[SJ-JOB] Application Security Engineer, Washington D.C.

[email protected] 29 Aug 2008 22:02:38 -0000
Newsgroups gmane.comp.security.jobs
Message-ID <[email protected]>
---------------------------------------------------
SECURITYFOCUS JOBS - NEW OPPORTUNITY
---------------------------------------------------


JOB DESCRIPTION
---------------------------------------------------
Position:       Application Security Engineer
Location:       Washington D.C., District of Columbia, United States
Type:           Permanent F/T

Closing Date:   2008-09-27

The Vulnerability Analysis Team within the CERT Program&#146;s CERT Coordination Center (CERT/CC) is a group of internet security experts that serve as a trusted and neutral coordination body, dedicated to remediating software vulnerabilities and providing practical guidance for customers, system administrators, security researchers, and the global internet security community to reduce the amount of time software systems are vulnerable. The primary roles of the Vulnerability Analysis Team include:

&#149;Software vulnerability analysis including black box testing, source
code examination, and attack reproduction
&#149;Customer, vendor, and reporter correspondence
&#149;Publication of technical documents and remediation information
&#149;Tool specification and development

The individual in this position must be self-motivated and will have the opportunity to serve as a strong contributor and technical leader in the analysis, coordination, and remediation of software vulnerabilities.

The intent is for this position to be primarily located in Washington D.C., but this position could be located in Pittsburgh, PA with travel
to the Washington D.C. area on a regular basis.


JOB REQUIREMENTS
---------------------------------------------------
Education and Training:
Bachelor of Science in Computer Science, Information Science,
Information Management with three years applicable experience as a
system or network administrator, software developer, database
administrator or similarly technical occupation; or Master of Science in
Computer Science, Information Science or Information or equivalent with
one year applicable experience.

We will consider other educational backgrounds in a technical discipline
with experience as described.


Experience:
Candidates should have experience working with the government community;
at least three years of experience in a Windows and Unix/Linux
environment and be able to demonstrate substantial knowledge of at least
four of the following
&#149;various internet protocols (e.g., TCP/IP, DNS, BGP, SMTP, HTTP)
&#149;computer system and Internet security issues
&#149;various security technologies (e.g., encryption, firewalls, and
anti-virus products)
&#149;software runtime analysis, debugging, and security testing techniques
&#149;security auditing practices
&#149;underlying software defects that routinely result in security
vulnerabilities (e.g., input validation errors)
&#149;understanding of intruder techniques and software exploitation methods
&#149;system, database, and/or network administration
&#149;operational details of multiple operating systems
&#149;cryptographic principles and common cryptographic protocols
&#149;one or more programming languages (e.g., C/C++, Perl, or Java)
&#149;vulnerability management concepts and tools


Skills/Abilities:
Successful candidates will
&#149;have an interest in and have extensive knowledge of network and
computer security issues
&#149;have the ability to analyze software to discover vulnerabilities
&#149;be able to develop and explain technical decisions
&#149;be able to separate fact from opinion and speculation
&#149;have excellent work prioritization, planning, and organizational skills
&#149;interact effectively with vulnerability reporters, system and network
administrators, vendors, experts, Internet users, sponsors, policy
makers, news reporters, managers and staff (i.e., stakeholders in the
vulnerability disclosure process)
&#149;be able to work with closely coordinated team during emergencies
&#149;excellent analytical, reasoning, and creative problem solving skills
&#149;excellent written, oral communication skills
&#149;recognize and deal appropriately with confidential and sensitive
information
&#149;be able to work meticulously with careful attention to detail
&#149;be able to collaborate effectively and work closely within a
coordinated team environment
&#149;be able to quickly learn new procedures, techniques, and approaches
&#149;maintain composure while dealing with difficult people
&#149;communicate and work effectively under normal and stressful situations
&#149;meet inflexible deadlines
&#149;possess strong leadership and mentoring abilities
&#149;be motivated to tackle challenging problems


Mobility:
Primarily sedentary, long periods of sitting. Ability to travel to
various locations within the SEI and CMU community, customer sites,
conferences, and offsite meetings with some frequency.

Environmental Conditions:
Normal office conditions; however close contact with computer for
prolonged periods of time.

Mental:
The ability to work well under pressure of deadlines

Other:
Candidate must be able to pass a background check, obtain a security
clearance, and be a U.S. citizen.

ESSENTIAL FUNCTIONS:

(1) Analyze vulnerability reports using tools, processes, and techniques
designed to provide fact-based analysis to other stakeholders in the
vulnerability disclosure process.

(2) Research, specify, and develop new tools, processes and techniques
to improve vulnerability analysis methodology and to support interaction
with stakeholders.

(3) Correspond with software vendors, vulnerability researchers,
sponsors, and other stakeholders.

(4) Communicate analytical results in various technical communities to
promote collaboration and shared understanding of vulnerability
preconditions and impacts.

(5) Write and publish short to medium-length documents describing
vulnerability mitigation strategies and root-cause analyses.

(6) Represent CERT/CC in other forums (e.g., conferences, workshops, etc.)

(7) Provide assistance and input to other teams and projects within the SEI.

(8) Be on call to respond to Internet emergencies (outside of normal
business hours)

(9) Review work of and act as mentor to other team members


CONTACT
---------------------------------------------------
TO APPLY:
Careers@CarnegieMellon makes it easy for you to search for positions at the SEI that match your interests, apply for positions electronically,
and create a Job Agent that will notify you by email when jobs that meet your criteria become available.

Please visit the Careers@CarnegieMellon web site
(https://secured.kenexa.com/cmu/cc/Home.ss) to create a profile and apply to this position (job number 4926).

Software Engineering Institute
Jeff Savinda
Technology Recruiter
[email protected]



---------------------------------------------------
SECURITYFOCUS JOBS
---------------------------------------------------
SecurityFocus now offers an online interface for
searching and managing job opportunities and resumes.

http://www.securityfocus.com/jobs