1

Penetration Testing Manager Jobs in Chicago, IL (NOW HIRING)

Senior Offensive Security Engineer

Naperville, IL · On-site

$114K - $156K/yr

Support improvements to Ecolab's vulnerability management, secure SDLC, DevSecOps, and product ... Support coordination with third-party penetration testing providers when appropriate, including ...

Senior Offensive Security Engineer

Naperville, IL · On-site

$114K - $156K/yr

Support improvements to Ecolab's vulnerability management, secure SDLC, DevSecOps, and product ... Support coordination with third-party penetration testing providers when appropriate, including ...

Manage or oversee penetration testing engagements (internal team or external vendors), track findings through remediation * Perform cyber risk assessments across systems, business units, and ...

Manage or oversee penetration testing engagements (internal team or external vendors), track findings through remediation * Perform cyber risk assessments across systems, business units, and ...

Security Manager

Chicago, IL · On-site

$120 - $160/hr

Manage or oversee penetration testing engagements (internal team or external vendors), track findings through remediation * Perform cyber risk assessments across systems, business units, and ...

New

Manage or oversee penetration testing engagements (internal team or external vendors), track findings through remediation * Perform cyber risk assessments across systems, business units, and ...

Synack's Penetration Testing as a Service platform manages customers' attack surfaces by discovering new assets, pentesting for critical vulnerabilities and gaining visibility into the root causes of ...

Security Test Onboarding & Management - Collecting and communicating required scope and access information for penetration testing and security assurance assessments, as well as handling the output ...

Director, Cybersecurity

Chicago, IL · On-site

$145 - $252/hr

Threat modeling fundamentals and penetration testing skills. * Analytical ability - The applicant ... Experience identifying and managing work performed by subcontractors, including negotiating budgets ...

Showing results 21-40

Penetration Testing Manager information

See Chicago, IL salary details

$58.7K

$137K

$191.6K

How much do penetration testing manager jobs pay per year?

As of Sep 4, 2026, the average yearly pay for penetration testing manager in Chicago, IL is $136,970.00, according to ZipRecruiter salary data. Most workers in this role earn between $114,300.00 and $154,500.00 per year, depending on experience, location, and employer.

What does a penetration testing manager do?

A Penetration Testing Manager oversees teams that simulate cyberattacks on an organization's systems, networks, and applications to identify vulnerabilities and assess security risks. They are responsible for planning, coordinating, and ensuring the quality of penetration tests, as well as communicating findings to stakeholders and recommending remediation strategies. Additionally, they often develop testing methodologies, manage team performance, and ensure compliance with industry standards and regulations.

What are some common challenges faced by a penetration testing manager when leading a security assessment team?

Penetration Testing Managers often face the challenge of balancing technical depth with project management responsibilities. Coordinating multiple engagements, ensuring consistent testing methodologies, and managing client expectations can be demanding. Additionally, staying updated with evolving threat landscapes and ensuring the team has the necessary skills and certifications are ongoing concerns. Effective communication with both technical staff and non-technical stakeholders is crucial for translating findings into actionable recommendations.

What are the key skills and qualifications needed to thrive as a penetration testing manager, and why are they important?

To thrive as a Penetration Testing Manager, you need deep expertise in cybersecurity, vulnerability assessment, and penetration testing methodologies, typically supported by a relevant degree and certifications like OSCP or CISSP. Familiarity with tools such as Metasploit, Burp Suite, and SIEM systems is essential for effectively managing testing operations. Strong leadership, communication, and project management skills help in guiding teams and translating technical findings for stakeholders. These capabilities are crucial to ensure robust security postures, clear risk communication, and successful management of security testing initiatives.

What is the difference between Penetration Testing Manager vs Penetration Tester?

AspectPenetration Testing ManagerPenetration Tester
CertificationsOSCP, CISSP, PMPOSCP, CEH, GPEN
Work EnvironmentOversees teams, manages projects, strategic planningConducts security assessments, performs testing, technical execution
Employer & Industry UsageSecurity firms, large corporations, government agenciesSecurity teams, consulting firms, internal security departments

The main difference is that a Penetration Testing Manager focuses on managing teams, planning projects, and strategic oversight, while a Penetration Tester is hands-on, performing security assessments and testing systems. Both roles require relevant certifications and are integral to cybersecurity, but they differ in responsibilities and scope.

