Lead Penetration Tester
$110k - $150kRevolutional, LLC
Job Description
Job Description
Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes.
We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy.
Lead Penetration TesterLocation: Washington, DC, Ft. Collins, CO, or Kansas City, MO (project-based; onsite)
Terms: Full-time
Salary Range: $110-$150k DOE
Clearance: Active Secret required
Travel: Yes – travel to agency sites required
Project DescriptionThis position leads operational security assessments and penetration testing across a portfolio of federal agencies and web applications. Assessments are conducted in accordance with the ISC Security Assessment Methodology and applicable federal rules of engagement, producing findings that reach agency CIO and CISO-level leadership. The program also requires FedRAMP-qualified penetration testing support for cloud service authorization activities.
The core challenge: leading a high-tempo assessment program across multiple agencies per year — each with distinct environments, rules of engagement, and stakeholder expectations — while producing deliverables that meet the evidentiary and presentation standards of senior federal leadership.
Position DescriptionAs a Lead Penetration Tester at Revolutional, you own the end-to-end execution of operational security assessments and web application penetration tests across a federal agency portfolio. You develop test plans, lead technical execution, produce security assessment reports and criticality matrices, and deliver out-brief presentations directly to agency CIO and CISO-level audiences. You are the senior technical authority on every engagement you lead.
You bring deep experience with federal assessment methodologies — ISC Security Assessment Methodology, OWASP, NIST SP 800 series, and DISA STIG — and hold or are actively pursuing CISA AES certification. You are equally comfortable executing a technically complex assessment and standing in front of agency leadership to explain what you found and what it means.
What You Will Own- Operational security assessment leadership across a portfolio of federal agencies (approximately 6–7 per year)
- Web application security assessments (approximately 3–4 applications per year)
- Test plan and rules of engagement development for each assessment
- Criticality matrix development and risk prioritization
- Security assessment report authorship and quality
- Out-brief presentations to agency CIO and CISO-level leadership
- FedRAMP penetration testing support for cloud service authorization
- Lead operational security assessments across federal agencies in accordance with the ISC Security Assessment Methodology and applicable rules of engagement; manage approximately 6–7 agency assessments per year
- Conduct web application security assessments using OWASP methodology; assess approximately 3–4 applications per year across a range of agency environments
- Develop comprehensive test plans for each engagement: scope definition, assessment objectives, methodology selection, rules of engagement, and timeline
- Build criticality matrices that prioritize findings by risk, asset value, and mission impact to support agency remediation planning
- Author detailed security assessment reports documenting findings, evidence, risk ratings, and actionable remediation guidance meeting federal evidentiary and reporting standards
- Develop and deliver out-brief presentations to agency CIO, CISO, and senior leadership audiences; communicate complex technical findings with clarity and executive-level credibility
- Conduct FedRAMP-qualified penetration testing in support of cloud service authorization activities; apply FedRAMP pen testing requirements and documentation standards
- Apply NIST SP 800 series guidance and DISA STIG methodology throughout assessment planning, execution, and reporting
- Coordinate with agency stakeholders before, during, and after assessments to manage expectations, address questions, and ensure findings are understood and acted upon
- Stay current on vulnerability research, offensive techniques, and emerging attack surfaces relevant to federal civilian agency environments
- Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience)
- 5 or more years of hands-on penetration testing experience, with demonstrated experience leading assessments in federal environments
- CISA AES (Authorized External Security) certification required, or actively in process of obtaining
- FedRAMP penetration testing experience required
- Active Secret clearance
- Ability and willingness to travel to agency sites as required
- Deep experience conducting operational security assessments in accordance with the ISC Security Assessment Methodology and federal rules of engagement
- Proficiency with OWASP methodology applied to web application security assessments across federal environments
- Working knowledge of NIST SP 800 series guidance as applied to security assessment planning, execution, and reporting
- Experience applying DISA STIG methodology to assessment scope and findings documentation
- Experience developing test plans, criticality matrices, and security assessment reports that meet federal evidentiary and leadership reporting standards
- Demonstrated experience presenting technical security findings to CIO, CISO, and senior agency leadership audiences
- FedRAMP-qualified penetration testing experience, including familiarity with FedRAMP pen test requirements, documentation, and cloud authorization processes
- Proficiency with industry-standard penetration testing toolsets for network, application, and infrastructure assessments
- Senior assessment lead: you own engagements end-to-end and your findings are technically sound, clearly documented, and risk-rated with precision
- Executive-ready communicator — you develop and deliver out-brief presentations that land with CIO and CISO audiences, not just technical teams
- Methodologically disciplined: you work within rules of engagement, document everything, and produce deliverables that hold up under agency and regulatory scrutiny
- High-tempo operator who manages multiple concurrent engagements across different agency environments without loss of quality or attention to detail
The following certifications are required or strongly preferred:
Required- CISA AES (Authorized External Security) Assessment Lead or Technical Lead certification (or actively in process)
- GPEN (GIAC Penetration Tester), GXPN (GIAC Exploit Researcher and Advanced Penetration Tester), OSCP (Offensive Security Certified Professional), or equivalent offensive security credential
- GWAPT (GIAC Web Application Penetration Tester) or equivalent web application security certification
- Experience conducting CISA AES assessments as Assessment Lead across multiple federal civilian agencies
- Familiarity with FedRAMP High, Moderate, and Low authorization boundaries and their penetration testing implications
- Background in Red Team operations or adversary emulation in addition to structured assessment methodology
- Experience with cloud-native application security assessments (AWS, Azure, GCP, or GovCloud)
- Active TS/SCI clearance
#DICE #LinkedIn
___________________________________________________________________________________________________________
Here at Revolutional we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day. Some of these recognitions include:
- Recognized as a Top 20 "Best Place to Work in Virginia"
- Recipient of Department of Labor's HireVets Gold Medallion
- Great Place to Work Certification for five years running
- A Virginia Chamber of Commerce Fantastic 50 company
- A Northern Virginia Technology Council Tech 100 company
- Inc. 5000 list of fastest growing companies for eleven years
- Two-time SBA SBIR Tibbett's Award winner
- Virginia Values Veterans (V3) Certification
We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Revolutional family! In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to
- Traditional and HSA- eligible medical insurance plans
- 100% employer-paid dental and vision insurance options
- 100% employer-sponsored STD, LTD, and life insurance
- 5% 401(k) company matching
- Flexible-schedules and teleworking options
- Paid holidays and PTO Accrual Plans
- Paid Parental Leave
- Professional development and career growth opportunities
- Team and company-wide events, recognition, and appreciation-- and so much more!
