Back to Jobs

HHS - Penetration Tester

Remote, USA Full-time Posted 2025-11-24
cFocus Software seeks a Penetration Tester to join our program supporting the Department of Health and Human Services (HHS) This position is remote. This position requires the ability a Public Trust clearance. Qualifications: • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field. • Minimum 5–8 years of experience performing penetration testing or offensive security assessments. • Hands-on experience testing enterprise networks, applications, and cloud environments. • Strong knowledge of attack techniques, exploitation frameworks, and post-exploitation methods. • Experience with federal environments and vulnerability management programs preferred. • Strong understanding of NIST SP 800-53, NIST SP 800-30, and vulnerability management processes. • Excellent analytical, documentation, and communication skills. • OSCP, GPEN, CEH, or GXPN preferred. Duties: • Plan, execute, and document penetration tests against networks, systems, web applications, APIs, databases, and cloud environments. • Conduct internal, external, authenticated, unauthenticated, and adversary-simulation testing activities. • Perform exploitation, post-exploitation, and privilege escalation to demonstrate real-world risk. • Validate vulnerability scan findings and identify false positives and chained attack paths. • Conduct application penetration testing aligned with OWASP Top 10 and NIST guidance. • Support red team and purple team exercises in coordination with SOC and Incident Response teams. • Analyze attacker techniques using MITRE ATT&CK and document TTPs and attack paths. • Develop detailed penetration test reports including executive summaries, risk ratings, and remediation guidance. • Provide technical remediation guidance to system owners, engineers, developers, and ISSOs. • Validate remediation effectiveness through retesting and evidence review. • Support compliance testing requirements related to FISMA, RMF, and continuous monitoring. • Maintain strict rules of engagement, authorization documentation, and testing approvals. • Ensure testing activities comply with HHS, HRSA, and federal legal and ethical requirements. Apply tot his job Apply To this Job

Similar Jobs

UPS Remote Jobs (Data Entry| Full Time) Work Fr...

Remote, USA Full-time

Specialist, Cargo Market Development – Americas

Remote, USA Full-time

Visual Designer (UI/UX + Graphics Designer)

Remote, USA Full-time

Experienced Remote Customer Service Specialist – Delivering Exceptional Support from the Comfort of Your Home with arenaflex

Remote, USA Full-time

**Part-time Chat Specialist – arenaflex – College Station, TX**

Remote, USA Full-time

Software Engineer (L5) - AV Tools & Tests

Remote, USA Full-time

[Remote] Principal .NET Developer - 100% Remote - Direct Hire (Full Time)

Remote, USA Full-time

Supply Chain Analyst III

Remote, USA Full-time

Client Executive-Business Sls

Remote, USA Full-time

SEO + SEM Specialist; Remote

Remote, USA Full-time

Overnight Remote Live Chat Support Specialist – Flexible Hours, $25‑$35/hr, Customer Service Excellence at Worklith

Remote, USA Full-time

SOUTH CAROLINA only - Work at Home Call Center Representative

Remote, USA Full-time

Shelf Stocker

Remote, USA Full-time

Group Director, Paid Media Strategy - Remote Leadership

Remote, USA Full-time

Auto Relationship Management Strategy & Support Sr. Business Growth Strategy Consultant (Remote)

Remote, USA Full-time

Remote Growth Marketing Manager - Paid Media

Remote, USA Full-time

Account Executive, Mid City

Remote, USA Full-time

Paid Media Specialist (SEM & LinkedIn Ads)

Remote, USA Full-time

Experienced Remote Data Entry Specialist – Part-Time/Full-Time Opportunities with arenaflex for Detail-Oriented and Motivated Individuals

Remote, USA Full-time

(REMOTE) Revenue Cycle - Sr. Business Intelligence Developer

Remote, USA Full-time