Penetration Testing - CEH/OSCP/CISSP Required
Role details
Job location
Tech stack
Job description
Bilqees Technology Solutions Inc. is seeking an experienced Penetration Testing Consultant to support a New York State Insurance Fund (NYSIF) engagement. This project includes external black-box and internal grey-box penetration testing across hybrid cloud and on-prem environments.
This is a short-term, high-impact engagement ideal for a certified penetration tester with strong hands-on experience and the ability to deliver professional reporting and executive-level presentations.
Key Responsibilities
Perform external black-box penetration testing
Perform internal grey-box penetration testing
Conduct wireless, cloud, and hybrid environment testing
Use industry-standard tools including:
Metasploit
Nmap
Wireshark
Aircrack-ng
John the Ripper
Nessus
Burp Suite
Conduct discovery, vulnerability analysis, exploitation, and reporting
Document findings with screenshots, evidence, and remediation recommendations
Deliver a detailed findings report and an executive summary
Present results to NYSIF management (virtual or onsite if required)
Follow NYS IT security policies and rules of engagement
Ensure all data remains within the Contiguous United States (CONUS)
Requirements
Do you have experience in Penetration testing?, U.S. Citizen or Green Card Holder (mandatory)
Minimum 2 years of penetration testing experience
Hands-on experience with black-box and grey-box testing
Experience testing hybrid cloud environments (Azure, AWS, GCP)
Experience with enterprise networks (servers, routers, switches, firewalls, web apps)
Ability to complete the project before December 31, 2025
Must provide three sample penetration test reports (sanitized)
Must provide a resume demonstrating required experience
Required Certifications (at least one)
CEH - Certified Ethical Hacker
CISSP
GPEN - GIAC Penetration Tester
OSCP - Offensive Security Certified Professional
CISA
Preferred Skills
Experience with AI-enhanced security research tools
Experience with NVD and vulnerability databases
Strong written and verbal communication skills
Ability to produce executive-level presentations