Penetration testers, also known as ethical hackers, simulate cyberattacks against networks, applications, and physical security systems to identify vulnerabilities before malicious actors can exploit them. They use a mix of automated tools and manual techniques to probe firewalls, web applications, wireless networks, and even employee behavior through social engineering tests. After completing an engagement, they document their findings in detailed reports and recommend remediation strategies to strengthen an organization's defenses.
| Entry level | $70,000 |
| Median | $110,000 |
| Senior | $145,000 |
| Top 10% | $185,000 |
| Job growth | +32% |
| Professionals in the USA | 0.2 million |
| Typical hours/week | 42 hrs |
| Remote work share | 55% |
| Annual job openings | 18,000/yr |
| Demand | Very High |
AI is transforming penetration testing by automating vulnerability scanning, reconnaissance, and basic exploit chaining, allowing testers to focus on complex, creative attack scenarios. However, adversarial thinking, social engineering, and business context understanding remain deeply human skills. The role is evolving toward AI-augmented testing rather than replacement.
Automation exposure: Automated scanning, known vulnerability detection, basic fuzzing, report generation, and repetitive compliance checks are increasingly handled by AI-driven tools.
The human edge: Creative exploitation of novel logic flaws, chaining unconventional attack paths, social engineering, understanding business risk context, and adapting to unique organizational environments require human intuition and judgment that AI cannot fully replicate.
Figures are estimates for exploration — verify current data with BLS.gov.