1

Penetration Testing Manager Jobs (NOW HIRING)

Penetration Tester

Herndon, VA · On-site

$100K - $200K/yr

Push the boundaries of penetration testing innovation through research and development of novel ... Manage and configure campaign infrastructure * Research and develop attacks on vulnerable systems ...

MD · On-site

Author formal penetration testing reports, conclusions memoranda, executive summaries, and technical findings. * Present complex technical findings to senior executives, IT management, and technical ...

Red Team Penetration Tester

Dahlgren, VA · On-site

$110K - $150K/yr

Penetration Testing (PENTEST) * Red Team Operations * Tool/Software Development (exploits/malware ... Managing identity and access in Microsoft Entra ID. * Experience conducting Red Team operations in ...

Showing results 41-60

Penetration Testing Manager information

See salary details

$57K

$133K

$186K

How much do penetration testing manager jobs pay per year?

As of Sep 4, 2026, the average yearly pay for penetration testing manager in the United States is $132,962.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,000.00 and $150,000.00 per year, depending on experience, location, and employer.

What does a penetration testing manager do?

A Penetration Testing Manager oversees teams that simulate cyberattacks on an organization's systems, networks, and applications to identify vulnerabilities and assess security risks. They are responsible for planning, coordinating, and ensuring the quality of penetration tests, as well as communicating findings to stakeholders and recommending remediation strategies. Additionally, they often develop testing methodologies, manage team performance, and ensure compliance with industry standards and regulations.

What are some common challenges faced by a penetration testing manager when leading a security assessment team?

Penetration Testing Managers often face the challenge of balancing technical depth with project management responsibilities. Coordinating multiple engagements, ensuring consistent testing methodologies, and managing client expectations can be demanding. Additionally, staying updated with evolving threat landscapes and ensuring the team has the necessary skills and certifications are ongoing concerns. Effective communication with both technical staff and non-technical stakeholders is crucial for translating findings into actionable recommendations.

What are the key skills and qualifications needed to thrive as a penetration testing manager, and why are they important?

To thrive as a Penetration Testing Manager, you need deep expertise in cybersecurity, vulnerability assessment, and penetration testing methodologies, typically supported by a relevant degree and certifications like OSCP or CISSP. Familiarity with tools such as Metasploit, Burp Suite, and SIEM systems is essential for effectively managing testing operations. Strong leadership, communication, and project management skills help in guiding teams and translating technical findings for stakeholders. These capabilities are crucial to ensure robust security postures, clear risk communication, and successful management of security testing initiatives.

What is the difference between Penetration Testing Manager vs Penetration Tester?

AspectPenetration Testing ManagerPenetration Tester
CertificationsOSCP, CISSP, PMPOSCP, CEH, GPEN
Work EnvironmentOversees teams, manages projects, strategic planningConducts security assessments, performs testing, technical execution
Employer & Industry UsageSecurity firms, large corporations, government agenciesSecurity teams, consulting firms, internal security departments

The main difference is that a Penetration Testing Manager focuses on managing teams, planning projects, and strategic oversight, while a Penetration Tester is hands-on, performing security assessments and testing systems. Both roles require relevant certifications and are integral to cybersecurity, but they differ in responsibilities and scope.

More about Penetration Testing Manager jobs

What cities are hiring for Penetration Testing Manager jobs?

Cities with the most Penetration Testing Manager job openings:

What are the most commonly searched types of Penetration Testing jobs?

The most popular types of Penetration Testing jobs are:

What states have the most Penetration Testing Manager jobs?

States with the most job openings for Penetration Testing Manager jobs include:

Infographic showing various Penetration Testing Manager job openings in the United States as of August 2026, with employment types broken down into 77% Full Time, 15% Part Time, and 8% Contract. Highlights an 61% In-person, 8% Hybrid, and 31% Remote job distribution, with an average salary of $132,962 per year, or $63.9 per hour.