What are the most commonly searched types of Penetration Testing jobs in Chicago, IL?

The most popular types of Penetration Testing jobs in Chicago, IL are:

What are popular job titles related to Penetration Testing Manager jobs in Chicago, IL?

For Penetration Testing Manager jobs in Chicago, IL, the most frequently searched job titles are:

Infographic showing various Penetration Testing Manager job openings in Chicago, IL as of August 2026, with employment types broken down into 71% Full Time, and 29% Part Time. Highlights an 67% In-person, and 33% Hybrid job distribution, with an average salary of $136,970 per year, or $65.9 per hour.

Senior Offensive Security Engineer

Ecolab

Naperville, IL • On-site

$114K - $156K/yr

Full-time

Re-posted 4 days ago


Ecolab rating

7.5

Company rating: 7.5 out of 10

Based on 211 frontline employees who took The Breakroom Quiz

57th of 103 rated chemical manufacturers


Job description

The Senior Offensive Security Engineer, Commercial Products will perform hands-on offensive security testing across Ecolab's commercial digital product portfolio. This role will focus on technical testing of customer-facing commercial products, including web and mobile applications, APIs, cloud services, IoT solutions, PLC/IPC-connected equipment, embedded or field-deployed devices, and related product integrations. The Senior Offensive Security Engineer, Commercial Products will actively perform security testing for most of their time while supporting offensive security engagements, mentoring engineers as needed, and helping improve engagement scope, testing methods, reporting quality, remediation validation, and risk-based prioritization. This role will partner closely with product security, engineering, architecture, cloud, IoT, legal/compliance, and business stakeholders to identify vulnerabilities before they are discovered externally and to help improve the security maturity of Ecolab's commercial offerings.

What you will do:

  • Perform hands-on offensive security testing across Ecolab commercial products, including web applications, mobile applications, APIs, cloud services, IoT platforms, PLC/IPC-connected equipment, embedded devices, and product integrations.

  • Plan, scope, and execute technical security assessments focused on identifying exploitable vulnerabilities, attack paths, insecure configurations, weak access controls, exposed secrets, insecure APIs, cloud misconfigurations, and product-specific security gaps.

  • Support offensive security engagements and mentor engineers as needed while remaining highly hands-on in day-to-day testing, analysis, documentation, and remediation validation activities.

  • Contribute to repeatable red team and offensive testing methods, engagement rules, reporting standards, evidence expectations, and risk-rating approaches appropriate for commercial digital products.

  • Partner with product security, application engineering, cloud engineering, IoT engineering, architecture, and business teams to translate testing results into clear remediation actions and risk-based priorities.

  • Conduct safe and authorized technical testing of IoT and industrially connected equipment, including physical access testing of product hardware, field devices, PLC/IPC interfaces, device communications, and related technology components where appropriate.

  • Use commercial and enterprise-approved security tools such as Snyk, Wiz, Burp Suite, OWASP ZAP, GitHub Advanced Security, Nmap, Horizon3 NodeZero, DAST tooling, and related technologies to identify, validate, and document security issues.

  • Validate vulnerabilities discovered through internal testing, automated scanning, third-party penetration testing, customer inquiries, bug reports, and product security reviews.

  • Prepare clear, actionable reports that explain vulnerability impact, exploitability, business context, affected assets, remediation guidance, compensating controls, and validation results.

  • Present technical findings to engineering teams and non-technical stakeholders at all levels of the organization, communicating risk, business impact, and practical remediation paths.

  • Support product threat modeling, secure architecture reviews, application security reviews, cloud security assessments, and security design discussions based on offensive testing insights.

  • Support improvements to Ecolab's vulnerability management, secure SDLC, DevSecOps, and product security governance practices by identifying recurring weakness patterns and practical control improvements.

  • Support coordination with third-party penetration testing providers when appropriate, including scope development, test readiness, evidence review, finding validation, and remediation tracking.

  • Maintain awareness of emerging offensive security techniques, AI-enabled attack methods, application security risks, cloud security trends, IoT attack vectors, and relevant industry standards.

  • Act as an advocate and champion for practical, risk-based product security across Ecolab's commercial digital product teams.

