Internal Network Penetration Tester
Xtreme Solutions Inc · San Bernardino, CA · Today
On-siteInformation TechnologyContract
Position Summary
Executes internal network penetration testing from two pre-determined footholds — an unauthenticated physical network port and a simulated-phishing authenticated workstation — across County facilities, testing servers, workstations, endpoints, and password strength.
Key Responsibilities
- Physically connect to County network ports to simulate an unauthenticated internal attacker.
- Simulate a successful phishing/Trojan compromise from an authenticated workstation foothold.
- Attempt password cracking and lateral movement while evading department detection and response efforts.
- Document internal attack paths, exploited vulnerabilities, and business impact for each department report.
Required Qualifications
- 4+ years of internal/network penetration testing experience, including Active Directory attack paths.
- Comfort working onsite at client facilities, including data centers and administrative offices.
- Experience with internal recon and lateral movement tooling (BloodHound, Responder, or equivalent).
Preferred Qualifications
- OSCP or GPEN certification.
- Experience testing in HIPAA-regulated or government network environments.
Travel
Onsite travel required to department locations in San Bernardino, Colton, Redlands, Rialto, Fontana, Ontario, Rancho Cucamonga, Montclair, Victorville, Hesperia, Apple Valley, Adelanto, Barstow, Needles, Big Bear Lake, and Yucca Valley; travel, lodging, and per diem are firm-borne.