$100K - $200K/yr

Full-time

Re-posted 11 days ago


Job description

Principal Penetration Tester
Altus Consulting seeks a seasoned cybersecurity professional to spearhead our penetration testing initiatives. As a key member of our elite team, you'll play a crucial role in safeguarding some of the world's most critical digital infrastructure.
Core Responsibilities:
  • Design and execute sophisticated penetration tests across complex networks, systems, and applications
  • Craft compelling, actionable reports that translate technical findings into clear business impact
  • Collaborate closely with clients to develop tailored remediation strategies that drive meaningful security improvements
  • Push the boundaries of penetration testing innovation through research and development of novel TTPs
  • Contribute to Altus Consulting's thought leadership efforts via publications, presentations, and industry forums
  • Lead quality assurance initiatives for our suite of penetration testing services
  • Engage in cross-functional collaboration to enhance our overall security offerings

Ideal Candidate Profile:
We are seeking candidates with a degree in Computer Science, Computer Engineering, or a related technical field. Alternatively, we will consider individuals with equivalent professional experience that demonstrates comparable skills and knowledge.
To be considered equivalent, candidates should be able to prove or quantify their experience through:
  • Relevant work history demonstrating hands-on experience in computer science/engineering principles
  • Completed projects or certifications that align with our technical requirements
  • Demonstrated proficiency in key skills like programming languages, algorithms, software design, etc.
  • Relevant coursework or training if transitioning from another field

We value both formal education and practical experience. Candidates who can show they have acquired equivalent knowledge through non-traditional means (e.g. self-study, online courses, bootcamps) are encouraged to apply.
Applicants should be prepared to discuss their qualifications in detail during the interview process.
Key Skills to Focus On:
  • Programming languages like Python, Java, C++, Linux scripting
  • Network and application security knowledge
  • Familiarity with security assessment tools
  • Threat modeling and cryptography skills
  • Knowledge of operating systems (Windows, Linux, macOS)
  • Experience with penetration testing frameworks and tools

Highly Valued Certifications:
  • OSCP (Offensive Security Certified Professional)
  • CPTS (Certified Penetration Testing Specialist)
  • GPEN (GIAC Penetration Tester)
  • GXPN (GIAC Exploit Programmer)
  • CRTO (Certified Red Team Operator)

Additional Considerations:
  • Familiarity with emerging threats and attack vectors in cloud and containerized environments
  • Experience with automated vulnerability scanning and exploitation platforms
  • Knowledge of security frameworks and regulations relevant to commercial companies
  • Track record of contributing to open-source security projects or publishing research in the field

What We Offer:
  • Competitive compensation and benefits package
  • Opportunities for professional development
  • Collaborative, dynamic work environment
  • Chance to work on cutting-edge security challenges

About Our Team:
Altus Consulting believes it's essential to keep innovating while safeguarding our digital infrastructure. Our team ensures that we maintain a secure operating environment and preserve the trust of our customers, partners, and stakeholders. We bring together a variety of services and capabilities to help prevent fraud, detect threats, and manage digital risk and access. In addition to mitigating attack risks and securing cloud transformation, we foster in our team members a culture of innovation and reliability.
Key Campaign Activities:
  • Execute full-scale, assumed breach, and transparent/collaborative campaigns
  • Develop, curate, and leverage offensive security tooling
  • Manage and configure campaign infrastructure
  • Research and develop attacks on vulnerable systems and defensive tooling (e.g., AntiVirus, EDR, XDR)
  • Provide ongoing consulting to defense teams as they design and implement responses to campaign findings
  • We're looking for candidates who can leverage their expertise in scripting, development, attack infrastructure, social engineering, and offensive security tooling to execute simulated attacks against our clients' networks and subsidiaries spanning the globe.
  • If you're passionate about pushing the boundaries of cybersecurity and want to join a team that's reshaping how organizations defend against modern threats, we encourage you to apply. Together, we can create a safer digital world for all.