Minimum Qualifications:

  • Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related technology-driven field.

  • 5+ years of hands-on experience in cybersecurity, application security, offensive security, penetration testing, product security, cloud security, IoT security, software engineering, or related technical field.

  • Demonstrated hands-on experience performing authorized technical security testing of web applications, mobile applications, APIs, cloud services, and/or IoT-connected products.

  • Experience supporting offensive security engagements, vulnerability assessments, penetration tests, remediation validation, and technical security reporting.

  • Experience supporting technical workstreams, mentoring engineers, or coordinating testing activities while remaining directly involved in hands-on testing and analysis.

  • Experience with Microsoft Azure; familiarity with AWS and/or GCP cloud security concepts, services, and common misconfiguration risks.

  • Experience with application security testing tools and practices, including SAST, SCA, DAST, API testing, cloud security posture assessment, vulnerability validation, and secure code review concepts.

  • Familiarity with tools such as Snyk, Wiz, Burp Suite, OWASP ZAP, GitHub Advanced Security, Nmap, Horizon3 NodeZero, DAST tooling, and related offensive or product security testing technologies.

  • Knowledge of secure software development, DevSecOps, CI/CD pipelines, identity and access management, encryption, secrets management, secure API design, and secure cloud architecture principles.

  • Understanding of IoT, embedded, industrial, or field-deployed technology security considerations, including device communications, network segmentation, authentication, update mechanisms, and physical access risks.

  • Familiarity with industry frameworks and standards such as OWASP, CIS, NIST, ISO 27001, SOC 2, and secure SDLC practices.

  • Strong interpersonal, analytical, problem-solving, organizational, and written/verbal communication skills.

  • Ability to communicate technical findings clearly to software engineers, architects, cybersecurity leaders, product owners, and non-technical business stakeholders.

  • Ability to accommodate a flexible work schedule for supporting global activities.

Preferred Qualifications:

  • One practical offensive security certification such as OSCP, GPEN, GWAPT, GWEB, PNPT, or similar hands-on application, web, cloud, or penetration testing certification.

  • Experience testing commercial software products, SaaS platforms, customer-facing applications, cloud-hosted services, mobile applications, APIs, IoT platforms, or connected equipment.

  • Experience with hardware, embedded systems, PLC/IPC-connected devices, industrial communications, device provisioning, secure firmware/update processes, or field-deployed technology.

  • Experience with Azure security services, cloud-native application security, container security, Kubernetes security, and identity-based cloud controls.

  • Experience integrating offensive security findings into vulnerability management, secure architecture, threat modeling, product risk governance, and engineering remediation workflows.

  • Experience contributing to testing playbooks, reporting templates, engagement standards, risk-rating models, and remediation validation procedures.

  • Experience with AI-enabled products, AI integrations, or the security implications of AI/ML capabilities in commercial software environments.

  • Ability to influence without authority and drive security improvements across globally distributed engineering, product, and technology teams.

Annual or Hourly Compensation Range

The pay range for this position is $101,400.00 - $152,100.00. Many factors are taken into consideration when determining compensation, such as experience, education, training, geography, etc. We comply with all minimum wage and overtime laws.

Benefits

Ecolab strives to provide comprehensive and market-competitive benefits to meet the needs of our associates and their families.Click here to see our benefits.

If you are viewing this posting on a site other than our Ecolab Career website, view our benefits at jobs.ecolab.com/working-here.


Potential Customer Requirements Notice

To meet customer requirements and comply with local or state regulations, applicants for certain customer-facing roles may need to:

- Undergo additional background screens and/or drug/alcohol testing for customer credentialing.


Americans with Disabilities Act (ADA)

Ecolab will provide reasonable accommodation (such as a qualified sign language interpreter or other personal assistance) with our application process upon request as required to comply with applicable laws. If you have a disability and require accommodation assistance in this application process, please visit the Recruiting Support link in the footer of each page of our career website.


What Ecolab employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Ecolab logo

About Ecolab

Sourced by ZipRecruiter

Ecolab is a global sustainability leader offering water, hygiene and infection prevention solutions and services that protect people and the resources vital to life.

Industry

Manufacturing

Company size

10,000+ Employees

Headquarters location

Saint Paul, MN, US

Year founded

1923