Internal Network Penetration Tester
Xtreme Inc
San Bernardino, CA, United States
7 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source
Tech stack
Password Cracking
Private Networks
Active Directory
Software System Penetration Testing
Data Centers
Phishing
Job description
Executes internal network penetration testing from two pre-determined footholds - an unauthenticated physical network port and a simulated-phishing authenticated workstation - across County facilities, testing servers, workstations, endpoints, and password strength., * Physically connect to County network ports to simulate an unauthenticated internal attacker.
- Simulate a successful phishing/Trojan compromise from an authenticated workstation foothold.
- Attempt password cracking and lateral movement while evading department detection and response efforts.
- Document internal attack paths, exploited vulnerabilities, and business impact for each department report.
Requirements
- 4+ years of internal/network penetration testing experience, including Active Directory attack paths.
- Comfort working onsite at client facilities, including data centers and administrative offices.
- Experience with internal recon and lateral movement tooling (BloodHound, Responder, or equivalent).
Preferred Qualifications
- OSCP or GPEN certification.
- Experience testing in HIPAA-regulated or government network environments.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
about 2 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
DC
Daniel Cranney
The Overflow: Security and Privacy
5 months ago
CH
Chris Heilmann
The top 200 passwords of 2024 can be cracked in less than a second
over 1 year ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
LM
Luis Minvielle
The 8 Best Code Testing Tools
over 2 years ago