Back to Blog

Penetration Tester Job Description Template 2026

CybersecurityIT Hiring

Last updated: August 9, 2026

By Mike Carter, Director of Partnership Success, KORE1

A penetration tester job description works when it names one attack surface, states the pay range, and describes the report as real work. Most postings skip all three, which is why they attract scanner operators instead of testers. The template further down does those three things. Everything before it is the scoping you have to finish first.

A payments company in Costa Mesa sent me a req last October. Senior Penetration Tester. Nine bullets, six certifications, a band of $120,000 to $135,000, and not one sentence describing what the person would be pointed at.

They ran it seven weeks. Sixty-one applicants. The shortlist was four people who ran Nessus and wrote up the output.

Nothing was wrong with those four. They were doing the job the posting described. The job the company actually needed was manual testing against a payment API and the identity layer around it, which is a different human being at a different price, and no line in that document said so. We rewrote it in about forty minutes. The rewrite named the API, named Burp Suite, named the SOC 2 and PCI DSS obligations driving the work, and moved the top of the band to $168,000. First qualified submittal went out nine days later.

The req was never the problem. The scoping underneath it was.

Fair warning about the source. I run technical and security desks at KORE1, our cybersecurity staffing practice and the penetration tester staffing desk inside it bill a fee when a placement sticks, and one section below argues that a good number of readers should hire a firm for a single engagement instead of posting anything at all. Weigh the rest of this knowing I get paid on the outcome I am talking some of you out of.

Technical recruiter and hiring manager scoping the attack surface for a penetration tester job description

Name the Surface Before You Write the Posting

Penetration testing splits into six target surfaces, and a tester who is excellent against web applications may be genuinely unqualified against industrial control systems. The surface you name determines who applies, what they cost, and whether the report is useful.

This is the decision most job description templates skip entirely. They hand you “conduct penetration tests on networks, applications, and systems,” which sounds thorough and filters nobody.

Pick one. Two at the outside.

Target SurfaceWhat the Tester Is Actually DoingBase Band (Mid to Senior)
External network and infrastructurePerimeter enumeration, service exploitation, password attacks, Nmap and Metasploit work with manual follow-through$95,000 – $135,000
Web application and APIHand testing against the OWASP WSTG, business logic abuse, auth and session flaws, Burp Suite all day$115,000 – $170,000
Cloud platformIAM privilege chains in AWS or Azure, misconfigured trust policies, Entra ID and Okta abuse paths, container escape$150,000 – $205,000
Mobile and thick clientiOS and Android binary analysis, certificate pinning bypass, local storage and IPC flaws$125,000 – $175,000
OT, ICS, and hardwareProtocol work on Modbus and DNP3, PLC and firmware analysis, testing where a crash stops a production line$170,000 – $215,000
Red team and adversary emulationFull-chain operations mapped to MITRE ATT&CK, Cobalt Strike and custom tooling, evading a live blue team$175,000 – $220,000

Those are base bands for someone with genuine depth in that column, not a generalist who has touched it once. The level-by-level view, junior through principal, lives in our penetration tester salary guide. Read the OT row against the external network row. Seventy-five thousand dollars apart at the floor of each band, between two people who share a job title.

Red team belongs on that table and probably not in your posting. Adversary emulation assumes you already have detection worth evading. If your SOC is two analysts and a Sentinel instance nobody has tuned since the rollout, a red team engagement produces an expensive document telling you what you already suspected. Build the defense. Test it later.

Penetration Tester Job Description Template

Copy the block, swap every bracket for something true about your environment, and delete the parenthetical notes before it goes live. Those are for you, not for candidates. It is written for a mid-to-senior tester on an internal security team. Push the ownership language up for a principal, and cut the two compliance bullets entirely if no framework is driving the hire.

