Morgan Stanley Technology – Level 3 UNIX Security Operation recruitment

Position Category: Information Technology

Position Title: Morgan Stanley Technology - Level 3 UNIX Security Operation

Job Level: Associate

Location: Hong Kong - Hong Kong

Education Required: Bachelors Degree

Position Description:
This is an opportunity for a highly motivated individual to join a high energy team of security administrators responsible for managing Morgan Stanley?s global security infrastructure
The diversity of products technologies under management, ranging from firewalls, IDS to entitlement/authentication systems provides for a learning experience that will satisfy even the ones the most eager to learn.
The position is fast paced, dynamic and challenging and the varied combination of technical skills and soft skills allows for the development of a well rounded individual
This position will base in Hong Kong and is part of a global team (NY HK) with global responsibilities. He/she will be reporting to the Asia Security Operation Manager.

Responsibilities
The technical aspects of the position include:
? Third level of operational support for IT Security core infrastructure products services
? Solaris and Linux system administration
? Firewall and VPN concentrator deployment and administration
? Systems, network and application troubleshooting
? Security policy administration
? Developing intermediate to advanced script tooling (Perl and shell) for managing, analyzing and reporting on the security infrastructure

The non-technical aspects of the position include:
? Coordinating and leading the response to technology problems
? Customer service. Including off hour coverage via cell phone/pager (oncall system, ~every 10-12 weeks):
? Creation/supplementation of Operational Runbooks
? Aligning global strategies with regional needs and demands
? Training teammates
? Interacting with service members of the networking, e-business, UNIX, and PC groups in four major metropolitan regions across the globe.

Skills Required:
Technical skills
? Comfortable with most aspects of operating system administration; for example, system installation and configuration, managing user accounts, managing filesystems, syslog management, system security fundamental and performance analysis.
? Has a solid understanding of a UNIX-based operating system; understands paging and swapping, inter-process communication, devices and what device drivers do, filesystem concepts (inode, clustering, logical partitions).
? Experience with host security (e.g., passwords, uids/gids, SIDs, file permissions, ACLs, filesystem integrity, use of security packages).
? Good knowledge of fundamental networking and distributed computing environment concepts; routing, switching, VLANs, VPN, DNS, NIS, NFS and Email systems;
? Experience with network security (e.g., configuring firewalls, deploying authentication systems- Kerberos, or applying cryptography to network applications).
? Understands packet filtering and stateful packet inspection and the differences between them
? Intermediate to advanced understanding of packet capture and analysis using snoop, tcpdump and Ethereal or similar tools
? Ability to write/debug administrative and reporting tools in some programming language (Perl/Shell or Python desired; Java, C++, Ruby or other experience acceptable).

Soft skills
? Active interest in IT Security and general knowledge of Information Security
? Excellent written and oral communication skills. Fluent English is required
? Strong interpersonal and communication skills; capable of writing documentation, training users in complex topics, making presentations to an internal audience, and interacting positively with upper management, colleagues and customers.
? Independent problem-solving, highly motivated and self-directing
? Comfortable working in an operations and support team with heavy end user interaction
? Ability to handle constantly changing flow of traffic; remain productive during slow times, be able to multitask effectively during busy times, exercise patience and professionalism during stressful situations.

Skills Desired:
Having skills and experience in the areas below is a major plus and will help the candidate integrate with the team and environment.
? Experience with any of the following firewalls
Cisco Pix; Juniper Netscreen; IPFilter or iptables; Checkpoint Firewall-1 or Firewall-1 GX
? Experience with any of the following load balancing devices
Cisco LocalDirector; Cisco CSS; F5 BIG-IP
? Understanding of routing protocols (RIP, BGP, OSPF?)
? Experience with any of the following Internet services
DNS ? BIND and/or djbdns; E-mail ? Sendmail and/or Postfix
? Experience with any of the following systems management and monitoring
Micromuse Netcool; Computer Associates Spectrum; Empire Sysedge; SNMP
? Experience deploying IPSec or SSL VPNs
? Experience using intrusion detection software
? Experience with MIT Kerberos and RSA SecurID
? Experience with NBAD (Network Behavior Anomaly Detection).
? Experience in customer support and experience in interacting with business units.