Penetration testers, also known as ethical hackers, simulate real-world cyberattacks against an organization's networks, applications, and systems to uncover vulnerabilities before malicious actors can exploit them. They use a combination of automated tools and manual techniques to probe firewalls, web applications, wireless networks, and even employees through social engineering tests. After completing an assessment, they document findings in detailed reports and recommend remediation steps to strengthen security posture.
| Entry level | $70,000 |
| Median | $110,000 |
| Senior | $145,000 |
| Top 10% | $185,000 |
| Job growth | +32% |
| Professionals in the USA | 0.06 million |
| Typical hours/week | 42 hrs |
| Remote work share | 60% |
| Annual job openings | 17,000/yr |
| Demand | Very High |
AI is augmenting penetration testing by automating vulnerability scanning, reconnaissance, and report drafting, allowing testers to focus on complex exploitation and creative attack chaining. However, the adversarial, judgment-driven nature of true penetration testing against evolving human-designed defenses keeps this role largely resistant to full automation. Demand is growing as organizations need experts to validate AI-generated findings and test AI systems themselves.
Automation exposure: Automated scanning, basic vulnerability identification, repetitive fuzzing, initial reconnaissance, and standardized report generation are increasingly handled by AI-powered tools.
The human edge: Creative exploit chaining, social engineering, business context understanding, adversarial thinking that anticipates novel attack paths, and the ability to bypass defenses designed to catch automated tools cannot be replicated by AI alone.
Figures are estimates for exploration — verify current data with BLS.gov.