PayCrunch Research · The exact AI playbook for your profession, sourced to the U.S. Bureau of Labor Statistics

PayCrunch AI Playbook · Technology

The penetration tester who owns one hard specialty

$222,690top of the range in California · middle $116,580 / yr
AI is transforming this role

Penetration Testers in the United States earn a median of $116,580 a year. Pay starts near $55,940. Pay reaches $222,690 at the top of the range in California, the best-paying state for this work among those with at least 500 people in the job.

Source: U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025 (Computer Occupations, All Other, SOC 15-1299). Last checked 9 September 2026.

Entry level
$55,940
Top of the range · California
$222,690
Education
Bachelor's degree in Cybersecurity
Lower disruption Higher exposure AI is transforming this role
Entry · $55,940 Top of range · $222,690 (California) Middle $116,580

Wages — U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025 (Computer Occupations, All Other). Top of the range is the highest state-level figure among states with at least 500 people in the job. AI-impact rating is PayCrunch's editorial assessment. Updated September 2026.

🆕 New & Trending AI Tools for Penetration TesterReviewed September 2026

We track new AI-tool launches every week and refresh this list — here’s what’s gaining traction for Penetration Tester work right now.

Claude CodeNEWFree / usage-based

Terminal coding agent that reads your repo, runs tests, and ships multi-file changes.

How a Penetration Tester uses it: describe a feature and let it implement and test it across the codebase

OpenAI CodexNEWIncl. w/ ChatGPT plans

Agent that runs longer, deterministic multi-step coding jobs on its own.

How a Penetration Tester uses it: delegate a well-defined build or migration and review the finished result

WindsurfNEWFree / $15 mo

Agentic IDE that keeps context across a whole project.

How a Penetration Tester uses it: make large, coordinated changes without losing track of the codebase

AWS KiroNEWPreview / see site

Spec-driven coding agent that turns written specs into working code.

How a Penetration Tester uses it: write the spec first and let it build to that spec

NotebookLMNEWFree / $7.99 mo

Google tool that answers questions grounded only in the documents you give it — with citations.

How a Penetration Tester uses it: load your own manuals, policies, or PDFs and ask questions that stay accurate to the source

CursorFree / $20 mo

AI-native code editor that edits across an entire project.

How a Penetration Tester uses it: describe a change in plain English and let it rewrite and refactor whole files

GitHub Copilot (Agent Mode)$10–19 mo

AI pair-programmer built into VS Code and GitHub that now completes multi-step tasks.

How a Penetration Tester uses it: hand off a task and have it plan, edit multiple files, and open a pull request

ChatGPTFree / $20 mo

The most-used AI assistant — writing, analysis, research, and images from a plain-language chat.

How a Penetration Tester uses it: draft emails and documents, summarize long files, and get instant answers to on-the-job questions

ClaudeFree / $20 mo

AI assistant known for careful writing, long-document analysis, and coding.

How a Penetration Tester uses it: analyze big reports or spreadsheets and turn messy notes into clean, finished writing

Permission is the first page of the work

A penetration tester works for an employer. Sometimes that employer is the company that owns the systems. Sometimes it is a firm the company has hired. Either way, the work starts when someone with authority writes down what you may test. You read that writing before you touch anything. You can point to what is included and what is out of bounds. If a sentence is ambiguous, you stop and ask the person who owns the engagement. Curiosity without that writing falls outside this career.

The day is professional and narrow on purpose. You are not a free agent looking for trouble on the internet. You are an employee or a contractor inside an agreement. You keep notes a colleague could follow. You tell the engagement lead when something unexpected appears, and you wait if the scope does not already cover it. The companies that hire this role are buying judgment as much as they are buying a test. Judgment means staying inside the page you were given.

People around you may use dramatic language for the field. Your calendar should stay plain. A kickoff, a period of authorized work, a report, and a retest after the client has made changes. Meetings exist so the client understands what they asked for and what they will receive. You speak in the terms the contract uses. You leave the folklore for someone else's hobby. This is a job with a manager, a client, and a file.

Scope, report, retest

The scope is the boundary. It names the systems in bounds, the dates, and the rules of the engagement. You plan your time against that boundary. You do not widen it because a finding looks interesting. You do not shrink it in the report so a missed area disappears. If the client wants a change, they change the writing. You work to the new page, not to a hallway conversation you cannot file. A tester who can describe the scope in a few clear sentences is already doing the job well.

