1

Penetration Testing Manager Jobs (NOW HIRING)

This role will support advanced penetration testing, software assurance, vulnerability assessment, cyber supply chain risk management, secure cloud and hybrid engineering, and cross-domain security ...

Senior Penetration Tester

Washington, DC · On-site

$124K - $180K/yr

Lead, plan, and oversee penetration testing operations for systems, networks, cloud resources, and ... Apply advanced security defense functions (encryption, access control, identity management) to ...

... t to make informed decisions about how to address the identified findings. Occasional off-hours testing and periodic travel required. Duties include the following: * Conducts penetration testing ...

Present findings to stakeholders, including technical teams and management. * Create and maintain documentation on penetration testing methodologies, tools, and techniques. * Remediation Support:

Penetration Tester

Arlington, VA · On-site

$86K - $138K/yr

Minimum of 2 years with penetration testing experience. * Possess one of the following ... NIST Risk Management Framework (RMF) and the Assessment and Authorization (A&A) process. * Security ...

Senior Penetration Tester

Washington, DC · On-site

$124K - $180K/yr

Lead, plan, and oversee penetration testing operations for systems, networks, cloud resources, and ... Apply advanced security defense functions (encryption, access control, identity management) to ...

Senior Penetration Tester

Washington, DC · On-site

$124K - $180K/yr

Lead, plan, and oversee penetration testing operations for systems, networks, cloud resources, and ... Apply advanced security defense functions (encryption, access control, identity management) to ...

Senior Penetration Tester

Washington, DC · On-site

$145K - $180K/yr

Conduct penetration testing and vulnerability assessments on Azure cloud infrastructure and ... Present findings, risk assessments, and conclusions to management and other relevant parties

Senior Penetration Tester

Washington, DC · On-site

$124K - $180K/yr

Lead, plan, and oversee penetration testing operations for systems, networks, cloud resources, and ... Apply advanced security defense functions (encryption, access control, identity management) to ...

This role will support advanced penetration testing, software assurance, vulnerability assessment, cyber supply chain risk management, secure cloud and hybrid engineering, and cross-domain security ...

Penetration Tester

Quantico, VA · On-site

$130K - $147K/yr

Present findings to stakeholders, including technical teams and management. * Create and maintain documentation on penetration testing methodologies, tools, and techniques. * Remediation Support:

Management or team lead experience * Experience performing continuous penetration testing * Experience conducting red team operations * Experience performing IoT, mobile, and cloud penetration ...

Penetration Tester

Portland, OR · On-site

$90 - $130/hr

Maintain and secure penetration testing infrastructure, tools, and testing equipment.Manage assigned projects, tickets, and deliverables while meeting established deadlines.Collaborate with internal ...

... management, and related enterprise support for DHRA, including DMDC and OUSD(P&R). Come join our ... Conduct Government-selected penetration-testing assessments and threat-hunting exercises in ...

Push the boundaries of penetration testing innovation through research and development of novel ... Manage and configure campaign infrastructure * Research and develop attacks on vulnerable systems ...

Penetration Tester

Herndon, VA · On-site

$100K - $200K/yr

... penetration testing initiatives. As a key member of our elite team, you'll play a crucial role in ... manage digital risk and access. In addition to mitigating attack risks and securing cloud ...

Showing results 21-40

Penetration Testing Manager information

See salary details

$57K

$133K

$186K

How much do penetration testing manager jobs pay per year?

As of Sep 4, 2026, the average yearly pay for penetration testing manager in the United States is $132,962.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,000.00 and $150,000.00 per year, depending on experience, location, and employer.

What does a penetration testing manager do?

A Penetration Testing Manager oversees teams that simulate cyberattacks on an organization's systems, networks, and applications to identify vulnerabilities and assess security risks. They are responsible for planning, coordinating, and ensuring the quality of penetration tests, as well as communicating findings to stakeholders and recommending remediation strategies. Additionally, they often develop testing methodologies, manage team performance, and ensure compliance with industry standards and regulations.

What are some common challenges faced by a penetration testing manager when leading a security assessment team?

Penetration Testing Managers often face the challenge of balancing technical depth with project management responsibilities. Coordinating multiple engagements, ensuring consistent testing methodologies, and managing client expectations can be demanding. Additionally, staying updated with evolving threat landscapes and ensuring the team has the necessary skills and certifications are ongoing concerns. Effective communication with both technical staff and non-technical stakeholders is crucial for translating findings into actionable recommendations.

