Loading jobs…
Loading jobs…
Revolutional, LLC — Fort Collins Colorado
Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes. We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy.
Lead Penetration Tester Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (project-based; onsite) Terms: Full-time Salary Range: $110-$150k DOE Clearance: Active Secret required Travel: Yes – travel to agency sites required Project Description This position leads operational security assessments and penetration testing across a portfolio of federal agencies and web applications. Assessments are conducted in accordance with the ISC Security Assessment Methodology and applicable federal rules of engagement, producing findings that reach agency CIO and CISO-level leadership.
The program also requires FedRAMP-qualified penetration testing support for cloud service authorization activities. The core challenge: leading a high-tempo assessment program across multiple agencies per year — each with distinct environments, rules of engagement, and stakeholder expectations — while producing deliverables that meet the evidentiary and presentation standards of senior federal leadership. Position Description As a Lead Penetration Tester at Revolutional, you own the end-to-end execution of operational security assessments and web application penetration tests across a federal agency portfolio.
You develop test plans, lead technical execution, produce security assessment reports and criticality matrices, and deliver out-brief presentations directly to agency CIO and CISO-level audiences. You are the senior technical authority on every engagement you lead. You bring deep experience with federal assessment methodologies — ISC Security Assessment Methodology, OWASP, NIST SP 800 series, and DISA STIG — and hold or are actively pursuing CISA AES certification.
You are equally comfortable executing a technically complex assessment and standing in front of agency leadership to explain what you found and what it means. What You Will Own Operational security assessment leadership across a portfolio of federal agencies (approximately 6–7 per year) Web application security assessments (approximately 3–4 applications per year) Test plan and rules of engagement development for each assessment Criticality matrix development and risk prioritization Security assessment report authorship and quality Out-brief presentations to agency CIO and CISO-level leadership FedRAMP penetration testing support for cloud service authorization
Responsibilities
Lead operational security assessments across federal agencies in accordance with the ISC Security Assessment Methodology and applicable rules of engagement; manage approximately 6–7 agency assessments per year Conduct web application security assessments using OWASP methodology; assess approximately 3–4 applications per year across a range of agency environments Develop comprehensive test plans for each engagement: scope definition, assessment objectives, methodology selection, rules of engagement, and timeline Build criticality matrices that prioritize findings by risk, asset value, and mission impact to support agency remediation planning Author detailed security assessment reports documenting findings, evidence, risk ratings, and actionable remediation guidance meeting federal evidentiary and reporting standards Develop and deliver out-brief presentations to agency CIO, CISO, and senior leadership audiences; communicate complex technical findings with clarity and executive-level credibility Conduct FedRAMP-qualified penetration testing in support of cloud service authorization activities; apply