Penetration Tester
Fortified Health Security · United States · Yesterday
RemoteRemoteInformation TechnologyFull-time
Job Summary
The Penetration Tester will provide impactful security testing on an organization's network, documenting findings and presenting them to various levels of the organization. They must also develop and communicate corrective action plans to mitigate potential data breaches.
Essential Job Functions
- Service coordination, delivery, and execution of internal, external, wireless, and application penetration tests.
- Delivery of findings (formal report, notes, presentation, and appendices) to the client within project schedules.
- Reporting of performance metrics for each project to team lead or department management.
- Maintain awareness of network, system, and application threats, vulnerabilities, and exploits.
- Maintain currency of existing and pursue relevant industry or professional certifications.
- Knowledge and familiarity with penetration testing tools, including Metasploit, NMAP, BURP Suite, NESSUS, etc.
- Possess an understanding of various penetration testing and hacking methodologies like OWASP, PTES, PTF, NIST SP800-115, MITRE ATT&CK, and apply them.
- Maintain working knowledge of networking technologies and network functionality.
- Follow company operating procedures and rules of engagement to detect, identify, and exploit vulnerabilities across various operating systems, applications, and hardware.
- Work effectively in a small team environment, communicating effectively and efficiently.
- Communicate with clients about penetration testing project scopes.
- Accurately enter and submit time by required deadlines.
- Routinely check and respond to communications from Fortified personnel, including participation in mandatory company training and team and departmental meetings.
- Book travel in accordance with the company/client travel policy.
- Maintain documentation regarding customer interactions and detailed notes of actions taken during an assigned project.
- Familiarity with Fortified Core Services and make appropriate client recommendations based on those offerings.
Knowledge & Skills
- Education & Experience:
- Associate degree in Computer Science, Management Information Systems, or other relevant combination of training and experience.
- 2+ years of proven work experience in an IT Security-related field.
- Healthcare IT experience a plus.
- Strong computer skills in Adobe and Microsoft Office applications (Project, Visio, Word, Excel, PowerPoint).
- Solid understanding of hardware and networking terminology and devices.
- Special Skills & Knowledge:
- Experience with network security, topology, networking technologies, and the OSI Model.
- Thorough understanding of the latest security principles, techniques, and protocols.
- Familiarity with generating and troubleshooting PowerShell/bash/python scripts.
- Ability to work and communicate effectively, positively, and professionally with clients, third-party system vendors, and other departments.
- Must possess and have proven problem-resolution/critical thinking skills.
- Must be flexible and work with a high level of initiative.
- Ability to retain and protect confidential material.
- Licenses, Certifications, etc.:
- Relevant security certifications (i.e., CISSP, SSCP, OSCP, CEH, GSEC, etc.).
- Other desired technology certifications (i.e., RHCA, MCSE, CCNA, etc.).
Requirements
- Supervisory Responsibility:
- N/A
- Working Conditions & Travel Requirements:
- Evenings and weekend hours should be anticipated.
- Travel as needed.