1

Penetration Testing Manager Jobs in Michigan (NOW HIRING)

Manager, Offensive Security

Warren, MI · On-site

$104K - $140K/yr

Lead and develop a team responsible for penetration testing, adversary emulation, responsible ... management, coaching, workforce planning, and team development. * 3+ years leading complex, cross ...

Manager, Offensive Security

Warren, MI · On-site

$104K - $140K/yr

Lead and develop a team responsible for penetration testing, adversary emulation, responsible ... management, coaching, workforce planning, and team development. * 3+ years leading complex, cross ...

... management activities. * Review supplier and third-party test reports and partner with internal teams and suppliers to resolve identified cybersecurity issues. * Support external penetration testing ...

... management activities. * Review supplier and third-party test reports and partner with internal teams and suppliers to resolve identified cybersecurity issues. * Support external penetration testing ...

Offensive Security Manager

Grand Rapids, MI · On-site

$106K - $144K/yr

In management at Crowe, you play a pivotal role in leading teams, guiding project execution, and ... Wireless penetration testing * Social engineering (phishing, telephone, onsite) * Red teaming ...

... with managed service providers, cybersecurity vendors, or penetration-testing firms. • Relevant certifications such as CompTIA A+, Network+, Security+, Cisco CCNA, Cisco CyberOps Associate, or ...

next page

Showing results 1-20

Penetration Testing Manager information

What does a penetration testing manager do?

A Penetration Testing Manager oversees teams that simulate cyberattacks on an organization's systems, networks, and applications to identify vulnerabilities and assess security risks. They are responsible for planning, coordinating, and ensuring the quality of penetration tests, as well as communicating findings to stakeholders and recommending remediation strategies. Additionally, they often develop testing methodologies, manage team performance, and ensure compliance with industry standards and regulations.

What are some common challenges faced by a penetration testing manager when leading a security assessment team?

Penetration Testing Managers often face the challenge of balancing technical depth with project management responsibilities. Coordinating multiple engagements, ensuring consistent testing methodologies, and managing client expectations can be demanding. Additionally, staying updated with evolving threat landscapes and ensuring the team has the necessary skills and certifications are ongoing concerns. Effective communication with both technical staff and non-technical stakeholders is crucial for translating findings into actionable recommendations.

What are the key skills and qualifications needed to thrive as a penetration testing manager, and why are they important?

To thrive as a Penetration Testing Manager, you need deep expertise in cybersecurity, vulnerability assessment, and penetration testing methodologies, typically supported by a relevant degree and certifications like OSCP or CISSP. Familiarity with tools such as Metasploit, Burp Suite, and SIEM systems is essential for effectively managing testing operations. Strong leadership, communication, and project management skills help in guiding teams and translating technical findings for stakeholders. These capabilities are crucial to ensure robust security postures, clear risk communication, and successful management of security testing initiatives.

What is the difference between Penetration Testing Manager vs Penetration Tester?

AspectPenetration Testing ManagerPenetration Tester
CertificationsOSCP, CISSP, PMPOSCP, CEH, GPEN
Work EnvironmentOversees teams, manages projects, strategic planningConducts security assessments, performs testing, technical execution
Employer & Industry UsageSecurity firms, large corporations, government agenciesSecurity teams, consulting firms, internal security departments

The main difference is that a Penetration Testing Manager focuses on managing teams, planning projects, and strategic oversight, while a Penetration Tester is hands-on, performing security assessments and testing systems. Both roles require relevant certifications and are integral to cybersecurity, but they differ in responsibilities and scope.

What are the most commonly searched types of Penetration Testing jobs in Michigan?

The most popular types of Penetration Testing jobs in Michigan are:

What cities in Michigan are hiring for Penetration Testing Manager jobs?

Cities in Michigan with the most Penetration Testing Manager job openings:

Infographic showing various Penetration Testing Manager job openings in Michigan as of August 2026, with employment types broken down into 70% Full Time, and 30% Part Time. Highlights an 73% In-person, and 27% Hybrid job distribution.

Senior Specialist, MAST Application Penetration Tester

KPMG US

Detroit, MI • On-site

Full-time

Re-posted 5 days ago


Job description

Job Summary:
KPMG is a leading advisory firm that offers excellent opportunities for career advancement. They are currently seeking a Senior Specialist, MAST Application Penetration Tester to conduct manual penetration testing and evaluate application security within their Managed Services practice.
Responsibilities:
• Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications
• Perform objective based on abstract penetration testing engagements
• Execute threat modeling, evaluate application business logic, and perform application architecture reviews
• Demonstrate application testing experience in real time via demos to both internal and external audiences
• Function independently in penetration testing engagements, with minimal oversight and guidance
• Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
Qualifications:
Required:
• Minimum three years of recent experience in application penetration testing of Application Programming Interface (API's), web applications, or mobile applications
• Bachelor's degree from an accredited college/university or equivalent industry experience
• Ability to communicate reporting results with technical and non-technical audiences and lead remediation conversations
• Experience with burp suite pro, and other app testing tools such as Netsparker and Checkmarx
• Ability to travel as required
• Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa)
Preferred:
• One or more major ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert (OSWE), Offensive Security Web Assessor (OSWA)
Company:
KPMG is one of the world’s leading professional services firms and the fastest growing Big Four accounting firm in the United States. Founded in 2010, the company is headquartered in New York, USA, with a team of 10001+ employees. The company is currently Late Stage.