Occupation Details
Penetration Testers
Evaluate network system security by conducting simulated internal and external cyberattacks using adversary tools and techniques. Attempt to breach and exploit critical systems and gain access to sensitive information to assess system security.
Quick Navigation
Salary & Job Outlook
Starting Salary
$54,820.00
New York StateMedian Salary
$92,750.00
New York StateExperienced Salary
$121,450.00
New York StateNational Average for Comparison
New York State Job Market Outlook
Jobs Right Now (2018)
6,380
professionals in NYFuture Job Growth (2030)
7,280
+90 jobs/yearNew Jobs Every Year
583
new opportunities yearlyGrowth Rate
0.1%
projected increasePreparation: Experience, Training, and Education
The list below outlines the prior educational experience required to perform in this occupation.
Degree Needed - Four-year college
Experience Requirements
A considerable amount of work-related skill, knowledge, or experience is needed for these occupations. For example, an accountant must complete four years of college and work for several years in accounting to be considered qualified.
Education Requirements
Most of these occupations require a four-year bachelor's degree, but some do not.
Training Details
Employees in these occupations usually need several years of work-related experience, on-the-job training, and/or vocational training.
Transferrable Skills and Experience
Many of these occupations involve coordinating, supervising, managing, or training others. Examples include real estate brokers, sales managers, database administrators, graphic designers, conservation scientists, art directors, and cost estimators.
School Programs
The following lists school programs which are applicable to this occupation.
Licensing & Certification
State License and Certifications Requirements are not currently associated with this occupation.
Apprenticeship
Contact your regional representative to learn more about apprenticeships available in your area by visiting Apprenticeship Contacts.
Skills
Skills information is not available for this occupation.
Knowledge
Knowledge information is not available for this occupation.
Work Environment
Work Environment information is not available for this occupation.
Work Styles
Work styles information is not available for this occupation.
Tools & Technology
This list below describes the machines, equipment, tools, software, and information technology that workers in this occupation will use.
Tools
Tool information is not available for this occupation.
Technology
Technology information is not available for this occupation.
Duties
Job duties information is not available for this occupation.
Tasks
The list below outlines specific tasks that a worker in this occupation is called upon to do regularly.
- Assess the physical security of servers, systems, or network devices to identify vulnerability to temperature, vandalism, or natural disasters.
- Collect stakeholder data to evaluate risk and to develop mitigation strategies.
- Conduct network and security system audits, using established criteria.
- Configure information systems to incorporate principles of least functionality and least access.
- Design security solutions to address known device vulnerabilities.
- Develop and execute tests that simulate the techniques of known cyber threat actors.
- Develop infiltration tests that exploit device vulnerabilities.
- Develop presentations on threat intelligence.
- Develop security penetration testing processes, such as wireless, data networks, and telecommunication security tests.
- Discuss security solutions with information technology teams or management.
- Document penetration test findings.
- Evaluate vulnerability assessments of local computing environments, networks, infrastructures, or enclave boundaries.
- Gather cyber intelligence to identify vulnerabilities.
- Identify new threat tactics, techniques, or procedures used by cyber threat actors.
- Identify security system weaknesses, using penetration tests.
- Investigate security incidents, using computer forensics, network forensics, root cause analysis, or malware analysis.
- Keep up with new penetration testing tools and methods.
- Maintain up-to-date knowledge of hacking trends.
- Prepare and submit reports describing the results of security fixes.
- Test the security of systems by attempting to gain access to networks, Web-based applications, or computers.
- Update corporate policies to improve cyber security.
- Write audit reports to communicate technical and procedural findings and recommend solutions.

