1

Penetration Testing Manager Jobs (NOW HIRING)

Present findings to stakeholders, including technical teams and management. * Create and maintain documentation on penetration testing methodologies, tools, and techniques. * Remediation Support:

... management, and related enterprise support for DHRA, including DMDC and OUSD(P&R). Come join our ... Conduct Government-selected penetration-testing assessments and threat-hunting exercises in ...

Push the boundaries of penetration testing innovation through research and development of novel ... Manage and configure campaign infrastructure * Research and develop attacks on vulnerable systems ...

Senior Penetration Tester

Washington, DC · On-site

$145K - $180K/yr

... management personnel, technical personnel, and third parties. Nice To Have: * Certification in focused on Web Application penetration testing. * i.e. eWPT, BSCP, etc * Relevant security research.

Develop risk management methodologies and recommend security improvements. * Analyze penetration testing results and develop risk and threat mitigation plans. * Test and review system configurations ...

... penetration testing initiatives. As a key member of our elite team, you'll play a crucial role in ... manage digital risk and access. In addition to mitigating attack risks and securing cloud ...

... testing practitioner / cyber practitioner in which you have developed capability in managing client ... penetration testing and assurance, network and infrastructure solutions, cloud security and ...

Push the boundaries of penetration testing innovation through research and development of novel ... Manage and configure campaign infrastructure * Research and develop attacks on vulnerable systems ...

... management, and related enterprise support for DHRA, including DMDC and OUSD(P&R). Come join our ... Conduct Government-selected penetration-testing assessments and threat-hunting exercises in ...

Penetration Tester

Washington, DC · On-site

$117K - $199K/yr

Design, develop, and maintain tools/scripts to automate and enhance penetration testing activities. * Manage and mentor a small team of junior penetration testers; provide technical guidance and ...

WV · On-site

Cyber and IT Risk Management Job Qualifications: Skills: Automated Testing, AWS Cloud Computing, Infrastructure Penetration Testing, Security Controls, Security Testing Certifications: None ...

The role will be in response to performing penetration testing engagements using major frameworks ... Communicate technical issues effectively to non-technical management, translating complex ...

New

Showing results 41-60

Penetration Testing Manager information

See salary details

$57K

$133K

$186K

How much do penetration testing manager jobs pay per year?

As of Aug 15, 2026, the average yearly pay for penetration testing manager in the United States is $132,962.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,000.00 and $150,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a penetration testing manager, and why are they important?

To thrive as a Penetration Testing Manager, you need deep expertise in cybersecurity, vulnerability assessment, and penetration testing methodologies, typically supported by a relevant degree and certifications like OSCP or CISSP. Familiarity with tools such as Metasploit, Burp Suite, and SIEM systems is essential for effectively managing testing operations. Strong leadership, communication, and project management skills help in guiding teams and translating technical findings for stakeholders. These capabilities are crucial to ensure robust security postures, clear risk communication, and successful management of security testing initiatives.

What does a penetration testing manager do?

A Penetration Testing Manager oversees teams that simulate cyberattacks on an organization's systems, networks, and applications to identify vulnerabilities and assess security risks. They are responsible for planning, coordinating, and ensuring the quality of penetration tests, as well as communicating findings to stakeholders and recommending remediation strategies. Additionally, they often develop testing methodologies, manage team performance, and ensure compliance with industry standards and regulations.

What is a penetration testing manager?

A penetration testing manager oversees security teams that conduct simulated cyberattacks to identify vulnerabilities in computer systems and networks. They coordinate testing activities, review findings, and ensure remediation, often requiring knowledge of security tools, methodologies, and relevant certifications like OSCP or CISSP.

What are some common challenges faced by a penetration testing manager when leading a security assessment team?

Penetration Testing Managers often face the challenge of balancing technical depth with project management responsibilities. Coordinating multiple engagements, ensuring consistent testing methodologies, and managing client expectations can be demanding. Additionally, staying updated with evolving threat landscapes and ensuring the team has the necessary skills and certifications are ongoing concerns. Effective communication with both technical staff and non-technical stakeholders is crucial for translating findings into actionable recommendations.

What is the difference between Penetration Testing Manager vs Penetration Tester?

AspectPenetration Testing ManagerPenetration Tester
CertificationsOSCP, CISSP, PMPOSCP, CEH, GPEN
Work EnvironmentOversees teams, manages projects, strategic planningConducts security assessments, performs testing, technical execution
Employer & Industry UsageSecurity firms, large corporations, government agenciesSecurity teams, consulting firms, internal security departments

The main difference is that a Penetration Testing Manager focuses on managing teams, planning projects, and strategic oversight, while a Penetration Tester is hands-on, performing security assessments and testing systems. Both roles require relevant certifications and are integral to cybersecurity, but they differ in responsibilities and scope.

