Thursday, February 5, 2015

Application Security Senior Analyst

The opening requires strong understanding of ethical hacking methodologies, frameworks, and industry resources in addition to the above skills. It is 10+ month CONTRACT opportunity located in FORT LAUDERDALE, FL OR IRVING, TX,  

Please Note: This position is 100% onsite (non Remote), No 3rd parties or H1b Please! 
Industry Certifications: CISSP, CEH and GIAC Highly Preferred!!!

The scope of the Application Vulnerability Assessment (AVA) process, is comprised of all Client business functions, subsidiaries, managed facilities, critical infrastructure components as well as service provider arrangements that include Client branded and co-branded applications. The AVA process is governed by the System Security Testing Standard (SSTS).

Application Security Senior Analyst
Candidates for this position must have strong understanding of ethical hacking methodologies, frameworks, and industry resources, e.g. OWASP, OSSTMM, NIST publications, SANS/CWE, among others, in order to be able to maintain, improve, and benchmark the Client Vulnerability Assessment process, allowing it to remain a world class service. Process engineering and documentation is key. Areas of focus are mobile security testing in the various platforms, threat modeling, source code review, and application/infrastructure penetration testing in general.

Other key duties include providing application vulnerability assessment services to Client businesses globally through a comprehensive testing process, as well as identifying weaknesses and vulnerabilities within the system and proposing/implementing countermeasures.
Pre-requisites for this position are a Bachelor's Degree with 3 to 7 years of experience in web development and programming languages i.e. Java, XML, Perl and HTML. A expert level understanding of security, web-based and infrastructure vulnerabilities is required.

Experience conducting one or more of the following functions:
1) Application vulnerability assessments
2) Source code review
3) Application architecture reviews or threat modeling

Articulating security issues to technical and non-technical audience is also required. In addition, knowledge of tools and processes used to expose common vulnerabilities and implement countermeasures is expected. Excellent communication skills (written and verbal) and the ability to communicate with all levels of staff and management are also essential.

Pre-requisites for this position are a Bachelor's Degree with 3 - 7 years' experience in web development and programming languages i.e. Java, XML, Perl and HTML. A basic understanding of security, web-based and infrastructure vulnerabilities is required. Experience conducting vulnerability assessments and articulating security issues to technical and non-technical audience is a plus. Industry-accredited security certifications will be required. The candidate must have or be willing to obtain all of the following certifications - CISSP, CEH and GIAC. In addition, knowledge of tools and processes used to expose common vulnerabilities and implement countermeasures is expected. Excellent communication skills (written and verbal) and the ability to communicate with all levels of staff and management are a plus.

Candice Perkins
Axelon Services Corporation
44 Wall Street 18th Floor
New York, NY 10005
Phone: (212) 384-6518 or (877) 711-8700
Fax  : (212) 306-0191
candice.perkins@axelon.com