> Markdown version of [/jobs/ext/1915918-external-network-penetration-tester](https://www.wearedevelopers.com/jobs/ext/1915918-external-network-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # External Network Penetration Tester - **Company:** Xtreme Inc - **Location:** San Bernardino, CA, United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Burp Suite, Nmap, Open Web Application Security, GWAPT, Metasploit, Vulnerability Analysis - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=f66ac04fd62a0658 ## About the Role * 4+ years of hands-on external network / web application penetration testing experience. * Proficiency with industry-standard tools (Burp Suite, Nmap, Metasploit, or equivalent). * Strong understanding of OWASP Top 10 and common network attack vectors., * OSCP, GPEN, GWAPT, or CEH certification. * Experience testing government or healthcare-sector environments. ## Description Performs blind and intelligent penetration testing against internet-facing assets - web applications, firewalls, remote access (VPN/RDP), and internet postings - for all 47 County departments, attempting to obtain confidential/sensitive data using real-world threat intelligence-based techniques while evading detection., * Conduct external network and web application penetration testing and vulnerability assessments per NIST SP 800-115 methodology. * Attempt to obtain ePHI, PII, financial data, and privileged communications from external sources without causing service disruption. * Document all findings with risk ratings, evidence, and remediation recommendations for the Assessment report. * Attempt to avoid detection and evade department response efforts during testing windows, as scoped. ## Related Videos - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)