What are the responsibilities and job description for the Pen Testing Program Manager position at Programming.com?
Role: Pen Testing Program Manager
Location: Sunnyvale CA or Bellevue WA
Employment Type: Contract
Job Summary
We are seeking a Pen Testing Program Manager to coordinate and operationalize the enterprise penetration testing program. This role acts as the central orchestrator between internal penetration testing teams, external security vendors, and engineering stakeholders.
The primary goal is to reduce coordination overhead for internal security engineers by managing scheduling, prerequisites, deliverables tracking, and reporting across multiple pen testing engagements.
This role requires strong program management skills combined with a solid understanding of application security concepts and penetration testing workflows, but does not require hands-on penetration testing expertise.
Key Responsibilities
Program Coordination & Execution
- Coordinate end-to-end penetration testing engagements across internal teams and external vendors.
- Act as the primary liaison between internal pen testers, engineering teams, and third-party vendors such as CrowdStrike.
- Manage testing schedules, engagement scopes, timelines, and deliverables.
- Ensure alignment between business priorities and testing coverage across applications, infrastructure, and cloud environments.
Engineering & Prerequisite Management
- Work with engineering and infrastructure teams to fulfill prerequisites for testing (access provisioning, environment readiness, test data setup, etc.).
- Track readiness status and ensure timely resolution of blockers before testing begins.
- Coordinate remediation validation cycles after findings are addressed.
Findings Management & Tooling
- Ingest penetration testing findings into enterprise security and tracking tools.
- Ensure proper categorization, prioritization, and assignment of findings.
- Maintain accurate tracking of remediation progress and closure validation.
- Support integration of findings into vulnerability management and security reporting systems.
Vendor & Stakeholder Management
- Manage relationships with external penetration testing vendors and ensure SLA adherence.
- Facilitate communication between vendors and internal technical teams.
- Review and track vendor deliverables for completeness and quality.
- Escalate risks, delays, and scope issues as needed.
Reporting & Governance
- Provide regular program updates, dashboards, and executive summaries.
- Track KPIs such as test coverage, remediation turnaround time, and findings closure rate.
- Support security governance meetings and audit requirements.
- Ensure visibility of penetration testing outcomes across leadership and stakeholders.
Required Skills & Experience
- 5 years of experience in Program Management, Security Program Management, or Technical Project Management roles.
- Strong understanding of application security fundamentals and penetration testing lifecycle.
- Experience coordinating technical programs involving multiple stakeholders and vendors.
- Familiarity with vulnerability and security testing workflows.
- Strong organizational, communication, and stakeholder management skills.
- Ability to manage complex dependencies and timelines across teams.
--