Internal Network Penetration Tester

Xtreme Inc
San Bernardino, CA, United States
7 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Password Cracking Private Networks Active Directory Software System Penetration Testing Data Centers Phishing

Job description

Executes internal network penetration testing from two pre-determined footholds - an unauthenticated physical network port and a simulated-phishing authenticated workstation - across County facilities, testing servers, workstations, endpoints, and password strength., * Physically connect to County network ports to simulate an unauthenticated internal attacker.

  • Simulate a successful phishing/Trojan compromise from an authenticated workstation foothold.
  • Attempt password cracking and lateral movement while evading department detection and response efforts.
  • Document internal attack paths, exploited vulnerabilities, and business impact for each department report.

Requirements

  • 4+ years of internal/network penetration testing experience, including Active Directory attack paths.
  • Comfort working onsite at client facilities, including data centers and administrative offices.
  • Experience with internal recon and lateral movement tooling (BloodHound, Responder, or equivalent).

Preferred Qualifications

  • OSCP or GPEN certification.
  • Experience testing in HIPAA-regulated or government network environments.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · WWC 2023

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

51 sec

Repurposing hardware and operating underwater data centers

Chris Heilmann +1 · LIVE

36 sec

Deploying private Tezos networks for enterprise use cases

Arthur Breitman Arthur Breitman · WWC 2021

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · WWC 2022

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · WWC Europe 2026

Videos

See all

Related articles

See all