1

Penetration Testing Manager Jobs in Washington (NOW HIRING)

Penetration Tester

Quantico, VA · On-site

$130K - $147K/yr

Present findings to stakeholders, including technical teams and management. * Create and maintain documentation on penetration testing methodologies, tools, and techniques. * Remediation Support:

This role will support advanced penetration testing, software assurance, vulnerability assessment, cyber supply chain risk management, secure cloud and hybrid engineering, and cross-domain security ...

This role will support advanced penetration testing, software assurance, vulnerability assessment, cyber supply chain risk management, secure cloud and hybrid engineering, and cross-domain security ...

Present findings to stakeholders, including technical teams and management. * Create and maintain documentation on penetration testing methodologies, tools, and techniques. * Remediation Support:

... management, and related enterprise support for DHRA, including DMDC and OUSD(P&R). Come join our ... Conduct Government-selected penetration-testing assessments and threat-hunting exercises in ...

Push the boundaries of penetration testing innovation through research and development of novel ... Manage and configure campaign infrastructure * Research and develop attacks on vulnerable systems ...

Senior Penetration Tester

Washington, DC · On-site

$145K - $180K/yr

... management personnel, technical personnel, and third parties. Nice To Have: * Certification in focused on Web Application penetration testing. * i.e. eWPT, BSCP, etc * Relevant security research.

Develop risk management methodologies and recommend security improvements. * Analyze penetration testing results and develop risk and threat mitigation plans. * Test and review system configurations ...

... penetration testing initiatives. As a key member of our elite team, you'll play a crucial role in ... manage digital risk and access. In addition to mitigating attack risks and securing cloud ...

Push the boundaries of penetration testing innovation through research and development of novel ... Manage and configure campaign infrastructure * Research and develop attacks on vulnerable systems ...

... management, and related enterprise support for DHRA, including DMDC and OUSD(P&R). Come join our ... Conduct Government-selected penetration-testing assessments and threat-hunting exercises in ...

Penetration Tester

Washington, DC · On-site

$117K - $199K/yr

Design, develop, and maintain tools/scripts to automate and enhance penetration testing activities. * Manage and mentor a small team of junior penetration testers; provide technical guidance and ...

Your expertise in cloud penetration testing (FedRAMP and other compliance frameworks) and security ... Ability to manage multiple priorities simultaneously * Proven analytical and problem-solving skills

Connsci is seeking a Penetration Tester to join our growing organization. This individual will be ... testing * 3+ years of experience with cloud technologies and Cloud Security Posture Management ...

Minimum of 2 years with penetration testing experience. * Possess one of the following ... NIST Risk Management Framework (RMF) and the Assessment and Authorization (A&A) process. * Security ...

Showing results 21-40

Penetration Testing Manager information

What are the key skills and qualifications needed to thrive as a penetration testing manager, and why are they important?

To thrive as a Penetration Testing Manager, you need deep expertise in cybersecurity, vulnerability assessment, and penetration testing methodologies, typically supported by a relevant degree and certifications like OSCP or CISSP. Familiarity with tools such as Metasploit, Burp Suite, and SIEM systems is essential for effectively managing testing operations. Strong leadership, communication, and project management skills help in guiding teams and translating technical findings for stakeholders. These capabilities are crucial to ensure robust security postures, clear risk communication, and successful management of security testing initiatives.

What does a penetration testing manager do?

A Penetration Testing Manager oversees teams that simulate cyberattacks on an organization's systems, networks, and applications to identify vulnerabilities and assess security risks. They are responsible for planning, coordinating, and ensuring the quality of penetration tests, as well as communicating findings to stakeholders and recommending remediation strategies. Additionally, they often develop testing methodologies, manage team performance, and ensure compliance with industry standards and regulations.

What is a penetration testing manager?

A penetration testing manager oversees security teams that conduct simulated cyberattacks to identify vulnerabilities in computer systems and networks. They coordinate testing activities, review findings, and ensure remediation, often requiring knowledge of security tools, methodologies, and relevant certifications like OSCP or CISSP.

What are some common challenges faced by a penetration testing manager when leading a security assessment team?

Penetration Testing Managers often face the challenge of balancing technical depth with project management responsibilities. Coordinating multiple engagements, ensuring consistent testing methodologies, and managing client expectations can be demanding. Additionally, staying updated with evolving threat landscapes and ensuring the team has the necessary skills and certifications are ongoing concerns. Effective communication with both technical staff and non-technical stakeholders is crucial for translating findings into actionable recommendations.