What are the key skills and qualifications needed to thrive as a penetration testing manager, and why are they important?

To thrive as a Penetration Testing Manager, you need deep expertise in cybersecurity, vulnerability assessment, and penetration testing methodologies, typically supported by a relevant degree and certifications like OSCP or CISSP. Familiarity with tools such as Metasploit, Burp Suite, and SIEM systems is essential for effectively managing testing operations. Strong leadership, communication, and project management skills help in guiding teams and translating technical findings for stakeholders. These capabilities are crucial to ensure robust security postures, clear risk communication, and successful management of security testing initiatives.

What is the difference between Penetration Testing Manager vs Penetration Tester?

AspectPenetration Testing ManagerPenetration Tester
CertificationsOSCP, CISSP, PMPOSCP, CEH, GPEN
Work EnvironmentOversees teams, manages projects, strategic planningConducts security assessments, performs testing, technical execution
Employer & Industry UsageSecurity firms, large corporations, government agenciesSecurity teams, consulting firms, internal security departments

The main difference is that a Penetration Testing Manager focuses on managing teams, planning projects, and strategic oversight, while a Penetration Tester is hands-on, performing security assessments and testing systems. Both roles require relevant certifications and are integral to cybersecurity, but they differ in responsibilities and scope.

More about Penetration Testing Manager jobs

What cities are hiring for Penetration Testing Manager jobs?

Cities with the most Penetration Testing Manager job openings:

What are the most commonly searched types of Penetration Testing jobs?

The most popular types of Penetration Testing jobs are:

What states have the most Penetration Testing Manager jobs?

States with the most job openings for Penetration Testing Manager jobs include:

Infographic showing various Penetration Testing Manager job openings in the United States as of August 2026, with employment types broken down into 77% Full Time, 15% Part Time, and 8% Contract. Highlights an 61% In-person, 8% Hybrid, and 31% Remote job distribution, with an average salary of $132,962 per year, or $63.9 per hour.

Senior Penetration Tester

Analygence

Washington, DC • Hybrid

Full-time

Re-posted yesterday


Job description

Tharros is seeking a Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer to support a DHS Intelligence and Analysis cybersecurity program in the National Capital Region.
This role will support advanced penetration testing, software assurance, vulnerability assessment, cyber supply chain risk management, secure cloud and hybrid engineering, and cross-domain security assessment activities. The ideal candidate is a senior technical assessor who can go beyond automated scanning to identify systemic weaknesses, validate exploitability, assess operational impact, and provide clear remediation recommendations for complex mission environments.
Responsibilities:
  • Conduct penetration testing, vulnerability assessments, software assurance, and cyber supply chain risk management activities for Federal mission systems.
  • Perform full-scope security testing using established methodologies such as MITRE ATT&CK, OWASP, NIST 800-115, and related Federal or IC assessment practices.
  • Support pre-engagement planning, rules of engagement, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting.
  • Use approved automated and manual testing methods to identify vulnerabilities, validate exploitability, and assess potential business and operational impacts.
  • Identify vulnerabilities commonly missed by automated tools through manual, expert-driven testing techniques.
  • Assess SOC detection and response capabilities through controlled testing activities.
  • Produce penetration testing reports, vulnerability assessment reports, software assurance recommendations, and corrective action guidance.
  • Support software assurance through vulnerability and compliance testing, source code review, static/dynamic analysis, dependency review, and software supply chain risk identification.
  • Conduct vulnerability assessments and interpret results to recommend corrective actions and mitigation strategies.
  • Support secure cloud, hybrid, DevSecOps, application, identity, API, microservices, CI/CD, Zero Trust, and cross-domain assessment activities.
  • Maintain secure testing kits and assessment tooling, including patching, configuration updates, and approved tool management.
  • Update and maintain penetration testing, SCRM, and vulnerability assessment procedures.
  • Support audits, working groups, and stakeholder briefings related to penetration testing, software assurance, vulnerability assessment, and cyber supply chain risk.
  • Identify opportunities to improve testing processes, automate assessment workflows, strengthen reporting, and produce useful metrics for leadership and technical stakeholders.
  • Translate assessment findings into actionable remediation plans, risk insights, POA&M inputs, dashboards, and decision-ready reporting.