The report is the product the client keeps. It says what you were allowed to examine, what you found, and what the client may choose to fix. You write for a manager who was not beside you. You separate fact from guess. You label severity in the language your team already uses, and you make the next step understandable to the people who own the system. A dramatic report that nobody can act on has failed. A calm report that a busy director can use has succeeded. Writing is not a side task in this career. It is the deliverable.

The retest closes the loop. After the client makes changes, you come back under the same kind of permission and you check what they asked you to check again. You write what is different and what remains. You treat the retest as a comparison with the earlier report, inside the scope you still have. Teams that skip the retest leave the client with a story and no confirmation. Teams that do it become the people a client calls the next year.

The whole engagement in three words

A written scope, a report a manager can use, and a retest after changes. If the writing does not allow a step, that step waits for a new authorization.

A credential many employers already recognize

A credential such as the Offensive Security Certified Professional is common in this field. Offensive Security grants it. The certificate shows you completed that vendor's hands-on assessment under the vendor's rules. It does not replace a written scope at work, and it does not authorize you to test anyone who has not hired you. Employers treat it as evidence that you have done practical work in a structured setting, then they still want to hear how you behave on a real engagement with a real client.

People prepare with the vendor's own course and practice materials, then sit the vendor's assessment. Follow the current rules on the vendor's site rather than a forum summary. The homepage is offsec.com. Other credentials exist, and some employers care more about a history of authorized reports than about any single badge. If you pursue the OSCP, describe it accurately: you hold it, or you are preparing for it. Do not blur that status in a resume sentence.

Preparation that helps you get hired is also about writing and about boundaries. Practice explaining a finding to someone who does not share your hobby. Practice stopping at a limit you were given in a lab or a class, and saying so. Keep a record of authorized work you are allowed to discuss, with names removed when a contract requires it. A credential opens doors. The report samples, cleared for sharing, are what a hiring manager reads when the door is open.

How security teams hire

Companies hire testers onto an internal security team, and consulting firms hire them to serve many clients. Banks, hospitals, manufacturers, and public agencies all buy this work when they want an authorized look at systems they own. Read whether the posting is internal or consulting. An internal role means one environment and a long relationship with the people who fix things. A consulting role means new scopes, more reports, and more time on the road or on calls. The skill overlaps. The week does not.

In the interview, talk about a scope you respected and a report you wrote. Describe a moment you stopped because the authorization ended, even though you wanted to continue. Describe how you explained a serious finding to an engineer who disagreed with you, without turning the conversation into a contest. Skip any demonstration of technique. The people across the table, if they are any good, are listening for restraint and for clarity. A performance of cleverness is a reason to worry.

Ask who writes the scope, who reviews your report before a client sees it, and how a retest is scheduled. Ask what a first year actually contains: shadowing, a piece of a report, or a client of your own. Ask how findings are handed to the teams that fix them, and whether testers are expected to vanish after the report or to stay through the retest. A firm that cannot describe that handoff is telling you the work may be sloppy. You want the firm that can.

From a first report to a lead

Early on you work under a lead. You take a portion of an authorized test, you document as you go, and someone senior edits your section of the report. You learn the firm's voice and the firm's limits. The milestone that matters is a report section a client can use without your lead rewriting every line. Speed comes later. Accuracy and staying inside the scope come first.

A lead agrees the scope with the client, assigns the work, reviews findings before they are final, and stands behind the report. Some leads then manage a practice: staffing, quality, and the relationship with repeat clients. Some testers move toward security program roles where the day is risk conversation and planning rather than testing. Both are real progressions. The weak move is a title change that removes you from report quality and gives you nothing clear instead. Ask what you would still sign.

The people who fix systems are your partners, not your audience. After a report goes out, an engineer may disagree with a finding, ask for clearer language, or need time before a retest makes sense. You answer in the same calm you used in the report. You do not widen the scope to settle an argument. You point back to what was authorized, what was found, and what the retest will confirm. Firms remember testers who make the fixers' work easier. They also remember testers who treat every conversation as a performance. Choose the first reputation, and let the lead handle client politics you have not been asked to own.

Reputation in this work is quiet. Clients remember whether you were easy to understand, whether you stayed inside the agreement, and whether the retest matched the original report. Colleagues remember whether your notes were usable. Build that reputation on purpose. A single story about a boundary you refused to cross will travel farther than a stack of boasts. Keep your credential current in the way the vendor requires, and keep your writing samples honest.

May 2025 pay inside a broad computer series

These figures are Occupational Employment and Wage Statistics, May 2025, for Computer Occupations, All Other. That is a broad series, and an authorized testing career for an employer sits inside it with other computer roles the Bureau groups here. Entry pay is $55,940. The national median is $116,580. The step from entry to the national median is $60,640. The high end of the published range in California is $222,690. From the national median up to that California high end is $106,110. California's high end is a different statistic from every median below. This set does not include a California median to set beside it, so do not invent one.

The District of Columbia holds the highest median, $156,590, which is $40,010 above the national median. Maryland's median is $144,680. Colorado shows $139,580. Virginia shows $139,030. Delaware shows $137,470. Puerto Rico holds the lowest median, $60,470. The spread from Puerto Rico's median to the District of Columbia's median is $96,120. Use $222,690 only as California's high end of the published range. Use $156,590 when you mean the highest median, which belongs to the District of Columbia.

Put the offer letter next to the right figure

Read an offer against $55,940 and $116,580 before you look at $222,690. Someone new to client work can sit near the entry figure while a lead still reviews every page. Someone who already writes a report section a client can use should look at the national median of $116,580 and ask why the offer remains $60,640 below it if the duties are no longer trainee duties. The OSCP, or a comparable credential, can support that sentence. It does not set the wage by itself. Pair it with scopes you have honored and reports you have finished.

Place changes the median you cite. The District of Columbia's $156,590 is the highest median, $40,010 above the national figure. Maryland is $144,680. Colorado is $139,580. Virginia is $139,030. Delaware is $137,470. Puerto Rico's $60,470 is the lowest median, and the $96,120 up to the District of Columbia is the spread between those medians. California enters this conversation only as the high end of $222,690, which sits $106,110 above the national median. That high end differs from the District of Columbia median and from every other median in the set. It is a poor opening number for a first testing job and a fairer topic for a lead whose duties you can read on the offer.

Compare two offers by the work, then by the figure that matches the work. An internal team that keeps you through the retest is a different year from a consultancy that wants a report and a goodbye. The national median of $116,580 can fit either shape once you are no longer new. The District of Columbia median of $156,590 fits a conversation about that place's midpoint, $40,010 above the country. Maryland, Colorado, Virginia, and Delaware stay in the conversation as medians: $144,680, $139,580, $139,030, and $137,470. If someone in California quotes $222,690, ask them to say high end out loud, and ask for the guaranteed salary in the same breath. Puerto Rico's median of $60,470 matters only if that is the market in front of you. The $96,120 spread up to the District of Columbia is a comparison of medians, useful when you are truly choosing between those places and useless as a personal demand.

Ask whether the pay covers travel, on-call during an engagement, and the writing time after the test ends. The report is the product, so unpaid nights of writing are a pay cut you should see before you sign. Get the guaranteed salary next to $116,580, name the state median that matches the office, and leave $222,690 in a separate sentence about California's high end. The figures check the offer. A scope you will honor, and a report a client can use, are why an employer should pay it.

The top of Penetration Tester pay — and how to get there with AI

$222,690what Penetration Tester pay reaches in California

Highest state-level top-of-range annual wage for Computer Occupations, All Other, among states with at least 500 people in the job. U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025.

And the role it leads to — Computer and Information Systems Managers — reaches $327,300 in Washington.

$55,940entry$116,580middle$222,690top end

Generalist application testing is the crowded floor of this range; the top belongs to testers who own one difficult target class that few people can assess and no client can skip.

Performing security analyses of developed or packaged software components, and verifying the security and scalability of a system architecture, is worth more when the architecture is unusual. Scanners and assistants now cover the routine findings, injection classes, misconfiguration, missing patches, and clients know it, so a report made of those findings prices like a commodity. What holds its price is depth: privilege paths across an Amazon Elastic Compute Cloud EC2, Amazon DynamoDB and Amazon Redshift estate; embedded and hardware targets; payment or industrial control systems; or the newest of them, applications wired into a model where the interesting flaw is in the tool call rather than the request.

