Penetration Tester

BARD BSG, LLC
San Jose, CA, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$110,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Active Directory Amazon Web Services Software System Penetration Testing Border Gateway Protocol Burp Suite CentOS Cisco PIX Cloud Computing Cloud Computing Security Control Objectives for Information and Related Technology (COBIT) Cyber Security
+34 more
Computer Networks Debian Linux Linux Digital Assets Enhanced Interior Gateway Routing Protocol Federal Information Processing Standards (FIPS) Internet Protocol Security (IP SEC) Intrusion Detection Systems Virtual Private Networks (VPN) Python (Programming Language) Kali Linux Lightweight Directory Access Protocols (LDAP) Network Architecture Routing Network Protocols Open Shortest Path First (OSPF) Public Key Infrastructure Security Information and Event Management TCP/IP Virtual Local Area Networks Software Vulnerability Management Scripting Google Cloud Load Balancing Cloud Platform System Information Technology Metasploit SolarWinds (Software) Network Support Hardware Infrastructure Firewall Services Module Splunk New Relic (SaaS) Vulnerability Analysis

Job description

  • Conduct thorough penetration testing across diverse IT systems, including LAN, WAN, cloud platforms (AWS, Google Cloud), and on-premises infrastructure.
  • Develop and execute attack frameworks using tools like Kali Linux, Metasploit, Burp Suite, and custom scripts to identify security weaknesses.
  • Perform vulnerability assessments aligned with NIST standards and ISO 27000 series to evaluate system security plans and compliance requirements.
  • Analyze network protocols such as TCP/IP, IPsec, BGP, OSPF, EIGRP, and routing protocols to detect potential exploitation points.
  • Test and evaluate firewall configurations (Cisco ASA), IDS/IPS systems, SIEM solutions (Splunk), and other security controls for effectiveness.
  • Assist in incident response activities by analyzing logs via tools like New Relic or SolarWinds, supporting incident recovery efforts.
  • Collaborate with system administrators to implement system hardening measures on operating systems including Windows, Linux (Debian, CentOS), macOS, and openSUSE.
  • Research emerging threats using threat intelligence platforms and maintain up-to-date knowledge of attack frameworks and vulnerabilities.

Requirements

Do you have experience in Windows?, We are seeking a highly motivated and detail-oriented Penetration Tester to join our cybersecurity team. In this vital role, you will proactively identify vulnerabilities within our IT infrastructure, network architecture, and cloud environments by simulating cyberattacks and conducting comprehensive vulnerability assessments. Your expertise will help strengthen our security posture, ensure compliance with industry standards such as NIST and ISO 27000, and safeguard critical information assets. This position offers an exciting opportunity to apply advanced security analysis techniques in a fast-paced, innovative environment committed to continuous improvement and excellence in cybersecurity., * Proven experience in computer networking including LAN/WAN architecture, routing protocols (OSPF, BGP), VLANs, VPNs (IPsec), load balancing, and network support.

  • Strong understanding of cybersecurity principles such as vulnerability management, threat detection & response, system security plans, and incident management.
  • Hands-on experience with vulnerability research tools and techniques for assessing system security across various platforms.
  • Familiarity with cloud computing environments like AWS or Google Cloud Platform along with cloud infrastructure security best practices.
  • Knowledge of encryption standards (FIPS), PKI implementations, LDAP/Active Directory integration, SSO protocols, GPO management, and system administration tasks.
  • Proficiency in scripting languages such as Python or Bash for automation of testing procedures.
  • Ability to interpret security policies aligned with frameworks like FedRAMP or FISMA while adhering to ITIL or COBIT governance models.
  • Relevant certifications such as OSCP (Offensive Security Certified Professional), CEH (Certified Ethical Hacker), CISSP or GIAC certifications are highly desirable. Join us to leverage your cybersecurity expertise in a dynamic environment that values innovation! Your skills will directly contribute to protecting vital digital assets while advancing your career in the ever-evolving field of information security.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC Europe 2026

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all