Job Title: Penetration Tester [or Security Consultant, or Offensive Security Engineer. Pick the one that matches your level and band, and do not use “Ethical Hacker” as the posted title unless you want a very different applicant pool]

Location: [City, State / Remote / Hybrid. If hybrid, say which days]
Employment Type: [Full-time / Contract / Contract-to-Hire]
Team: [Offensive Security / Security Engineering / GRC]
Reports To: [Director of Security / Security Engineering Manager]
Travel: [None / up to X% for on-site physical and wireless assessments]

About the Role

We are hiring a penetration tester to find and prove real attack paths against [the specific surface: our customer-facing web application and its API / our AWS production accounts and the identity layer around them / the internal network across 14 sites]. You will scope engagements with the teams who own the systems, execute the testing by hand rather than by scanner, and write findings that an engineer can fix and an executive can fund. You will also retest, because a finding that never gets closed did not help anyone.

What You’ll Own

  • Plan and execute [external / internal / web and API / cloud] penetration tests against [name the real scope: 40 internet-facing hosts, two production AWS accounts, one Django application handling PHI], following a recognized methodology such as PTES, NIST SP 800-115, or the OWASP WSTG
  • Chain findings into demonstrated attack paths, because a list of unrelated medium-severity items is a scan result, not a test
  • Write the report. Technical detail with reproduction steps for the engineers, a two-page summary with business impact for leadership, and a severity rating you can defend when someone pushes back on it
  • Agree rules of engagement in writing before any testing begins, including scope boundaries, testing windows, out-of-scope systems, and the escalation path if something breaks
  • Retest remediated findings and track closure with the owning teams
  • [If applicable] Support [SOC 2 / PCI DSS 4.0.1 / HIPAA / CMMC] evidence requirements and work with the assessor on scope and results
  • [If applicable] Build and maintain internal tooling and automation so the repeatable parts of an engagement stop eating your week

What We’re Looking For

  • [3+ / 6+] years of hands-on penetration testing, with engagements you can walk through end to end, including the ones where you found nothing and had to say so
  • Real depth in [the surface named above] rather than surface familiarity with all of them
  • Fluency with [Burp Suite Professional, Nmap, Metasploit, BloodHound, Kali, and whatever your team actually runs], plus scripting in Python or Go to build what does not exist yet
  • Report writing you are willing to be judged on. We will ask for a redacted sample or a written exercise
  • Judgment about blast radius. You know when to stop, when to call someone, and what not to run against production at 4 p.m. on a Thursday

Nice to Have

  • [OSCP, OSCP+, OSWE, GPEN, GWAPT, CRTO, or CREST registration] listed as a plus rather than a filter, unless a client contract genuinely requires one
  • Published research, CVEs, bug bounty history, CTF placements, or a public tool repository
  • Experience testing [LLM-backed features against the OWASP Top 10 for LLM Applications / Kubernetes / SCADA environments], if that is where your product is heading
  • [Active clearance] only if the work touches classified systems. Otherwise leave this line out

Compensation and Authorization

$[low] to $[high] base depending on level and depth in [surface], plus [bonus, equity, cert and training budget, conference travel]. All testing is performed under written authorization and defined rules of engagement, with scope agreed by the system owners before work begins.

The authorization sentence at the bottom carries more weight than its length suggests. Experienced testers read for it. Its absence suggests a company that has not thought about the legal shape of the work, and that is the company where somebody gets asked to test a system a third party actually owns.

Security engineers agreeing penetration test scope and rules of engagement before testing begins

The Lines That Quietly Shrink Your Pool

I see security reqs before searches open, usually a few a month. Five patterns do most of the damage.

“Perform penetration testing on networks, applications, systems, cloud, mobile, and wireless.” You have described six jobs and committed to none. A web application specialist reads that and assumes you want a generalist who does everything shallowly, which is a fair reading, and moves on. Name one surface. Add a second as a secondary responsibility if you must. The posting gets shorter and the applicants get better.

Then there is CEH. It shows up as a hard requirement on roughly a third of the pen tester postings I see, and it is a multiple-choice exam. Hands-on testers know that. Listing it as required, especially above OSCP or a practical alternative, tells the market you are filtering on paperwork, and the practitioners you want are the ones most likely to notice. Move it to preferred, or drop it.

Nothing about the report. This is the one that surprises hiring managers when I raise it. Report writing is somewhere between a third and half of a real engagement, the deliverable is the entire product the client or the board sees, and testers who write well know exactly how scarce that is and price accordingly. A posting silent on reporting reads as a shop that treats the write-up as an afterthought, which is a warning sign to a senior candidate and a magnet for the tool operator who would rather never write a paragraph.

