1

Security Test Engineer Jobs (NOW HIRING)

Everforth ECS is seeking a Senior Security Test Engineer to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax . Please Note: This position is contingent upon ...

New

They are seeking a Senior Security Test Engineer to oversee security test engineering across the War Data Platform, focusing on embedding automated security validation and compliance in DevSecOps ...

New

We're looking for a Security Test Engineer to design and execute test strategies that ensure the robustness and integrity of advanced silicon and IP products. You'll work across teams to identify ...

Senior Security Test Engineer

Holmdel, NJ

$127.90K - $175.40K/yr

The Role We're looking for an experienced and driven Senior Security Test Engineer to join our awesome Engineering team. In this role, you'll take our security test strategy to the next level ...

next page

Showing results 1-20

Security Test Engineer information

See salary details

$11K

$109.6K

$183.5K

How much do security test engineer jobs pay per year?

As of Jun 1, 2026, the average yearly pay for security test engineer in the United States is $109,565.00, according to ZipRecruiter salary data. Most workers in this role earn between $80,000.00 and $143,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Security Test Engineer, and why are they important?

Security Test Engineers require a solid background in cybersecurity, vulnerability assessment, and penetration testing, often supported by a degree in computer science or a related field. Familiarity with tools such as Burp Suite, Metasploit, Nessus, and certifications like CEH or OSCP is typically necessary. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for identifying and explaining security risks. These competencies are essential to proactively detect vulnerabilities and ensure the robustness of critical systems against evolving cyber threats.

How does a Security Test Engineer typically collaborate with development and operations teams during a project?

Security Test Engineers work closely with both development and operations teams to integrate security practices throughout the software development lifecycle. They often participate in design reviews, provide input on secure coding practices, and coordinate with developers to remediate identified vulnerabilities. Additionally, they may run penetration tests or vulnerability scans and then work with operations to ensure any security controls or patches are properly implemented. Effective communication and teamwork are crucial, as Security Test Engineers help bridge the gap between security requirements and practical application.

What is a Security Test Engineer?

A Security Test Engineer is a professional who specializes in identifying and addressing security vulnerabilities within software applications, networks, and systems. They design and execute tests to simulate cyberattacks and assess how well existing security measures protect against threats. Their work involves using tools for vulnerability scanning, penetration testing, and security audits, as well as collaborating with development teams to recommend improvements. Security Test Engineers play a crucial role in ensuring an organization's digital assets remain secure against evolving cyber threats.

Can I make $200,000 a year in cyber security?

Security Test Engineers with extensive experience, advanced skills, and relevant certifications such as CISSP or OSCP can potentially earn $200,000 or more annually, especially in high-demand markets or senior roles. Achieving this salary often requires specialized knowledge, leadership responsibilities, or working for large organizations with competitive compensation packages.

What is the difference between Security Test Engineer vs Security Analyst?

AspectSecurity Test EngineerSecurity Analyst
CertificationsOSCP, CEH, CISSP (preferred)CISSP, CISA, GIAC certifications
Work EnvironmentFocuses on testing security measures, vulnerability assessments, penetration testingMonitors security systems, analyzes threats, develops security policies
Employer & Industry UsageUsed in cybersecurity firms, IT departments, software companiesCommon in financial institutions, government agencies, large corporations

While both roles focus on cybersecurity, Security Test Engineers primarily conduct testing and vulnerability assessments to identify security flaws. Security Analysts monitor and analyze security threats, responding to incidents and developing security strategies. Both roles are essential for a comprehensive security posture but differ in their core responsibilities and daily tasks.

More about Security Test Engineer jobs
Who are the top companies hiring for Security Test Engineer jobs? The top employers for Security Test Engineer jobs are:
What states have the most Security Test Engineer jobs? States with the most job openings for Security Test Engineer jobs include:
Infographic showing various Security Test Engineer job openings in the United States as of May 2026, with employment types broken down into 1% As Needed, 81% Full Time, 17% Part Time, and 1% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $109,565 per year, or $52.7 per hour.
Senior Security Test Engineer

