1

Penetration Testing Manager Jobs in Colorado (NOW HIRING)

Penetration Tester

Aurora, CO · On-site

$150K - $195K/yr

... testing methodologies; identifies common vulnerabilities that can be potentially exploited ... collaborating with management to develop security policies, training other cybersecurity ...

Lead Penetration TestEngineer Location: Hybrid 2 days per week onsite on one of our following sites ... testing. Vulnerability Management & Remediation Collaborate with engineering and development teams ...

Lead Penetration TestEngineer Location: Hybrid 2 days per week onsite on one of our following sites ... testing. Vulnerability Management & Remediation Collaborate with engineering and development teams ...

Duties will be focused on application security and penetration testing of applications, and this ... management -Cryptography -Code review Desired Skills: 1) Agile. 2) Healthcare. 3) Bachelor's degree ...

Senior Penetration Testing (Red Team

Denver, CO · On-site

$88K - $109K/yr

Self-motivated and self-management skills Preferred * Strong knowledge of Penetration Testing and covert Red Team operations and Information Security demonstrated by one or more of the following:

Senior Penetration Testing (Red Team

Denver, CO · On-site

$88K - $109K/yr

Self-motivated and self-management skills Preferred * Strong knowledge of Penetration Testing and covert Red Team operations and Information Security demonstrated by one or more of the following:

Program Manager

Colorado Springs, CO · Hybrid

$150K - $190K/yr

... and software penetration testing methodologies for Unmanned Underwater Vehicles (UUVs) or ... Managing technical functions and work efforts across the program portfolio. * Architecting and ...

... management, rollback mechanisms and update orchestration • Oversee cybersecurity validation and verification activities including penetration testing and vulnerability assessments • Collaborate ...

... management, rollback mechanisms and update orchestration • Oversee cybersecurity validation and verification activities including penetration testing and vulnerability assessments • Collaborate ...

... management, rollback mechanisms and update orchestration • Oversee cybersecurity validation and verification activities including penetration testing and vulnerability assessments • Collaborate ...

Senior Manual Ethical Hacker

Denver, CO · On-site

$109K - $148K/yr

... managing risks. • Learn and develop advanced technical and leadership skills, mentor Junior and ... penetration testing tools, triage, and support incidents, and produce high value findings • ...

next page

Showing results 1-20

Penetration Testing Manager information

See Colorado salary details

$59.9K

$139.8K

$195.6K

How much do penetration testing manager jobs pay per year?

As of Aug 10, 2026, the average yearly pay for penetration testing manager in Colorado is $139,812.00, according to ZipRecruiter salary data. Most workers in this role earn between $116,700.00 and $157,700.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a penetration testing manager, and why are they important?

To thrive as a Penetration Testing Manager, you need deep expertise in cybersecurity, vulnerability assessment, and penetration testing methodologies, typically supported by a relevant degree and certifications like OSCP or CISSP. Familiarity with tools such as Metasploit, Burp Suite, and SIEM systems is essential for effectively managing testing operations. Strong leadership, communication, and project management skills help in guiding teams and translating technical findings for stakeholders. These capabilities are crucial to ensure robust security postures, clear risk communication, and successful management of security testing initiatives.

What does a penetration testing manager do?

A Penetration Testing Manager oversees teams that simulate cyberattacks on an organization's systems, networks, and applications to identify vulnerabilities and assess security risks. They are responsible for planning, coordinating, and ensuring the quality of penetration tests, as well as communicating findings to stakeholders and recommending remediation strategies. Additionally, they often develop testing methodologies, manage team performance, and ensure compliance with industry standards and regulations.

What is a penetration testing manager?

A penetration testing manager oversees security teams that conduct simulated cyberattacks to identify vulnerabilities in computer systems and networks. They coordinate testing activities, review findings, and ensure remediation, often requiring knowledge of security tools, methodologies, and relevant certifications like OSCP or CISSP.

What are some common challenges faced by a penetration testing manager when leading a security assessment team?

Penetration Testing Managers often face the challenge of balancing technical depth with project management responsibilities. Coordinating multiple engagements, ensuring consistent testing methodologies, and managing client expectations can be demanding. Additionally, staying updated with evolving threat landscapes and ensuring the team has the necessary skills and certifications are ongoing concerns. Effective communication with both technical staff and non-technical stakeholders is crucial for translating findings into actionable recommendations.

What is the difference between Penetration Testing Manager vs Penetration Tester?

