*Please respond back to sate...@protegellc.com <sate...@protegellc.com> or
call me on 703-957-5309.*

*Job Title: Manual Application Penetration tester*
*Location: Brooklyn, NY  *
*Duration : 24+ months*

*Job Description: *
Iooking to bring on an experienced application security contractor in order
to supplement internal efforts.
Candidate should have all of the following technical and professional
characteristics as well:

*This is a manual penetration testing position (not automated) so strong
scripting is crucial.*
Min 3 years of experience penetration/vulnerability testing  for web and
thick-client applications in an enterprise environment
Strong understanding of web technologies, e.g. HTTP, HTML, CSS, Forms,
Database Connectivity, etc.
Understanding of compliance and regulatory requirements such as PCI DSS,
SOX, HIPAA, etc.
Full grasp and ability to articulate and/or train others on the “OWASP Top
10” and related concepts
Minimum 3 years of experience with programming and/or scripting in one or
more of the following languages: .NET, Java, PHP, Ruby, Perl, Bash, or
similar language
Minimum 3 years of experience with SQL, including a strong understanding of
SQL syntax and the ability to perform basic management of MS SQL databases
Ability to perform manual web application vulnerability assessments without
the use of automated tools such as web application scanners
Ability to capture and analyze network traffic at all seven layers of the
OSI model, including ability to discern whether said network traffic
contains vulnerabilities and/or sensitive data
Have a solid grasp of core security fundamentals and concepts, including
knowing one’s system, defense in depth, the principle of least privilege,
access control, encryption and cryptography, security architecture and
design, business continuity and disaster recovery, etc.
Minimum 3 years of experience with enterprise-level security control
implementations, including Network Intrusion Detection/Prevention (NIDS/NIPS),
Corporate Antivirus, Enterprise Web Filtering, Data Loss Prevention,
Insider-threat Mitigation, Botnet Detection, etc., as well as demonstrable
knowledge of the principles and techniques used to bypass said controls.
Ability to create extremely high quality written reports containing the
findings from web and thick-client vulnerability assessments, as well as
the ability to articulate those findings to peer technical staff as well as
various levels of management
Preference is for candidates with two or more of the following
certifications: GSEC, GWAPT, CISSP, GPEN, GXPEN, CISA, CISM, OSCP, OSCE

*Thanks & Regards*
*Sateesh | Sr. Technical Recruiter*
*Protege, LLC.*
*12020 Sunrise Valley Dr, Suite 100, Reston VA 20191*
*Email: sate...@protegellc.com <sate...@protegellc.com> | Gtalk:
recruiter.sateesh*
*Office: 703-957-5309; Fax: 877 481 9005*
*Visit us at: www.protegellc.com <http://www.protegellc.com>*

-- 
You received this message because you are subscribed to the Google Groups 
"US_IT.Groups" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to us_itgroups+unsubscr...@googlegroups.com.
To post to this group, send email to us_itgroups@googlegroups.com.
Visit this group at http://groups.google.com/group/us_itgroups.
For more options, visit https://groups.google.com/d/optout.

Reply via email to