Back to Jobs

HHS - Penetration Tester

Remote, USA Full-time Posted 2025-11-24
cFocus Software seeks a Penetration Tester to join our program supporting the Department of Health and Human Services (HHS) This position is remote. This position requires the ability a Public Trust clearance. Qualifications: • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field. • Minimum 5–8 years of experience performing penetration testing or offensive security assessments. • Hands-on experience testing enterprise networks, applications, and cloud environments. • Strong knowledge of attack techniques, exploitation frameworks, and post-exploitation methods. • Experience with federal environments and vulnerability management programs preferred. • Strong understanding of NIST SP 800-53, NIST SP 800-30, and vulnerability management processes. • Excellent analytical, documentation, and communication skills. • OSCP, GPEN, CEH, or GXPN preferred. Duties: • Plan, execute, and document penetration tests against networks, systems, web applications, APIs, databases, and cloud environments. • Conduct internal, external, authenticated, unauthenticated, and adversary-simulation testing activities. • Perform exploitation, post-exploitation, and privilege escalation to demonstrate real-world risk. • Validate vulnerability scan findings and identify false positives and chained attack paths. • Conduct application penetration testing aligned with OWASP Top 10 and NIST guidance. • Support red team and purple team exercises in coordination with SOC and Incident Response teams. • Analyze attacker techniques using MITRE ATT&CK and document TTPs and attack paths. • Develop detailed penetration test reports including executive summaries, risk ratings, and remediation guidance. • Provide technical remediation guidance to system owners, engineers, developers, and ISSOs. • Validate remediation effectiveness through retesting and evidence review. • Support compliance testing requirements related to FISMA, RMF, and continuous monitoring. • Maintain strict rules of engagement, authorization documentation, and testing approvals. • Ensure testing activities comply with HHS, HRSA, and federal legal and ethical requirements. Apply tot his job Apply To this Job

Similar Jobs

UPS Remote Jobs (Data Entry| Full Time) Work Fr...

Remote, USA Full-time

Specialist, Cargo Market Development – Americas

Remote, USA Full-time

Visual Designer (UI/UX + Graphics Designer)

Remote, USA Full-time

Experienced Remote Customer Service Specialist – Delivering Exceptional Support from the Comfort of Your Home with arenaflex

Remote, USA Full-time

**Part-time Chat Specialist – arenaflex – College Station, TX**

Remote, USA Full-time

Software Engineer (L5) - AV Tools & Tests

Remote, USA Full-time

[Remote] Principal .NET Developer - 100% Remote - Direct Hire (Full Time)

Remote, USA Full-time

Supply Chain Analyst III

Remote, USA Full-time

Client Executive-Business Sls

Remote, USA Full-time

SEO + SEM Specialist; Remote

Remote, USA Full-time

Probate Attorney - Consultant

Remote, USA Full-time

[Remote] Recruiter | $60/hr Remote

Remote, USA Full-time

Accounts Payable and Accounts Receivable Specialist job at Trustees of Reservations in Boston, MA

Remote, USA Full-time

Watch Netflix (Tagger): $12-$46

Remote, USA Full-time

**Experienced Retail Sales and Customer Service Specialist – arenaflex Seasonal Opportunity**

Remote, USA Full-time

Director of Clinical Data Management

Remote, USA Full-time

VAPT & SOC 2 Type II / ISO 27001 Compliance Consultant Needed

Remote, USA Full-time

Associate Director, Clinical Operations

Remote, USA Full-time

Experienced Customer Service Representative – Remote Work Opportunity with a Sustainable and Innovative arenaflex Team

Remote, USA Full-time

Remote Recruiter Partner — AI-Powered

Remote, USA Full-time