Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Jobs
[Top] [All Lists]

[SJ-JOB] Security Researcher, Santa Clara

Subject: [SJ-JOB] Security Researcher, Santa Clara
Date: 21 Nov 2006 22:31:56 -0000
---------------------------------------------------
SECURITYFOCUS JOBS - NEW OPPORTUNITY
---------------------------------------------------


JOB DESCRIPTION
---------------------------------------------------
Position:       Security Researcher
Location:       Santa Clara, California, United States
Type:           Permanent P/T

Closing Date:   2006-12-15

Senior Security Researcher

Summary:
Looking for a security professional to lead ongoing application security 
initiatives. This person will be an internal expert in finding and fixing 
security issues in our applications at all stages of the software development 
cycle. They will serve as a trusted resource for development and QA teams, and 
engage in high profile work. There will be regular interaction with individuals 
responsible for platform and operational security, outsourced security testers, 
and occasional meetings with customers. The Security Engineering and Operations 
department is a dynamic team responsible for security of applications, 
operations, and internal business units. Individuals focus on one area but 
regularly collaborate with others on the team. This position reports to the 
Manager of Security Engineering and Operations, and will be an integral part of 
that team.
Position Responsibilities: 
•  Lead application security efforts
•  Advocate strong security across the enterprise
•  Provide specialized technical assistance to various departments
•  Identify potential areas for abuse in new and existing applications and 
confirm through testing
•  Identify areas for improvement related to security in existing 
development and QA processes
•  Justify and articulate application security requirements
•  Conduct application security reviews at various points in the SDLC 
– including design reviews, code reviews, and internal pen test activity
•  Coordinate outsourced reviews and pen tests
•  Document open issues and requirements, and track status thereof
•  Help design security-related functionality and verify proper 
implementation thereof
•  Present application security issues to technical and non-technical 
audiences
•  Maintain understanding of latest application exploits. Identify and 
assess their associated risks in regard to applications and infrastructure. 
Communicate those risks to management and recommend corresponding remediation 
strategies. This may include design, and documentation of technical solutions.
•  Maintain secure coding guidelines
•  Educate development and QA teams on security practices by personal 
example, hands on training, and occasional presentations
•  Serve as a resource to platform security team for discussion of third 
party exploits and potential impacts
•  Identify and assist in evaluations of new technologies, tools, and 
processes for integration into the existing security program and SDLC. This may 
also include design and development of tools to be utilized by Security, QA, 
and development teams for automation and more efficient discovery and 
resolution of security issues
•  Stay current on relevant trends and technologies, to maintain and 
increase  overall security posture 
•  Rotating on-call for operational incident response
•  Position requires some after-hours (nights and weekend) work, and 
occasional travel, but is mostly 8AM to 5PM, M-F




JOB REQUIREMENTS
---------------------------------------------------
Position Requirements:
•  Must have hands-on practical information security experience in a large 
organization, with a thorough understanding of information security fundamentals
•  Detailed understanding of attack methods, methodologies, and 
countermeasures
•  Familiarity with a broad depth of exploit classes, including buffer 
overflows, SQL injection, and others
•  Solid understanding of malware and their workings
•  Experience testing the integrity of software application security, 
including use of pen testing tools
•  Experience leading code reviews, pen tests, or similar projects
•  Ability to craft exploits for demo purposes
•  Strong understanding of secure application architectures
•  Expert knowledge of encryption technologies and implementations
•  Detailed understanding of the complexity and development effort in 
coding specific solutions
•  Previous software development experience – candidate should have 
experience working with product managers, QA teams, and application developers
•  Expert programming skills – Java, C, C++, and web application 
development
•  Strong oral and written communication skills, including the ability to 
effectively convey technical information to all levels of the organization
o       Should be comfortable presenting to small and medium size audiences
o       Proven documentation skills
•  Strong Team Player with solid interpersonal skills. A collaborative 
work ethic is necessary for success in this team. Must be able to work closely 
with all levels throughout the organization.
•  Effective project management – must be able to manage multiple 
simultaneous security reviews, and track status of open items and corresponding 
remediation schedules
•  U.S. Citizenship
•  Candidate must be self-directed, and willing to pursue and maintain 
various technical/security certifications as necessary for the position


Preferred Qualifications:
•  Ability to speak/read/write Mandarin
•  Expertise in PHP, J2EE, and Java Script
•  Experience teaching security coding practices and security focused QA 
testing/pen testing skills and methodologies
•  Database administration experience
•  Experience with Voice over IP and security risks of associated 
protocols and implementations
•  System administration experience
•  Working knowledge of IP networking, and common Internet technologies 
(DNS, SMTP, SSH, etc, including a good understanding of secure infrastructure 
architectures
•  CISSP
•  Technical certifications that support job duties
•  Military service with information security responsibilities
•  Bachelor or higher in Computer Science, Engineering, or equivalent 
technical field, plus 5+ years of technical security experience, or an 
equivalent combination of education and work experience
•  



CONTACT
---------------------------------------------------
Please forward a Word Version Resumes to: John@altaassociates.com


Alta Associates, Inc
John Ahn
Sr Recruiter
john@altaassociates.com



---------------------------------------------------
SECURITYFOCUS JOBS
---------------------------------------------------
SecurityFocus now offers an online interface for
searching and managing job opportunities and resumes.

http://www.securityfocus.com/jobs

<Prev in Thread] Current Thread [Next in Thread>