Find Jobs
Find Jobs Near You – Available Work in Your Location
Lead Penetration Tester
Career Insights for Vulnerability Analyst / Penetration Tester
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Colorado data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.
$107,473 / year median in Colorado
+6% projected growth
Job Description
Lead Penetration Tester Location:
Washington, DC, Ft. Collins, CO, or Kansas City, MO (project-based; onsite)Terms:
Full-time Clearance:
Active Secret requiredTravel:
Yes- travel to agency sites required Project Description This position leads operational security assessments and penetration testing across a portfolio of federal agencies and web applications.
The core challenge:
leading a high-tempo assessment program across multiple agencies per year — each with distinct environments, rules of engagement, and stakeholder expectations — while producing deliverables that meet the evidentiary and presentation standards of senior federal leadership. Position Description As a Lead Penetration Tester at Revolutional, you own the end-to-end execution of operational security assessments and web application penetration tests across a federal agency portfolio. You develop test plans, lead technical execution, produce security assessment reports and criticality matrices, and deliver out-brief presentations directly to agency CIO and CISO-level audiences. You are the senior technical authority on every engagement you lead. You bring deep experience with federal assessment methodologies — ISC Security Assessment Methodology, OWASP, NIST SP 800 series, andDISA STIG
— and hold or are actively pursuingCISA AES
certification. You are equally comfortable executing a technically complex assessment and standing in front of agency leadership to explain what you found and what it means. What You Will Own Operational security assessment leadership across a portfolio of federal agencies (approximately 6-7 per year) Web application security assessments (approximately 3-4 applications per year) Test plan and rules of engagement development for each assessment Criticality matrix development and risk prioritization Security assessment report authorship and quality Out-brief presentations to agency CIO and CISO-level leadership FedRAMP penetration testing support for cloud service authorization Responsibilities Lead operational security assessments across federal agencies in accordance with the ISC Security Assessment Methodology and applicable rules of engagement; manage approximately 6-7 agency assessments per year Conduct web application security assessments using OWASP methodology; assess approximately 3-4 applications per year across a range of agency environments Develop comprehensive test plans for each engagement: scope definition, assessment objectives, methodology selection, rules of engagement, and timeline Build criticality matrices that prioritize findings by risk, asset value, and mission impact to support agency remediation planning Author detailed security assessment reports documenting findings, evidence, risk ratings, and actionable remediation guidance meeting federal evidentiary and reporting standards Develop and deliver out-brief presentations to agency CIO, CISO, and senior leadership audiences; communicate complex technical findings with clarity and executive-level credibility Conduct FedRAMP-qualified penetration testing in support of cloud service authorization activities; apply FedRAMP pen testing requirements and documentation standards ApplyNIST SP 800
series guidance andDISA STIG
methodology throughout assessment planning, execution, and reporting Coordinate with agency stakeholders before, during, and after assessments to manage expectations, address questions, and ensure findings are understood and acted upon Stay current on vulnerability research, offensive techniques, and emerging attack surfaces relevant to federal civilian agency environments What You Bring (Requirements) Baseline Requirements Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience) 5 or more years of hands-on penetration testing experience, with demonstrated experience leading assessments in federal environmentsCISA AES
(Authorized External Security) certification required, or actively in process of obtaining FedRAMP penetration testing experience required Active Secret clearance Ability and willingness to travel to agency sites as required Technical & Domain Capabilities Deep experience conducting operational security assessments in accordance with the ISC Security Assessment Methodology and federal rules of engagement Proficiency with OWASP methodology applied to web application security assessments across federal environments Working knowledge ofNIST SP 800
series guidance as applied to security assessment planning, execution, and reporting Experience applyingDISA STIG