The band that contradicts the bullets. Cloud IAM attack paths, adversary emulation, and OSCP required, posted at $115,000. The market priced that gap a while ago. You will get applications, they will come in a level short, and eleven weeks later the req reopens with the same number in it. Same result.

Last one is quieter, and it sits in the education line. A bachelor’s degree in computer science, listed as required. Offensive security draws more self-taught practitioners than almost any technical discipline, a lot of the best ones came through help desk, sysadmin work, the military, or four years of CTFs and a home lab, and a degree line screens them out before a human ever reads the resume. Write “degree or equivalent practical experience.” Two extra words. Meaningfully larger pool.

Certifications, and the OSCP Line Almost Every Posting Gets Wrong

List certifications as preferred, not required, unless a client contract obligates one. The exception worth knowing in 2026 is OSCP versus OSCP+, because they are not the same credential and most postings ask for the wrong one.

Here is the part almost nobody writing a JD has caught up on. OffSec split the certification in late 2024. The classic OSCP still does not expire. The OSCP+ designation does, three years from issuance, and holders keep it by earning another qualifying OffSec certification, passing a recertification exam, or completing roughly 40 continuing education credits a year.

So when a posting says “current OSCP required,” it is asking for something that does not exist. A tester who earned the OSCP in 2019 holds it permanently and correctly. If what you mean is ongoing proof of practice, say OSCP+ or name a recertification path. If you do not care, say OSCP.

Small thing. Also the kind of thing an experienced tester catches in about four seconds, and it colors how they read the rest of your posting.

For the rest, a rough hierarchy that holds up in our searches. OSCP and OSCP+ remain the practical baseline the market recognizes. OSWE and GWAPT signal genuine web depth. CRTO and OSEP point toward red team work. CREST registration matters if you are hiring in or selling into the UK and parts of the Middle East. GPEN sits fine alongside any of them. CISSP is a management and breadth credential that says almost nothing about whether someone can get a shell, and putting it on a hands-on tester req is how you end up interviewing people who have not touched Burp in three years. Leave it off.

What Goes in the Compensation Section

A number. Post it.

California, Colorado, New York, Washington, and a growing list of others require a range on the posting anyway, so for a lot of you this is settled. The better argument is your own calendar. A hidden band is how a search reaches round four with a finalist whose number was never reachable, which costs you five weeks and the candidate a lot of goodwill.

Public data on this role is unusually noisy, so calibrate before you commit. Glassdoor puts the median total pay for a penetration tester near $154,700, with the middle half running roughly $117,000 to $207,000. ZipRecruiter, which reads posted listings rather than closed offers, lands closer to $119,900 with most listings between $96,000 and $141,000. Both are describing something real. Glassdoor is counting bonus and additional pay at product companies, and ZipRecruiter is counting what employers are willing to advertise, which skews lower on purpose.

The Bureau of Labor Statistics projects 29% growth for information security roles from 2024 to 2034, about 16,000 openings a year. That bucket lumps analysts and offensive specialists together, so treat it as direction rather than a benchmark. Direction is still useful. Demand is not your constraint on this hire. Supply is, and specifically supply of people who can chain findings and then write about them clearly.

For a market-specific band, run the role through the KORE1 salary benchmark tool before the posting goes up. Contract testers are a separate calculation, generally $90 to $175 an hour by surface and clearance status.

Hiring panel interviewing a penetration tester candidate in a glass-walled meeting room

Three Versions of the Same Template

Where the role sits changes which paragraphs carry the weight.

First offensive hire on an internal team. This person will scope their own work, buy their own tooling, build the process from nothing, and spend real energy convincing engineering teams to fix things. Say that. The autonomy is the pitch, and the people who want it are not the same people who want a mature program with a defined queue. Weight the posting toward ownership and breadth, and be honest that there is no offensive team to learn from yet.

Consultancy or MSSP side. Volume, variety, and client contact. Fifteen to thirty engagements a year across environments the tester did not design, which is genuinely harder and builds range faster than any internal role. Put client-facing communication in the requirements and mean it, because the readout call with a nervous CTO is part of the job. Utilization targets belong in the conversation early rather than in week three.