AspectPenetration Testing ManagerPenetration Tester
CertificationsOSCP, CISSP, PMPOSCP, CEH, GPEN
Work EnvironmentOversees teams, manages projects, strategic planningConducts security assessments, performs testing, technical execution
Employer & Industry UsageSecurity firms, large corporations, government agenciesSecurity teams, consulting firms, internal security departments

The main difference is that a Penetration Testing Manager focuses on managing teams, planning projects, and strategic oversight, while a Penetration Tester is hands-on, performing security assessments and testing systems. Both roles require relevant certifications and are integral to cybersecurity, but they differ in responsibilities and scope.

What are the most commonly searched types of Penetration Testing jobs in Colorado? The most popular types of Penetration Testing jobs in Colorado are:
What are popular job titles related to Penetration Testing Manager jobs in Colorado? For Penetration Testing Manager jobs in Colorado, the most frequently searched job titles are:
What cities in Colorado are hiring for Penetration Testing Manager jobs? Cities in Colorado with the most Penetration Testing Manager job openings:
Infographic showing various Penetration Testing Manager job openings in Colorado as of August 2026, with employment types broken down into 70% Full Time, and 30% Part Time. Highlights an 74% In-person, and 26% Hybrid job distribution, with an average salary of $139,812 per year, or $67.2 per hour.

Lead Penetration Tester

Revolutional, LLC

Fort Collins, CO • On-site

$110 - $150K/hr

Full-time

Posted 27 days ago


Job description

Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes.

We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy.

Lead Penetration Tester

Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (project-based; onsite)

Terms: Full-time

Salary Range: $110-$150k DOE

Clearance: Active Secret required

Travel: Yes – travel to agency sites required

Project Description

This position leads operational security assessments and penetration testing across a portfolio of federal agencies and web applications. Assessments are conducted in accordance with the ISC Security Assessment Methodology and applicable federal rules of engagement, producing findings that reach agency CIO and CISO-level leadership. The program also requires FedRAMP-qualified penetration testing support for cloud service authorization activities.

The core challenge: leading a high-tempo assessment program across multiple agencies per year — each with distinct environments, rules of engagement, and stakeholder expectations — while producing deliverables that meet the evidentiary and presentation standards of senior federal leadership.

Position Description

As a Lead Penetration Tester at Revolutional, you own the end-to-end execution of operational security assessments and web application penetration tests across a federal agency portfolio. You develop test plans, lead technical execution, produce security assessment reports and criticality matrices, and deliver out-brief presentations directly to agency CIO and CISO-level audiences. You are the senior technical authority on every engagement you lead.

You bring deep experience with federal assessment methodologies — ISC Security Assessment Methodology, OWASP, NIST SP 800 series, and DISA STIG — and hold or are actively pursuing CISA AES certification. You are equally comfortable executing a technically complex assessment and standing in front of agency leadership to explain what you found and what it means.

