Lead Penetration Tester
Listed on 2026-07-16
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Lead Penetration Tester
This position leads operational security assessments and penetration testing across a portfolio of federal agencies and web applications. Assessments are conducted in accordance with the ISC Security Assessment Methodology and applicable federal rules of engagement, producing findings that reach agency CIO and CISO-level leadership. The program also requires FedRAMP-qualified penetration testing support for cloud service authorization activities.
The core challenge: leading a high-tempo assessment program across multiple agencies per year — each with distinct environments, rules of engagement, and stakeholder expectations — while producing deliverables that meet the evidentiary and presentation standards of senior federal leadership.
As a Lead Penetration Tester at Revolutional, you own the end-to-end execution of operational security assessments and web application penetration tests across a federal agency portfolio. You develop test plans, lead technical execution, produce security assessment reports and criticality matrices, and deliver out-brief presentations directly to agency CIO and CISO-level audiences. You are the senior technical authority on every engagement you lead.
You bring deep experience with federal assessment methodologies — ISC Security Assessment Methodology, OWASP, NIST SP 800 series, and DISA STIG — and hold or are actively pursuing CISA AES certification. You are equally comfortable executing a technically complex assessment and standing in front of agency leadership to explain what you found and what it means.
Operational security assessment leadership across a portfolio of federal agencies (approximately 6–7 per year)
Web application security assessments (approximately 3–4 applications per year)
Test plan and rules of engagement development for each assessment
Criticality matrix development and risk prioritization
Security assessment report authorship and quality
Out-brief presentations to agency CIO and CISO-level leadership
FedRAMP penetration testing support for cloud service authorization
Lead operational security assessments across federal agencies in accordance with the ISC Security Assessment Methodology and applicable rules of engagement; manage approximately 6–7 agency assessments per year
Conduct web application security assessments using OWASP methodology; assess approximately 3–4 applications per year across a range of agency environments
Develop comprehensive test plans for each engagement: scope definition, assessment objectives, methodology selection, rules of engagement, and timeline
Build criticality matrices that prioritize findings by risk, asset value, and mission impact to support agency remediation planning
Author detailed security assessment reports documenting findings, evidence, risk ratings, and actionable remediation guidance meeting federal evidentiary and reporting standards
Develop and deliver out-brief presentations to agency CIO, CISO, and senior leadership audiences; communicate complex technical findings with clarity and executive-level credibility
Conduct FedRAMP-qualified penetration testing in support of cloud service authorization activities; apply FedRAMP pen testing requirements and documentation standards
Apply NIST SP 800 series guidance and DISA STIG methodology throughout assessment planning, execution, and reporting
Coordinate with agency stakeholders before, during, and after assessments to manage expectations, address questions, and ensure findings are understood and acted upon
Stay current on vulnerability research, offensive techniques, and emerging attack surfaces relevant to federal civilian agency environments
- Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience)
- 5 or more years of hands-on penetration testing experience, with demonstrated experience leading assessments in federal environments
- CISA AES (Authorized External Security) certification required, or actively in process of obtaining
- FedRAMP penetration testing experience required
- Active Secret clearance
- Ability and willingness to travel to agency sites as required
- Deep experience conducting operational…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).