Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Jobs
[Top] [All Lists]

[SJ-JOB] Application Security Engineer, Dulles

Subject: [SJ-JOB] Application Security Engineer, Dulles
Date: 28 Dec 2006 00:30:21 -0000
---------------------------------------------------
SECURITYFOCUS JOBS - NEW OPPORTUNITY
---------------------------------------------------


JOB DESCRIPTION
---------------------------------------------------
Position:       Application Security Engineer
Location:       Dulles, Virginia, United States
Type:           Permanent F/T

Closing Date:   2007-01-26

General Responsibilities:
As Cigital engages with clients in the application of our software or process 
improvement methodologies, the Senior Security Consultant is responsible for 
the execution and delivery of planned project deliverables and milestones that 
assist clients in learning, understanding, and applying software or process 
improvement methodologies.  He/She has task responsibility within one or more 
projects, typically with one client. The Senior Consultant possesses solid 
business knowledge, Cigital methodology, technical, general consulting, project 
management and teaching skills. He/She is current on industry issues and 
supports proposal preparation.  The Senior Consultant supports marketing 
efforts, is expected to identify follow on work, and mentor employees.

General Qualifications:
•  Consulting skills
–  Ability to interface with clients, utilizing consulting and negotiating 
skills
–  Ability to undertake and complete tasks independently, meet schedules 
and delivery timelines, and to move swiftly from concepts and theory to action
–  Ability to provide pre-sales/post-sales technical support
•  Team Oriented skills
–  Ability to collaborate with project team members
•  Project Management
–  Ability to give direction as project lead and execute tasks consistently
•  Project Leadership
–  Ability to mentor consultants and to lead and execute projects to 
successful completion
•  Communication
–  Requires written communication skills for use in preparing formal 
documentation, Statements of Work, proposals, white papers, and case studies
–  Verbal requirements that include the ability to clearly articulate 
thoughts and deliver presentation and training to all levels of management
–  Ability to persuade
•  Demeanor
–  Enthusiasm and commitment with professional interpersonal skill and an 
entrepreneurial drive

Specific Qualifications:
•  Deep knowledge of TCP/IP and related application protocols
•  Perform Web application penetration testing and security vulnerability 
testing
•  Ability to scope testing activities based on requirements analysis and 
design
•  Able to do manual vulnerability assessment and verification
•  Ability to write proof-of-concept exploit code
•  Can develop tools and scripts in various languages (e.g., Perl, 
Javascript, PHP, Python, etc.)
•  Can do root cause analysis and report writing
•  Can mentor and perform knowledge transfer with team members and clients
•  Familiar with best-practice test methodologies
•  




JOB REQUIREMENTS
---------------------------------------------------
Education and Experience:
•  BS in CS, Engineering or equivalent. MS preferred
•  Experience with C/C++, Java, .Net coding or code analysis
•  2 - 3 Years consulting experience
•  Working knowledge of source code analysis tools preferred
•  Industry Experience: - Background in the Financial Services Industry 
preferred
•  Assessments on multi-protocol enterprise network and application systems
•  Experience using commercial and open source tools such as WebInspect, 
AppScan, and WebScarab, etc. 
•  Assessments of network security products, cryptographic suites, 
firewalls, databases a plus
•  Computer forensics, network exploitation, ethical hacking, penetration 
testing and tool development
•  Experience in bypassing firewalls, evading intrusion detection are a 
nice-to-have
•  Experience in application level attacks on higher-order functions, such 
as business logic
•  Knowledge of the software development lifecycle in a large enterprise



CONTACT
---------------------------------------------------
Please write Ethical Hacker in the subject line. Email resume to 
atheodore@cigital.com.
Principles only. 


Cigital Inc.
Amy  Theodore
Senior Technical Recruiter
atheodore@cigital.com



---------------------------------------------------
SECURITYFOCUS JOBS
---------------------------------------------------
SecurityFocus now offers an online interface for
searching and managing job opportunities and resumes.

http://www.securityfocus.com/jobs

<Prev in Thread] Current Thread [Next in Thread>
  • [SJ-JOB] Application Security Engineer, Dulles, atheodore <=