Monday, September 27, 2010

[KITlist-Tech] Sr Security Engineer - web Application (Redwood Shores, CA)

Please direct your responses to: http://tbe.taleo.net/NA8/ats/careers/requisition.jsp?org=QUALYS&cws=7&rid=192

Qualys, Inc. is the leading provider of on demand IT security risk and compliance management solutions – delivered as a service. Qualys' Software-as-a-Service solutions are deployed in a matter of hours anywhere in the world, providing customers an immediate and continuous view of their security and compliance postures. The QualysGuard® service is used today by more than 3,500 organizations in 85 countries, including 35 of the Fortune Global 100 and performs more than 200 million IP audits per year. Qualys has the largest vulnerability management deployment in the world at a Fortune Global 50 company. Qualys has established strategic agreements with leading managed service providers and consulting organizations including BT, Etisalat, Fujitsu, IBM, I(TS)2, LAC, SecureWorks, Symantec, TELUS and VeriSign.

This individual will be the primary resource for creating, designing, and implementing test plans to ensure the security of applications, systems, processes, and environments.

Qualifications

• Experience planning and executing testing (in cooperation with developers and infrastructure engineers) of Web Servers, Web applications, and back-end database Servers.
• In-depth understanding of safe and ethical penetration test methodologies and best practices.
• Experience using commercial and open-source automated and semi-automated test tools to include planning, analysis, interpretation, and report writing.
• Detailed understanding of testing authentication, authorization and session management, HTML injection, input validation, information leakage, and denial-of-service
• Hands-on experience with JAVA, PHP, HTML, and java script
• Highly capable and experience in writing security test plans, procedures, guidelines and policies.

Education/Experience

• BS in CS, Engineering or equivalent
• Code reviewing
• Application penetration testing
• Static code analysis
• In-depth understanding of SDLC
• Experience coding with Java
• Consulting experience is a plus


------------------------------------

********************************************************************

Read the new KIT List blog at www.kitlist.wordpress.com for job tips and to connect to our community!

Please go to www.KITlist.org to join, post jobs, or get answers to common questions. If you have any comments or questions, you can reach us directly at KITtechmoderator@KITlist.org.

By using the KIT List you agree to comply with the Terms of Use on the site, and will not use discriminatory employment practices. The KIT List is a service of Connelly Communications, Inc.

TO UNSUBSCRIBE:
Replying to KIT emails with an "unsubscribe" request does not work.
Instead, just send an email (from the same account you used to subscribe) to KITlist-Tech-unsubscribe@yahoogroups.com. If you are still receiving emails after a few days, please email us at KITtechmoderator@KITlist.org and we will manually remove you. Thanks!
Yahoo! Groups Links

<*> To visit your group on the web, go to:
http://groups.yahoo.com/group/KITlist-Tech/

<*> Your email settings:
Individual Email | Traditional

<*> To change settings online go to:
http://groups.yahoo.com/group/KITlist-Tech/join
(Yahoo! ID required)

<*> To change settings via email:
KITlist-Tech-digest@yahoogroups.com
KITlist-Tech-fullfeatured@yahoogroups.com

<*> To unsubscribe from this group, send an email to:
KITlist-Tech-unsubscribe@yahoogroups.com

<*> Your use of Yahoo! Groups is subject to:
http://docs.yahoo.com/info/terms/

No comments:

Post a Comment