1

Penetration Testing Manager Jobs (NOW HIRING)

... management, access controls, and data handling practices for security flaws. • Execute ... years of experience in penetration testing or ethical hacking, with a strong focus on web ...

Minimum of 2 years with penetration testing experience. * Possess one of the following ... NIST Risk Management Framework (RMF) and the Assessment and Authorization (A&A) process. * Security ...

Responsibilities : • Experience in management or as a team leader, managing projects and tasks against tight deadlines. • Experience with continuous penetration testing methodologies. • ...

Minimum of 2 years with penetration testing experience. * Possess one of the following ... NIST Risk Management Framework (RMF) and the Assessment and Authorization (A&A) process. * Security ...

Management or team lead experience * Experience performing continuous penetration testing * Experience conducting red team operations * Experience performing IoT, mobile, and cloud penetration ...

Design, develop, and maintain tools/scripts to automate and enhance penetration testing activities. * Manage and mentor a small team of junior penetration testers; provide technical guidance and ...

Present findings to stakeholders, including technical teams and management. * Create and maintain documentation on penetration testing methodologies, tools, and techniques. * Remediation Support:

This role will support advanced penetration testing, software assurance, vulnerability assessment, cyber supply chain risk management, secure cloud and hybrid engineering, and cross-domain security ...

Management or team lead experience * Experience performing continuous penetration testing * Experience conducting red team operations * Experience performing IoT, mobile, and cloud penetration ...

Penetration Tester

Arlington, VA · On-site

$86K - $138K/yr

Minimum of 2 years with penetration testing experience. * Possess one of the following ... NIST Risk Management Framework (RMF) and the Assessment and Authorization (A&A) process. * Security ...

... t to make informed decisions about how to address the identified findings. Occasional off-hours testing and periodic travel required. Duties include the following: * Conducts penetration testing ...

Senior Penetration Tester

Washington, DC · On-site

$124K - $180K/yr

Lead, plan, and oversee penetration testing operations for systems, networks, cloud resources, and ... Apply advanced security defense functions (encryption, access control, identity management) to ...

The NCIA manages NATO's information technology infrastructure, including its databases ... Perform web application, infrastructure, and application-level penetration testing. Conduct ...

New

Penetration Tester

Quantico, VA · On-site

$130K - $147K/yr

Present findings to stakeholders, including technical teams and management. * Create and maintain documentation on penetration testing methodologies, tools, and techniques. * Remediation Support:

This role will support advanced penetration testing, software assurance, vulnerability assessment, cyber supply chain risk management, secure cloud and hybrid engineering, and cross-domain security ...

This role will support advanced penetration testing, software assurance, vulnerability assessment, cyber supply chain risk management, secure cloud and hybrid engineering, and cross-domain security ...

Showing results 21-40

Penetration Testing Manager information

See salary details

$57K

$133K

$186K

How much do penetration testing manager jobs pay per year?

As of Aug 15, 2026, the average yearly pay for penetration testing manager in the United States is $132,962.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,000.00 and $150,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a penetration testing manager, and why are they important?

To thrive as a Penetration Testing Manager, you need deep expertise in cybersecurity, vulnerability assessment, and penetration testing methodologies, typically supported by a relevant degree and certifications like OSCP or CISSP. Familiarity with tools such as Metasploit, Burp Suite, and SIEM systems is essential for effectively managing testing operations. Strong leadership, communication, and project management skills help in guiding teams and translating technical findings for stakeholders. These capabilities are crucial to ensure robust security postures, clear risk communication, and successful management of security testing initiatives.

What does a penetration testing manager do?

A Penetration Testing Manager oversees teams that simulate cyberattacks on an organization's systems, networks, and applications to identify vulnerabilities and assess security risks. They are responsible for planning, coordinating, and ensuring the quality of penetration tests, as well as communicating findings to stakeholders and recommending remediation strategies. Additionally, they often develop testing methodologies, manage team performance, and ensure compliance with industry standards and regulations.

What is a penetration testing manager?

A penetration testing manager oversees security teams that conduct simulated cyberattacks to identify vulnerabilities in computer systems and networks. They coordinate testing activities, review findings, and ensure remediation, often requiring knowledge of security tools, methodologies, and relevant certifications like OSCP or CISSP.

What are some common challenges faced by a penetration testing manager when leading a security assessment team?

Penetration Testing Managers often face the challenge of balancing technical depth with project management responsibilities. Coordinating multiple engagements, ensuring consistent testing methodologies, and managing client expectations can be demanding. Additionally, staying updated with evolving threat landscapes and ensuring the team has the necessary skills and certifications are ongoing concerns. Effective communication with both technical staff and non-technical stakeholders is crucial for translating findings into actionable recommendations.

