1

Penetration Testing Government Jobs (NOW HIRING)

Penetration Tester

Washington, DC · On-site

$117K - $199K/yr

ASRC Federal is a leading government contractor furthering missions in space, public health and ... This role combines hands-on testing with leadership, mentoring, and collaboration across ...

Senior Penetration Tester

Middletown, RI · On-site

$96.80 - $161.50/hr

Overview AMERICAN SYSTEMS is an employee‑owned federal government contractor supporting national ... Penetration Testing: Plan, execute, and report on penetration tests and security assessments on ...

CHENG Team Leader

Alexandria, VA · Hybrid

$180K - $225K/yr

Deputy Chief Engineer directly interfaces with DoW Government management leadership. Responsibilities As the lead of the engineering staff of the Chief Engineer, Developmental Test, Evaluation, and ...

Penetration Tester II

Chandler, AZ · On-site

$60K - $180K/yr

M9 Solutions is dedicated to providing IT services and solutions to the Federal Government by ... Experience with continuous penetration testing methodologies. * Experience with planning and ...

Plan, scope, and execute penetration testing engagements across a variety of environments ... government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and ...

Senior Penetration Tester

Middletown, RI · On-site

$118K - $128K/yr

Overview AMERICAN SYSTEMS is an employee-owned federal government contractor supporting national ... Penetration Testing: Plan, execute, and report on penetration tests and security assessments on ...

Showing results 41-60

Penetration Testing Government information

See salary details

$22.5K

$119.9K

$168.5K

How much do penetration testing government jobs pay per year?

As of Aug 8, 2026, the average yearly pay for penetration testing government in the United States is $119,895.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,000.00 per year, depending on experience, location, and employer.

What is penetration testing in government?

Penetration testing in government refers to authorized simulated cyberattacks on government systems, networks, or applications to identify vulnerabilities before malicious actors can exploit them. These tests help government agencies strengthen their cybersecurity defenses, comply with regulations, and protect sensitive data. Penetration testers use a variety of tools and techniques to mimic real-world cyber threats, ensuring that security measures are effective and up to date.

What are some common challenges faced by penetration testers working in government environments?

Penetration testers in government settings often encounter unique challenges, such as navigating strict security protocols, handling sensitive or classified information, and complying with complex regulatory frameworks. They may also work within rigid change management processes, which can impact the speed and flexibility of testing activities. Collaboration with various departments is essential, as testers must communicate findings clearly to both technical and non-technical stakeholders to ensure vulnerabilities are properly understood and remediated.

What are the key skills and qualifications needed to thrive as a penetration tester in a government setting?

To thrive as a Penetration Tester in government, a deep understanding of network security, vulnerability assessment, and common attack methodologies is required, typically supported by a degree in cybersecurity or a related field. Familiarity with tools like Metasploit, Nmap, Burp Suite, and certifications such as OSCP, CEH, or CISSP are highly valued. Strong analytical thinking, attention to detail, and clear written and verbal communication skills distinguish top performers in this role. These skills are vital to effectively identify security weaknesses, communicate risks, and ensure the protection of sensitive government data and infrastructure.

What is the difference between Penetration Testing Government vs Penetration Testing Private Sector?

AspectPenetration Testing GovernmentPenetration Testing Private Sector
CredentialsCertifications like OSCP, CISSP, CEH often requiredSimilar certifications widely recognized, such as OSCP, CEH, CISSP
Work EnvironmentGovernment agencies, secure facilities, strict protocolsCorporate offices, consulting firms, diverse environments
Employer & Industry UsageFederal, state, or local government agenciesPrivate companies, cybersecurity firms, consulting agencies
Search & Comparison IntentUnderstanding roles within government cybersecurityComparing government vs private sector penetration testing roles

Penetration Testing Government professionals focus on securing government systems within strict protocols, often requiring specific certifications and working in secure environments. Private sector penetration testers work with commercial clients, offering more diverse projects and flexible settings. Both roles demand similar skills and certifications but differ mainly in work environment and employer type.