Your playbook, by where you are now

Just startingDo the whole cycle properly first

  1. Build a lab and rebuild it after each engagement, so your tooling is yours rather than borrowed from a course.
  2. Write the report as though a developer, not a security person, has to act on it, because writing is what clients are really buying.
  3. Research and test the patches and fixes yourself, so you can say precisely what a remediation changed.
  4. Take the practical, hands-on certification your target employers list, not the multiple-choice one that is easier to book.
  5. Use Cursor or GitHub Copilot for throwaway tooling, and read every line before you point it at a client's estate.

What proves it: A hands-on certification plus one redacted report you are willing to show a hiring panel.

Realistic span: the first two or three years

A few years inChoose the corner and go deep

  1. Commit to one target class: cloud identity, embedded devices, payment systems, industrial control, or model-backed applications.
  2. Rebuild that target class in your lab, including the parts that are awkward to obtain, since that awkwardness is the barrier keeping others out.
  3. Publish research or tooling for the class, because in this field visible work is how the narrow engagements find you.
  4. Give customers and installation teams written guidelines for implementing that class securely, rather than only listing what you broke.
  5. Learn the standard your clients are assessed against in your corner, so your findings map onto it without translation.

What proves it: Published research or a released tool in your target class, and engagements booked for it by name.

Realistic span: years four through seven

ExperiencedBecome the escalation, then sell it

  1. Take the engagements nobody else can staff and set your rate against that scarcity rather than against a day-rate table.
  2. Train system users and internal teams in your specialty, and build a practice around it instead of a personal reputation.
  3. Move into red-team leadership or offensive research, where scoping and technique development are the actual job.
  4. Advise on design concepts and project costs before systems are built, which is where a tester's judgement is worth most.
  5. Compare markets; California prices this work highest among the states, and systems leadership is the usual rung above a named practice.

What proves it: A named practice or research line, with clients asking for you by specialty.

Realistic span: year eight and beyond

The next 90 days

Over the next ninety days, read back through your last ten reports and sort every finding into two piles: the ones a scanner or a junior could have produced, and the ones that needed you. The second pile is small, and it is your whole future rate. Look at what those findings have in common, because that is usually a target class rather than a technique: a cloud identity path, a device you took apart, a protocol nobody else on the team reads. Then spend the rest of the quarter building that one thing in a lab you control, deliberately including the setup that is tedious to arrange. Tedious setup is exactly why the work stays scarce, and scarce work is what this range pays for at the top.

Wage figures: BLS OEWS, May 2025. The playbook is PayCrunch editorial guidance, not a guarantee of pay or placement.

Careers related to Penetration Tester

Similar pay, same field

Where this can lead

Every figure is the national median from the U.S. Bureau of Labor Statistics (OEWS) shown on that role’s own page.

Never used AI before? Start here (2 minutes).

Add AI to the tools you already run, starting with your web proxy. Burp Suite now has AI features and Caido is an AI-friendly alternative; use them to triage traffic and spot anomalies faster. Pair that with PentestGPT for structured next-step guidance during an engagement, and treat its suggestions as hypotheses you verify, never commands you run blindly.

For learning and scripting, use Claude or ChatGPT to explain an unfamiliar protocol, write a proof-of-concept in a lab, or decode obfuscated code, and NotebookLM to turn a target's public documentation and the OWASP guides into a queryable reference. Keep client data and real findings out of consumer tools - use your own lab, sanitized snippets, or approved enterprise AI only.

The one rule, forever: Only test systems you have explicit, written authorization to test, strictly within the agreed scope - unauthorized access is a crime under laws like the CFAA, no matter how good your intentions. Never point AI-driven tooling at out-of-scope targets, never paste client findings, credentials, or sensitive data into a consumer AI tool (NDA and leakage risk), and never run an AI-suggested exploit against production without understanding exactly what it does - it can cause real damage or outages. AI can also hallucinate CVEs and exploits; verify everything.
The plays — exact steps, exact prompts

Do these in order. Each one is copy-paste ready. You do not need to know anything about AI going in.

