Specialist Infrastructure Services
Ernst Young U.S. LLP, Specialist Infrastructure Services - Supervising Associate, Secaucus, New Jersey: Demonstrate a thorough understanding of technology, tools, policies and standards related to information and network security systems and work in a team responsible for the design, engineering and implementation of security services across the Global Ernst and Young environment. Defines complex engineering information for security solutions to address business needs. Create designs based on industry best practices, sound engineering principles and have the ability to incorporate both local and global requirements into the designs produced. Participate in projects and act as the central contact point for security related questions and to develop infrastructure designs. Develop network and security infrastructure designs and solutions, support their implementation and provide transition to the various teams via documentation and knowledge transition efforts. Design and implement perimeter security solutions including Checkpoint/Nokia/Cisco Firewalls. Evaluate, design and implement IP Security based Virtual Private Networks on multi-vendor global WAN networks. Planning, designing, implementation and documentation of the network security and structured cabling solutions with various facets of complex data center and branch office facilities. Work with application developers to ensure proper security controls are identified, implemented, and tested. Act as a liaison between Operations, Engineering and Information Security groups to successfully implement enterprise class network security solutions. Implement policies, processes and develop solutions to network security problems. Conduct firewall policy reviews for audit and inventory. Evaluate firewall architecture of existing platforms and recommend changes to accommodate migration to new platforms. Very good understanding of network security controls, network monitoring systems, and business drivers that impact network security policy and practices. Responsible for moderate projects that require the ability to create and implement timelines related to project deliverables, assign tasks and follow up on their completion and manage sponsor/customer expectations of the outcome of the deliverable. Understands the firm's business, organizational structure and operations. Applies strong process and technology enablement knowledge to analyses and problem solving with moderate complexity. Monitors project/program plans to make certain that activities and deliverables are occurring as planned. Identifies points of contention for missed deliverables and creates strategy to mitigate shortfalls in the timeline that missed or unexpected deliverables may create. Makes/Presents recommendations to mid to high level management on solutions and influences decisions. Manages own portfolio of work; delegates tasks, as needed. Escalates complex issues with recommendations to project sponsors and/or leadership.
Minimum Requirements:
- Must have a Bachelor's degree in Engineering or Computer Science, plus 5 years of post-bachelor's, progressive related experience; OR a Master's degree in Engineering or Computer Science, plus 3 years of related experience.
- Must have experience working at the highest technical level of all phases of design, implementation and support.
- Must have expert level knowledge of Checkpoint Security product suite to design, implement and maintain global Firewall architecture.
- Must be able to upgrade Firewall Operating Systems (IPSO or SPLAT) Checkpoint software on High availability systems.
- Must have experience with firewall administration with network security policy configuration under strict change management controls.
- Must have experience with Checkpoint VPN configurations and support, web filtering technologies (Cisco/Checkpoint) and Checkpoint remote access configurations.
- Must have advanced knowledge of Checkpoint/Nokia Hardware IP appliances series for management, troubleshooting, installation and upgrade.
- Must be able to lead new Data Center implementations and migrations of network security devices.
- Must have experience with performing out of box installations, racking, cabling and must be able to move 50-70 lbs boxes.
- Must have experience conducting development, testing, and implementation of network security plans, products, and control techniques.
- Must have strong ability to evaluate design and integrate business needs within the network security space including data center consolidation and migration, network security virtualization and process enhancements.
- Must have experience with Document Global Network Security Architecture diagrams, processes and procedures to be used by Level 1/2 support teams.
- Must have experience with lead deployment of Intrusion detection systems as required by the Information Security standards and principles.
- Must have sound knowledge of IBM ISS products and Proventia network appliances.
- Must be able to participate in future strategy discussions and conduct presentations to business and technical teams.
- Must have experience being responsible for IDS alert response and review, IDS tuning, process RMA request for hardware failures, coordinate with the vendor, root cause analysis and incident mitigation.
- Must have exposure to some of the following tools: Wireshark, ssldump, Snort, Nessus, nmap, ntop,NA/Sniffer Pro, snoop, tcpdump, ethereal and other Open Source tools.
- Must have the following certifications:
- Must have experience working at the highest technical level of all phases of design, implementation and support.
o Valid Checkpoint Certified Security Administrator NGX R65 (CCSA)
o Valid Checkpoint Certified Security Expert NGX R65 (CCSE)
o Valid or Expired Cisco Firewall Specialist and Cisco Quality Specialist (CFS, CQS)
o Valid or Expired Cisco Certified Network Associate (CCNA)
This particular position at Ernst Young in the United States requires the qualified candidate to be a "United States worker" as defined by the U.S. Department of Labor regulations at 20 CFR 656.3. You can review this definition at http://www.gpoaccess.gov/cfr/retrieve.html at the bottom of page 687. Please feel free to apply to other positions that do not require you to be a "U.S. worker".