Information Security Pentester - job id 30568


Your Way To Work™

Information Security Pentester

HOURLY W2 RATE

Jersey City, NJ



How to Apply

logo

Thomas Pan


logo

(917) 512-6932


logo

(646) 591-7396


logo



A Contract position at One of the largest international banking networks with strong positions in Asia and a significant presence in the United States..

Pay Options: w2.

Contact Thomas Pan. call (917) 512-6932 or email thomas@sans.com with the Job Code TP30568 or Click the Apply Now button (Sorry, NO IC - Self Incorporated or 3rd Party (Subcontract) or 1099 for this position!).

Location: Jersey City.

Skills required for the position: Information Security, INFRASTRUCTURE, C++, JAVA, HTTP.


Detailed Info: to be focused on working with application project and development teams to see standard firm's security controls and industry best practices integrated into project life-cycles in alignment with the security strategy. Responsible in advising security risk impact to senior management and sponsors. Should be able to pentest applications (web applications and thick client apps). Should be able to understand Network level and Application level reference architecture and be able to advise implementation teams on secure design. Must be able to translate vulnerabilities and gaps into business risks. Educate developers on secure coding practices and hands-on involvement in advising on secure tool kits or frameworks. Work with IT project community and to advise on application security standard controls and best practices. Work closely with other IT operation groups for identifying and remediation of systems with security issues. Should have practical implementation knowledge to advise IT development and implementation teams on how to fix potential vulnerabilities. Advise senior management including business sponsors on Security risks and should be able to translate security risks to business impact. Review application, database and network architecture and highlight risks. Onboard applications into the existing Security frameworks and participate in an advisory capacity until project deployment.

Development/Computing Environment: 1-3 years professional experience as an Application Developer. 8-10 years of professional experience in an information security function for a financial, insurance, pharmaceutical, or similar commercial industry preferred. Bachelor's Degree in Computer Science or related field preferred. Perform Risk assessments for applications and underlying systems and recommend security requirements based on upstream Business requirements. Should have knowledge on Network and Infrastructure architecture. Ability to review and understand organizational security policies and incorporate into standard processes in a project. Expert understanding of HTTP, HTTPS, and other application layer protocols. Expert understanding of network layer protocols & industry best practices. Demonstrated proficiency in developing secure solutions developed using common development frameworks (J2EE, .NET, Spring, Struts, Hibernate, etc) and languages (Java, C#, C++, etc) Actively contributes to strategic security departmental planning in alignment with architectural goals. Strong analytical and problem solving skills. Excellent written, verbal communication & presentation skills. Should be able to work as a team player.


Helpful:

CISSP Certified.

CISM/CRISC Certified

CEH, GXPN, OSCP Certification

Experience with the following:

oOWASP

oWeb application proxies.

oArchitecture Reviews.

oDB vulnerability management.

oWeb Application vulnerability management.

oCloud Security.

The position offers competitive rate.


Job Id: 30568