What is the difference between Penetration Testing Manager vs Penetration Tester?

AspectPenetration Testing ManagerPenetration Tester
CertificationsOSCP, CISSP, PMPOSCP, CEH, GPEN
Work EnvironmentOversees teams, manages projects, strategic planningConducts security assessments, performs testing, technical execution
Employer & Industry UsageSecurity firms, large corporations, government agenciesSecurity teams, consulting firms, internal security departments

The main difference is that a Penetration Testing Manager focuses on managing teams, planning projects, and strategic oversight, while a Penetration Tester is hands-on, performing security assessments and testing systems. Both roles require relevant certifications and are integral to cybersecurity, but they differ in responsibilities and scope.

What are the most commonly searched types of Penetration Testing jobs in Washington?

The most popular types of Penetration Testing jobs in Washington are:

What are popular job titles related to Penetration Testing Manager jobs in Washington?

For Penetration Testing Manager jobs in Washington, the most frequently searched job titles are:

What job categories do people searching Penetration Testing Manager jobs in Washington look for?

The top searched job categories for Penetration Testing Manager jobs in Washington are:

What cities in Washington are hiring for Penetration Testing Manager jobs?

Cities in Washington with the most Penetration Testing Manager job openings:

Vulnerability Assessment & Penetration Testing Specialist - Level III

RiVidium, Inc

Washington, DC • On-site

Full-time

Posted 12 days ago


Job description

Full-Time/Part-Time
Full-Time
Description
The Vulnerability Assessment & Penetration Testing Specialist - Level III serves as the senior technical expert responsible for planning, executing, and leading advanced penetration testing, vulnerability assessments, software assurance, and cyber supply chain risk management activities across the Department of Homeland Security (DHS) Intelligence Enterprise (DHS IE). This role performs comprehensive security assessments of enterprise networks, cloud environments, applications, operating systems, and Cross Domain Solutions (CDS) using industry-recognized methodologies and advanced manual testing techniques.
The specialist leverages frameworks such as MITRE ATT&CK, OWASP, NIST, and industry best practices to identify vulnerabilities that may not be detected by automated tools. The position also supports software assurance initiatives through secure code reviews, application security testing, and Supply Chain Risk Management (SCRM) activities to strengthen the cybersecurity posture of DHS IE systems.
Working closely with Security Operations Center (SOC) personnel, Cybersecurity Engineers, Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), developers, and Government stakeholders, the Vulnerability Assessment & Penetration Testing Specialist provides expert recommendations to reduce enterprise cyber risk while ensuring compliance with Federal, DHS, and Intelligence Community (IC) cybersecurity requirements.
Key Responsibilities
  • Lead and conduct comprehensive penetration testing engagements for DHS Intelligence Enterprise systems, networks, applications, cloud environments, and infrastructure.
  • Perform penetration testing using industry-recognized methodologies, including:
    • MITRE ATT&CK Framework
    • OWASP Web Security Testing Guide
    • NIST penetration testing guidance
    • PTES (Penetration Testing Execution Standard)
  • Plan and execute all phases of penetration testing, including:
    • Pre-engagement planning
    • Rules of Engagement (ROE)
    • Threat intelligence gathering
    • Threat modeling
    • Vulnerability identification
    • Exploitation
    • Post-exploitation analysis
    • Reporting and remediation recommendations
  • Utilize advanced manual testing techniques to identify vulnerabilities that are not detectable through automated scanning tools.
  • Perform network, web application, wireless, cloud, and infrastructure penetration testing using ethical hacking techniques while ensuring no disruption to production environments.
  • Validate Security Operations Center (SOC) detection and incident response capabilities through controlled adversary emulation and red team testing.
  • Assess logging, monitoring, detection, and response mechanisms to identify gaps in defensive capabilities.
  • Perform software assurance reviews by conducting security and compliance testing of software requests and applications prior to deployment.
  • Review Software Assurance Request Forms and provide technical adjudication and security recommendations.
  • Conduct vulnerability assessments of enterprise systems and deliver comprehensive Security Assessment Reports (SARs) and Vulnerability Assessment Reports (VARs) within established service-level agreements.
  • Perform Supply Chain Risk Management (SCRM) and Cyber Supply Chain Risk Management (C-SCRM) assessments for software, hardware, and third-party technologies supporting DHS IE.
  • Conduct secure source code reviews using both automated and manual analysis techniques to identify software vulnerabilities and coding weaknesses.
  • Utilize static application security testing (SAST), dynamic application security testing (DAST), and software composition analysis (SCA) tools to evaluate software security.
  • Maintain the penetration testing toolkit, ensuring monthly software updates, quarterly configuration reviews, and compliance with approved security baselines.
  • Develop comprehensive penetration testing reports documenting:
    • Testing methodology
    • Attack paths
    • Exploited vulnerabilities
    • MITRE ATT&CK mappings
    • Risk ratings
    • Technical findings
    • Executive summaries
    • Remediation recommendations
  • Develop and maintain Standard Operating Procedures (SOPs) supporting penetration testing, software assurance, vulnerability assessment, and SCRM activities.
  • Collaborate with cybersecurity engineering, DevSecOps, cloud engineering, and system administration teams to remediate identified vulnerabilities.
  • Support cybersecurity audits, security assessments, authorization activities, and continuous monitoring initiatives.
  • Participate in cybersecurity working groups and provide technical guidance on emerging threats, offensive security techniques, and vulnerability management best practices.

