ISO 27001 Compliance Penetration Tester Required

Job ID: 38715745

Budget: $750 – $1,500 USD

We are seeking an experienced penetration tester to assess the security of our internal network, including Active Directory (AD), in preparation for an upcoming ISO 27001 audit. This project will focus on identifying vulnerabilities and ensuring our internal systems are compliant with ISO 27001 standards.

Responsibilities:

Perform a penetration test on our internal network and systems, with an emphasis on Active Directory security.
Identify vulnerabilities and provide recommendations to align with ISO 27001 standards.
Provide detailed remediation steps for any identified issues.
Ensure minimal disruption to active services during testing.
Requirements:

Proven experience with internal network penetration testing, particularly with Active Directory.
Familiarity with ISO 27001 compliance and security standards.
Experience with tools such as Burp Suite, Metasploit, Nmap, Nessus, and others.
Relevant certifications (e.g., OSCP, CEH, CISSP, ISO 27001 Lead Auditor/Implementer) preferred.
Ability to provide detailed reports with remediation recommendations.
Excellent communication skills and attention to detail.
Scope:

Internal network and AD penetration test with a focus on ISO 27001 compliance.
Identify misconfigurations, vulnerabilities, and potential security risks.
Comprehensive report with risk ratings and remediation recommendations.
Deliverables:

Full penetration test report.
Specific recommendations for improving our security posture and aligning with ISO 27001 standards.
Optional: assistance with remediation, if needed (please indicate availability and rates).