Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead Penetration Tester

$110k - $150k

Revolutional, LLC

Job Description

Job Description

Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes.

We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy.

Lead Penetration Tester

Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (project-based; onsite)

Terms: Full-time

Salary Range: $110-$150k DOE

Clearance: Active Secret required

Travel: Yes – travel to agency sites required

Project Description

This position leads operational security assessments and penetration testing across a portfolio of federal agencies and web applications. Assessments are conducted in accordance with the ISC Security Assessment Methodology and applicable federal rules of engagement, producing findings that reach agency CIO and CISO-level leadership. The program also requires FedRAMP-qualified penetration testing support for cloud service authorization activities.

The core challenge: leading a high-tempo assessment program across multiple agencies per year — each with distinct environments, rules of engagement, and stakeholder expectations — while producing deliverables that meet the evidentiary and presentation standards of senior federal leadership.

Position Description

As a Lead Penetration Tester at Revolutional, you own the end-to-end execution of operational security assessments and web application penetration tests across a federal agency portfolio. You develop test plans, lead technical execution, produce security assessment reports and criticality matrices, and deliver out-brief presentations directly to agency CIO and CISO-level audiences. You are the senior technical authority on every engagement you lead.

You bring deep experience with federal assessment methodologies — ISC Security Assessment Methodology, OWASP, NIST SP 800 series, and DISA STIG — and hold or are actively pursuing CISA AES certification. You are equally comfortable executing a technically complex assessment and standing in front of agency leadership to explain what you found and what it means.

What You Will Own
  • Operational security assessment leadership across a portfolio of federal agencies (approximately 6–7 per year)
  • Web application security assessments (approximately 3–4 applications per year)
  • Test plan and rules of engagement development for each assessment
  • Criticality matrix development and risk prioritization
  • Security assessment report authorship and quality
  • Out-brief presentations to agency CIO and CISO-level leadership
  • FedRAMP penetration testing support for cloud service authorization
Responsibilities
  • Lead operational security assessments across federal agencies in accordance with the ISC Security Assessment Methodology and applicable rules of engagement; manage approximately 6–7 agency assessments per year
  • Conduct web application security assessments using OWASP methodology; assess approximately 3–4 applications per year across a range of agency environments
  • Develop comprehensive test plans for each engagement: scope definition, assessment objectives, methodology selection, rules of engagement, and timeline
  • Build criticality matrices that prioritize findings by risk, asset value, and mission impact to support agency remediation planning
  • Author detailed security assessment reports documenting findings, evidence, risk ratings, and actionable remediation guidance meeting federal evidentiary and reporting standards
  • Develop and deliver out-brief presentations to agency CIO, CISO, and senior leadership audiences; communicate complex technical findings with clarity and executive-level credibility
  • Conduct FedRAMP-qualified penetration testing in support of cloud service authorization activities; apply FedRAMP pen testing requirements and documentation standards
  • Apply NIST SP 800 series guidance and DISA STIG methodology throughout assessment planning, execution, and reporting
  • Coordinate with agency stakeholders before, during, and after assessments to manage expectations, address questions, and ensure findings are understood and acted upon
  • Stay current on vulnerability research, offensive techniques, and emerging attack surfaces relevant to federal civilian agency environments
What You Bring (Requirements)Baseline Requirements
  • Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience)
  • 5 or more years of hands-on penetration testing experience, with demonstrated experience leading assessments in federal environments
  • CISA AES (Authorized External Security) certification required, or actively in process of obtaining
  • FedRAMP penetration testing experience required
  • Active Secret clearance
  • Ability and willingness to travel to agency sites as required
Technical & Domain Capabilities
  • Deep experience conducting operational security assessments in accordance with the ISC Security Assessment Methodology and federal rules of engagement
  • Proficiency with OWASP methodology applied to web application security assessments across federal environments
  • Working knowledge of NIST SP 800 series guidance as applied to security assessment planning, execution, and reporting
  • Experience applying DISA STIG methodology to assessment scope and findings documentation
  • Experience developing test plans, criticality matrices, and security assessment reports that meet federal evidentiary and leadership reporting standards
  • Demonstrated experience presenting technical security findings to CIO, CISO, and senior agency leadership audiences
  • FedRAMP-qualified penetration testing experience, including familiarity with FedRAMP pen test requirements, documentation, and cloud authorization processes
  • Proficiency with industry-standard penetration testing toolsets for network, application, and infrastructure assessments
Core Strengths
  • Senior assessment lead: you own engagements end-to-end and your findings are technically sound, clearly documented, and risk-rated with precision
  • Executive-ready communicator — you develop and deliver out-brief presentations that land with CIO and CISO audiences, not just technical teams
  • Methodologically disciplined: you work within rules of engagement, document everything, and produce deliverables that hold up under agency and regulatory scrutiny
  • High-tempo operator who manages multiple concurrent engagements across different agency environments without loss of quality or attention to detail
Certifications

