External Network Penetration Tester

Xtreme Inc
San Bernardino, CA, United States
7 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Burp Suite Nmap Open Web Application Security GWAPT Metasploit Vulnerability Analysis

Job description

Performs blind and intelligent penetration testing against internet-facing assets - web applications, firewalls, remote access (VPN/RDP), and internet postings - for all 47 County departments, attempting to obtain confidential/sensitive data using real-world threat intelligence-based techniques while evading detection., * Conduct external network and web application penetration testing and vulnerability assessments per NIST SP 800-115 methodology.

  • Attempt to obtain ePHI, PII, financial data, and privileged communications from external sources without causing service disruption.
  • Document all findings with risk ratings, evidence, and remediation recommendations for the Assessment report.
  • Attempt to avoid detection and evade department response efforts during testing windows, as scoped.

Requirements

  • 4+ years of hands-on external network / web application penetration testing experience.
  • Proficiency with industry-standard tools (Burp Suite, Nmap, Metasploit, or equivalent).
  • Strong understanding of OWASP Top 10 and common network attack vectors., * OSCP, GPEN, GWAPT, or CEH certification.
  • Experience testing government or healthcare-sector environments.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · WWC 2023

4:36 min

Exploiting e-commerce basket identifiers with Burp Suite

Anna Bacher · LIVE

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · WWC Europe 2026

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

1:51 min

Leveraging continuous penetration testing via red teams

Reto Kaeser · LIVE

Videos

See all

Related articles

See all