*Position:* Network Security Engineer
*Location: *Washington, DC
*Employment:* 6 month

*Summary:*

The ideal candidate will have advanced experience with advanced
computer-adaptive algorithms and Mobile support for the user interfaces.
Must have hands on experience with learning management systems with social
media features and user interfaces that are universally accessible to
people with or without disabilities. Local candidates preferred.

*Responsibilities:*

Perform the day to day monitoring of security tools such as vulnerability
scanners and act as an escalation point for notifications sent by hosting
providers or internal teams regarding malware, vulnerabilities, indicators
of compromise and other security related incident indicators.
Work with software architects and developers to understand the application
deeply, to then define logging and auditing standards.
Define the network zoning policies and standards to be applied to the
different types of systems, and the rules governing the communications with
all of them.
Coordinate and ensure of the proper implementation of network controls with
hosting provider(s), such as firewalls, IDS/IPS, DNS monitoring, WAF and
DDoS protection.
Implement processes and tools to ensure that all exchanges of information
with third parties and clients use secured paths.
Work with internal security to ensure specific threats and compromise
scenarios are covered by internal controls, or to design or modify existing
controls currently in place.
Coordinate penetration testing engagement with external vendors as well as
the Security Team.
Coordinate the remediation of issues discovered through penetration
testing, integrating these results to the vulnerability management process.
Perform manual and automated testing of new software and infrastructure
used before they are deployed to production.
Define patterns and circumstances that should be deemed suspicious or
malicious, and deploy systems to monitor these patterns across the
application and underlying infrastructure.
Perform account reviews to ensure account creation, modification and
deletion respect policy.
Work with systems administrators and hosting providers to ensure
authentication security tools such as Two Factor Authentication are
deployed securely, and that service accounts and other highly privileged
and administrator/support accounts are restricted as much as possible.

*Qualifications:*

Bachelors degree in Computer Science, Engineering, Sciences, Mathematics
(or related disciplines)
8+ years of technical information security experience; minimum of 5 years
with hands-on experience in application and system/network security testing
Strong understanding of information system security vulnerability
assessment/testing on a wide variety of technologies and implementations
utilizing both automated tools and manual techniques
Significant experience performing web application security/penetration
testing in accordance with well- known methodologies from OWASP, SANS, and
NIST
Demonstrate significant experience in testing multiple Operating Systems
(Windows, Linux, and OSX) as well network devices
Significant hands on experience with manual web application assessment and
penetration testing methods related to web application mapping, reviewing
client-side controls, testing user-input fields, and attacking session
management, authentication, access controls, encryption, and backend
databases/data stores
Maintain high level of proficiency of hands-on experience with open source
and commercial vulnerability assessment and penetration testing tools such
as HP WebInspect/IBM AppScan/, Tenable Nessus/Rapid 7 NeXpose/Cenzic
Hailstorm, Burp Suite, OWASP tools, Nmap, Wireshark, Fiddler, Firebug,
Metasploit/Core Impact, sqlmap, ettercap, Caine and Able, BeEF, DirBuster,
as well as tailor-made penetration testing distributions such as Kali Linux
and Samurai WTF
Work in a team environment or independently when necessary and be
self-directed when appropriate

*Preferred Qualifications:*

Industry information security certifications: OSCP/OSCE/OSWE, GPEN, GWAPT,
CEH, CISSP
Good understanding of the components of a secure SDLC
Experience with scripting languages/programming languages: JavaScript, PHP,
Python, JavaScript, Java, shell scripting, C/C++, jQuery, ASP, .NET, and
HTML
Experience with mobile application assessment and penetration testing
Knowledge of and/or experience with Security Event and Incident Management
systems, intrusion detection/prevention system technologies and deployment
strategies, content/spam filtering, firewall configuration and rule
maintenance
Experience in performing static code analysis tools such as HP Fortify,
Veracode, or IBM AppScan Source
Ability to identify and 0-day issues employing scripting languages,
programming languages, Assembly, and disassemblers/decompilers (IDA Pro,
Flare) and debuggers (Ollydbg, GDB, WinDbg)




*Thanks and Regards,*



*Warm Regards,*

*Randhir Kumar*

*IDC Technologies*

*1851 McCarthy Blvd. Suite 116, Milpitas, CA 95035*

*Email: **randhir.ku...@idctechnologies.com
<randhir.ku...@idctechnologies.com>*

*Phone: **408-459-1535*[Direct]
* Web: www.idctechnologies.com <http://www.idctechnologies.com/>c*

-- 
You received this message because you are subscribed to the Google Groups "IT 
RECURITER" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to it-recuriter+unsubscr...@googlegroups.com.
To post to this group, send email to it-recuriter@googlegroups.com.
Visit this group at https://groups.google.com/group/it-recuriter.
For more options, visit https://groups.google.com/d/optout.

Reply via email to