More about Penetration Testing Manager jobs

What cities are hiring for Penetration Testing Manager jobs?

Cities with the most Penetration Testing Manager job openings:

What are the most commonly searched types of Penetration Testing jobs?

The most popular types of Penetration Testing jobs are:

What states have the most Penetration Testing Manager jobs?

States with the most job openings for Penetration Testing Manager jobs include:

Infographic showing various Penetration Testing Manager job openings in the United States as of August 2026, with employment types broken down into 67% Full Time, and 33% Part Time. Highlights an 67% In-person, and 33% Hybrid job distribution, with an average salary of $132,962 per year, or $63.9 per hour.

Penetration Tester

asrcfh

Quantico, VA • Hybrid

Full-time

Posted 24 days ago


Job description

ASRC Federal is actively hiring an Assured Compliance Assessment Solution (ACAS) Engineer in support of our Defense Counterintelligence Security Agency (DCSA) program based out of Quantico VA.

Remote flexibility available! Telework offered with a requirement to be onsite up to two (2) days a week at Quantico Marine Corps Base VA.

Position Description:

The Cybersecurity Penetration Tester is a hands-on technical role responsible for conducting simulated attacks on systems and networks to identify vulnerabilities and weaknesses that could be exploited by malicious actors. This role requires a deep understanding of security principles, hacking techniques, and attack methodologies. The Penetration Tester will plan, execute, and document penetration tests, provide recommendations for remediation, and contribute to the overall improvement of the organization's security posture.

Minimum Requirements: 

  • Minimum of 5 – 7 years of experience in security principles such as attack frameworks, threat landscapes, and attacker tactics, techniques and procedures. 
  • Proven experience conducting penetration tests of web applications, networks, and other systems.
  • Experience with a variety of penetration testing tools and techniques (e.g., Rapid7 Nexpose, Appspider Pro, Metasploit, Cobalt Strike and/or Burp Suite).
  • Active Top-Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI
  • Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent experience.
  • Must meet 8570 certification requirements at the time of hire.  IAT II Information Assurance Baseline (e.g., CASP+ CE, CCMP Security, CISA, CISSP, GCED, GCIH, Security+ CE or CCSP) In addition to the IA baseline, a CSSP Auditor cert is preferred (e.g., CEH, CySA+, CISA, GSNA, CFR or PenTest) 

 

Responsibilities:

  • Penetration Testing:
    • Conduct penetration tests of web applications, mobile applications, networks, cloud environments, and other systems.
    • Utilize a variety of tools and techniques to identify vulnerabilities, including SQL injection, cross-site scripting (XSS), buffer overflows, and other common attack vectors.
    • Perform reconnaissance to gather information about target systems and networks.
    • Develop and execute exploit code to demonstrate the impact of identified vulnerabilities.
    • Bypass security controls and evade detection.
  • Vulnerability Assessment:
    • Perform vulnerability assessments using automated scanning tools and manual techniques.
    • Analyze scan results to identify false positives and prioritize vulnerabilities.
    • Develop custom scripts and tools to automate vulnerability assessment tasks.
  • Reporting and Documentation:
    • Document all findings in detailed and comprehensive reports, including descriptions of vulnerabilities, methods used to exploit them, and recommendations for remediation.
    • Present findings to stakeholders, including technical teams and management.
    • Create and maintain documentation on penetration testing methodologies, tools, and techniques.
  • Remediation Support:
    • Provide guidance and technical assistance to system owners and developers on vulnerability remediation.
    • Validate remediation efforts to ensure that vulnerabilities have been properly addressed.
    • Conduct retests to verify the effectiveness of implemented security controls.
  • Research and Development:
    • Stay up-to-date on the latest security threats, vulnerabilities, and attack techniques.
    • Research and evaluate new penetration testing tools and methodologies.
    • Develop custom tools and scripts to enhance penetration testing capabilities.
    • Contribute to the development of security policies and procedures.
  • Collaboration:
    • Collaborate with other cybersecurity professionals, including security architects, incident responders, and security engineers.
    • Share knowledge and expertise with team members.
    • Participate in security training and awareness programs.
  • Ethical Hacking:
    • Conduct all penetration testing activities in a legal and ethical manner, adhering to established rules of engagement.
    • Protect the confidentiality and integrity of sensitive data.
    • Respect the privacy of users and systems.

Work Environment and Physical Demands: 

  • This is primarily a Telework position with a requirement to be onsite up to two (2) days a week
  • If alternate worksite is other than DCSA facilities or corporate office space, must have the reliable ability to communicate over voice (cell phone preferred) and stable, capable internet connection
  • Must be able to communicate complex technical ideas to a diverse customer base both verbally and in written form