External Network Penetration Tester
Position Summary
Performs blind and intelligent penetration testing against internet-facing assets — web applications, firewalls, remote access (VPN/RDP), and internet postings — for all 47 County departments, attempting to obtain confidential/sensitive data using real-world threat intelligence-based techniques while evading detection.
Key Responsibilities
• Conduct external network and web application penetration testing and vulnerability assessments per NIST SP 800-115 methodology.
• Attempt to obtain ePHI, PII, financial data, and privileged communications from external sources without causing service disruption.
• Document all findings with risk ratings, evidence, and remediation recommendations for the Assessment report.
• Attempt to avoid detection and evade department response efforts during testing windows, as scoped.