1
Recon and map attack surface faster
Why this pays: Coverage is everything - the vulnerabilities you find are limited by the attack surface you actually map. AI-accelerated recon lets you enumerate more assets and spot the promising targets faster, which means more findings per engagement and more paid bounties per hour.
NucleiShodanClaude
1
Run template-based scanning with Nuclei and asset discovery with Shodan, then use AI to triage the noise and rank targets by likely exploitability.
2
Turn scattered recon output into a prioritized attack plan.
Copy-paste this prompt
Act as a penetration tester. Here is sanitized recon output for an authorized engagement - open ports, technologies, and endpoints: [paste sanitized data]. Prioritize the most promising attack paths, the specific vulnerability classes to test for each technology, and the OWASP checks I should not skip.
Authorized, in-scope targets only, and paste sanitized data. The plan is a hypothesis - verify each finding manually.
3
Generate custom Nuclei templates with AI to test for a specific pattern you noticed, then validate them in your lab before firing at the target.
What you'll haveBroader, better-prioritized coverage in less time - more validated findings per engagement, the core of a tester's value and bounty income.
2
Go deeper on exploitation and payload crafting
Why this pays: The findings that pay - critical, chained, business-impacting bugs - require real exploitation skill. AI that helps you understand a vulnerability, adapt a payload, and script a proof-of-concept lets you push past surface findings into the high-severity ones that command senior rates and top bounties.
Burp SuitePentestGPTMetasploit
1
Use Burp Suite's AI features and PentestGPT to reason about a tricky injection or auth flaw and suggest payload variations - which you test manually and understand fully.
2
Build and adapt a proof-of-concept safely in a lab.
Copy-paste this prompt
Explain how an SSRF vulnerability in this sanitized request could be exploited and what to test to confirm impact - internal service access, metadata endpoints, chaining potential. Write a safe proof-of-concept I will run only in my authorized lab. Educational, in-scope testing only.
Lab and authorized scope only. Understand every line before running it; never fire an AI-generated exploit at production blindly.
3
Chain individual findings into a full attack narrative - the difference between a low-value list of bugs and a high-impact, well-paid report.
What you'll haveDeeper, chained, high-severity findings - the critical bugs that earn senior rates and the largest bounty payouts.
3
Reclaim your biggest time sink: reporting
Why this pays: Report writing eats 30 to 50 percent of a pentester's time and none of it is hacking. AI that drafts clear, accurate findings and remediation returns that time - directly increasing how many engagements or bounties you can complete, which is how income scales.
ClaudePentestGPTHackerOne (Hai)
1
Turn your verified findings and evidence into a first-draft report you refine.
Copy-paste this prompt
Act as a senior penetration tester writing a client report. From these verified findings - title, affected asset, sanitized reproduction steps, evidence - write clear write-ups with a business-impact summary, CVSS rationale, and specific remediation for both a technical and an executive audience. I will verify all technical detail.
Draft only - you verify every technical claim, CVSS score, and reproduction step. Sanitize client-identifying data before pasting.
2
Use AI to translate the same finding into an executive-summary version - the business-impact framing is what makes clients and program managers act.
3
Build a reusable, AI-assisted report template and finding library so each report starts mostly written.
What you'll haveReports done in a fraction of the time with no loss of rigor - the reclaimed hours that let you take on more paid work.
4
Turn skills into direct bug bounty income
Why this pays: Bug bounty is an uncapped, direct top-of-range lever - top hunters earn well beyond any salary. AI multiplies the two things that drive bounty income: how many targets you can cover and how fast you can write a payout-worthy report.
Burp SuiteCaidoHackerOne
1
Pick a program on HackerOne or Bugcrowd, read the scope carefully, and use AI to quickly get up to speed on the target's tech stack and likely weak points - strictly within the program's rules.
2
Study disclosed reports to find recurring, high-value patterns.
Copy-paste this prompt
Summarize the common vulnerability patterns in disclosed bug bounty reports for GraphQL APIs: the root causes, how they were found, and a testing checklist I can apply to similar targets. Educational summary for authorized testing.
For skill-building on authorized programs; every submission must be found and verified by you within the program's defined scope.
3
Use AI-drafted, verified reports to submit faster and cleaner - well-written reports triage quicker and can earn higher payouts.
What you'll haveMore authorized targets covered and faster, cleaner submissions - the uncapped bounty income that can dwarf a base salary.
5
Level up with certifications the market pays for
Why this pays: Offensive-security certifications - OSCP, then OSEP, OSWE, and beyond - directly gate rates and senior roles. AI is a relentless lab partner that compresses the brutal prep time these hands-on exams demand.
ClaudePentestGPTKali Linux
1
Work through lab machines and use AI as a hint engine when you are truly stuck - ask for the next concept to explore, not the answer, so you actually learn.
2
Drill weak areas with a targeted study plan.
Copy-paste this prompt
Act as an OSCP coach. Build me a study plan to close my weak areas in Active Directory attacks and privilege escalation, with the core concepts, a practice sequence, and the mistakes people make on the exam. Then quiz me one scenario at a time and critique my methodology.
A learning aid - most certs forbid AI during the exam itself, so use it to build genuine skill beforehand, not to lean on.
3
Have AI review your methodology and note-taking - the disciplined, repeatable process is what passes hands-on exams and impresses employers.
What you'll haveFaster progress through the certifications that gate offensive-security pay - the credentials behind senior rates.
6
Own the scarce niche: AI and LLM red teaming
Why this pays: Every company is shipping AI features, and almost no one can test them. Becoming the person who red-teams LLM applications - prompt injection, data leakage, agent abuse - puts you in the highest-demand, least-crowded offensive-security niche of 2026, where rates are set by scarcity.
Microsoft PyRITgarakPromptfoo
1
Learn the OWASP Top 10 for LLM Applications and practice against test systems with AI red-team tooling like PyRIT and garak.
2
Build a repeatable LLM assessment methodology.
Copy-paste this prompt
Act as an AI security specialist. Help me build a test plan to red-team an LLM-powered customer-support agent for prompt injection, sensitive-data leakage, jailbreaking, and tool/agent abuse, mapped to the OWASP LLM Top 10. List concrete test cases and what a finding looks like. Authorized testing only.
For authorized engagements only; adapt to the specific system and confirm scope covers the AI components and their tools.
3
Publish a sanitized write-up or a tooling contribution to establish yourself as a name in AI red teaming - visibility in a scarce niche sets your rate.
What you'll havePositioning in the hottest, least-crowded offensive-security niche - the scarcity that pushes rates to the top of the band.
Your 12-month sequence to the top of the range

