Description
The role performs internal network penetration testing from two footholds: an unauthenticated physical network port and a simulated-phishing authenticated workstation. Responsibilities include connecting to county network ports, simulating phishing or Trojan compromises, attempting password cracking and lateral movement, evading detection, and documenting attack paths, vulnerabilities, and business impact. The position requires at least four years of internal or network penetration-testing experience, including Active Directory attack paths, onsite work at client facilities, and experience with recon and lateral-movement tooling. OSCP or GPEN certification and experience in HIPAA-regulated or government environments are preferred. Onsite travel is required to department locations across multiple California cities.
