1

Penetration Testing Government Jobs (NOW HIRING)

Koniag IT Systems, LLC, a Koniag Government Services company, is seeking a Penetration Testing Lead to support KITS and our government customer in Washington, DC. This position is for a Future New ...

Koniag IT Systems, LLC, a Koniag Government Services company, is seeking a Penetration Testing Lead to support KITS and our government customer in Washington, DC. This position is for a Future New ...

Koniag IT Systems, LLC, a Koniag Government Services company, is seeking a Penetration Testing Lead to support KITS and our government customer in Washington, DC. This position is for a Future New ...

Penetration Tester

Chantilly, VA · On-site

$90K - $130K/yr

Conduct penetration testing that uses both active and passive capabilities to expose and exploit IA vulnerabilities. * Review and evaluate information systems and recommend changes to the Government ...

Penetration Tester

Alexandria, VA · On-site

$85 - $110/hr

Assists with planning, scoping, and execution of penetration tests in coordination with Government stakeholders and senior cybersecurity personnel. * Conducts technical testing activities, including ...

Demonstrated experience conducting advanced penetration testing and red team operations within a federal government or large enterprise IT environment. * One or more of the following certifications:

Demonstrated experience conducting advanced penetration testing and red team operations within a federal government or large enterprise IT environment. * One or more of the following certifications:

... government systems. Responsibilities : • Conduct web application, API, and network penetration ... testing following NIST SP 800-115 and OWASP Testing Framework methodologies. • Evaluate ...

Experience with cloud penetration testing (AWS, Azure). * Familiarity with aircraft systems, avionics, or aviation communication protocols. * Prior red team experience in a government or military ...

gTANGIBLE Corporation (gTC), www.gtangible.com, is a C corporation and a registered Government ... Penetration testing will use both automated tools and manual techniques in order to identify ...

Penetration Tester

Washington, DC · On-site

$120 - $180/hr

Experience with cloud penetration testing (AWS, Azure). * Familiarity with aircraft systems, avionics, or aviation communication protocols. * Prior red team experience in a government or military ...

... and government services industry. We deliver tailored solutions, tested leadership, and trusted ... This role is responsible for conducting penetration testing and red team activities, assessing ...

next page

Showing results 1-20

Penetration Testing Government information

See salary details

$22.5K

$119.9K

$168.5K

How much do penetration testing government jobs pay per year?

As of Aug 28, 2026, the average yearly pay for penetration testing government in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What is penetration testing in government?

Penetration testing in government refers to authorized simulated cyberattacks on government systems, networks, or applications to identify vulnerabilities before malicious actors can exploit them. These tests help government agencies strengthen their cybersecurity defenses, comply with regulations, and protect sensitive data. Penetration testers use a variety of tools and techniques to mimic real-world cyber threats, ensuring that security measures are effective and up to date.

What are the key skills and qualifications needed to thrive as a penetration tester in a government setting?

To thrive as a Penetration Tester in government, a deep understanding of network security, vulnerability assessment, and common attack methodologies is required, typically supported by a degree in cybersecurity or a related field. Familiarity with tools like Metasploit, Nmap, Burp Suite, and certifications such as OSCP, CEH, or CISSP are highly valued. Strong analytical thinking, attention to detail, and clear written and verbal communication skills distinguish top performers in this role. These skills are vital to effectively identify security weaknesses, communicate risks, and ensure the protection of sensitive government data and infrastructure.

What are some common challenges faced by penetration testers working in government environments?

Penetration testers in government settings often encounter unique challenges, such as navigating strict security protocols, handling sensitive or classified information, and complying with complex regulatory frameworks. They may also work within rigid change management processes, which can impact the speed and flexibility of testing activities. Collaboration with various departments is essential, as testers must communicate findings clearly to both technical and non-technical stakeholders to ensure vulnerabilities are properly understood and remediated.

What is the difference between Penetration Testing Government vs Penetration Testing Private Sector?

AspectPenetration Testing GovernmentPenetration Testing Private Sector
CredentialsCertifications like OSCP, CISSP, CEH often requiredSimilar certifications widely recognized, such as OSCP, CEH, CISSP
Work EnvironmentGovernment agencies, secure facilities, strict protocolsCorporate offices, consulting firms, diverse environments
Employer & Industry UsageFederal, state, or local government agenciesPrivate companies, cybersecurity firms, consulting agencies
Search & Comparison IntentUnderstanding roles within government cybersecurityComparing government vs private sector penetration testing roles

Penetration Testing Government professionals focus on securing government systems within strict protocols, often requiring specific certifications and working in secure environments. Private sector penetration testers work with commercial clients, offering more diverse projects and flexible settings. Both roles demand similar skills and certifications but differ mainly in work environment and employer type.

How much do penetration testing government professionals make?

Penetration testing professionals working for government agencies typically earn between $70,000 and $130,000 annually, depending on experience, security clearance level, and location. Advanced skills in cybersecurity tools, certifications like CISSP or CEH, and knowledge of government security protocols can influence salary levels.

Is there a demand for penetration testing government?

There is strong demand for penetration testers in government sectors due to increasing cybersecurity threats and the need to protect sensitive information. These roles often require knowledge of security tools, compliance standards, and certifications such as CEH or CISSP, and may involve working in secure environments with regular updates to security protocols.

What is the average pay for penetration testing government?

Penetration testers working for government agencies typically earn between $70,000 and $120,000 annually, depending on experience, security clearance, and location. Higher salaries are common for those with specialized skills, certifications like OSCP or CISSP, and roles requiring clearance or advanced technical expertise.
More about Penetration Testing Government jobs

What cities are hiring for Penetration Testing Government jobs?

Cities with the most Penetration Testing Government job openings:

What states have the most Penetration Testing Government jobs?

States with the most job openings for Penetration Testing Government jobs include:

Infographic showing various Penetration Testing Government job openings in the United States as of August 2026, with employment types broken down into 90% Full Time, 3% Part Time, and 7% Contract. Highlights an 97% In-person, and 3% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

External Network Penetration Tester

San Bernardino, CA • On-site

Xtreme Solutions Corporate
IT Services • 51 - 200 employees

Full-time

Posted 27 days ago


Job description

Description:

Position Summary

Performs blind and intelligent penetration testing against internet-facing assets — web applications, firewalls, remote access (VPN/RDP), and internet postings — for all 47 County departments, attempting to obtain confidential/sensitive data using real-world threat intelligence-based techniques while evading detection.


Key Responsibilities

• Conduct external network and web application penetration testing and vulnerability assessments per NIST SP 800-115 methodology.

• Attempt to obtain ePHI, PII, financial data, and privileged communications from external sources without causing service disruption.

• Document all findings with risk ratings, evidence, and remediation recommendations for the Assessment report.

• Attempt to avoid detection and evade department response efforts during testing windows, as scoped.

Requirements:

Required Qualifications

• 4+ years of hands-on external network / web application penetration testing experience.

• Proficiency with industry-standard tools (Burp Suite, Nmap, Metasploit, or equivalent).

• Strong understanding of OWASP Top 10 and common network attack vectors.


Preferred Qualifications

• OSCP, GPEN, GWAPT, or CEH certification.

• Experience testing government or healthcare-sector environments.


Travel

Fully remote; must remain within the continental United States.