Web Security Engineer

RESPONSIBILITIES/DUTIES

ß Provide primary support for Websense Web Security.  Support the firm's Internet URL content filtering 

security policy, respond to incidents, and assess business requirements and resolution.

ß Conduct and schedule regular vulnerability assessment scans, reports and remediation plans.  

ß Analyze and investigate suspicious activity using log files, IPS, SEIM, network monitoring tools, and 

remediate accordingly.

ß Monitor and research current industry security threat metrics, technology best practices, security posture, 

tools, threat detection and counter measures, and formulate process improvement.

ß Maintain and coordinate security controls for Windows servers/workstations, and Unix/Linux servers.

ß Security project management and monitor Helpdesk ticketing system for issues related to Security.

ß Work with Windows, UNIX, and other business teams with regards to OS and application level patch 

management.  This includes conducting system security reviews, patch management plans, risk mitigation 

and conformance plans.

COMPETENCIES:

Required Skills (minimum 3 years)

ß Advanced knowledge and working experience with Websense web content security filtering technology.

ß Experience with one or more of the following security vulnerability assessment and management tools 

(Foundstone, Qualys, GFI LanGuard).

ß Excellent written, verbal, and presentation communication skills.

ß Experience with endpoint security methodologies.  Strong incident handling background is required.

ß Strong understanding of TCP, UDP, security protocols, IP protocols and packet analysis.

ß Experience with Microsoft Windows server and client administration.

Desirable Skills 

ß Experience and/or exposure to SIEM technologies including event correlation and syslog analysis.

ß Experience with mobile and smart device security and management framework.

ß Experience with security risk assessment, risk management, compliance, and security policy formulation.

ß Project management background with good multitasking and prioritization skills.

ß Experience with network firewalls, intrusion prevention systems, and network architecture.

ß Experience with computer forensics methodologies.

ß Experience with Linux and UNIX operating systems.

ß Prior financial industry experience is a plus.

1

ACADEMIC QUALIFICATIONS (MINIMUM REQUIREMENTS):

ß CISSP, GCFA, CISA or CISM security certificates is required.

ß Knowledge of standards, rules and regulations related to information security and data confidentiality.

ß Strong analytical and problem solving skills.

ß College degree preferred.

August 12, 2013 • Tags:  • Posted in: Financial

Leave a Reply

You must be logged in to post a comment.