Define effective information security standards, processes, and procedures.
Perform security assessments and penetration tests.
Administer security tools and technologies.
Evaluate, recommend, and deploy security tools and technologies.
Collect and analyze systems/application security logs.
Monitor industry trends and threat landscape and recommend necessary controls or countermeasures.
Ensure compliance with internal policies/standards and regulatory requirements.
Respond to security incidents; perform forensics activities and root cause analyses.
Perform other duties as assigned.
Qualifications:
3+ years of hands-on information security experience.
Expertise in Windows and IIS. Working knowledge of Linux/Unix (advanced Linux skills are a big plus).
Working knowledge of network security -- thorough understanding of the OSI model and comprehensive knowledge of common protocols and services for levels 3 through 7.
Proven track record of effectively supporting commonly-used information security tools and processes (e.g.: patch management, log management, malware management, web filtering, firewalls, proxies, APT, IDS, DLP, HIDS/NIDS, network access control, threat and vulnerability management)