Position: Security Services Testing Resource
Location: Houston, TX
Duration: 12+ Months
VISA: No Restrictions
Assignment Start Date: ASAP
Job Responsibilities:
Penetration/vulnerability testing for web and thick client applications in an enterprise environment
Articulate and/or train others on the “OWASP Top 10” and related concepts
Create extremely high quality written reports containing the findings from web and thick client vulnerability assessments, as well as the ability to articulate those findings to peer technical staff as well as various levels of management
Requirements:
A minimum of three (3) years experience testing web and thick client applications in an enterprise environment.
A strong understanding of web technologies, e.g. HTTP, HTML, CSS, Forms, Database Connectivity, etc.
An understanding of compliance and regulatory requirements such as PCI DSS, SOX, HIPAA, etc…
A full grasp and ability to articulate and/or train others on the “OWASP Top 10” and related concepts.
A minimum of three (3) years experience with programming and/or scripting in one or more of the following languages: .NET, Java, PHP, Ruby, Perl, Bash, or similar language.
A minimum of (3) years experience with SQL, including a strong understanding of SQL syntax and the ability to perform basic management of MS SQL databases.
The ability to perform manual web application vulnerability assessments without the use of automated tools such as web application scanners.
The ability to capture and analyze network traffic at all seven layers of the OSI model, including the ability to discern whether said network traffic contains vulnerabilities and/or sensitive data.
Have a solid grasp of core security fundamentals and concepts, including knowing one’s system, defence in depth, the principle of least privilege, access control, encryption and cryptography, security architecture and design, business continuity and disaster recovery, etc.
Have three (3) years experience with enterprise level security control implementations, including Network Intrusion Detection/Prevention (NIDS/NIPS), Corporate Antivirus, Enterprise Web Filtering, Data Loss Prevention, Insider threat Mitigation, Botnet Detection, etc., as well as demonstrable knowledge of the principles and techniques used to bypass said controls.
The ability to create extremely high quality written reports containing the findings from web and thick client vulnerability assessments, as well as the ability to articulate those findings to peer technical staff as well as various levels of management
Preference is for candidates with two or more of the following certifications: GSEC, GWAPT, CISSP, GPEN, GXPEN, CISA, CISM, OSCP, OSCE
“Our industry does respect tradition, but it respects innovation more than tradition”
By CHOWDARY...
Regards,
RG,
Sun Technologies, Inc.
Mail to: ram...@suntechnologies.com
Work: 678-298-9284
Fax: 678 459 1068
3700 Mansell Road Suite 125, Alpharetta GA 30022. USA
http://www.suntechnologies.com
Disclaimer:We respect your on-line privacy. This is not an unsolicited mail. Under Bill 1618 Title III passed by the 105th US Congress this mail cannot be considered Spam as long as we include contact information and a method to be removed from our mailing list. If you are not interested in receiving our e-mails then please click here to remove your name from the mailing list. We are very sorry for any inconvenience.