity and software development services to defense agencies.
3+ YOE3+ years in penetration testing, red team, vulnerability assessment; strong Windows, Linux, mobile; cloud (AWS/Azure/GCP); scripting; onsite work in Ogden, UT; US Citizenship with TS/SCI clearance.
AWS, Azure, Google Cloud Platform, Kubernetes, DevSecOps tools
3w
Save
Mark Applied
Hide
Penetration Tester
United States
RemoteFull Time
A-LIGN
A-LIGN: Provides cybersecurity compliance and audit services.
2+ YOE2+ years performing network and application penetration tests, OSCP certification, Bachelor’s or Master’s in cybersecurity/MIS/CS, familiarity with Kali Linux, nMap, Nano/Vi, SSH, Bash scripting, and strong communication skills.
Kali Linux, Nano, Vi, nMap, Bash, SSH
3d
Save
Mark Applied
Hide
Penetration Tester
Quantico, Virginia, United States
HybridFull Time
ASRC Federal
ASRC Federal: Provides engineering and IT services to federal government agencies.
5+ YOE5+ years security experience, conduct penetration tests across apps/networks/cloud, active Top-Secret clearance, IAT II baseline certs, bachelor's degree or equivalent, strong reporting and remediation skills.
Assured Compliance Assessment Solution (ACAS), Rapid7 Nexpose, Appspider Pro, Metasploit, Cobalt Strike, Burp Suite
1mo
Save
Mark Applied
Hide
Penetration Tester
United Kingdom or London or San Francisco or New Hampshire
RemoteFull Time
Bugcrowd
Bugcrowd: Provides a crowdsourced platform for security vulnerability testing.
0.5+ YOE6+ months equivalent penetration testing experience, familiarity with BurpSuite and Nmap, strong written/spoken English (C1+), ability to follow methodologies, and willingness to work UK core hours (09:00-17:30 GMT).
BurpSuite, Nmap
2mo
Save
Mark Applied
Hide
Penetration Tester
Fort Meade, Maryland, United States
$160k-$235k/yr OnsiteFull Time
M2 Technology Group
M2 Technology Group: Providing specialized cybersecurity and engineering services for government agencies.
12+ YOESenior RMF subject matter expert with 12+ years experience, DoD 8570 IAT/IAM Level III, CEH, vendor OS certification, active security clearance with polygraph, advanced penetration testing and regulatory expertise.
2w
Save
Mark Applied
Hide
Penetration Testing Lead
Washington, District of Columbia, United States
HybridFull Time
OCH Technologies
OCH Technologies: Provides IT and cybersecurity services for federal government agencies.
15+ YOE5+ Mgmt15+ years cybersecurity experience with 5+ years leading penetration testing; bachelor's degree in a technical field; Public Trust eligibility; security certifications (OSCP, CEH, GPEN, etc.); proficiency with Metasploit, Burp Suite, Nmap and testing methodologies.
Metasploit, Burp Suite, Nmap, Cobalt Strike, Sliver, Mythic, BloodHound, Impacket, Nuclei, Pacu, AzureHound, HackRF, NIST SP 800-115, PTES, OWASP
3w
Save
Mark Applied
Hide
Penetration Tester
United States
RemoteFull Time
A-LIGN
A-LIGN: Provides cybersecurity audits and compliance assessments for global businesses.
2+ YOEPerform internal, external, wireless, web app, and social engineering penetration tests; run vulnerability scans; write client reports; use Kali Linux command line and Bash; reimage devices; familiarity with text editors, Nmap, SSH.
Kali Linux, Bash, Nano, Vi, Nmap, SSH