How the plays above stack into a path from median pay toward the $222,690 tier.

Month 1
Add AI to your proxy and recon workflow (Burp/Caido, Nuclei, PentestGPT) and start every engagement with an AI-prioritized attack plan - verifying manually. Draft your first AI-assisted report.
Months 2-3
Use AI to go deeper on exploitation in your lab and chain findings; build a reusable report template and finding library.
Months 3-6
Start authorized bug bounty work with AI-accelerated recon and reporting; use AI as a lab partner to progress toward OSCP or your next cert.
Months 6-12
Specialize - cloud, Active Directory, or the scarce AI/LLM red-teaming niche - and publish a sanitized write-up that establishes your name and rate.
Gear for this job

As an Amazon Associate, PayCrunch earns from qualifying purchases. Links to books and tools are for the job on this page; we only recommend what we’d use in the work.

Li Bug Bounty Bootcamp (No Starch)

No Starch Press 2021, ISBN 978-1-71850-154-6. Publisher web-hacking / reporting desk book for this page’s Turn skills into direct bug bounty income play. Not OffSec store-only PEN-200, not a leftover OSCP dump, and not CompTIA Security+ (that is infosec / software-engineer). HTTP 200 on /dp/1718501544.

Next steps for a Penetration Tester

Some links below are affiliate or partner links. PayCrunch may earn a commission if you enroll or subscribe through them, at no extra cost to you. Wage figures on this page still come from the Bureau of Labor Statistics, not from these programs.

Penetration Tester work is specific enough that a stamped 'check out these courses' block would be noise. BLS files this work as Computer Occupations, All Other (SOC 15-1299). O*NET Job Zone 4 is typical: a bachelor's degree, so the honest next credential is a professional certificate or bachelor's-level coursework — not a random catalog dump.

The occupation's listed knowledge area is Geography, which is what the course searches below actually query.

Penetration Testers in this dataset list AJAX among the tools in use, so a program that names that stack is a better fit than a survey course.

Geography programs on Coursera for Penetration Tester work

Coursera search for geography — a professional certificate or bachelor's-level coursework that lines up with computing, not a generic professional-development aisle.

Geography courses on edX

edX search for geography, aimed at computing (SOC 15-1299). Same field as the Coursera link, different university catalog.

