1

Penetration Testing Manager Jobs in Orem, UT (NOW HIRING)

Senior Application Security Engineer

American Fork, UT ยท On-site

$102K - $140K/yr

Lead proactive security initiatives including threat modeling, deep-dive code reviews, and offensive security exercises/penetration testing. * Vulnerability Management: Architect and manage the ...

Information Security Officer

Midvale, UT ยท On-site

$190K - $200K/yr

Conduct regular security audits, IT risk assessments, penetration testing, and compliance reviews ... Manage security awareness training programs for employees and ensure ongoing education on emerging ...

Senior Application Security Engineer

American Fork, UT ยท On-site

$102K - $140K/yr

Lead proactive security initiatives including threat modeling, deep-dive code reviews, and offensive security exercises/penetration testing. * Vulnerability Management: Architect and manage the ...

Lead proactive security initiatives including threat modeling, deep-dive code reviews, and offensive security exercises/penetration testing. * Vulnerability Management: Architect and manage the ...

Special Inspector

Sandy, UT ยท On-site

$60 - $80/hr

Assisting and supporting laboratory testing in accordance with the Quality Management Systems (QMS ... Spray-applied fireproofing, fire penetration/fire stops * Structural bolting, structural steel ...

Help the team manage daily dialer operations, ensuring campaigns start on time, run efficiently ... Queue Penetration * Agent Occupancy * Average Handle Time (AHT) * Abandon Rate * Contact Rate

Help the team manage daily dialer operations, ensuring campaigns start on time, run efficiently ... Queue Penetration * Agent Occupancy * Average Handle Time (AHT) * Abandon Rate * Contact Rate

Penetration Testing Manager information

See Orem, UT salary details

$49.6K

$115.6K

$161.7K

How much do penetration testing manager jobs pay per year?

As of Sep 7, 2026, the average yearly pay for penetration testing manager in Orem, UT is $115,593.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,500.00 and $130,400.00 per year, depending on experience, location, and employer.

What does a penetration testing manager do?

A Penetration Testing Manager oversees teams that simulate cyberattacks on an organization's systems, networks, and applications to identify vulnerabilities and assess security risks. They are responsible for planning, coordinating, and ensuring the quality of penetration tests, as well as communicating findings to stakeholders and recommending remediation strategies. Additionally, they often develop testing methodologies, manage team performance, and ensure compliance with industry standards and regulations.

What are some common challenges faced by a penetration testing manager when leading a security assessment team?

Penetration Testing Managers often face the challenge of balancing technical depth with project management responsibilities. Coordinating multiple engagements, ensuring consistent testing methodologies, and managing client expectations can be demanding. Additionally, staying updated with evolving threat landscapes and ensuring the team has the necessary skills and certifications are ongoing concerns. Effective communication with both technical staff and non-technical stakeholders is crucial for translating findings into actionable recommendations.

What are the key skills and qualifications needed to thrive as a penetration testing manager, and why are they important?

To thrive as a Penetration Testing Manager, you need deep expertise in cybersecurity, vulnerability assessment, and penetration testing methodologies, typically supported by a relevant degree and certifications like OSCP or CISSP. Familiarity with tools such as Metasploit, Burp Suite, and SIEM systems is essential for effectively managing testing operations. Strong leadership, communication, and project management skills help in guiding teams and translating technical findings for stakeholders. These capabilities are crucial to ensure robust security postures, clear risk communication, and successful management of security testing initiatives.

What is the difference between Penetration Testing Manager vs Penetration Tester?

AspectPenetration Testing ManagerPenetration Tester
CertificationsOSCP, CISSP, PMPOSCP, CEH, GPEN
Work EnvironmentOversees teams, manages projects, strategic planningConducts security assessments, performs testing, technical execution
Employer & Industry UsageSecurity firms, large corporations, government agenciesSecurity teams, consulting firms, internal security departments

The main difference is that a Penetration Testing Manager focuses on managing teams, planning projects, and strategic oversight, while a Penetration Tester is hands-on, performing security assessments and testing systems. Both roles require relevant certifications and are integral to cybersecurity, but they differ in responsibilities and scope.

What are the most commonly searched types of Penetration Testing jobs in Orem, UT?

The most popular types of Penetration Testing jobs in Orem, UT are:

What are popular job titles related to Penetration Testing Manager jobs in Orem, UT?

For Penetration Testing Manager jobs in Orem, UT, the most frequently searched job titles are:

Senior Application Security Engineer

LVT

American Fork, UT โ€ข On-site

$102K - $140K/yr

Full-time

Re-posted 10 days ago


Job description

ABOUT THIS ROLE

As a Senior Application Security Engineer at LVT, you will be a cornerstone of our commitment to building secure-by-design technology. You will partner deeply with our Engineering and Product teams to weave advanced security protocols into every layer of our Software Development Lifecycle (SDLC). This isn't just about finding bugs; it's about architecting a proactive security culture and scaling our defenses alongside our rapid growth. You will serve as a technical expert, mentor, and advocate, ensuring our AI-driven platform remains as resilient as it is innovative.

This role is based in-office out of our Headquarters in American Fork, Utah.

ROLE RESPONSIBILITIES
  • Strategic Integration: Partner with Product and Engineering to embed reproducible, high-standard security practices directly into the SDLC.

  • Defense Engineering: Develop and maintain sophisticated manual and automated security processes to identify, evaluate, and mitigate risks across our software ecosystem.

  • Offensive Security: Lead proactive security initiatives including threat modeling, deep-dive code reviews, and offensive security exercises/penetration testing.

  • Vulnerability Management: Architect and manage the deployment of vulnerability scanning tools, driving the remediation process to ensure rapid resolution of identified issues.

  • Policy Stewardship: Assist in the development and continuous improvement of secure development policies and procedural documentation.

  • Technical Translation: Communicate complex vulnerability details and risk assessments to both technical and non-technical stakeholders, ensuring organizational alignment.

  • Security Culture: Mentor junior team members and foster a strong, transparent security culture across the company.

  • Impact Measurement: Success in this role is measured by the reduction of critical vulnerabilities in production, the speed of remediation cycles, and the successful adoption of security tools by the broader engineering team.

OUR IDEAL CANDIDATE
  • Proven Experience: At least 3+ years of professional experience in an Information Security role with a dedicated focus on modern application environments.

  • Cloud Proficiency: 3+ years of hands-on security experience with AWS and other cloud service platforms.

  • Modern Stack Familiarity: Comfortable navigating common web languages and frameworks such as HTML, PHP, Node.js, React.js, Nest.js, and Next.js.

  • Pipeline Expertise: A solid understanding of CI/CD tools and artifacts including GitHub, Docker, JFrog, CircleCI, and ArgoCD.

  • Technical Depth: A comprehensive understanding of common application vulnerabilities (OWASP Top 10) and the orchestration of automated tools used to combat them (SAST, DAST, SCA).

  • IT Foundations: Strong grasp of foundational IT domains, including operating systems, networking protocols, and the OSI model.

  • Compliance Awareness: Familiarity with standard security and regulatory compliance frameworks such as CIS, NIST, ISO/IEC 27001, SOC2, or FedRAMP.

  • Exceptional Communicator: Ability to articulate risk with clarity and professional poise, maintaining high levels of personal integrity while working with cross-functional partners.

  • Preferred Credentials: A degree in IT/Security or industry certifications such as Security+, OSCP, GPEN, or ITCA are highly valued.