Internal Network Penetration Tester
Xtreme Inc
San Bernardino, United States of America
3 days ago
Role details
Contract type
Permanent contract Employment type
Full-time (> 32 hours) Working hours
Regular working hours Languages
English Experience level
IntermediateJob location
San Bernardino, United States of America
Tech stack
Password Cracking
Private Networks
Microsoft Active Directory
Software System Penetration Testing
Data Centers
Phishing
Job description
Executes internal network penetration testing from two pre-determined footholds - an unauthenticated physical network port and a simulated-phishing authenticated workstation - across County facilities, testing servers, workstations, endpoints, and password strength., * Physically connect to County network ports to simulate an unauthenticated internal attacker.
- Simulate a successful phishing/Trojan compromise from an authenticated workstation foothold.
- Attempt password cracking and lateral movement while evading department detection and response efforts.
- Document internal attack paths, exploited vulnerabilities, and business impact for each department report.
Requirements
- 4+ years of internal/network penetration testing experience, including Active Directory attack paths.
- Comfort working onsite at client facilities, including data centers and administrative offices.
- Experience with internal recon and lateral movement tooling (BloodHound, Responder, or equivalent).
Preferred Qualifications
- OSCP or GPEN certification.
- Experience testing in HIPAA-regulated or government network environments.