More about Penetration Testing Government jobs
What cities are hiring for Penetration Testing Government jobs? Cities with the most Penetration Testing Government job openings:
What states have the most Penetration Testing Government jobs? States with the most job openings for Penetration Testing Government jobs include:
Infographic showing various Penetration Testing Government job openings in the United States as of August 2026, with employment types broken down into 90% Full Time, 5% Part Time, and 5% Contract. Highlights an 95% In-person, and 5% Remote job distribution, with an average salary of $119,895 per year, or $57.6 per hour.

Penetration Tester

ASRC Federal Holding

Washington, DC • On-site

$117K - $199K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 19 days ago


ASRC Federal rating

7.8

Company rating: 7.8 out of 10

Based on 28 frontline employees who took The Breakroom Quiz

240th of 443 rated engineering


Job description

ASRC Federal is a leading government contractor furthering missions in space, public health and defense. As an Alaska Native owned corporation, our work helps secure an enduring future for our shareholders. Join our team and discover why we are a top veteran employer and Certified Great Place to Work™
ASRC Federal Technology Solutions is seeking an experienced Penetration Testerto lead advanced security assessments and contribute to the development and execution of penetration testing strategies. This role combines hands-on testing with leadership, mentoring, and collaboration across cybersecurity disciplines.
Work Location: Hybrid, DC (3 days per week onsite)
Responsibilities
  • Lead and perform advanced security assessments, including hands-on penetration testing of systems and applications.
  • Identify vulnerabilities, assess risks, and deliver clear, actionable remediation recommendations.
  • Develop and maintain assessment plans aligned withNIST SP 800-53 and FedRAMP Cloud Security Controls.
  • Execute security assessments per defined plans and document findings accurately and promptly.
  • Design, develop, and maintain tools/scripts to automate and enhance penetration testing activities.
  • Manage and mentor a small team of junior penetration testers; provide technical guidance and training.
  • Build and lead a Purple Team to perform joint red/blue team exercises with customer sites.
  • Support secure systems operations and maintenance, including security validation and accreditation activities.
  • Analyze and mitigate system security threats throughout the lifecycle, including risk assessments and implementation of security engineering controls.
  • Ensure compliance with business continuity, operations security, insider threat detection, physical security analysis, and regulatory requirements.
  • Communicate technical findings effectively to technical teams and executive stakeholders.

Requirements
  • Education: Bachelor's degree in a related field.
  • Experience: 5+ years of relevant experience in cybersecurity and penetration testing (or equivalent combination of education and experience).
  • Clearance: Active DOE Q-Clearance or Top Secret (TS) equivalent required.
  • Certifications (Preferred):
    • OSCP (Offensive Security Certified Professional)
    • OSCE (Offensive Security Certified Expert)
    • CEH (Certified Ethical Hacker)
    • CISSP (Certified Information Systems Security Professional)

Technical Skills & Tools
  • Strong proficiency in vulnerability analysis, risk remediation, and reporting.
  • Ability to clearly replicate vulnerabilities and provide actionable mitigation steps.
  • Familiarity with tools including:
    • Linux, Tenable Nessus, Forescout, Carbon Black, Invicti,
    • Scythe, Rubrik, Fidelis
  • Excellent written and verbal communication skills; ability to present technical findings to executive audiences.

We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law. The salary offered will depend on several factors including, but not limited to, relevant experience, skills, education, geographic location, internal equity, business needs, and other factors permitted by law. Posted pay ranges are a general guideline only and are not a guarantee of compensation or salary.
EEO Statement
ASRC Federal and its Subsidiaries are Equal Opportunity employers. All qualified applicants will receive consideration for employment without regard to race, gender, color, age, sexual orientation, gender identification, national origin, religion, marital status, ancestry, citizenship, disability, protected veteran status, or any other factor prohibited by applicable law.

What ASRC Federal employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom