Penetration Testers: Career Profile
Evaluate network system security by conducting simulated internal and external cyberattacks using adversary tools and techniques. Attempt to breach and exploit critical systems and gain access to sensitive information to assess system security.
Featured schools near , edit
What Do Penetration Testers Take On?
The day-to-day responsibilities of penetration testers include:
- Assess the physical security of servers, systems, or network devices to identify vulnerability to temperature, vandalism, or natural disasters.
- Collect stakeholder data to evaluate risk and to develop mitigation strategies.
- Conduct network and security system audits, using established criteria.
- Configure information systems to incorporate principles of least functionality and least access.
- Design security solutions to address known device vulnerabilities.
- Develop and execute tests that simulate the techniques of known cyber threat actors.
- Develop infiltration tests that exploit device vulnerabilities.
- Develop presentations on threat intelligence.
Types of Penetration Testers Jobs
People in this occupation may also be known by titles such as:
- Application Security Assessor
- Application Security Hacker
- Application Security Tester
- Certified Hacker
- Certified Tester
- Consulting Advisory Tester
- Cyber Analyst
- Cyber Assessment Tester
Job Outlook
There are about 91,324 penetration testers working in the United States today. Demand is forecast to grow by +6.6% over the projection horizon.
How Much Do Penetration Testers Make?
| Statistic | Value |
|---|---|
| Annual median | $93,800 |
| Hourly median | $45.10 |
| 10th percentile | $65,810 |
| 25th percentile | $79,805 |
| 75th percentile | $107,795 |
| 90th percentile | $121,789 |
Compensation varies based on experience, location, and industry.
Pay by State
| State | Annual median salary |
|---|---|
| Virgin Islands | $179,830 |
| Maryland | $141,540 |
| District of Columbia | $137,610 |
| Virginia | $132,810 |
| Delaware | $132,670 |
| Washington | $131,800 |
| California | $128,750 |
| Colorado | $119,560 |
| West Virginia | $113,030 |
| Hawaii | $112,050 |
| Arizona | $112,010 |
| Vermont | $109,220 |
| Texas | $108,170 |
| North Carolina | $106,240 |
| Massachusetts | $105,890 |
| New York | $105,210 |
| Ohio | $104,330 |
| Alabama | $104,330 |
| South Carolina | $104,330 |
| New Jersey | $103,910 |
| Iowa | $103,690 |
| Oregon | $102,940 |
| Florida | $102,750 |
| New Mexico | $102,500 |
| Pennsylvania | $102,330 |
| Michigan | $102,300 |
| Maine | $101,760 |
| Georgia | $100,950 |
| Nevada | $100,570 |
| Illinois | $100,310 |
| Kansas | $100,090 |
| Alaska | $100,040 |
| Minnesota | $99,740 |
| South Dakota | $98,550 |
| Connecticut | $97,870 |
| Rhode Island | $96,990 |
| Indiana | $96,530 |
| Idaho | $95,640 |
| Utah | $95,640 |
| Oklahoma | $95,640 |
| Kentucky | $90,380 |
| Wyoming | $90,010 |
| Nebraska | $87,920 |
| New Hampshire | $87,420 |
| Mississippi | $86,380 |
| Wisconsin | $85,290 |
| Missouri | $84,250 |
| Montana | $78,690 |
| Arkansas | $77,830 |
| Louisiana | $75,560 |
| North Dakota | $69,640 |
| Tennessee | $65,370 |
| Puerto Rico | $42,250 |
Top-Paying U.S. Regions
Compensation for penetration testers shift depending on where you work. The following regions pay the most:
| Region | Median annual wage | Share of U.S. jobs | Location quotient |
|---|---|---|---|
| Far Western US | $126,964 | 25.0% | 1.54 |
| Middle Atlantic | $121,117 | 18.1% | 2.97 |
| Rocky Mountains | $108,235 | 3.6% | 0.97 |
| Southwest | $107,900 | 16.0% | 1.38 |
| New England | $102,646 | 2.6% | 0.65 |
| Southeast | $101,290 | 22.4% | 1.02 |
| Great Lakes | $97,392 | 6.3% | 0.61 |
| Plains States | $89,865 | 5.8% | 1.14 |
Where the Jobs Cluster
| Metro area | State | Median annual wage | Employment |
|---|---|---|---|
| San Jose-Sunnyvale-Santa Clara, CA | CA | $168,070 | 15,550 |
| San Francisco-Oakland-Fremont, CA | CA | $157,380 | 18,680 |
| Washington-Arlington-Alexandria, DC-VA-MD-WV | DC | $144,040 | 35,080 |
| Charlottesville, VA | VA | $142,150 | 140 |
| Hagerstown-Martinsburg, MD-WV | MD | $139,940 | 420 |
| Lexington Park, MD | MD | $138,090 | 1,020 |
| Seattle-Tacoma-Bellevue, WA | WA | $134,230 | 10,400 |
| Baltimore-Columbia-Towson, MD | MD | $133,680 | 9,110 |
Industry Breakdown
Most penetration testers work in these industries:
| Industry | Employment | Median annual wage |
|---|---|---|
| Professional, Scientific, and Technical Services | 130,160 | $106,200 |
| Information | 43,000 | $126,550 |
| Finance and Insurance | 28,690 | $126,080 |
| Management of Companies and Enterprises | 25,660 | $127,600 |
| Administrative and Support and Waste Management and Remediation Services | 24,880 | $96,000 |
| Manufacturing | 21,020 | $102,950 |
| Educational Services | 18,100 | $79,900 |
| Wholesale Trade | 13,130 | $100,550 |
Software Penetration Testers Use
- Data base user interface and query software: Amazon Web Services AWS software (hot technology)
- Expert system software: Ansible software (hot technology)
- Operating system software: Apple iOS (hot technology)
- Operating system software: Apple macOS (hot technology)
- Operating system software: Bash (hot technology)
- Development environment software: C (hot technology)
- Object or component oriented development software: C# (hot technology)
- Object or component oriented development software: C++ (hot technology)
- Application server software: Docker (hot technology)
- Application server software: GitHub (hot technology)
- Development environment software: Go (hot technology)
- Operating system software: Google Android (hot technology)
Getting Started in This Career
This career aligns with Considerable Preparation Needed (Job Zone 4), indicating the level of preparation typically expected.
Other Careers to Consider
Similar Occupations
- Security Managers (Supplemental)
- Computer and Information Systems Managers (Supplemental)
- Security Management Specialists (Supplemental)
- Computer Systems Analysts (Primary-Short)
- Information Security Analysts (Primary-Short)
- Computer Network Support Specialists (Primary-Long)
- Computer Network Architects (Supplemental)
- Database Administrators (Primary-Long)
Degree Programs
Future penetration testers commonly pursue programs in:
Computer and Information Sciences and Support Services
5 programs across 5 majors
References
This profile draws on the following authoritative sources:
- U.S. Bureau of Labor Statistics — Occupational Employment and Wage Statistics (OEWS) for employment and wage data by state and industry.
- BLS Employment Projections for total employment and growth forecasts.
- O*NET (Occupational Information Network) for skills, knowledge, tasks, work activities, work context, technology, and education-zone data.
SOC code: 15-1299.04 (Computer Occupations, All Other).
Featured Schools
Request Info
|
Southern New Hampshire University You have goals. Southern New Hampshire University can help you get there. Whether you need a bachelor's degree to get into a career or want a master's degree to move up in your current career, SNHU has an online program for you. Find your degree from over 200 online programs. Learn More > |