Senior Penetration Tester

CoStar Group

Confirmed live 2 days ago High trust

Quick summary

Work type
On-site
Location
Arlington, VA
Salary
$115,000–$203,000 / yr
Posted
74 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $169k
This role $159k
$104k most similar roles pay here $214k

This role pays less than 59% of similar roles. Most pay $142,400–$195,181 — the shaded band above. At the midpoint, this role pays about $159k versus about $169k for comparable roles.

Based on 240 similar postings.

Employer

About CoStar Group

CoStar Group is the leading provider of commercial real estate information, analytics, and online marketplaces, including CoStar, Apartments.com, and LoopNet platforms. Industry: Commercial Real Estate Data & Analytics

CoStar Group currently has 65 open roles on FindRole.

Listed pay typically runs $133,000–$190,000 across 63 roles with salary data.

Most-posted roles

View all roles at CoStar Group

At a glance

TL;DR · Senior Penetration Tester

As a Senior Penetration Tester, you will join the security team to evolve pentesting capabilities for internal and external facing processes, infrastructure, and applications. You will lead penetration tests on web applications and underlying infrastructure using manual and automated techniques while developing test plans to validate vulnerabilities and demonstrate exploitability to engineering teams and senior leadership. Your daily work involves collaborating on purple team exercises, performing secure code reviews, and recommending architectural improvements. You will utilize tools such as Burp Suite, Nmap, Metasploit, and Bloodhound, while leveraging Python, PowerShell, C#, Java, JavaScript, or Go for scripting. The role addresses security risks within cloud-native domains, including CI/CD pipelines, Active Directory, AWS, and Kubernetes, while also exploring emerging areas like AI and LLM security testing to protect the organization's digital infrastructure.

What you'll do

  • Lead manual and automated penetration tests on web applications and underlying infrastructure.
  • Develop test plans to validate vulnerabilities and demonstrate exploitability to engineering teams and senior leadership.
  • Participate in purple team exercises to validate preventative and detective controls against adversary techniques.
  • Expand pentesting capabilities across cloud-native domains, including CI/CD pipelines, Active Directory, AWS, and Kubernetes.
  • Recommend remediation strategies that address root causes through code changes and architectural improvements.
  • Perform secure code reviews to identify flaws in authentication, authorization, and business logic.
  • Mentor team members on offensive techniques and how to think like an attacker.

What we're looking for

  • Bachelor's Degree from an accredited institution in Computer Science, Cybersecurity, or a related field.
  • 6 years of experience in technical roles such as security, software development, or systems engineering.
  • At least 3 years of experience focused on penetration testing or offensive security.
  • Experience with web application and API penetration testing including complex logic, authentication, and authorization flows.
  • Proficiency in scripting languages like Python or PowerShell and ability to read code in C#, Java, JavaScript, or Go.
  • Ability to perform secure code reviews to identify vulnerabilities such as injection and business logic flaws.
  • Experience writing reports that communicate vulnerability risk and remediation paths to both technical teams and senior leadership.
  • Security certifications such as OSCP, OSWE, OSEP, GPEN, GXPN, or similar.

More like this

Similar roles

Penetration Tester

Leidos

Huntsville, AL 10 days ago $87,100$157,450
Penetration Testing Python Bash PowerShell Burp Suite Metasploit Cobalt Strike Nmap OWASP Top 10 AWS Azure GCP REST SOAP GraphQL TCP/IP Vulnerability Assessment ScoutSuite Prowler
4+ yrs exp

Lead Penetration Test Engineer

S&P Global

Boston, MA +11 22 days ago $135,000$200,000
Penetration Testing Vulnerability Management DAST SAST SCA CI/CD Burp Suite Nessus Metasploit Nmap OWASP Top 10 MITRE ATT&CK Python Go Bash PowerShell JavaScript AWS Azure GCP Java
8+ yrs exp Hybrid

Red Team Penetration Tester

Booz Allen Hamilton

Dahlgren, VA 2 days ago $86,800$198,000
Penetration Testing Red Team Operations Kali Metasploit NMAP Cobalt Strike Wireshark tcp dump Java PHP SQL No SQL HTML Linux Windows Reverse Engineering C2 WSUS
5+ yrs exp

Red Team Penetration Tester

Booz Allen Hamilton

Virginia Beach, VA 2 days ago $86,800$198,000
Penetration Testing Kali Metasploit NMAP Cobalt Strike Wireshark tcp dump Java PHP SQL NoSQL HTML Linux Windows Reverse Engineering C2 WSUS
5+ yrs exp

Principal Senior Penetration Tester

Northrop Grumman

San Antonio, TX 52 days ago $103,600$155,400
Penetration Testing AWS Azure CI/CD Docker Kubernetes Python Bash PowerShell Terraform Ansible Splunk Sentinel ELK CrowdStrike Linux Windows Infrastructure-as-Code Vulnerability Management RMF
8+ yrs exp

Senior Red Team Operator

Booz Allen Hamilton

Chantilly, VA 17 days ago $86,800$198,000
Red Teaming Purple Teaming Active Directory Python Bash C/C++ C# Rust Go PowerShell Java Nessus Metasploit Burp Suite Pro Cobalt Strike Mythic Azure M365 Terraform x86 Reverse Engineering JTAG UART OWASP ATT&CK