Jobs / Security / 15-1299.04

Penetration Testers

Evaluate network system security by conducting simulated internal and external cyberattacks using adversary tools and techniques. Attempt to breach and exploit critical systems and gain access to sensitive information to assess system security.

US jobs
435,370 (SOC 15-1299 group, "Computer Occupations, All Other")
Median wage
$116,580 a year
Job family
Security

Can agents do the work of penetration testers?

We read the evidence at the level of the job family, Security:

  • Task levelPartialMixed. Capture-the-flag and vulnerability-reproduction tasks are near their ceiling: Anthropic reports 100% on its 35-task Cybench subset, and the top CyberGym entry reproduces 98.5% of vulnerabilities (Level 1). Exploitation of real web applications is not shown: the last published CVE-Bench result is 12.5% (GPT-4o, 2025), and we found no newer frontier result.
  • Project levelUnexploredNo benchmark in our collection tests security work at project scale, such as a full penetration test, a security review of a whole system, or a compliance audit.

Benchmarks for the job family

These cover work in security, not always this occupation's tasks.

Typical tasks

From O*NET 31.0. Core tasks first. Few of these tasks have a benchmark today.

  • Document penetration test findings.
  • Identify security system weaknesses, using penetration tests.
  • Write audit reports to communicate technical and procedural findings and recommend solutions.
  • Gather cyber intelligence to identify vulnerabilities.
  • Maintain up-to-date knowledge of hacking trends.
  • Keep up with new penetration testing tools and methods.
  • Identify new threat tactics, techniques, or procedures used by cyber threat actors.
  • Conduct network and security system audits, using established criteria.
  • Develop security penetration testing processes, such as wireless, data networks, and telecommunication security tests.
  • Test the security of systems by attempting to gain access to networks, Web-based applications, or computers.
  • Evaluate vulnerability assessments of local computing environments, networks, infrastructures, or enclave boundaries.
  • Prepare and submit reports describing the results of security fixes.
Other job titles for this occupation (37)

Cyber Systems Engineer · Security Consultant · Security Engineer · System Vulnerability Analyst · Threat Hunter · Vulnerability Assessor · Application Security Assessor · Application Security Hacker · Application Security Tester · Certified Tester · Cyber Assessment Tester · Cyber Assessor · Cyber Security Engineer · Cyber Security Tester · Cybersecurity Engineer (Cyber Engineer) · Cybersecurity Specialist · Embedded Tester · Hardware Hacker · Information Security Assessor · Network Exploitation Analyst · Network Security Tester · Penetration Testing Consultant · Risk Tester · Security Application Tester · Security Architect · Security Assessment Tester · Security Automation Tester · Security Consulting Tester · Security Control Assessor · Security Tester · Systems Security Tester · Tester · Vulnerability Analyst · Vulnerability Assessment Analyst · Vulnerability Management Analyst · Vulnerability Management Engineer · Vulnerability Researcher