Compliance-driven and regulated. An annual PCI DSS test, a SOC 2 cycle, HIPAA obligations, maybe CMMC if you sell to the Department of Defense. Name the framework in the posting. Testers who have worked with a QSA and know what evidence an assessor will accept are a specific subset, and the ones who have will self-select immediately. One more thing worth saying plainly. If this describes you and the work is genuinely one or two engagements a year, a full-time hire is expensive idle capacity, and our guide to hiring a penetration tester walks through the firm-versus-headcount math in detail.

What Hiring Managers Ask Us About Pen Tester Postings

My posting says OSCP required. Is that costing me candidates?

It is costing you some, and the ones it costs you are not random. Requiring any single certification on a mid-level offensive role removes capable testers who took a different path, and the OSCP is the one most often used as a lazy proxy for hands-on skill. Move it to preferred and put a practical exercise in your interview loop instead. The exception is a client contract or a government requirement that names the credential, in which case it is a real requirement and belongs at the top. We ran a search last spring where dropping “required” to “preferred” roughly doubled the qualified applicant flow inside two weeks.

How much should the posting say about report writing?

More than one bullet. Reporting is close to half the engagement and it is the part clients and boards actually consume. Describe both audiences, the technical write-up with reproduction steps and the executive summary with business impact, and say you will ask for a redacted sample. Two effects follow. Strong writers, who are scarce and know it, read that as a company that values the deliverable. Tool operators who dread writing self-select out before you spend an hour on a screen.

Does the posting need language about authorization?

One sentence is enough, and it is worth including. Something like “all testing is performed under written authorization and defined rules of engagement, with scope agreed by system owners before work begins.” Experienced testers look for it, because the alternative is a company that improvises, and improvising is how somebody ends up testing a system a vendor owns without a signature anywhere. It also signals that your program is mature enough to have thought about scope boundaries, blast radius, and an escalation path. Cheap sentence. Real signal.

We want AI and LLM testing in the scope. How do we write that without it reading as a wish list?

Anchor it to something concrete. Reference the OWASP Top 10 for LLM Applications and name the actual feature, the support chatbot with retrieval over customer records, the agent with write access to your ticketing system. That tells a candidate you have a real target instead of a slide. Put it under Nice to Have unless the LLM surface is genuinely the primary reason you are hiring, since the population with production prompt-injection and agentic-abuse experience is still small and pricing it as a hard requirement narrows your pool fast.

One posting for network, web, and cloud, or three separate reqs?

Three reqs if you have three roles funded. One posting naming one primary surface if you have one. The failure mode is a single posting listing all three, which reads to a specialist as a generalist role and to a generalist as an impossible one, so neither applies with confidence. If you truly need coverage across all three with one head, say so directly and price it at the top of the range, because breadth at real depth is rare and the person who has it knows their market value precisely.

Eleven weeks open, forty applicants, nobody qualified. Where do I look first?

The band, then the requirements, then your loop speed. In that order. Nine times out of ten the number sits a level under the scope described in the bullets, and the qualified people read the gap and never apply. Next, count your hard requirements. If a candidate needs a degree, a clearance, CEH, OSCP, and five years to clear the filter, you have built a wall around a small room. Last, time your process. Offensive candidates run multiple conversations at once and a week of silence between rounds loses them, which stings more than it should when the search is already three months old.

Before You Post It

Read your draft once and check four things. One surface named. A real range showing. Reporting described as work rather than an afterthought. Certifications sitting under preferred unless a contract forces your hand.

Four checks. They catch most of what goes wrong.

If you want a second set of eyes on a pen tester req, help calibrating a band against your market, or a shortlist of testers who can prove an attack path and then explain it to a board, talk to a recruiter on our team. KORE1 has placed security and IT talent since 2005 across 30+ U.S. metros, on contract, contract-to-hire, and direct hire. Our average fill runs 17 days, and 92% of those hires are still in seat a year later, which is the number that actually matters once the offer is signed. When the shortlist lands, our cybersecurity interview questions help separate the people who have broken real systems from the ones who interview well about it.

Leave a Comment