TITLE: Application Security Analyst
LOCATION: Austin, Texas – USA
RELOCATION/VISA: Need to have a relevant visa
SALARY: On request
COMPANY: On request
KEY REQUIREMENTS:
- Certified Ethical Hacker (CEH or equivalent)
- At least 8 years total experience – years in ethical hacking and penetration testing (would consider substitution of QA testing)
- Penetration Testing Skills
- Basic Forensic and Investigation Skills
- Knowledge of Unix and Windows operating systems
- Understanding security issues associated with application development
- Advanced knowledge of vulnerability management at both the infrastructure and software level
- Understanding of Networking and OSI model
- Able to work with teams to find solutions to technical problems
- Experience in various commercial testing tools such as WebInspect, AppScan, etc.
- Experience with various open source testing tools
Position-specific Desired Skills:
- Certified Information Security Systems Professional (CISSP)
- Familiar with intrusion prevention, file integrity monitoring, user management, and other security domains
- Basic understanding of databases and security/disaster recovery issues with them
- Able to play paintball at least once a month
- Past programming experience
JOB DESCRIPTION:
The company is looking to hire a full time employee to perform security application testing on one of the largest portals in the country. This position works with almost all of the domains of CISSP.
This position offers the opportunity to advance within the organization and the opportunity to learn and grow in a mixed Windows and Unix environment. Few organizations expose an individual to both software development and data center operations on this scale.
Day-to-Day Activities:
- Perform vulnerability scanning of infrastructure and systems
- Perform vulnerability scanning of applications in development and production
- Penetration testing
- Assist with other day-to-day operation security tasks such as intrusion prevention and file integrity monitoring
- Assist development and operations teams with strategies to remediate and prevent vulnerabilities
- Investigate potential security issues
- Develop and write reports in support of security audits and processes.