What You Will Own
  • Operational security assessment leadership across a portfolio of federal agencies (approximately 6–7 per year)
  • Web application security assessments (approximately 3–4 applications per year)
  • Test plan and rules of engagement development for each assessment
  • Criticality matrix development and risk prioritization
  • Security assessment report authorship and quality
  • Out-brief presentations to agency CIO and CISO-level leadership
  • FedRAMP penetration testing support for cloud service authorization
Responsibilities
  • Lead operational security assessments across federal agencies in accordance with the ISC Security Assessment Methodology and applicable rules of engagement; manage approximately 6–7 agency assessments per year
  • Conduct web application security assessments using OWASP methodology; assess approximately 3–4 applications per year across a range of agency environments
  • Develop comprehensive test plans for each engagement: scope definition, assessment objectives, methodology selection, rules of engagement, and timeline
  • Build criticality matrices that prioritize findings by risk, asset value, and mission impact to support agency remediation planning
  • Author detailed security assessment reports documenting findings, evidence, risk ratings, and actionable remediation guidance meeting federal evidentiary and reporting standards
  • Develop and deliver out-brief presentations to agency CIO, CISO, and senior leadership audiences; communicate complex technical findings with clarity and executive-level credibility
  • Conduct FedRAMP-qualified penetration testing in support of cloud service authorization activities; apply FedRAMP pen testing requirements and documentation standards
  • Apply NIST SP 800 series guidance and DISA STIG methodology throughout assessment planning, execution, and reporting
  • Coordinate with agency stakeholders before, during, and after assessments to manage expectations, address questions, and ensure findings are understood and acted upon
  • Stay current on vulnerability research, offensive techniques, and emerging attack surfaces relevant to federal civilian agency environments
What You Bring (Requirements)Baseline Requirements
  • Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience)
  • 5 or more years of hands-on penetration testing experience, with demonstrated experience leading assessments in federal environments
  • CISA AES (Authorized External Security) certification required, or actively in process of obtaining
  • FedRAMP penetration testing experience required
  • Active Secret clearance
  • Ability and willingness to travel to agency sites as required
Technical & Domain Capabilities
  • Deep experience conducting operational security assessments in accordance with the ISC Security Assessment Methodology and federal rules of engagement
  • Proficiency with OWASP methodology applied to web application security assessments across federal environments
  • Working knowledge of NIST SP 800 series guidance as applied to security assessment planning, execution, and reporting
  • Experience applying DISA STIG methodology to assessment scope and findings documentation
  • Experience developing test plans, criticality matrices, and security assessment reports that meet federal evidentiary and leadership reporting standards
  • Demonstrated experience presenting technical security findings to CIO, CISO, and senior agency leadership audiences
  • FedRAMP-qualified penetration testing experience, including familiarity with FedRAMP pen test requirements, documentation, and cloud authorization processes
  • Proficiency with industry-standard penetration testing toolsets for network, application, and infrastructure assessments
Core Strengths
  • Senior assessment lead: you own engagements end-to-end and your findings are technically sound, clearly documented, and risk-rated with precision
  • Executive-ready communicator — you develop and deliver out-brief presentations that land with CIO and CISO audiences, not just technical teams
  • Methodologically disciplined: you work within rules of engagement, document everything, and produce deliverables that hold up under agency and regulatory scrutiny
  • High-tempo operator who manages multiple concurrent engagements across different agency environments without loss of quality or attention to detail
Certifications

The following certifications are required or strongly preferred:

Required
  • CISA AES (Authorized External Security) Assessment Lead or Technical Lead certification (or actively in process)
Strongly Preferred
  • GPEN (GIAC Penetration Tester), GXPN (GIAC Exploit Researcher and Advanced Penetration Tester), OSCP (Offensive Security Certified Professional), or equivalent offensive security credential
  • GWAPT (GIAC Web Application Penetration Tester) or equivalent web application security certification
Nice to Have (Differentiators)
  • Experience conducting CISA AES assessments as Assessment Lead across multiple federal civilian agencies
  • Familiarity with FedRAMP High, Moderate, and Low authorization boundaries and their penetration testing implications
  • Background in Red Team operations or adversary emulation in addition to structured assessment methodology
  • Experience with cloud-native application security assessments (AWS, Azure, GCP, or GovCloud)
  • Active TS/SCI clearance

#DICE #LinkedIn

___________________________________________________________________________________________________________

Here at Revolutional we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day. Some of these recognitions include:

  • Recognized as a Top 20 "Best Place to Work in Virginia"
  • Recipient of Department of Labor's HireVets Gold Medallion
  • Great Place to Work Certification for five years running
  • A Virginia Chamber of Commerce Fantastic 50 company
  • A Northern Virginia Technology Council Tech 100 company
  • Inc. 5000 list of fastest growing companies for eleven years
  • Two-time SBA SBIR Tibbett's Award winner
  • Virginia Values Veterans (V3) Certification

We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Revolutional family! In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to

  • Traditional and HSA- eligible medical insurance plans
  • 100% employer-paid dental and vision insurance options
  • 100% employer-sponsored STD, LTD, and life insurance
  • 5% 401(k) company matching
  • Flexible-schedules and teleworking options
  • Paid holidays and PTO Accrual Plans
  • Paid Parental Leave
  • Professional development and career growth opportunities
  • Team and company-wide events, recognition, and appreciation-- and so much more!

Check out our Revolutional | LinkedIn to find out a little more about who we are and if we are the right next step for your career!

Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Revolutional does and will take affirmative action to employ and advance in employment individuals with disabilities and protected veterans. To perform the above job successfully, an individual must possess the knowledge, skills, and abilities listed; meet the education and work experience required; and must be able to perform each essential duty and responsibility satisfactorily. Other duties in addition to those listed may be assigned as necessary to meet business needs. Reasonable accommodation will be made to enable an applicant with a disability to successfully apply for and/or perform the essential duties of the job. If you are in need of an accommodation, please contact HR@revolutional.com.