Internal Network Penetration Tester
Position Summary
Executes internal network penetration testing from two pre-determined footholds — an unauthenticated physical network port and a simulated-phishing authenticated workstation — across County facilities, testing servers, workstations, endpoints, and password strength.
Key Responsibilities
• Physically connect to County network ports to simulate an unauthenticated internal attacker.
• Simulate a successful phishing/Trojan compromise from an authenticated workstation foothold.
• Attempt password cracking and lateral movement while evading department detection and response efforts.
• Document internal attack paths, exploited vulnerabilities, and business impact for each department report.