> Markdown version of [/jobs/ext/1781138-nih-penetration-tester](https://www.wearedevelopers.com/jobs/ext/1781138-nih-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # NIH - Penetration Tester - **Company:** cFocus Software Incorporated - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Software System Penetration Testing, Wireless Security, Comptia Pentest+ CE, Red Team (Cyber Security), Software Security, Information Technology, Operating System Security - **Published:** July 1, 2026 - **Apply:** http://cfocussoftware.applytojob.com/apply/jobs/details/0YDaiIeTpZ ## About the Role * Public Trust Clearance * B.S. Computer Science, Information Technology, or a related field * 5+ years of experience conducting penetration testing or offensive cybersecurity operations. * Experience performing enterprise penetration testing. * Experience with network and application security assessments. * Experience documenting technical security findings. * Ability to obtain and maintain NIH suitability/background investigation. * Active OSCP, OSEP, GPEN, GXPN, CEH, PenTest+, or CISSP ## Description cFocus Software seeks a Penetration Tester to join our program supporting the National Institutes of Health (NIH). This position is fully remote. This position requires a Public Trust or the ability to obtain a public trust clearance., * Conduct enterprise penetration testing activities including: + Perform internal and external network penetration testing. + Conduct web application penetration testing. + Execute infrastructure security testing. + Perform cloud penetration testing. + Conduct operating system security assessments. + Perform wireless security testing. + Assess Active Directory security. + Conduct application security testing. + Simulate real-world cyberattacks using industry-standard offensive security methodologies. + Perform controlled exploitation activities to identify security weaknesses. + Validate effectiveness of implemented security controls. + Identify attack paths and privilege escalation opportunities. + Document technical findings and supporting evidence. * Prepare comprehensive penetration testing plans * Provide Red Team Support ## Related Videos - [MCP Mashups: How AI Agents are Reviving the Programmable Web](https://www.wearedevelopers.com/videos/1392-mcp-mashups-how-ai-agents-are-reviving-the-programmable-web) - [WeAreDevelopers LIVE - Building The World’s Worst Image Editor™](https://www.wearedevelopers.com/videos/1836-wearedevelopers-live-building-the-world-s-worst-image-editor) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Capture the Flag 101](https://www.wearedevelopers.com/videos/416-capture-the-flag-101) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)