1

Penetration Testing Manager Jobs in Washington (NOW HIRING)

Penetration Tester

Gaithersburg, MD · On-site

$100K - $130K/yr

Connsci is seeking a Penetration Tester to join our growing organization. This individual will be ... testing * 3+ years of experience with cloud technologies and Cloud Security Posture Management ...

Penetration Tester

Gaithersburg, MD · On-site

$100K - $130K/yr

Vulnerability & Compliance Testing: Conduct authenticated vulnerability scans and compliance ... Assess security of API tokens, keys, and session management practices. Review error handling, data ...

Cleared Penetration Tester

Herndon, VA · On-site

$130K - $160K/yr

Your expertise in cloud penetration testing (FedRAMP and other compliance frameworks) and security ... Ability to manage multiple priorities simultaneously * Proven analytical and problem-solving skills

Minimum of 2 years with penetration testing experience. * Possess one of the following ... NIST Risk Management Framework (RMF) and the Assessment and Authorization (A&A) process. * Security ...

Minimum of 2 years with penetration testing experience. * Possess one of the following ... NIST Risk Management Framework (RMF) and the Assessment and Authorization (A&A) process. * Security ...

Showing results 41-60

Penetration Testing Manager information

What are the key skills and qualifications needed to thrive as a penetration testing manager, and why are they important?

To thrive as a Penetration Testing Manager, you need deep expertise in cybersecurity, vulnerability assessment, and penetration testing methodologies, typically supported by a relevant degree and certifications like OSCP or CISSP. Familiarity with tools such as Metasploit, Burp Suite, and SIEM systems is essential for effectively managing testing operations. Strong leadership, communication, and project management skills help in guiding teams and translating technical findings for stakeholders. These capabilities are crucial to ensure robust security postures, clear risk communication, and successful management of security testing initiatives.

What does a penetration testing manager do?

A Penetration Testing Manager oversees teams that simulate cyberattacks on an organization's systems, networks, and applications to identify vulnerabilities and assess security risks. They are responsible for planning, coordinating, and ensuring the quality of penetration tests, as well as communicating findings to stakeholders and recommending remediation strategies. Additionally, they often develop testing methodologies, manage team performance, and ensure compliance with industry standards and regulations.

What is a penetration testing manager?

A penetration testing manager oversees security teams that conduct simulated cyberattacks to identify vulnerabilities in computer systems and networks. They coordinate testing activities, review findings, and ensure remediation, often requiring knowledge of security tools, methodologies, and relevant certifications like OSCP or CISSP.

What are some common challenges faced by a penetration testing manager when leading a security assessment team?

Penetration Testing Managers often face the challenge of balancing technical depth with project management responsibilities. Coordinating multiple engagements, ensuring consistent testing methodologies, and managing client expectations can be demanding. Additionally, staying updated with evolving threat landscapes and ensuring the team has the necessary skills and certifications are ongoing concerns. Effective communication with both technical staff and non-technical stakeholders is crucial for translating findings into actionable recommendations.

What is the difference between Penetration Testing Manager vs Penetration Tester?

AspectPenetration Testing ManagerPenetration Tester
CertificationsOSCP, CISSP, PMPOSCP, CEH, GPEN
Work EnvironmentOversees teams, manages projects, strategic planningConducts security assessments, performs testing, technical execution
Employer & Industry UsageSecurity firms, large corporations, government agenciesSecurity teams, consulting firms, internal security departments

The main difference is that a Penetration Testing Manager focuses on managing teams, planning projects, and strategic oversight, while a Penetration Tester is hands-on, performing security assessments and testing systems. Both roles require relevant certifications and are integral to cybersecurity, but they differ in responsibilities and scope.

What are the most commonly searched types of Penetration Testing jobs in Washington?

The most popular types of Penetration Testing jobs in Washington are:

What are popular job titles related to Penetration Testing Manager jobs in Washington?

For Penetration Testing Manager jobs in Washington, the most frequently searched job titles are:

What job categories do people searching Penetration Testing Manager jobs in Washington look for?

The top searched job categories for Penetration Testing Manager jobs in Washington are:

What cities in Washington are hiring for Penetration Testing Manager jobs?