The following certifications are required or strongly preferred:

Required
  • CISA AES (Authorized External Security) Assessment Lead or Technical Lead certification (or actively in process)
Strongly Preferred
  • GPEN (GIAC Penetration Tester), GXPN (GIAC Exploit Researcher and Advanced Penetration Tester), OSCP (Offensive Security Certified Professional), or equivalent offensive security credential
  • GWAPT (GIAC Web Application Penetration Tester) or equivalent web application security certification
Nice to Have (Differentiators)
  • Experience conducting CISA AES assessments as Assessment Lead across multiple federal civilian agencies
  • Familiarity with FedRAMP High, Moderate, and Low authorization boundaries and their penetration testing implications
  • Background in Red Team operations or adversary emulation in addition to structured assessment methodology
  • Experience with cloud-native application security assessments (AWS, Azure, GCP, or GovCloud)
  • Active TS/SCI clearance

#DICE #LinkedIn

 

___________________________________________________________________________________________________________

Here at Revolutional we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day.  Some of these recognitions include:  

  • Recognized as a Top 20 "Best Place to Work in Virginia"
  • Recipient of Department of Labor's HireVets Gold Medallion
  • Great Place to Work Certification for five years running
  • A Virginia Chamber of Commerce Fantastic 50 company
  • A Northern Virginia Technology Council Tech 100 company 
  • Inc. 5000 list of fastest growing companies for eleven years
  • Two-time SBA SBIR Tibbett's Award winner
  • Virginia Values Veterans (V3) Certification

We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Revolutional family!   In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to

  • Traditional and HSA- eligible medical insurance plans 
  • 100% employer-paid dental and vision insurance options 
  • 100% employer-sponsored STD, LTD, and life insurance
  • 5% 401(k) company matching
  • Flexible-schedules and teleworking options
  • Paid holidays and PTO Accrual Plans
  • Paid Parental Leave
  • Professional development and career growth opportunities 
  • Team and company-wide events, recognition, and appreciation-- and so much more! 

Check out our Revolutional | LinkedIn to find out a little more about who we are and if we are the right next step for your career!   

Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Revolutional does and will take affirmative action to employ and advance in employment individuals with disabilities and protected veterans.  To perform the above job successfully, an individual must possess the knowledge, skills, and abilities listed; meet the education and work experience required; and must be able to perform each essential duty and responsibility satisfactorily.  Other duties in addition to those listed may be assigned as necessary to meet business needs.  Reasonable accommodation will be made to enable an applicant with a disability to successfully apply for and/or perform the essential duties of the job.  If you are in need of an accommodation, please contact View email address on ziprecruiter.com.

"Know Your Rights: Workplace Discrimination is Illegal" Poster | U.S. Equal Employment Opportunity Commission

Vacancy posted 20 days ago
Similar jobs that could be interesting for youBased on the Lead Penetration Tester in Washington DC vacancy
  •  ...protecting what matters. Advance how our customers operate while you advance your career. Join GDIT as an Ethical Hacker/Penetration Tester Sr Principal and build an impactful career in enterprise IT, collaborating with people who are driven and resourceful like you... 
    Suggested
    Work experience placement

    General Dynamics Information Technology

    Bethesda, MD
    19 hours ago
  •  ...Required Experience Minimum of 5 years’ experience in the conduct of, supporting the conduct of, or leading penetration tests. Key skills include a strong understanding of operating systems and networking protocols, strong understanding of how to identify and exploit... 
    Suggested

    Saliense

    Alexandria, VA
    20 hours ago
  •  ...Job Description Job Description **CONTINGENT UPON CONTRACT AWARD**Overview: Job Title: Lead Information System Security Officer (ISSO) Security Clearance: Ability to Obtain Tier 4 High-Risk Public Trust Location : Washington, D.C. (Due to the nature of the... 
    Suggested
    Contract work

