Recommended skills and capabilities
Experience with performing vulnerability scans and assessments as well as computer forensics
Familiarity with SOA governance and policy management best practices
Information Security best practices and common processes.
Security Information and Event Management (SIEM).
Knowledge of Windows and UNIX/Linux vulnerabilities and exploits
A solid understanding of various firewalls, with actual experience in design, installation, configuration, and operation
Knowledge of network protocols, data flows, and vulnerabilities within a TCP/IP environment
Ability to perform network protocol analysis and raw data capture
A solid understanding and knowledge of LDAP
Knowledge of OWASP , ISO 27001/2, PCI-DSS
Self-motivated, self-directed and shows attention to detail while working
Works ethically and with integrity supporting organizational goals and values
Displays commitment to excellence
Completes work in a timely manner and meets deadlines
Contributes to building a positive team spirit and treats others with respect
Maintains confidentiality of information and uses information appropriately
Exhibits sound judgment when making decisions and recommendations
Fosters collaboration toward a common vision and shared goals
Must have
Bachelor Degree) in Computer Science, Engineering or related discipline with 2-5 years of experience
Minimum of 10 years of information systems security or related auditing experience
Preferred certifications: CISSP, CEH,
Ability to clearly communicate Information Security matters to executives, auditors, end users, and engineers, using appropriate language, examples, and tone
Strong analytical, technical, and problem solving skills
Ability to work effectively, independent of assistance or supervision
Innovative, creative, and extremely responsive, with a strong sense of urgency
Willing to share knowledge and assist others in understanding technical and business topics
Willingness to work outside of regular business hours as required which can include evenings, weekends and holidays
Experience with firewalls, routers, load balancers and DMZ silos
Working knowledge of information systems security standards and practices (e.g., access control and system hardening, system audit and log file monitoring, security policies, and incident handling)
Demonstrated experience of "hands on" security knowledge of one or more of the following platforms: Windows/Unix/Linux
Working knowledge with F5 ASM and Data Loss Prevention
Experience with DNS, NTP and Citrix, TACACS, IDS, IPS and various SIEMS
Working knowledge of protocols and technologies such as TCP, UDP, SSL, FTP, SMTP, NetBIOS and DHCP
Working knowledge of HTML, CSS, JavaScript and WML
At least one technical certification related to a major platform (IBM, Microsoft or Cisco)
Ability to interpret information security data and processes to identify potential compliance issues
Ability to quickly understand security systems in order to identify and validate security requirements