[SJ-JOB] Security Consultant, Somerville

[email protected] 11 Sep 2008 16:58:49 -0000
Newsgroups gmane.comp.security.jobs
Message-ID <[email protected]>
---------------------------------------------------
SECURITYFOCUS JOBS - NEW OPPORTUNITY
---------------------------------------------------


JOB DESCRIPTION
---------------------------------------------------
Position:       Security Consultant
Location:       Somerville, Massachusetts, United States
Type:           Permanent P/T

Closing Date:   2008-10-11

Balancing Work/Life/Career.  A career at Tufts is more than a job; it provides a culture that values hard work, intellectual curiosity, diversity, collegiality, creativity, innovative thinking and teamwork, making it a great place to grow and develop professionally.  Tufts is committed to providing a progressive and productive work environment that meets the challenges of a changing world, and offers its employees generous benefit programs, with a full range of plan choices.  Tufts is currently seeking candidates for:

Senior Application Risk Consultant #33733

As a trusted advisor and partner to Tufts University, the UIT Information Security Department is responsible for coordinating and implementing a university-wide, proactive and distributed information security management program to ensure the continuous confidentiality, integrity and availability of information assets owned and used by the Tufts University community, consistent with university management's informed risk tolerance. Reporting directly to the Chief Information Security Officer, the Senior Application Risk Consultant works with the entire University community in a consultative manner to understand organizational missions, values and goals, analyze application based information risks which threaten those objectives, recommend appropriate control solutions, and assist in implementing and auditing them to reduce operational and compliance based exposures. 
Responsibilities include a range of proactive application security activities including: consultation for the development of secure development lifecycles, pre- and post-deployment design reviews, threat modeling and risk assessments, operational process reviews and improvements, regulatory compliance solutions, control implementation, project management, training, document preparation and review, independent and collaborative security research, security awareness training, presentations and briefings, developing and collecting decision quality security program metrics, and guiding and assisting the information security team's overall efforts. 



JOB REQUIREMENTS
---------------------------------------------------
This is a full-time position, requiring occasional work after hours as needed.  A Bachelors degree and two years of applicable enterprise and/or professional services information security experience, with progressively increasing levels of capability and responsibility is required OR four or more years of directly applicable professional services and/or enterprise information security experience and expertise can be substituted.  Required skills: Application development and security QA testing skills, including experience with technologies such as web based services, Java, .Net, SQL scripting, VB, Perl, etc; Well developed manual and automated application penetration skills, design review skills including threat modeling and risk profiling, Familiarity with OWASP principles and skill in careful, limited live testing in live production environments; highly advanced PC / Macintosh / Unix workstation and internet software skills, groupware, office productivity software, project management software, architecture tools (e.g. Visio, etc.); advanced experience with typical application components such as web servers, application servers, database software, middleware and underlying infrastructure devices (WAN and LAN devices, operating systems for server platforms, workstations, and a broad range of application, host and network security devices, etc.); operational familiarity with core organizational processes, their associated IT enabled counterparts, and regulatory compliance issues affecting their operation; and skills necessary to design scalable, secure processes, application architecture solutions, and the ability to develop scripts and other facilitative technical tools are also required. Occasional travel to higher education and other information security conferences may also be necessary. Successful candidate must also be able to meet the physical challenges of the job, including the ability to lift up to 25 lbs. The successful candidate selected for the position must pass a "CORI" (Criminal Offender Record Information) background check. 

University Information Technology &#150; UIT



CONTACT
---------------------------------------------------
To apply to this position on-line, go to www.tufts.edu, click on careers then job listings, and search for requisition number 33733.
Tufts University is an AA/EOE employer and actively seeks candidates from diverse backgrounds.  


Tufts
Harry Alexanian

[email protected]



---------------------------------------------------
SECURITYFOCUS JOBS
---------------------------------------------------
SecurityFocus now offers an online interface for
searching and managing job opportunities and resumes.

http://www.securityfocus.com/jobs