External Network Penetration Tester
Job Description
Job DescriptionDescription:
Position Summary
Performs blind and intelligent penetration testing against internet-facing assets — web applications, firewalls, remote access (VPN/RDP), and internet postings — for all 47 County departments, attempting to obtain confidential/sensitive data using real-world threat intelligence-based techniques while evading detection.
Key Responsibilities
• Conduct external network and web application penetration testing and vulnerability assessments per NIST SP 800-115 methodology.
• Attempt to obtain ePHI, PII, financial data, and privileged communications from external sources without causing service disruption.
• Document all findings with risk ratings, evidence, and remediation recommendations for the Assessment report.
• Attempt to avoid detection and evade department response efforts during testing windows, as scoped.
Requirements:
Required Qualifications
• 4+ years of hands-on external network / web application penetration testing experience.
• Proficiency with industry-standard tools (Burp Suite, Nmap, Metasploit, or equivalent).
• Strong understanding of OWASP Top 10 and common network attack vectors.
Preferred Qualifications
• OSCP, GPEN, GWAPT, or CEH certification.
• Experience testing government or healthcare-sector environments.
Travel
Fully remote; must remain within the continental United States.