Screened remote and flexible Penetration Tester listings on FlexJobs

FlexJobs screens remote, hybrid, freelance, and flexible listings so you are not wading through unverified ads. This is a job-board search for Penetration Tester work, not a claim that they list a counted SOC 15-1299 inventory.

Build a Penetration Tester resume on Resume Now

Write a Penetration Tester resume, or one aimed at Computer and Information Systems Managers, instead of a blank template. Resume Now is a resume builder; we are not claiming a counted template set for this SOC.

Build a Penetration Tester resume on Zety

A Penetration Tester resume that names the actual tasks on this page, or the step-up title Computer and Information Systems Managers, beats a blank template when you apply.

What Penetration Testers earn by state

These are the Bureau of Labor Statistics’ own figures for Computer Occupations, All Other, state by state — not a cost-of-living adjustment applied to the national number. Only states employing at least 500 people in the occupation are shown, because a state median drawn from a handful of workers is noise rather than a signal.

District of Columbia
$156,590
highest of them · +34% vs the national median
Puerto Rico
$60,470
lowest of the 50 states and territories that qualify · -48% vs the national median
The same job pays $96,120 more a year at the median in District of Columbia than in Puerto Rico — 159% higher. That gap is what the Bureau measured, before any question of what it costs to live in either place. The top-of-range figure quoted at the head of this page, $222,690, is a different statistic in a different place: it is the 90th-percentile wage in California. The state that pays the typical worker most and the state where the best-paid go highest are not always the same one.
District of Columbia$156,590Maryland$144,680Colorado$139,580Virginia$139,030Delaware$137,470California$134,440Washington$128,940Connecticut$127,720

Source: U.S. Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025, SOC 15-1212. 50 states and territories clear the 500-employee reporting floor for this occupation; those below it are left out rather than shown with a wide error band.

Free data. Use any of it.

PayCrunch publishes verified, BLS-sourced salary + AI-playbook data on 1,000+ professions — free, no signup.

Frequently asked
Will AI replace penetration testers?
No, though it is changing the work and autonomous pentest tools are getting real. AI handles breadth - recon, known-pattern scanning, first-draft reports - but it cannot legally scope an engagement, creatively chain vulnerabilities, judge true business impact, or take responsibility for testing a live system. Testers who use AI to cover more ground and report faster pull ahead; those who only ran a scanner and pasted the output are exactly who automation replaces. Move toward deep exploitation, red teaming, and AI security.
Is it safe to use ChatGPT or PentestGPT during an engagement?
Only with sanitized inputs and only against authorized, in-scope targets. Never paste client findings, credentials, or sensitive data into a consumer AI tool - NDA and data-leakage rules apply - and never run an AI-suggested exploit against production without fully understanding it. Use approved enterprise AI or your own lab, and verify everything, because AI hallucinates CVEs and exploits.
How does AI actually increase a pentester's pay?
By multiplying coverage and reclaiming time. Faster recon and exploitation mean more validated, higher-severity findings per engagement; AI-assisted reporting gives back the 30 to 50 percent of time reporting used to consume; and both effects supercharge uncapped bug bounty income. Add AI-accelerated certification prep and the scarce AI red-teaming niche, and you have several direct paths above the median.
Is it legal to use AI hacking tools?
The tools are legal; using them without authorization is not. Everything you do must be within an explicit, written scope - a signed engagement or a bug bounty program's rules. Pointing AI-driven tooling at systems you are not authorized to test is a crime under laws like the CFAA regardless of intent. Authorization first, always.
Which AI skill should a penetration tester build first?
AI-assisted reporting, because it instantly returns the biggest non-hacking time sink and lets you take on more work. Right behind it, build the AI/LLM red-teaming skill set - it is the scarcest, fastest-growing niche in offensive security and commands premium rates.
Methodology & sources
  • Salary (median, 10th, top of the range) — U.S. Bureau of Labor Statistics, OEWS.
  • By state — the Bureau of Labor Statistics’ own state medians, limited to states employing at least 500 people in the occupation. No cost-of-living arithmetic is applied to a wage anywhere on this page.
  • The plays — PayCrunch's own step-by-step guidance using publicly available AI tools. Tool names/URLs are real and current as of August 2026; prompts written to work as-is. Verify any professional output before relying on it.

Sources