Cities in Washington with the most Penetration Testing Manager job openings:

Penetration Tester

Connsci

Gaithersburg, MD • On-site

$100K - $130K/yr

Full-time

Posted 9 days ago


Job description

Connsci is seeking a Penetration Tester to join our growing organization. This individual will be directly supporting one of our government programs and will be responsible for penetration testing, vulnerability and compliance testing, web application testing, API testing, and supporting various audit and reporting functions.
Responsibilities:
  • Vulnerability & Compliance Testing:
    • Conduct authenticated vulnerability scans and compliance evaluations across networks, systems, endpoints, and cloud platforms.
  • Web Application Testing:
    • Conduct security assessments of agency web applications using OWASP Top 10 and industry best practices.
    • Perform authenticated/unauthenticated scans using tools like Burp Suite and OWASP ZAP.
    • Identify vulnerabilities such as injection flaws, authentication weaknesses, session mismanagement, and sensitive data exposure.
    • Validate application security controls against NIST CSF subcategories
  • API Testing:
    • Evaluate REST/GraphQL APIs for authentication, authorization, and input validation weaknesses.
    • Conduct fuzzing and misuse testing to identify broken object-level authorization (BOLA) and mass assignment vulnerabilities.
    • Assess security of API tokens, keys, and session management practices.
    • Review error handling, data leakage, and logging practices for compliance.
  • Penetration Testing & Exploitation Validation:
    • Perform controlled penetration testing (internal and external) to simulate adversary behaviors and evaluate defensive effectiveness.
  • Audit Support & Reporting:
    • Document findings, prepare audit evidence, and provide recommendations for improving governance, risk, and compliance posture.
  • Collaboration:
    • Provide technical assistance to Agency OIGs and coordinate with operational IT and security teams to ensure findings are actionable and evidence based.

Location/Travel: This role will be able to work primarily remotely but will require travel to company and government client site locations across Florida and the Washington DC metro region on an as needed basis. Preference will be given to candidates who are local to the DC Metro Region or who reside in Florida.
Basic Qualifications:
  • Bachelor's degree in Cybersecurity, Information Systems, or related field; or equivalent experience.
  • At least 5 years of experience in penetration testing to include web application testing and API testing
  • At least 2 years of experience years supporting audit, compliance, or oversight functions to include preparing audit-ready documentation, evidence, and reports for executive leadership
  • At least 2 years of experience with NIST Cybersecurity Framework to include NIST 800-53
  • At least one cyber security certification such as: CISSP, CISA, CISM, CCE, CFCE, GCFE, or CEH

Preferred Qualifications:
  • Master's degree in Cybersecurity, Information Technology, Computer Science
  • 7+ years of experience in penetration testing
  • 3+ years of experience with cloud technologies and Cloud Security Posture Management

About Connsci
At Connsci, our mission is to be a trusted strategic partner for our clients, helping them achieve impactful results by addressing mission-critical issues that affect their bottom line. We recognize the importance of customizing our services to best fit our clients' needs and understanding what it takes to propel their organizations forward. By implementing industry-leading best practices and leveraging our multifaceted experience and expertise, we deliver services that are essential for any organization aiming to reach its goals.
What You Can Expect:
  • Collaboration and Innovation: Work in an environment where collaboration and innovation are key. You'll have the opportunity to contribute to projects that make a real difference for our clients.
  • Professional Growth: Be part of a team that values professional development. We offer opportunities for growth and advancement, allowing you to enhance your skills and career.
  • Impactful Work: Engage in meaningful work that addresses mission-critical issues and supports organizations in achieving their goals.

By joining Connsci, you'll become part of a dedicated team that is committed to delivering strategic, impactful solutions tailored to our clients' unique needs, enabling them to achieve their goals with confidence and efficiency. If you're passionate about cybersecurity and IT services, and eager to contribute to a dynamic team, we encourage you to explore opportunities with us.
At this time, Connsci will not sponsor a new applicant for employment authorization for this position.
Connsci is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, color, sex, religion, sexual orientation, national origin, disability, genetic information, pregnancy, or any other protected characteristic as outlined by federal, state, or local laws.
This policy applies to all employment practices within our organization, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, compensation, benefits, training, and apprenticeship. Connsci makes hiring decisions based solely on qualifications, merit, and business needs at the time.