Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [SJ-JOB] Security Researcher, Santa Clara |
|---|---|
| Date: | 21 Nov 2006 22:31:56 -0000 |
--------------------------------------------------- SECURITYFOCUS JOBS - NEW OPPORTUNITY --------------------------------------------------- JOB DESCRIPTION --------------------------------------------------- Position: Security Researcher Location: Santa Clara, California, United States Type: Permanent P/T Closing Date: 2006-12-15 Senior Security Researcher Summary: Looking for a security professional to lead ongoing application security initiatives. This person will be an internal expert in finding and fixing security issues in our applications at all stages of the software development cycle. They will serve as a trusted resource for development and QA teams, and engage in high profile work. There will be regular interaction with individuals responsible for platform and operational security, outsourced security testers, and occasional meetings with customers. The Security Engineering and Operations department is a dynamic team responsible for security of applications, operations, and internal business units. Individuals focus on one area but regularly collaborate with others on the team. This position reports to the Manager of Security Engineering and Operations, and will be an integral part of that team. Position Responsibilities: • Lead application security efforts • Advocate strong security across the enterprise • Provide specialized technical assistance to various departments • Identify potential areas for abuse in new and existing applications and confirm through testing • Identify areas for improvement related to security in existing development and QA processes • Justify and articulate application security requirements • Conduct application security reviews at various points in the SDLC – including design reviews, code reviews, and internal pen test activity • Coordinate outsourced reviews and pen tests • Document open issues and requirements, and track status thereof • Help design security-related functionality and verify proper implementation thereof • Present application security issues to technical and non-technical audiences • Maintain understanding of latest application exploits. Identify and assess their associated risks in regard to applications and infrastructure. Communicate those risks to management and recommend corresponding remediation strategies. This may include design, and documentation of technical solutions. • Maintain secure coding guidelines • Educate development and QA teams on security practices by personal example, hands on training, and occasional presentations • Serve as a resource to platform security team for discussion of third party exploits and potential impacts • Identify and assist in evaluations of new technologies, tools, and processes for integration into the existing security program and SDLC. This may also include design and development of tools to be utilized by Security, QA, and development teams for automation and more efficient discovery and resolution of security issues • Stay current on relevant trends and technologies, to maintain and increase overall security posture • Rotating on-call for operational incident response • Position requires some after-hours (nights and weekend) work, and occasional travel, but is mostly 8AM to 5PM, M-F JOB REQUIREMENTS --------------------------------------------------- Position Requirements: • Must have hands-on practical information security experience in a large organization, with a thorough understanding of information security fundamentals • Detailed understanding of attack methods, methodologies, and countermeasures • Familiarity with a broad depth of exploit classes, including buffer overflows, SQL injection, and others • Solid understanding of malware and their workings • Experience testing the integrity of software application security, including use of pen testing tools • Experience leading code reviews, pen tests, or similar projects • Ability to craft exploits for demo purposes • Strong understanding of secure application architectures • Expert knowledge of encryption technologies and implementations • Detailed understanding of the complexity and development effort in coding specific solutions • Previous software development experience – candidate should have experience working with product managers, QA teams, and application developers • Expert programming skills – Java, C, C++, and web application development • Strong oral and written communication skills, including the ability to effectively convey technical information to all levels of the organization o Should be comfortable presenting to small and medium size audiences o Proven documentation skills • Strong Team Player with solid interpersonal skills. A collaborative work ethic is necessary for success in this team. Must be able to work closely with all levels throughout the organization. • Effective project management – must be able to manage multiple simultaneous security reviews, and track status of open items and corresponding remediation schedules • U.S. Citizenship • Candidate must be self-directed, and willing to pursue and maintain various technical/security certifications as necessary for the position Preferred Qualifications: • Ability to speak/read/write Mandarin • Expertise in PHP, J2EE, and Java Script • Experience teaching security coding practices and security focused QA testing/pen testing skills and methodologies • Database administration experience • Experience with Voice over IP and security risks of associated protocols and implementations • System administration experience • Working knowledge of IP networking, and common Internet technologies (DNS, SMTP, SSH, etc, including a good understanding of secure infrastructure architectures • CISSP • Technical certifications that support job duties • Military service with information security responsibilities • Bachelor or higher in Computer Science, Engineering, or equivalent technical field, plus 5+ years of technical security experience, or an equivalent combination of education and work experience • CONTACT --------------------------------------------------- Please forward a Word Version Resumes to: John@altaassociates.com Alta Associates, Inc John Ahn Sr Recruiter john@altaassociates.com --------------------------------------------------- SECURITYFOCUS JOBS --------------------------------------------------- SecurityFocus now offers an online interface for searching and managing job opportunities and resumes. http://www.securityfocus.com/jobs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [SJ-JOB] Security Engineer, White Plains, cshea |
|---|---|
| Next by Date: | [SJ-JOB] Forensics Engineer, Arlington, katie . hanson |
| Previous by Thread: | [SJ-JOB] Security Engineer, White Plains, cshea |
| Next by Thread: | [SJ-JOB] Security Researcher, Santa Clara, Jeffrey . Lovelace |
| Indexes: | [Date] [Thread] [Top] [All Lists] |