[SJ-JOB] Security Engineer, Pittsburgh
[email protected] 4 Nov 2008 19:53:53 -0000
| Newsgroups | gmane.comp.security.jobs |
|---|---|
| Message-ID | <[email protected]> |
--------------------------------------------------- SECURITYFOCUS JOBS - NEW OPPORTUNITY --------------------------------------------------- JOB DESCRIPTION --------------------------------------------------- Position: Security Engineer Location: Pittsburgh, Pennsylvania, United States Type: Permanent F/T Closing Date: 2008-11-29 Position Summary:=0D The Information Coordination and Analysis Team (ICAT) within the CERT Pro= gram’s Coordination Center (CERT/CC) is responsible for managing=0D daily operations that integrate disperse sources of analytical informatio= n into strategic and tactical intelligence and ensure coordinated respons= es to ongoing internet security activity.=0D =0D The successful candidate will be responsible for performing tasks related= to analyzing information from a wide variety of sources, conducting tech= nical analysis of incidents and other security threats,coordinating respo= nse actions, and disseminating technical information as appropriate in su= pport of the protection of national and economic security and our critica= l infrastructure assets. Key responsibilities include:=0D •Monitoring, managing, and coordinating the information collection a= nd cataloging activities from a variety of public and private analytical=0D information sources=0D •Corresponding with internal analysis teams, sponsors, reporters, an= d other Computer Security Incident Response Teams (CSIRTs)=0D •Managing the authentication of vendor contacts, which includes vali= dating encryption keys and technical diagnosis of problems related to var= ious channels of communication=0D •Conducting technical investigation of computer security incidents,i= ncluding forensic analysis, and coordinating incident response activities= =0D •Assessing the severity of security threats (e.g., incidents, vulner= abilities, malicious code) and coordinating broad notifications in a time= ly manner=0D •Performing initial surface analysis of vulnerability reports and co= ordinating responses to incoming email sent to the CERT® Coordination= =0D Center=0D •Answering constituent telephone inquiries during normal business ho= urs and outside of business hours for emergencies=0D •Developing and maintaining procedural documentation and participati= ng in internal tools specification=0D =0D This position could be located in either Pittsburgh, PA or Washington D.C= . JOB REQUIREMENTS --------------------------------------------------- Education/Training:=0D BS in Computer Science Information Science, Information Systems Managemen= t with eight years applicable experience or MS in Computer Science, Infor= mation Technology with five years applicable experience=0D =0D Experience:=0D Candidates should have at least 5 years of experience in a Windows and Un= ix/Linux environment and be able to demonstrate knowledge in all of the f= ollowing areas:=0D •core Internet protocols (e.g., IP, TCP, UDP, BGP, DNS, HTTP, SMTP)=0D •system and/or network administration=0D •computer security incident handling and analysis=0D •common types of security vulnerabilities=0D •basic computer security forensics=0D •current internet security issues=0D •various security technologies (e.g., encryption, firewalls, antivir= us)=0D •defending against common types of attacks against systems and netwo= rks=0D •one or more programming languages (e.g., C++, Perl, Java)=0D =0D =0D Skills/Abilities:=0D Successful candidates will=0D • have a strong interest in and possess basic knowledge of network a= nd computer security issues=0D •be able to work meticulously with careful attention to detail=0D •be able to identify and ensure the timely delivery of critical info= rmation to internal analysis teams, sponsors, customers, and other=0D interested parties=0D •be able to communicate effectively within a team environment=0D •be able to effectively prioritize work=0D •be able to develop and explain technical decisions=0D •recognize and deal appropriately with confidential and sensitive in= formation=0D •interact effectively with technical and non-technical audiences via= both verbal and written communications (e.g., technical writing, user gu= ide development, requirements analysis)=0D •be able to quickly learn new procedures, techniques, and approaches= =0D =0D =0D Mobility: Primarily sedentary, long periods of sitting; ability to travel= to various locations within the SEI and CMU community, customer sites, c= onferences, and offsite meetings with some frequency.=0D =0D Environmental Conditions:=0D Normal office conditions; however close contact with computer for prolong= ed periods of time.=0D =0D Mental: Ability to work under pressure; pay attention to detail; meet in= flexible deadlines; deal with difficult individuals while maintaining=0D composure.=0D =0D Other: =0D Candidate must be able to pass a background investigation, obtain a secur= ity clearance, and be a US citizen.=0D =0D =0D ESSENTIAL FUNCTIONS:=0D (1) Conducting technical investigation of computer security incidents, in= cluding forensic analysis and coordinating incident response activities.=0D =0D (2) Monitoring, managing, and coordinating the information collection and= cataloging activities from disperse sources of analytical information (e= .g., mailing lists, web sites, rss feeds), performing surface analysis, a= nd producing strategic and tactical intelligence that can be shared with = interested parties.=0D =0D (3) Performing initial surface analysis of vulnerability reports and coor= dinating responses to incoming email sent to the CERT® Coordination=0D Center.=0D =0D (4) Corresponding with internal analysis teams, sponsors, reporters, and = other Computer Security Incident Response Teams (CSIRTs).=0D =0D (5) Managing the authentication of vendor contacts, which includes valida= ting encryption keys and technical diagnosis of problems related=0D to various channels of communication.=0D =0D (6) Developing and maintaining procedural documentation, participating in= internal tools specification, and serving as team liaison to=0D development and infrastructure teams.=0D =0D (7) Answering constituent telephone inquires during normal business hours= and outside of business hours for emergencies.=0D =0D (8) Representing and presenting material in open forums and conferences.=0D =0D (9) Travel for training, conferences, and customer meetings. CONTACT --------------------------------------------------- To Apply:=0D Careers@CarnegieMellon makes it easy for you to search for positions at t= he SEI that match your interests, apply for positions electronically,=0D and create a Job Agent that will notify you by email when jobs that meet = your criteria become available.=0D =0D Please visit the Careers@CarnegieMellon web site=0D (https://secured.kenexa.com/cmu/cc/Home.ss) to create a profile and apply= to this position (job number 4885). Software Engineering Institute Jeff Savinda Technical Recruiter [email protected] --------------------------------------------------- SECURITYFOCUS JOBS --------------------------------------------------- SecurityFocus now offers an online interface for searching and managing job opportunities and resumes. http://www.securityfocus.com/jobs