    C3EL

    Washington DC
    27 days ago
  •  ..., a premier strategic services firm that meets IT and Service needs for commercial and government clients, is seeking a full-time Lead Senior Information Systems Security Officer (ISSO)  to support the government customer located in Washington, DC . This is an exempt... 
    Suggested
    Full time
    Contract work
    For contractors
    Remote work
    2 days per week

    Dynamic Solutions Technology LLC

    Washington DC
    15 days ago
  •  ...identifying candidates for the following position. Requisition Type:Full Time Position Status: Contingent Position Title: Penetration Tester Location:Arlington, VA Security Clearance:Secret   Duties and Responsibilities The Penetration Testersupports... 
    Suggested
    Full time
    For contractors

    gTANGIBLE Corporation

    Arlington, VA
    more than 2 months ago
  • $129.36k - $215.6k

     ...us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking a Lead IAM Systems Analyst to join our team in Seattle, Washington (US-WA), United States (US).   Lead IAM Systems Analyst & Product Owner... 
    Temporary work
    Work at office
    Remote work
    Flexible hours

    NTT DATA, Inc.

    Washington DC
    20 days ago
  •  ...recognize that our employees are our number one resource. If you are a problem-solving people-person, apply today! Position Title: Lead Cyber Threat Analyst Location: Washington, DC Position Summary The Lead Cyber Threat Analyst serves as the technical and... 
    For contractors
    Local area

    DirectViz Solutions, LLC

    Washington DC
    15 days ago
  •  ...Job Description Job Description Evolver Federal is seeking a Lead Cyber Threat Analyst to fulfil a requirement for a potential government client. The Lead Cyber Threat Analyst is responsible for identifying, analyzing, and mitigating advanced cyber threats targeting... 
    Flexible hours

    Evolver Federal

    Washington DC
    15 days ago
  • $116.9k - $243.1k

     ...Join us to drive positive, lasting change that moves missions and the government forward! Job Description The Penetration Tester will conduct comprehensive penetration tests on applications, networks, and systems. Identify and exploit security vulnerabilities... 
    Full time
    Live in
    Work at office
    Local area

    Accenture Federal Services

    Arlington, VA
    2 days ago
  • Saliense is seeking a senior security analyst with extensive digital forensics and incident response experience. You will conduct forensic analysis across Windows, Linux, and Mac and perform malware analysis, data/triple-check acquisitions, and cloud-activity investigations...

    Saliense

    Alexandria, VA
    2 days ago
  • $130k - $180k

     ...technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy. Lead Cyber Threat Intelligence Analyst Location: Onsite – Government-controlled secure facility Terms: Full-time Salary: $130-$... 
    Full time
    Work experience placement
    Flexible hours
    Shift work

    Revolutional, LLC

    Suitland, MD
    27 days ago
  • Business Computers Management Consulting Group, LLC (BCMC) seeks a Senior JCDC Cyber Triage Analyst to provide expert threat triage, analysis, and interagency coordination for national cyber defense. The role mentors junior analysts and liaises with FBI, NSA, USCYBERCOM...

    bcmcllc

    Arlington, VA
    2 days ago
  • Peraton is seeking a Cyber Program Analyst (Communications / Collaboration) to support HQDA G-3/5/7 DAMO-SO initiatives, policies, and directives. The role requires coordinating with senior staffs across OSD, Joint Staff, HQDA, and Army components to enable EW and non-kinetic...

    Peraton

    Arlington, VA
    5 days ago
  •  ...rockITdata is a unique SDVOSB services company that partners with leading commercial healthcare/life sciences organizations on cutting...  ...impact for the American taxpayer and consumer. The Integration Tester is responsible for validating and testing integrations across... 
    Full time

    rockITdata

    Arlington, VA
    8 days ago
  •  ...The Integration Tester plays a critical role in ensuring the stability, accuracy, and reliability of Navy Mutual's enterprise applications...  ...The Integration Tester will serve as a champion of quality by leading testing efforts across multiple projects while helping drive... 

    Navy Mutual

    Arlington, VA
    3 days ago
  •  ...force protection, law enforcement, military security, or related security operations. Minimum of 1-2 years of supervisory, team lead, or shift lead experience preferred. Ability to obtain and maintain required security clearances, certifications, and site access... 
    For contractors
    Work at office
    Shift work
    Rotating shift

    T47 INTERNATIONAL, INC.

