Penetration Testers

Information TechnologyO*NET 15-1299.04United States

Evaluate network system security by conducting simulated internal and external cyberattacks using adversary tools and techniques. Attempt to breach and exploit critical systems and gain access to sensitive information to assess system security.

COMING SOON See related ASU learning
Median annual earnings
$113,638

50th percentile, United States

Projected change
+11.4%

2025 to 2035

Typical education
Bachelor's degree

75.2% of the workforce

Employment
499.03K jobs

Growing to 555.79K by 2035

Explore this career by location

Compare nationwide estimates with state or county job-market data.

Showing United States

Loading available locations…

Build the skills

ASU learning related to this career

These courses and certificates are connected through catalog career relationships and Lightcast skill tags.

Loading related ASU learning

The work

What penetration testers do

Tasks reported for this occupation, ordered by how often they come up in the role.

  • Keep up with new penetration testing tools and methods.
  • Maintain up-to-date knowledge of hacking trends.
  • Prepare and submit reports describing the results of security fixes.
  • Test the security of systems by attempting to gain access to networks, Web-based applications, or computers.
  • Update corporate policies to improve cyber security.
  • Write audit reports to communicate technical and procedural findings and recommend solutions.
  • Assess the physical security of servers, systems, or network devices to identify vulnerability to temperature, vandalism, or natural disasters.
  • Collect stakeholder data to evaluate risk and to develop mitigation strategies.
  • Conduct network and security system audits, using established criteria.
  • Configure information systems to incorporate principles of least functionality and least access.
  • Design security solutions to address known device vulnerabilities.
  • Develop and execute tests that simulate the techniques of known cyber threat actors.
  • Develop infiltration tests that exploit device vulnerabilities.
  • Develop presentations on threat intelligence.
  • Develop security penetration testing processes, such as wireless, data networks, and telecommunication security tests.
  • Discuss security solutions with information technology teams or management.
  • Document penetration test findings.
  • Evaluate vulnerability assessments of local computing environments, networks, infrastructures, or enclave boundaries.
  • Gather cyber intelligence to identify vulnerabilities.
  • Identify new threat tactics, techniques, or procedures used by cyber threat actors.
  • Identify security system weaknesses, using penetration tests.
  • Investigate security incidents, using computer forensics, network forensics, root cause analysis, or malware analysis.

Pay and outlook

What the job pays and where it is heading

Annual earnings range

Reported earnings by percentile, United States

10th percentile
$53,796
25th percentile
$76,983
50th percentile
$113,638
75th percentile
$155,092
90th percentile
$191,936

The gold marker shows the median. Half earn more than $113,638 and half earn less.

Employment outlook

2025 to 2035 projection

+11.4%faster than average
2025499,030 jobs
2035 projected555,787 jobs

56,757 more positions over the decade, before replacement hiring.

Preparation

Education levels

What people currently working in the career hold. These are not entry requirements.

Bachelor's degree
75.2%
Associate degree
12.9%
Certificate
7.2%
Master's or Professional degree
2.8%
Some college
2%

Skills

Skills employers ask for

Technical skills appearing most often in job postings for this occupation.

  • Cyber Security
  • Vulnerability Management
  • Penetration Testing
  • Python (Programming Language)
  • Computer Science
  • Automation
  • Scripting
  • Auditing
  • Cyber Threat Intelligence
  • Workflow Management
  • Vulnerability Assessments
  • Incident Response
  • Windows PowerShell
  • Vulnerability Scanning
  • Amazon Web Services
  • Security Controls
  • Microsoft Azure
  • Linux
  • Operating Systems
  • Offensive Security

How the work gets done

Core competencies

Broad capabilities associated with strong performance in this occupation.

In the market

Job titles and employers

Recent job postings in United States

Common job titles

  1. 01Penetration Testers1,002 postings
  2. 02Cybersecurity Analysts796 postings
  3. 03Vulnerability Management Analysts603 postings
  4. 04Vulnerability Analysts440 postings
  5. 05Vulnerability Management Engineers367 postings
  6. 06Security Consultants/Penetration Testers349 postings
  7. 07Security Analysts282 postings
  8. 08Vulnerability Researchers256 postings
  9. 09Engineers208 postings
  10. 10Offensive Security Engineers165 postings
  11. 11Operations Team Managers162 postings
  12. 12Cyber Analysts135 postings
  13. 13Security Control Assessors130 postings
  14. 14Network Exploitation Analysts114 postings
  15. 15Systems Test Engineers113 postings
  16. 16DevSecOps Engineers103 postings
  17. 17Cybersecurity Researchers95 postings
  18. 18Principal Engineers89 postings
  19. 19Assessment Managers87 postings
  20. 20Subject Matter Experts86 postings

Top employers

  1. 01Datavant215 postings
  2. 02Northrop Grumman208 postings
  3. 03KPMG204 postings
  4. 04Accenture190 postings
  5. 05Motorola Solutions182 postings
  6. 06Insight Global179 postings
  7. 07Leidos166 postings
  8. 08Shi International Ltd158 postings
  9. 09Simventions145 postings
  10. 10Peraton124 postings
  11. 11CVS Health111 postings
  12. 12UKG108 postings
  13. 13Cai106 postings
  14. 14Maximus104 postings
  15. 15TEKsystems82 postings
  16. 16Beacon Hill Staffing Group81 postings
  17. 17General Dynamics81 postings
  18. 18Deloitte73 postings
  19. 19GE Aerospace67 postings
  20. 20CACI International65 postings

Keep looking