AI Penetration Tester.
San Francisco.
$232,000
median salary, 35% above the national average
$176,000 to $308,000. Updated for 2026.
The numbers.
Everything you need to negotiate with confidence.
San Francisco is 35% more expensive than the national average. For AI Penetration Testers, that shakes out to a median of $232,000, with the full range spanning $176,000 to $308,000. Salary scales with the sophistication of AI-specific attacks performed and the criticality of systems tested. Know the range before you walk in.
Salary range
Tap to place your salary
How San Francisco compares
San Francisco, CA
$232,000
Cost of living: 35% above average
National Average
$172,000
San Francisco is $60,000 above
What you should know
The AI Penetration Tester landscape in San Francisco is not what most salary sites will tell you. San Francisco is the epicenter of venture capital and startup innovation, consistently producing the highest tech salaries in the nation. The city's concentration of AI labs, SaaS companies, and fintech firms creates intense competition for talent. Despite remote work trends, SF still commands the steepest salary premiums for engineering and product roles. Salary scales with the sophistication of AI-specific attacks performed and the criticality of systems tested. Testers who can execute model extraction, membership inference, and adversarial evasion attacks against production systems command premiums. Bug bounty track records and published AI vulnerability research significantly boost compensation.
Junior AI pen testers start at $110,000 to $130,000 executing structured test plans. Mid-level testers designing custom AI attack chains earn $150,000 to $172,000. Senior testers leading enterprise AI security assessments reach $200,000 to $228,000, with principal roles and team leads exceeding $260,000. In San Francisco, those numbers run higher. The cost of living here is 35% above average, and employers adjust to compete.
Base salary is not the full picture. Bonuses of 15 to 25% are typical, with some organizations offering per-vulnerability bounties on top of base compensation. Equity is common at AI security companies, and top testers may earn significant additional income from external bug bounty programs. And on the tax side: california's top marginal state income tax rate is 13.3%, the highest in the U.S. San Francisco has no additional city income tax, but overall tax burden remains steep. When someone quotes you $232,000, ask what the total package looks like. The gap between base and total comp is where real money hides.
On negotiation: Leverage competing offers aggressively. SF employers expect candidates to shop around, and matching or beating a rival offer is standard practice here. The range for AI Penetration Testers in San Francisco runs from $176,000 to $308,000. That is not a narrow window. Where you land inside it depends almost entirely on whether you negotiate and how well you prepare.
Top industries in San Francisco
Negotiating in San Francisco
Leverage competing offers aggressively. SF employers expect candidates to shop around, and matching or beating a rival offer is standard practice here.