NIH - Penetration Tester

cFocus Software Incorporated
United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Active Directory Software System Penetration Testing Wireless Security Comptia Pentest+ CE Red Team (Cyber Security) Software Security Information Technology Operating System Security

Job description

cFocus Software seeks a Penetration Tester to join our program supporting the National Institutes of Health (NIH). This position is fully remote. This position requires a Public Trust or the ability to obtain a public trust clearance., * Conduct enterprise penetration testing activities including:

  • Perform internal and external network penetration testing.
  • Conduct web application penetration testing.
  • Execute infrastructure security testing.
  • Perform cloud penetration testing.
  • Conduct operating system security assessments.
  • Perform wireless security testing.
  • Assess Active Directory security.
  • Conduct application security testing.
  • Simulate real-world cyberattacks using industry-standard offensive security methodologies.
  • Perform controlled exploitation activities to identify security weaknesses.
  • Validate effectiveness of implemented security controls.
  • Identify attack paths and privilege escalation opportunities.
  • Document technical findings and supporting evidence.
  • Prepare comprehensive penetration testing plans
  • Provide Red Team Support

Requirements

  • Public Trust Clearance
  • B.S. Computer Science, Information Technology, or a related field
  • 5+ years of experience conducting penetration testing or offensive cybersecurity operations.
  • Experience performing enterprise penetration testing.
  • Experience with network and application security assessments.
  • Experience documenting technical security findings.
  • Ability to obtain and maintain NIH suitability/background investigation.
  • Active OSCP, OSEP, GPEN, GXPN, CEH, PenTest+, or CISSP

Benefits & conditions

Invitation for Job Applicants to Self-Identify as a U.S. Veteran

  • A “disabled veteran” is one of the following:
  • a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or
  • a person who was discharged or released from active duty because of a service-connected disability.
  • A “recently separated veteran” means any veteran during the three-year period beginning on the date of such veteran’s discharge or release from active duty in the U.S. military, ground, naval, or air service.
  • An “active duty wartime or campaign badge veteran” means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.
  • An “Armed forces service medal veteran” means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on cfocussoftware.applytojob.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · WWC 2023

4:34 min

Highway compromise and wireless key fob vulnerabilities

Martin Schmiedecker ¡ LIVE

1:45 min

Evolution from manual setups to automated monolith deployments

Axel Barbier ¡ WWC 2023

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 ¡ WWC 2025

4:36 min

Developer challenges in securing modern connected vehicles

Martin Schmiedecker ¡ LIVE

3:18 min

Eliminating passwords using Azure managed identities

Markus MÜller ¡ WWC 2021

Videos

See all

Related articles

See all