> Markdown version of [/jobs/ext/290346-penetration-tester](https://www.wearedevelopers.com/jobs/ext/290346-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Tester - **Company:** BARD BSG, LLC - **Location:** San Jose, CA, United States - **Salary:** $110,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Amazon Web Services, Software System Penetration Testing, Border Gateway Protocol, Burp Suite, CentOS, Cisco PIX, Cloud Computing, Cloud Computing Security, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Computer Networks, Debian Linux, Linux, Digital Assets, Enhanced Interior Gateway Routing Protocol, Federal Information Processing Standards (FIPS), Internet Protocol Security (IP SEC), Intrusion Detection Systems, Virtual Private Networks (VPN), Python (Programming Language), Kali Linux, Lightweight Directory Access Protocols (LDAP), Network Architecture, Routing, Network Protocols, Open Shortest Path First (OSPF), Public Key Infrastructure, Security Information and Event Management, TCP/IP, Virtual Local Area Networks, Software Vulnerability Management, Scripting, Google Cloud, Load Balancing, Cloud Platform System, Information Technology, Metasploit, SolarWinds (Software), Network Support, Hardware Infrastructure, Firewall Services Module, Splunk, New Relic (SaaS), Vulnerability Analysis - **Published:** May 31, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=1b781ac8ef3959b8 ## About the Role Do you have experience in Windows?, We are seeking a highly motivated and detail-oriented Penetration Tester to join our cybersecurity team. In this vital role, you will proactively identify vulnerabilities within our IT infrastructure, network architecture, and cloud environments by simulating cyberattacks and conducting comprehensive vulnerability assessments. Your expertise will help strengthen our security posture, ensure compliance with industry standards such as NIST and ISO 27000, and safeguard critical information assets. This position offers an exciting opportunity to apply advanced security analysis techniques in a fast-paced, innovative environment committed to continuous improvement and excellence in cybersecurity., * Proven experience in computer networking including LAN/WAN architecture, routing protocols (OSPF, BGP), VLANs, VPNs (IPsec), load balancing, and network support. * Strong understanding of cybersecurity principles such as vulnerability management, threat detection & response, system security plans, and incident management. * Hands-on experience with vulnerability research tools and techniques for assessing system security across various platforms. * Familiarity with cloud computing environments like AWS or Google Cloud Platform along with cloud infrastructure security best practices. * Knowledge of encryption standards (FIPS), PKI implementations, LDAP/Active Directory integration, SSO protocols, GPO management, and system administration tasks. * Proficiency in scripting languages such as Python or Bash for automation of testing procedures. * Ability to interpret security policies aligned with frameworks like FedRAMP or FISMA while adhering to ITIL or COBIT governance models. * Relevant certifications such as OSCP (Offensive Security Certified Professional), CEH (Certified Ethical Hacker), CISSP or GIAC certifications are highly desirable. Join us to leverage your cybersecurity expertise in a dynamic environment that values innovation! Your skills will directly contribute to protecting vital digital assets while advancing your career in the ever-evolving field of information security. ## Description * Conduct thorough penetration testing across diverse IT systems, including LAN, WAN, cloud platforms (AWS, Google Cloud), and on-premises infrastructure. * Develop and execute attack frameworks using tools like Kali Linux, Metasploit, Burp Suite, and custom scripts to identify security weaknesses. * Perform vulnerability assessments aligned with NIST standards and ISO 27000 series to evaluate system security plans and compliance requirements. * Analyze network protocols such as TCP/IP, IPsec, BGP, OSPF, EIGRP, and routing protocols to detect potential exploitation points. * Test and evaluate firewall configurations (Cisco ASA), IDS/IPS systems, SIEM solutions (Splunk), and other security controls for effectiveness. * Assist in incident response activities by analyzing logs via tools like New Relic or SolarWinds, supporting incident recovery efforts. * Collaborate with system administrators to implement system hardening measures on operating systems including Windows, Linux (Debian, CentOS), macOS, and openSUSE. * Research emerging threats using threat intelligence platforms and maintain up-to-date knowledge of attack frameworks and vulnerabilities. ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany)