Senior Security Risk Engineer Job in Chicago, Illinois Us
Immediate need for a talented Senior Security Risk Engineer that brings experience in the Financial Services Industry. This is a Permanent Opportunity and is located in Chicago IL. Please review the below job description and contact me ASAP.
Key Responsibilities:
We are looking for a Senior Security Risk Engineer with outstanding technical and communication skills. This individual will be performing network, web, host and database security assessments on a diverse and distributed enterprise network and application infrastructure. Responsibilities include: Conducts vulnerability assessments and penetration testing of Internet, Extranet and Intranet networks, and systems. Develops and executes customized testing strategies and plans. Incorporates and uses penetration testing tools and scripts. Actively analyzes technology platforms for architecture and design weaknesses, technical flaws and system vulnerabilities; and recommends appropriate mitigations and controls. Develops and coordinates annual plans for periodic penetration testing of all applicable applications and network elements. In-depth knowledge of web applications, network and platform operating systems is required. Understands and adjusts testing techniques appropriately to various system environments.
The Security Risk Engineer will be responsible for conducting testing of web, client server, and other applications. Additionally, the engineer will conduct testing of a wide variety of operating systems, application servers, and databases. The engineer must have very strong expertise in conducting application and infrastructure security testing. The engineer must also be passionate about assessing and discovering vulnerability in systems, as evidenced through the engineer's skill and strong patterns of continuous learning. The engineer must be effective in communicating to technical teams and business owners in both verbal and written form. Strong self-motivation and a solid risk mind set are essential. Experience in the financial services industry a plus.
Required Experience
- Minimum six years experience in an Information Security position, with a strong background in application security best practices and ethical hacking.
- Desktop/Network Operating Systems: Windows, HP-UX, Linux, Solaris, Linux, Cisco, Juniper, etc.
- Experienced in using commercial and freeware application security and scripting tools
- In-depth knowledge of network application exploitation, web services, ethical hacking/pen testing
- Coding background preferred (C/C, XML, and PERL, JAVA programming knowledge)
- UNIX/LINUX and Windows administration is a plus
- Experience in working with software security design engineering
Required Skills
- Application Security/Penetration testing
- Flavors of UNIX/Linux and databases
- Web Server, Applications Services (IIS/Apache/Websphere, etc.)
- Expert knowledge of OWASP published risks and controls
- Good communication in English, both oral and written (presentations, technical reports and proposals).
- Strong analytical, evaluative, and problem-solving abilities.
- Active involvement in industry groups such as OWASP, ISSA and certifications such as GIAC, CISSP, CISA, is a plus.
- Bachelor's degree in information systems or computer sciences preferred.
Our client is a leading financial institution and we are currently interviewing to fill this and other similar contract positions. Qualified candidates should apply NOW for immediate consideration.
Please email me the most current version of your resume and refer to 11-08836 in the subject line.
Regards,
Kevin Verbovsky
Technical Recruiter
New York, NY 10006
LinkedIn: http://www.linkedin.com/pub/kevin-verbovsky/8/801/7b3
Twitter: http://twitter.com/KevinVerbovsky
Due to the nature of the position, Diversant can only consider direct applicants. Third party resumes will not be considered.
Diversant is one of the largest African-American owned IT staffing and solutions firms in the U.S. We are a fully-certified Minority Business Enterprise (MBE) provider, dedicated to the promotion of diversity in the supply chain and throughout the workplace. Equally important to us is our commitment to providing the highest level of service to all our clients, consultants, and partners. We believe that diversity in all its forms leads to greater opportunities for consultants and partners, and to more innovative solutions for clients.
Open all references in tabs: [1 - 3]