Senior Security Test Engineer

ECS

Falls Church, VA โ€ข On-site

Full-time

Posted 2 days ago


Job description

Everforth ECS is seeking a Senior Security Test Engineer to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax. Please Note: This position is contingent upon contract award.
The War Data Platform (WDP) is a key initiative within the U.S. Department of War's (DoW) AI-First strategy introduced in early 2026. The WDP separates business and financial data from operational warfighting data, aiming to accelerate the deployment of artificial intelligence (AI) on the battlefield. The WDP extends to Unclassified, Secret, and Top Secret environments, and supports collaboration between Combatant Commands, Joint Staff directorates, Senior Executive Service leaders, and operational analysts.
The Senior Security Test Engineer serves as the principal authority for security test engineering across WDP Core Integration's full software development lifecycle, embedding automated security validation, compliance gating, and penetration testing activities directly into DevSecOps pipelines spanning NIPRNet, SIPRNet, and JWICS. This is a senior technical role responsible for translating DoW cybersecurity requirements and contract obligations into concrete, measurable test strategies that protect mission-critical software releases and sustain continuous authorization across all WDP enclaves.
โ€ข Conducts advanced test engineering operations supporting War Data Platform (WDP) Core Integration software lifecycle activities across development, testing, integration, staging, and production environments on NIPRNet, SIPRNet, and JWICS.
โ€ข Designs automated test suites using GitLab CI, Jenkins, Selenium, JMeter, SonarQube, OpenSCAP, and approved scanning tools to validate functionality, security, performance, and compliance requirements.
โ€ข Translates contract-level DevSecOps and cybersecurity requirements into concrete security-test objectives and embeds static analysis, software-composition analysis, and dynamic or interactive security testing directly into continuous integration and continuous deployment pipelines with automated gating and reporting.
โ€ข Implements DevSecOps-aligned testing strategies integrating automated gate checks, artifact-lineage verification, regression safety controls, and STIG-based compliance validation.
โ€ข Creates reusable security-testing scripts and supplements automated workflows with targeted manual or penetration-testing activities for high-risk release candidates.
โ€ข Uses Infrastructure-as-Code patterns to provision secure sandboxes that mirror production controls and employ synthetic or masked data to protect sensitive information during testing.
โ€ข Performs virtual-machine and container-security validation using Department of War Security Technical Implementation Guides and defense container-hardening standards embedded in CI workflows.
โ€ข Executes automated and manual testing, documents defects, validates fixes, and triages findings while maintaining a security-testing risk register.
โ€ข Reviews scan results, collaborates with developers for fix verification, and refines rulesets, tooling, and documentation to meet audit and regulatory obligations.
โ€ข Tracks key performance indicators including coverage, detection speed, pipeline stability, and reliability trends to support program reporting and continuous improvement.
โ€ข Coordinates with software engineers, DevSecOps pipeline operators, cybersecurity teams, and system-engineering personnel to reproduce issues, verify corrective actions, and synchronize readiness for sprint and release events.
โ€ข Supports maintenance of test environments, synthetic data sets, and repeatable validation workflows enabling stable, high-confidence software releases across all War Data Platform (WDP) Core Integration enclaves.
โ€ข Performs other duties as assigned.
โ€ข Current Secret security clearance with the ability to obtain and maintain a Top Secret (TS) security clearance with Sensitive Compartmented Information (SCI).
โ€ข 10-12 years of experience in security test engineering, software quality assurance, application security, or a closely related technical discipline, with demonstrated senior-level ownership of security testing strategy and automated pipeline integration in federal or enterprise software delivery environments.
โ€ข Demonstrated hands-on expertise designing and operating automated security test pipelines using tools such as GitLab CI, Jenkins, SonarQube, and OpenSCAP, with applied experience in SAST, DAST, software-composition analysis, STIG compliance validation, and container hardening in classified or government cloud environments.
โ€ข Proven ability to lead penetration testing coordination, security test planning, and risk register management in support of Authority to Operate (ATO) packages, Interim Authority to Test (IATT) preparation, and continuous monitoring obligations under the Risk Management Framework.
โ€ข Experience operating within DoW or federal classified multi-enclave environments, including familiarity with IL2, IL5, IL6, and JWICS software delivery constraints, DoW container hardening standards, and cross-domain security testing requirements.
โ€ข Strong problem-solving and decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
โ€ข Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management).