Search

External Network Penetration Tester

PublishedPublished: 6/14/2022
Technology

Job Description

Job DescriptionDescription:

Position Summary

Performs blind and intelligent penetration testing against internet-facing assets — web applications, firewalls, remote access (VPN/RDP), and internet postings — for all 47 County departments, attempting to obtain confidential/sensitive data using real-world threat intelligence-based techniques while evading detection.


Key Responsibilities

• Conduct external network and web application penetration testing and vulnerability assessments per NIST SP 800-115 methodology.

• Attempt to obtain ePHI, PII, financial data, and privileged communications from external sources without causing service disruption.

• Document all findings with risk ratings, evidence, and remediation recommendations for the Assessment report.

• Attempt to avoid detection and evade department response efforts during testing windows, as scoped.

Requirements:

Required Qualifications

• 4+ years of hands-on external network / web application penetration testing experience.

• Proficiency with industry-standard tools (Burp Suite, Nmap, Metasploit, or equivalent).

• Strong understanding of OWASP Top 10 and common network attack vectors.


Preferred Qualifications

• OSCP, GPEN, GWAPT, or CEH certification.

• Experience testing government or healthcare-sector environments.


Travel

Fully remote; must remain within the continental United States.

Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...