*Remote Opportunity*
- Perform vulnerability scanning for network devices, applications, and databases in order to determine if these assets have any vulnerabilities to potential internal or external threats
- Analyze and assess security incidents that occur to assets and escalate incidents by following incident plan
- Create, develop, and maintain standard practices and procedures to respond appropriately to internal and external threats
- Work with internal Infrastructure team and vendor partners to solve information security system problems and issues in a timely and accurate manner
- Follow information security process, policies, and procedures congruent with standards and industry best practices
- Monitor activities and events in the environment to ensure that anomalous behavior is detected, identified, classified, and acted upon where appropriate
- Execute penetration testing on network and applications using ethical hacking techniques in order to determine network and application vulnerability
- Develop and execute corrective action plans and remediation plans when issues are identified in order to mitigate the risk of exploitation
- Strong understanding of security testing practices and methodologies
- Experience developing proper log correlation rules for identifying key events
- Hands-on experience using security testing and analysis tools, such as Metasploit, Burp Suite, Kali, Wireshark, Nmap, and Veracode
- Hands-on experience using common vulnerability scanning tools (Nessus, Nexpose Rapid7, Qualys, Veracode, AppScan, etc.)
- Experience conducting security testing for cloud services and establishing cloud security requirements
- Demonstrated knowledge of common vulnerability frameworks (OWASP Top 10, CVSS)
- Experience with security source code review and development experience in C/C++, Java, and Python
- Authoritative technical knowledge of internet security and networking protocols
- Scripting skills such as Python, Perl, shell, and Bash
- At least 3 years of demonstrated experience in penetration testing
- Expert knowledge of UNIX, AIX, or Linux platforms
- Expert knowledge of Cisco-based firewalls and intrusion detection systems
- Knowledge of mainframe technologies
- Knowledge of Windows 200x Server platforms
- Knowledge of VMware and VM server platforms
19-00165
by via developer jobs - Stack Overflow
No comments:
Post a Comment