Security Consultant: Application Security / Engineering - Verizon Business
Categories: Account Manager
Website: http://www.verizonbusiness.jobs
Position Description
Security Consultant: Application Security / Engineering
Los Angeles Area, CA
Functional Responsibilities:
The Verizon consultant will provide support for conducting application vulnerability assessments utilizing tools such as WebInspect and AppScan. The Verizon consultant will provide support for application security reviews, application security control audits, and application penetration testing. Application security code review experience is preferred. The Verizon consultant will provide support for periodic security testing by external auditors and the associated remediation activities. The Verizon consultant will provide support for on-going and new security projects, including, but not limited to documenting application security standards, application monitoring, and activity logging. The Verizon consultant will provide support for security incident response services, including participating in the cross-functional incident response team (SIRT) and handling those security events whose threat level doesn’t warrant the mobilization of the SIRT. This support also includes providing timely response to urgent staff termination actions.
Required Qualifications/Skills:
2+ years experience with application security reviews and analysis, security monitoring, and implementing application security solutions. Working knowledge of application security concepts and industry guidelines such as OWASP Top 10. Working knowledge of application security testing techniques and tools, database interaction, and operating system security. Working knowledge of application encryption/authentication technologies. Working knowledge of security services involving networks, firewalls, client-server environments, and relational database systems. Information security theory and practices. 3-4 years previous experience with security testing tools like Nessus, nCircle, Metasploit, Canvas, Core Impact, WebInspect, AppScan, or similar tools and experience with penetration testing. Previous consulting experience. Good communication and technical writing skills.
Preferred Certifications:
CISSP, SSCP, CEH, SANS certifications such as GWAS and GSSP