methodology to assessment scope and findings documentation Experience developing test plans, criticality matrices, and security assessment reports that meet federal evidentiary and leadership reporting standards Demonstrated experience presenting technical security findings to CIO, CISO, and senior agency leadership audiences FedRAMP-qualified penetration testing experience, including familiarity with FedRAMP pen test requirements, documentation, and cloud authorization processes Proficiency with industry-standard penetration testing toolsets for network, application, and infrastructure assessments Core Strengths Senior assessment lead: you own engagements end-to-end and your findings are technically sound, clearly documented, and risk-rated with precision Executive-ready communicator — you develop and deliver out-brief presentations that land with CIO and CISO audiences, not just technical teams Methodologically disciplined: you work within rules of engagement, document everything, and produce deliverables that hold up under agency and regulatory scrutiny High-tempo operator who manages multiple concurrent engagements across different agency environments without loss of quality or attention to detail Certifications The following certifications are required or strongly preferred: RequiredCISA AES
(Authorized External Security) Assessment Lead or Technical Lead certification (or actively in process) Strongly Preferred GPEN (GIAC Penetration Tester), GXPN (GIAC Exploit Researcher and Advanced Penetration Tester), OSCP (Offensive Security Certified Professional), or equivalent offensive security credential GWAPT (GIAC Web Application Penetration Tester) or equivalent web application security certification Nice to Have (Differentiators) Experience conductingCISA AES
assessments as Assessment Lead across multiple federal civilian agencies Familiarity with FedRAMP High, Moderate, and Low authorization boundaries and their penetration testing implications Background in Red Team operations or adversary emulation in addition to structured assessment methodology Experience with cloud-native application security assessments (AWS, Azure, GCP, or GovCloud) Active TS/SCI clearance #DICE #LinkedIn ___________________________________________________________________________________________________________ Here at Revolutional we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day.Some of these recognitions include:
Recognized as a Top 20 "Best Place to Work in Virginia" Recipient of Department of Labor's HireVets Gold Medallion Great Place to Work Certification for five years running A Virginia Chamber of Commerce Fantastic 50 company A Northern Virginia Technology Council Tech 100 company Inc. 5000 list of fastest growing companies for eleven years Two-timeSBA SBIR
Tibbett's Award winner Virginia Values Veterans (V3) Certification We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Revolutional family! In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to Traditional and HSA- eligible medical insurance plans 100% employer-paid dental and vision insurance options 100% employer-sponsored STD, LTD, and life insurance 5% 401(k) company matching Flexible-schedules and teleworking options Paid holidays and PTO Accrual Plans Paid Parental Leave Professional development and career growth opportunities Team and company-wide events, recognition, and appreciation
- and so much more!
- indicates a required field Quick Apply with MyGreenhouse First Name
- Last Name
- Preferred First Name Email
- Phone Country Phone Resume/CV Attach Attach Dropbox Enter manually Enter manually Accepted file types: pdf, doc, docx, txt, rtf Cover Letter Attach Attach Dropbox Enter manually Enter manually Accepted file types: pdf, doc, docx, txt, rtf LinkedIn Profile Website Are you authorized to work for any employer in the United States?
- Select... Will you at any time require sponsorship from Revolutional to obtain or extend your authorization to work in the United States?
- Select... Have you been employed by Revolutional/Harmonia/Maveris in the past? If yes, please provide your last date employed by the company.
- Are you related to anyone that works for Revolutional?
- Select... If you are related to a current employee at Revolutional please provide the name of the employee and your relation to them. Were you referred by a current employee of Revolutional?
- Select... If you were referred by a current employee of Revolutional, please provide the person's name who referred you. What are your salary expectations?
- $0•$50,000 $50,000•$65,000 $65,000•$80,000 $80,000•$100,000 $100,000•$120,000 $120,000•$140,000 $140,000•$160,000 $160,000•$180,000 $180,000•$200,000 $200,000+ Do you have an active Secret Clearance or higher?
- Select... Do you have 5 or more years of hands-on penetration testing experience, with demonstrated experience leading assessments in federal environments?
- Select.
CISA AES
(Authorized External Security) certification, or are you actively in the process of obtaining it?- Select... Do you have FedRAMP penetration testing experience?
- Select.