    Bowie, MD
    22 days ago
  • Sikich is seeking a highly motivated IT Senior Auditor for positions in Alexandria, VA, Columbus, OH, and Indianapolis, IN. The role requires active interim Secret clearance or the ability to obtain it, with responsibilities spanning IT controls testing, documentation, ...
    Interim role
    Work at office

    Sikich

    Alexandria, VA
    4 days ago
  • Lead Cyber Security Specialist This is currently a remote position in our SOC, but return to Washington D.C. in a part-time on-site capacity once COVID-19 restrictions are eased. We specifically need someone who can do several weeks of training with our day shift and then... 
    Part time
    Work experience placement
    Remote work
    Day shift

    Samprasoft

    Washington DC
    4 days ago
  • $17 - $27.75 per hour

     ...deliver an exceptional customer experience • Serves as a Brand Ambassador embodying of Coach values and increasing brand awareness • Leads implementation of Company initiatives and support full operation of the business • Maintain a growth mindset for business and... 
    Minimum wage
    Shift work

    Tapestry

    Bethesda, MD
    19 hours ago
  •  ..., and other cyber intelligence reports Required Skills Experience as a hands-on cybersecurity analyst (i.e. SOC Analyst or Penetration Tester) is required Experience with the analysis and characterization of cyber attacks Skilled in identifying different classes of... 
    For contractors

    kozmetickesluzby.vecnakraska.sk - Jobboard

    Arlington, VA
    3 days ago
  • A leading IT service provider in Arlington, VA seeks a Network Engineer - Level III responsible for designing and managing complex network systems. Key responsibilities include leading network projects, optimizing performance, and mentoring junior engineers. Applicants... 

    ActioNet, Inc.

    Arlington, VA
    6 days ago
  •  ...with remediation of 3rd party accounts receivable, call center support and a variety of revenue cycle outsource capabilities. Team leads supervise and promote teamwork to Patient Account Representatives I and II and assign work activities to deliver superior third party... 

    TRC Talent Solutions

    Washington DC
    14 days ago
  •  ...Job Description Job Description CyberLinx Solutions LLC is seeking a forward thinking Cybersecurity GRC Lead / Cyber Risk Manager responsible for leading the organization’s cybersecurity governance, risk, and compliance (GRC) program. This role oversees enterprise... 

    CyberLinx Solutions LLC

    Washington DC
    26 days ago
  • $62k - $141k

     ...analyze and correlate data from multiple technical sources to identify malicious activity, artifacts, indicators, or investigative leads ~ Ability to communicate clearly with both technical and non-technical audiences, including the production of high‑quality incident... 
    Full time
    Contract work
    Part time
    Local area
    Remote work

    Booz Allen Hamilton

    Bethesda, MD
    7 hours ago
  •  ...Job Description Job Description Senior Platform Lead & Delivery Manager Location: Arlington, VA (Remote with occasional onsite requirements in Arlington, VA) Position Description: The Senior Platform Lead & Delivery Manager is a player-coach role at the center... 
    Work at office
    Local area
    Remote work

    Far West Federal

    Arlington, VA
    15 days ago
  • Job Description Job Description JOB SUMMARY Supervises and coordinates activities of workers engaged in all phases of plant operation. Prepares operations schedules and coordinates manufacturing activities to ensure safety, production, and quality meets specifications...
    Immediate start
    Shift work
    Rotating shift

    Basic American Foods

    Washington DC
    15 days ago
  • $237.6k - $297k

     ...the world's most important decisions. Our products provide the high-quality data and full-stack technologies that power the world's leading models, and help enterprises and governments build, deploy, and oversee AI applications that deliver real impact. We work closely... 
    Full time

    United States Digital Space LLC

    Washington DC
    4 days ago
  • $300k - $320k

     ...purple team engagements simulating advanced threat actors across our cloud infrastructure, endpoints and bare metal deployments. Penetration test specific, high value deployments. Contribute to AI-assisted security testing tooling and workflows. Work cross... 
    Work at office
    Visa sponsorship
    Flexible hours

    Anthropic

    Washington DC
    5 days ago
  • $136k - $184k

     ...Engineering, Computer Science, or a related field- Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent- Experience with web protocols, common security attacks, and remediation (... 
    Internship
    Flexible hours

    Amazon

    Arlington, VA
    2 days ago
  •  ...of Homeland Security (DHS) Entry on Duty (EOD) Suitability - 5+ years of direct relevant experience in cyber defense analysis using leading edge technologies and industry standard cyber defense tools- - Experience successfully developing and deploying signatures -... 
    Contract work
    Immediate start

    Nightwing Group

    Arlington, VA
    20 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead Penetration Tester. Be the first to apply!