What is the difference between Penetration Testing Manager vs Penetration Tester?

AspectPenetration Testing ManagerPenetration Tester
CertificationsOSCP, CISSP, PMPOSCP, CEH, GPEN
Work EnvironmentOversees teams, manages projects, strategic planningConducts security assessments, performs testing, technical execution
Employer & Industry UsageSecurity firms, large corporations, government agenciesSecurity teams, consulting firms, internal security departments

The main difference is that a Penetration Testing Manager focuses on managing teams, planning projects, and strategic oversight, while a Penetration Tester is hands-on, performing security assessments and testing systems. Both roles require relevant certifications and are integral to cybersecurity, but they differ in responsibilities and scope.

More about Penetration Testing Manager jobs

What cities are hiring for Penetration Testing Manager jobs?

Cities with the most Penetration Testing Manager job openings:

What are the most commonly searched types of Penetration Testing jobs?

The most popular types of Penetration Testing jobs are:

What states have the most Penetration Testing Manager jobs?

States with the most job openings for Penetration Testing Manager jobs include:

Infographic showing various Penetration Testing Manager job openings in the United States as of August 2026, with employment types broken down into 67% Full Time, and 33% Part Time. Highlights an 67% In-person, and 33% Hybrid job distribution, with an average salary of $132,962 per year, or $63.9 per hour.

Web Application Penetration Testing

Ampcus Inc

Remote

Full-time

Re-posted 5 days ago


Job description

Job Summary:
Ampcus Inc. is a certified global provider of a broad range of Technology and Business consulting services. We are seeking an experienced and results-driven Penetration Tester to perform comprehensive web application security assessments. The role involves conducting penetration tests, evaluating security mechanisms, and providing actionable insights to enhance the security posture of critical government systems.
Responsibilities:
• Conduct web application, API, and network penetration tests to identify and validate security vulnerabilities.
• Perform grey-box and black-box testing following NIST SP 800-115 and OWASP Testing Framework methodologies.
• Evaluate authentication mechanisms, session management, access controls, and data handling practices for security flaws.
• Execute vulnerability exploitation and proof-of-concept validation to demonstrate real-world risk impact.
• Document findings with technical precision and provide clear remediation recommendations to stakeholders.
• Collaborate with internal security engineers and client teams to verify vulnerability fixes and perform retesting.
• Prepare and deliver comprehensive technical and executive-level reports that align with the COV Information Security Standard (SEC530).
• Support secure configuration reviews and compliance with applicable state and federal cybersecurity standards.
Qualifications:
Required:
• Bachelor’s degree in computer science, Cybersecurity, Information Technology, or a related field (or equivalent experience).
• Preferably 7 years of experience in penetration testing or ethical hacking, with a strong focus on web applications and APIs.
• In-depth knowledge of web technologies, networking protocols, authentication systems, and encryption standards.
• Strong understanding of secure development practices (SDLC) and common vulnerabilities (OWASP Top 10).
• Excellent analytical, documentation, and communication skills.
Preferred:
• CEH (Certified Ethical Hacker) – Required.
• OSCP (Offensive Security Certified Professional) – Preferred.
• CompTIA Security / CySA / GPEN / GWAPT – Desirable.
Company:
Ampcus is a global business, technology consulting and an staff augmentation firm specializing in AI/ML,digital solutions, Cybersecurity & Risk management, Testing, Forensics & Fraud services and human capital management. Founded in 2004, the company is headquartered in Chantilly, USA, with a team of 1001-5000 employees. The company is currently Late Stage.

Ampcus logo

About Ampcus

Sourced by ZipRecruiter

Ampcus Inc. is a ISO 20000, ISO 27000, ISO 9001, CMMI DEV/3 SM and CMMI SVC/3 SM certified global provider of a broad range of Technology and Business consulting services. From strategy to execution, our disciplined yet flexible approach starts and ends with our clients. By listening hard and working harder, client goals become our goals. Their success is our satisfaction. It’s why our clients sleep well at night. We believe that the success of an engagement is determined by strong project management, as well as clear communication and mutual commitment working collaboratively. Our methodology begins with listening to the customer about their needs, then working with their team to gain a clear understanding of the requirements, while providing knowledge transfer of best practices for the organization.

Industry

It services

Company size

1,001 - 5,000 Employees

Headquarters location

Chantilly, VA, US

Year founded

2004