Back to Jobs

HHS - Penetration Tester

Remote, USA Full-time Posted 2025-11-24
cFocus Software seeks a Penetration Tester to join our program supporting the Department of Health and Human Services (HHS) This position is remote. This position requires the ability a Public Trust clearance. Qualifications: • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field. • Minimum 5–8 years of experience performing penetration testing or offensive security assessments. • Hands-on experience testing enterprise networks, applications, and cloud environments. • Strong knowledge of attack techniques, exploitation frameworks, and post-exploitation methods. • Experience with federal environments and vulnerability management programs preferred. • Strong understanding of NIST SP 800-53, NIST SP 800-30, and vulnerability management processes. • Excellent analytical, documentation, and communication skills. • OSCP, GPEN, CEH, or GXPN preferred. Duties: • Plan, execute, and document penetration tests against networks, systems, web applications, APIs, databases, and cloud environments. • Conduct internal, external, authenticated, unauthenticated, and adversary-simulation testing activities. • Perform exploitation, post-exploitation, and privilege escalation to demonstrate real-world risk. • Validate vulnerability scan findings and identify false positives and chained attack paths. • Conduct application penetration testing aligned with OWASP Top 10 and NIST guidance. • Support red team and purple team exercises in coordination with SOC and Incident Response teams. • Analyze attacker techniques using MITRE ATT&CK and document TTPs and attack paths. • Develop detailed penetration test reports including executive summaries, risk ratings, and remediation guidance. • Provide technical remediation guidance to system owners, engineers, developers, and ISSOs. • Validate remediation effectiveness through retesting and evidence review. • Support compliance testing requirements related to FISMA, RMF, and continuous monitoring. • Maintain strict rules of engagement, authorization documentation, and testing approvals. • Ensure testing activities comply with HHS, HRSA, and federal legal and ethical requirements. Apply tot his job Apply To this Job

Similar Jobs

UPS Remote Jobs (Data Entry| Full Time) Work Fr...

Remote, USA Full-time

Specialist, Cargo Market Development – Americas

Remote, USA Full-time

Visual Designer (UI/UX + Graphics Designer)

Remote, USA Full-time

Experienced Remote Customer Service Specialist – Delivering Exceptional Support from the Comfort of Your Home with arenaflex

Remote, USA Full-time

**Part-time Chat Specialist – arenaflex – College Station, TX**

Remote, USA Full-time

Software Engineer (L5) - AV Tools & Tests

Remote, USA Full-time

[Remote] Principal .NET Developer - 100% Remote - Direct Hire (Full Time)

Remote, USA Full-time

Supply Chain Analyst III

Remote, USA Full-time

Client Executive-Business Sls

Remote, USA Full-time

SEO + SEM Specialist; Remote

Remote, USA Full-time

Virtual Medical Assistant/Admin

Remote, USA Full-time

Experienced Customer Service Representative – Remote Work Opportunity with a Sustainable and Innovative arenaflex Team

Remote, USA Full-time

**Experienced Customer Service Representative – Remote Call Center Opportunity at arenaflex**

Remote, USA Full-time

Director of Clinical Data Management

Remote, USA Full-time

Remote Senior Business Analyst, Public Health IT; PAL

Remote, USA Full-time

Senior Admin – Corporate Safety & Security; Remote

Remote, USA Full-time

**Director, Customer Marketing – Empowering Customer Loyalty and Advocacy at arenaflex**

Remote, USA Full-time

Marketing Automation Specialist

Remote, USA Full-time

**Experienced Mobile Customer Service Representative – Delivering Exceptional Arenaflex Customer Experiences**

Remote, USA Full-time

Chaplain-Resource

Remote, USA Full-time