Lead Penetration Tester
Manager
Application Security
Data Security
Facilities Management
Information Security
InfoSec
Offensive Security
Owasp
Project Management
Risk Management
Security
Security Assessment & Authorization
Security Clearance
Security Compliance
Security Operations
Security Standards
Security Testing
Software Security
Job Description
Lead operational security assessment and penetration testing efforts for a federal agency portfolio, delivering evidentiary results to CIO and CISO-level stakeholders.
Responsibilities
- Lead operational security assessments across federal agencies using the ISC Security Assessment Methodology and applicable rules of engagement; manage approximately 6–7 agency assessments per year
- Perform web application security assessments using OWASP methodology; assess approximately 3–4 applications per year across a range of agency environments
- Create end-to-end test plans for each engagement, including scope definition, objectives, methodology selection, rules of engagement, and timeline
- Develop criticality matrices that prioritize findings by risk, asset value, and mission impact to support remediation planning
- Author security assessment reports with findings, evidence, risk ratings, and actionable remediation guidance aligned to federal evidentiary and reporting expectations
- Develop and deliver executive out-briefs to agency CIO/CISO and senior leadership audiences, explaining complex technical results clearly
- Conduct FedRAMP-qualified penetration testing in support of cloud service authorization, following FedRAMP pen testing requirements and documentation standards
- Apply NIST SP 800 series guidance and DISA STIG methodology across assessment planning, execution, and reporting
- Coordinate with agency stakeholders before, during, and after assessments to manage expectations and ensure findings are understood and acted upon
- Maintain currency on vulnerability research, offensive techniques, and emerging attack surfaces relevant to federal civilian environments
Requirements
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience)
- 5+ years of hands-on penetration testing experience, including demonstrated experience leading assessments in federal environments
- CISA AES (Authorized External Security) certification required, or actively in process of obtaining
- FedRAMP penetration testing experience required
- Active Secret clearance
- Ability and willingness to travel to agency sites as required
- Deep experience conducting operational security assessments aligned to ISC Security Assessment Methodology and federal rules of engagement
- Proficiency applying OWASP methodology to web application assessments in federal environments
- Working knowledge of NIST SP 800 series for security assessment planning, execution, and reporting
- Experience applying DISA STIG methodology to assessment scope and findings documentation
- Experience producing test plans, criticality matrices, and security assessment reports meeting federal evidentiary and leadership reporting standards
- Demonstrated ability presenting technical security findings to CIO, CISO, and senior agency leadership audiences
- FedRAMP-qualified penetration testing experience, including familiarity with FedRAMP pen test requirements, documentation, and cloud authorization processes
- Proficiency with industry-standard penetration testing toolsets for network, application, and infrastructure assessments
Strongly Preferred / Additional Credentials
- GPEN (GIAC Penetration Tester), GXPN (GIAC Exploit Researcher and Advanced Penetration Tester), OSCP (Offensive Security Certified Professional), or equivalent offensive security credential
- GWAPT (GIAC Web Application Penetration Tester) or equivalent web application security certification
Nice to Have
- Experience conducting CISA AES assessments as Assessment Lead across multiple federal civilian agencies
- Familiarity with FedRAMP High, Moderate, and Low authorization boundaries and associated penetration testing implications
- Background in Red Team operations or adversary emulation alongside structured assessment methodology
- Experience with cloud-native application security assessments (AWS, Azure, GCP, or GovCloud)
- Active TS/SCI clearance
Benefits
- Traditional and HSA-eligible medical insurance plans
- 100% employer-paid dental and vision insurance options
- 100% employer-sponsored STD, LTD, and life insurance
- 5% 401(k) company matching
- Flexible schedules and teleworking options
- Paid holidays and PTO accrual plans
- Paid Parental Leave
- Professional development and career growth opportunities
Location / Terms
- Onsite in Fort Collins, CO (project-based; onsite)
- Also listed: Washington, DC, Ft. Collins, CO, or Kansas City, MO
- Full-time position
Compensation / Clearance
- $110,000 - $150,000 per year (DOE)
- Active Secret clearance required
Travel
- Yes – travel to agency sites required