External Network Penetration Tester
Xtreme Inc
San Bernardino, CA, United States
7 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source
Tech stack
Software System Penetration Testing
Burp Suite
Nmap
Open Web Application Security
GWAPT
Metasploit
Vulnerability Analysis
Job description
Performs blind and intelligent penetration testing against internet-facing assets - web applications, firewalls, remote access (VPN/RDP), and internet postings - for all 47 County departments, attempting to obtain confidential/sensitive data using real-world threat intelligence-based techniques while evading detection., * Conduct external network and web application penetration testing and vulnerability assessments per NIST SP 800-115 methodology.
- Attempt to obtain ePHI, PII, financial data, and privileged communications from external sources without causing service disruption.
- Document all findings with risk ratings, evidence, and remediation recommendations for the Assessment report.
- Attempt to avoid detection and evade department response efforts during testing windows, as scoped.
Requirements
- 4+ years of hands-on external network / web application penetration testing experience.
- Proficiency with industry-standard tools (Burp Suite, Nmap, Metasploit, or equivalent).
- Strong understanding of OWASP Top 10 and common network attack vectors., * OSCP, GPEN, GWAPT, or CEH certification.
- Experience testing government or healthcare-sector environments.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
over 2 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
about 2 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
DC
Daniel Cranney
The Overflow: Security and Privacy
5 months ago