Check out our Revolutional | LinkedIn to find out a little more about who we are and if we are the right next step for your career!
Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Revolutional does and will take affirmative action to employ and advance in employment individuals with disabilities and protected veterans. To perform the above job successfully, an individual must possess the knowledge, skills, and abilities listed; meet the education and work experience required; and must be able to perform each essential duty and responsibility satisfactorily. Other duties in addition to those listed may be assigned as necessary to meet business needs. Reasonable accommodation will be made to enable an applicant with a disability to successfully apply for and/or perform the essential duties of the job. If you are in need of an accommodation, please contact View email address on us.fitly.work.
- ...eligibility for Top Secret due to classified threat intelligence. Citizenship: US Citizen (MUST) Key Responsibilities : Lead SBA’s penetration, offensive, and adversarial testing services, including gray/black box testing, red teaming, API testing, and DevSecOps...SuggestedLocal areaRemote work
- Peraton is seeking a Senior Risk and Vulnerability Analyst to support a 24x7 Security Operations Center, identifying, analyzing, and prioritizing vulnerabilities across enterprise, cloud, and application environments. The role requires coordinating remediation efforts, ...Suggested
- DescriptionSAIC is seeking a highly motivated Penetration Tester. The successful candidate will provide support to the Cybersecurity Integrity Center (CIC) in the Department of State Bureau of Information Resource Management (IRM). Duties are in the Washington, D.C. metropolitan...SuggestedWork at officeLocal areaShift work3 days per week
- ...missions worldwide.Job DescriptionOverviewSOSi is seeking a Penetration Tester III to support proactive cyber defense activities in alignment... ...7) years of penetration testing experienceManagement or team lead experienceExperience performing continuous penetration testingExperience...SuggestedContract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
$90k - $130k
...Full-Time Clearance Requirement: TS/SCI Clearance Required Position Overview:Praescient Analytics is seeking a highly motivated Penetration Tester to join our cybersecurity team in Arlington, VA, supporting the Department of War (DoW) Chief Digital and Artificial...SuggestedFull timeWork at office$124.54k - $180k
GovCIO is currently hiring for a Senior Pentration Tester with an active TS/SCI clearance to support DHS... ...onsite in Washington, DC.ResponsibilitiesThe Senior Penetration Tester serves as Key Personnel responsible for leading advanced penetration testing and vulnerability...Currently hiring$104k - $166k
ResponsibilitiesPeraton is currently seeking to hire an experienced Penetration Tester for its Federal Strategic Cyber Group. Location: Chandler, AZ... ..., mobile, IoT, and High Value Asset (HVA) systems.You will lead technical engagements, drive red team operations, and...Contract workCurrently hiringShift work$86k - $138k
ResponsibilitiesPeraton is seeking an experienced Cyber Penetration Tester to become part of Peratons’ Federal Strategic Cyber programs. Location... ...role, you will: Support the Red Cell Team by performing and leading penetration tests to assess the security of customer systems...Contract workFlexible hoursShift work$130k - $190k
...and stability worldwide.Job SummaryWe are currently seeking a Penetration Tester. This position is a full-time opportunity located in... ...financial future: Build financial stability with an industry-leading 401(k) retirement savings plan. For most employees, we put in...Full timeWork experience placementWork at officeLocal areaRemote workWorldwideFlexible hours- ASRC Federal Technology Solutions is seeking an experienced Penetration Testerto lead advanced security assessments and contribute to the... ...activities.Manage and mentor a small team of junior penetration testers; provide technical guidance and training.Build and lead a Purple...3 days per week
- ...conduct analysis, mitigation, remediation, and monitoring to ensure compliance with agency policies and procedures. The ISSPO will lead, and guide efforts associated with obtaining and maintaining RMF Authorities to Operate (ATO) for systems within the customer’s multi...Work at officeFlexible hours2 days per week
$90.3k - $189.6k
Job Title: Lead Senior Information System Security OfficerJob Category: Information TechnologyTime Type: Full timeMinimum Clearance Required to Start: NoneEmployee Type: RegularPercentage of Travel Required: NoneType of Travel: None* * *The Opportunity:CACI is searching...Contract workWork experience placementWork at officeFlexible hours$69.4k - $158k