Minimum Qualifications
  • Active Top Secret/Sensitive Compartmented Information (TS/SCI) security clearance.
  • Minimum 7-10 years of experience performing penetration testing, vulnerability assessments, software assurance, and offensive cybersecurity activities within Federal Government or Intelligence Community environments.
  • Current Certified Ethical Hacker (CEH) certification.
  • Current Certified Information Systems Security Professional (CISSP) certification.
  • Expert knowledge of:
    • MITRE ATT&CK Framework
    • OWASP Testing Methodology
    • OWASP Top 10
    • NIST Cybersecurity Framework
    • Penetration Testing Execution Standard (PTES)
  • Demonstrated experience with penetration testing and vulnerability assessment tools such as:
    • Burp Suite Professional
    • Nessus / ACAS
    • Nmap
    • Metasploit Framework
    • Wireshark
    • Kali Linux
    • WebInspect
    • Nikto
    • Other industry-standard offensive security tools
  • Experience performing software assurance using:
    • SonarQube
    • GitLab Security
    • Static Application Security Testing (SAST)
    • Dynamic Application Security Testing (DAST)
    • Software Composition Analysis (SCA)
  • Minimum 2 years of experience in each of the following:
    • Software Assurance
    • Penetration Testing
    • Vulnerability Assessment
    • Patch Management
    • Secure Cloud and Hybrid Cloud Security Engineering
  • Experience performing secure code reviews and identifying application security vulnerabilities.
  • Bachelor's degree in Cybersecurity, Computer Science, Software Engineering, Information Systems, or a related technical discipline.

Preferred Qualifications
  • Offensive Security Certified Professional (OSCP) certification.
  • GIAC Penetration Tester (GPEN) certification.
  • Experience conducting penetration testing of Cross Domain Solutions (CDS) and classified information systems.
  • Experience supporting DHS Intelligence & Analysis (I&A) or other Intelligence Community cybersecurity programs.
  • Familiarity with:
    • DISA Security Technical Implementation Guides (STIGs)
    • Container security (Docker, Kubernetes)
    • Kubernetes security
    • Serverless application security
    • Secure DevSecOps pipelines
  • Experience supporting Cloud Service Provider (AWS, Azure, or Google Cloud) penetration testing and cloud-native security assessments.
  • Experience performing adversary emulation, purple team, or red team exercises.
  • Familiarity with NIST SP 800-161 Cyber Supply Chain Risk Management (C-SCRM) guidance.

Required Certifications
The following current certifications are required:
  • Certified Ethical Hacker (CEH)
  • Certified Information Systems Security Professional (CISSP)

Preferred certifications include:
  • Offensive Security Certified Professional (OSCP)
  • GIAC Penetration Tester (GPEN)

Clearance Requirement
Active Top Secret/Sensitive Compartmented Information (TS/SCI) Clearance Required
About the Organization
Established in 2008, RiVidium, Inc. (dba TripleCyber) is a VA-Verified SDVOSB and an SBA-Certified 8(a) company. To prepare our clients for the future, RiVidium has balanced all parts of our organization to attract the finest employees in order to 'Strive to be the missing element defining tomorrow's technology'. RiVidium keeps pace and surpasses its competitors by meeting challenges of advancements in Logistics, Human Capital, Cyber, Intelligence & Technology.
EOE Statement
We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law. If you need a reasonable accommodation for any part of the employment process, please contact Human Resources (HR) at hr@rividium.com.
This position is currently accepting applications.