[SJ-JOB] Security Engineer, Pittsburgh

[email protected] 4 Nov 2008 19:53:53 -0000
Newsgroups gmane.comp.security.jobs
Message-ID <[email protected]>
---------------------------------------------------
SECURITYFOCUS JOBS - NEW OPPORTUNITY
---------------------------------------------------


JOB DESCRIPTION
---------------------------------------------------
Position:       Security Engineer
Location:       Pittsburgh, Pennsylvania, United States
Type:           Permanent F/T

Closing Date:   2008-11-29

Position Summary:=0D
The Information Coordination and Analysis Team (ICAT) within the CERT Pro=
gram&#146;s Coordination Center (CERT/CC) is responsible for managing=0D
daily operations that integrate disperse sources of analytical informatio=
n into strategic and tactical intelligence and ensure coordinated respons=
es to ongoing internet security activity.=0D
=0D
The successful candidate will be responsible for performing tasks related=
 to analyzing information from a wide variety of sources, conducting tech=
nical analysis of incidents and other security threats,coordinating respo=
nse actions, and disseminating technical information as appropriate in su=
pport of the protection of national and economic security and our critica=
l infrastructure assets. Key responsibilities include:=0D
&#149;Monitoring, managing, and coordinating the information collection a=
nd cataloging activities from a variety of public and private analytical=0D
information sources=0D
&#149;Corresponding with internal analysis teams, sponsors, reporters, an=
d other Computer Security Incident Response Teams (CSIRTs)=0D
&#149;Managing the authentication of vendor contacts, which includes vali=
dating encryption keys and technical diagnosis of problems related to var=
ious channels of communication=0D
&#149;Conducting technical investigation of computer security incidents,i=
ncluding forensic analysis, and coordinating incident response activities=
=0D
&#149;Assessing the severity of security threats (e.g., incidents, vulner=
abilities, malicious code) and coordinating broad notifications in a time=
ly manner=0D
&#149;Performing initial surface analysis of vulnerability reports and co=
ordinating responses to incoming email sent to the CERT&reg; Coordination=
=0D
Center=0D
&#149;Answering constituent telephone inquiries during normal business ho=
urs and outside of business hours for emergencies=0D
&#149;Developing and maintaining procedural documentation and participati=
ng in internal tools specification=0D
=0D
This position could be located in either Pittsburgh, PA or Washington D.C=
.


JOB REQUIREMENTS
---------------------------------------------------
Education/Training:=0D
BS in Computer Science Information Science, Information Systems Managemen=
t with eight years applicable experience or MS in Computer Science, Infor=
mation Technology with five years applicable experience=0D
=0D
Experience:=0D
Candidates should have at least 5 years of experience in a Windows and Un=
ix/Linux environment and be able to demonstrate knowledge in all of the f=
ollowing areas:=0D
&#149;core Internet protocols (e.g., IP, TCP, UDP, BGP, DNS, HTTP, SMTP)=0D
&#149;system and/or network administration=0D
&#149;computer security incident handling and analysis=0D
&#149;common types of security vulnerabilities=0D
&#149;basic computer security forensics=0D
&#149;current internet security issues=0D
&#149;various security technologies (e.g., encryption, firewalls, antivir=
us)=0D
&#149;defending against common types of attacks against systems and netwo=
rks=0D
&#149;one or more programming languages (e.g., C++, Perl, Java)=0D
=0D
=0D
Skills/Abilities:=0D
Successful candidates will=0D
&#149; have a strong interest in and possess basic knowledge of network a=
nd computer security issues=0D
&#149;be able to work meticulously with careful attention to detail=0D
&#149;be able to identify and ensure the timely delivery of critical info=
rmation to internal analysis teams, sponsors, customers, and other=0D
interested parties=0D
&#149;be able to communicate effectively within a team environment=0D
&#149;be able to effectively prioritize work=0D
&#149;be able to develop and explain technical decisions=0D
&#149;recognize and deal appropriately with confidential and sensitive in=
formation=0D
&#149;interact effectively with technical and non-technical audiences via=
 both verbal and written communications (e.g., technical writing, user gu=
ide development, requirements analysis)=0D
&#149;be able to quickly learn new procedures, techniques, and approaches=
=0D
=0D
=0D
Mobility: Primarily sedentary, long periods of sitting; ability to travel=
 to various locations within the SEI and CMU community, customer sites, c=
onferences, and offsite meetings with some frequency.=0D
=0D
Environmental Conditions:=0D
Normal office conditions; however close contact with computer for prolong=
ed periods of time.=0D
=0D
Mental:  Ability to work under pressure; pay attention to detail; meet in=
flexible deadlines; deal with difficult individuals while maintaining=0D
composure.=0D
=0D
Other:  =0D
Candidate must be able to pass a background investigation, obtain a secur=
ity clearance, and be a US citizen.=0D
=0D
=0D
ESSENTIAL FUNCTIONS:=0D
(1) Conducting technical investigation of computer security incidents, in=
cluding forensic analysis and coordinating incident response activities.=0D
=0D
(2) Monitoring, managing, and coordinating the information collection and=
 cataloging activities from disperse sources of analytical information (e=
.g., mailing lists, web sites, rss feeds), performing surface analysis, a=
nd producing strategic and tactical intelligence that can be shared with =
interested parties.=0D
=0D
(3) Performing initial surface analysis of vulnerability reports and coor=
dinating responses to incoming email sent to the CERT&reg; Coordination=0D
Center.=0D
=0D
(4) Corresponding with internal analysis teams, sponsors, reporters, and =
other Computer Security Incident Response Teams (CSIRTs).=0D
=0D
(5) Managing the authentication of vendor contacts, which includes valida=
ting encryption keys and technical diagnosis of problems related=0D
to various channels of communication.=0D
=0D
(6) Developing and maintaining procedural documentation, participating in=
 internal tools specification, and serving as team liaison to=0D
development and infrastructure teams.=0D
=0D
(7) Answering constituent telephone inquires during normal business hours=
 and outside of business hours for emergencies.=0D
=0D
(8) Representing and presenting material in open forums and conferences.=0D
=0D
(9) Travel for training, conferences, and customer meetings.


CONTACT
---------------------------------------------------
To Apply:=0D
Careers@CarnegieMellon makes it easy for you to search for positions at t=
he SEI that match your interests, apply for positions electronically,=0D
and create a Job Agent that will notify you by email when jobs that meet =
your criteria become available.=0D
=0D
Please visit the Careers@CarnegieMellon web site=0D
(https://secured.kenexa.com/cmu/cc/Home.ss) to create a profile and apply=
 to this position (job number 4885).

Software Engineering Institute
Jeff Savinda
Technical Recruiter
[email protected]



---------------------------------------------------
SECURITYFOCUS JOBS
---------------------------------------------------
SecurityFocus now offers an online interface for
searching and managing job opportunities and resumes.

http://www.securityfocus.com/jobs