...required to analyze the policies that determine our cyber resilience.As an Information Systems Security Officer (ISSO) on our team, you’ll lead the assessment of the Department of War's IT infrastructure against current cyber policies, including RMF, and identify areas of...Full timeContract workPart timeWork at officeLocal areaRemote work- ...Apogee Global RMS is seeking a Senior Cybersecurity Engineer / Offensive Security Lead to support high‑visibility federal and IC programs. This role is designed for operators who bring hands‑on offensive tradecraft, current certifications, and recent red‑team experience...Full time
$95k - $112k
...SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications... ...customer approval. SkyePoint Decisions is seeking a Penetration Tester to support the Diplomatic Security Cyber Mission (DSCM)...Contract workRemote work$115k - $203k
...Senior Penetration Tester Job Description Overview CoStar Group is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index, CoStar Group is on a mission to digitize the...Hourly payFull timeWork at officeWork from homeMonday to Thursday$126.3k - $243.1k
...Penetration Tester At Accenture Federal Services, nothing matters more than helping the US federal government make the nation stronger... ...agent-based or Agentic AI architectures. Prior experience leading penetration-testing teams or programs. Industry certifications...For contractorsLive inLocal area- ...primary responsibility will be to plan, execute, and report on penetration tests targeting high-impact applications, platforms, and... ...peer reviews of penetration test reports and mentoring junior testers. ~ Continuous learner who keeps up with the latest offensive...
- ...Penetration Tester Alexandria, VA Type: Contract-to-Hire Category: Security Industry: Government Reference ID: JN -0820... ...Minimum of 5 years of experience conducting, supporting, or leading penetration tests across enterprise environments. Strong...Hourly payFull timeContract workLocal area2 days per week3 days per week
- ...Job Summary: The Penetration Testing Specialist / Information Security Analyst Journeyman is responsible for conducting thorough... ...Testing) certification. GPEN (GIAC Penetration Tester) certification. Special Considerations: May require...Flexible hours
- ...Description Tharros is seeking a Senior Penetration Testing, Software Assurance and Vulnerability Assessment Engineer to support a DHS Intelligence and Analysis cybersecurity program in the National Capital Region. This role will support advanced penetration...
- ...Description Penetration Tester Xcelerate Solutions is seeking a Penetration Tester to support CyberPRIMES cybersecurity, privacy, records and information management, and related enterprise support for DHRA, including DMDC and OUSD(P&R). Come join our award-winning...
- ...Penetration Tester Locations: Los Angeles (CA), Dallas (TX), Washington DC. Responsibilities: Assist in project scoping and SOW creation Perform offensive engagements including red teaming and penetration testing Perform penetration tests against external...Work experience placement
- ...Job Title: Senior Penetration Tester Pay Type : SALARIED EXEMPT Location : Hybrid, Washington, DC US Citizenship :... ...assessments on Azure cloud infrastructure and applications Lead and mentor a team of penetration testers, providing guidance...Full timeWork experience placementRemote workMonday to FridayShift workNight shift
$71.6k - $119.4k
...Delaware Michigan New Jersey Philadelphia Colorado New York Full time R115215 Are you a collaborative Penetration Tester looking to work for a mission driven global organization? About the role - This role supports the offensive security function...Full timeLocal areaWork from home- ...Penetration Tester OCH Technologies is seeking a Penetration Tester to execute network, system, application, and specialized penetration... ...infrastructure under the direction of the Penetration Testing Lead. The candidate will work within formal Rules of Engagement, operate...Temporary workFor contractorsLocal areaImmediate start
$66k - $106k
...Jr Cyber Penetration Tester Job Locations US-VA-Arlington Requisition ID 2026-167214 Position Category... ...extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise...Contract workLocal areaRemote workShift work- ...The Judge Group is currently seeking a Penetration Tester with an active secret clearance to support a classified customer in Beltsville, MD. This position is onsite five days per week. Core Requirements Active Security Clearance Federal Contracting...
$131.3k - $237.35k
The Leidos DoW CIO Mission Support Services (CMSS) program is seeking a Systems Integration Lead Analyst located at The Mark Center in Alexandria, VA.POSITION SUMMARY:This position will support the planning and implementation of the DoW Information Enterprise (IE) in support...Full time- ...benefits package. Required Experience Minimum of 5 years' experience in the conduct of, supporting the conduct of, or leading penetration tests. Key skills include a strong understanding of operating systems and networking protocols, strong understanding of...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead Penetration Tester. Be the first to apply!


