date: june 2018 word - blueprint job descr penetration tester (1).docx created date 20180622172857z

1
Date: June 2018 Job Title: Information Security Consultant – Penetration Tester Description: The primary responsibilities for this position will include conducting operational and technical information security assessments for organizations per the HIPAA Security Rule and relevant security framework(s) such as the HITRUST Common Security Framework. In addition, this position will require contributing to client projects in which appropriate security controls to address vulnerabilities found during the assessments are recommended. This position offers considerable growth potential as BluePrint expands its services and solutions and grows its client base. This position will receive a high degree of coaching and knowledge development in the field of information security and will work directly with senior information security consultants on client-facing projects. A strong technical background, willingness to learn and good work ethic will be necessary for success in this position. The employee will gain hands on experience while participating in critical business projects aligned with company goals. The Information Security Consultant – Penetration Tester will gain experience in analysis, documentation, troubleshooting process improvement and technical troubleshooting for project implementations. Previous information security experience is a plus. Qualifications: The primary responsibilities for this position will include conducting technical information security assessments and performing vulnerability scanning and penetration testing for organizations per the HIPAA Security Rule and relevant security framework(s). In addition, this position will require contributing to client projects in which appropriate security controls to address vulnerabilities found during the assessments are recommended. This position offers considerable growth potential as BluePrint expands its services and solutions and grows its client base. This position will receive a high degree of coaching and knowledge development in the field of information security and will work directly with senior information security consultants on client- facing projects. A strong technical background, willingness to learn and good work ethic will be necessary for success in this position. The employee will gain hands on experience while participating in critical business projects aligned with company goals. The Information Security Consultant – Penetration Tester will gain experience in analysis, documentation, troubleshooting process improvement and technical troubleshooting for project implementations. Previous information security experience is a plus. Qualifications: Bachelor's degree in Computer Science, Information Systems, or equivalent Experience in information systems, specifically network administration or infrastructure, information security, audit, and/or risk assessments preferred Experience with network vulnerability scanning tools such as Tenable’s Nessus and/or BeyondTrust’s Retina required Experience with internal and external penetration testing methodologies and tools required Critical thinking and initiative to learn new areas a requirement Proficiency with Microsoft Office suite required; advanced proficiency with Excel and plus Experience in customer-facing projects a plus Understanding of/experience in the healthcare industry a plus Certified Ethical hacker certification a plus CISSP, CISM, CRISC, HCISPP, or SSCP highly preferred (current or pursuing) Excellent communication skills required Familiarity with security frameworks such as NIST, ISO 27001, and HITRUST highly desired Ability to travel up to 20% Location: West Chester, PA

Upload: doanmien

Post on 15-Aug-2018

216 views

Category:

Documents


0 download

TRANSCRIPT

Date:June2018JobTitle:InformationSecurityConsultant–PenetrationTesterDescription:TheprimaryresponsibilitiesforthispositionwillincludeconductingoperationalandtechnicalinformationsecurityassessmentsfororganizationspertheHIPAASecurityRuleandrelevantsecurityframework(s)suchastheHITRUSTCommonSecurityFramework.Inaddition,thispositionwillrequirecontributingtoclientprojectsinwhichappropriatesecuritycontrolstoaddressvulnerabilitiesfoundduringtheassessmentsarerecommended.ThispositionoffersconsiderablegrowthpotentialasBluePrintexpandsitsservicesandsolutionsandgrowsitsclientbase.Thispositionwillreceiveahighdegreeofcoachingandknowledgedevelopmentinthefieldofinformationsecurityandwillworkdirectlywithseniorinformationsecurityconsultantsonclient-facingprojects.

Astrongtechnicalbackground,willingnesstolearnandgoodworkethicwillbenecessaryforsuccessinthisposition.Theemployeewillgainhandsonexperiencewhileparticipatingincriticalbusinessprojectsalignedwithcompanygoals.TheInformationSecurityConsultant–PenetrationTesterwillgainexperienceinanalysis,documentation,troubleshootingprocessimprovementandtechnicaltroubleshootingforprojectimplementations.Previousinformationsecurityexperienceisaplus.

Qualifications:

TheprimaryresponsibilitiesforthispositionwillincludeconductingtechnicalinformationsecurityassessmentsandperformingvulnerabilityscanningandpenetrationtestingfororganizationspertheHIPAASecurityRuleandrelevantsecurityframework(s).Inaddition,thispositionwillrequirecontributingtoclientprojectsinwhichappropriatesecuritycontrolstoaddressvulnerabilitiesfoundduringtheassessmentsarerecommended.ThispositionoffersconsiderablegrowthpotentialasBluePrintexpandsitsservicesandsolutionsandgrowsitsclientbase.Thispositionwillreceiveahighdegreeofcoachingandknowledgedevelopmentinthefieldofinformationsecurityandwillworkdirectlywithseniorinformationsecurityconsultantsonclient-facingprojects.

Astrongtechnicalbackground,willingnesstolearnandgoodworkethicwillbenecessaryforsuccessinthisposition.Theemployeewillgainhandsonexperiencewhileparticipatingincriticalbusinessprojectsalignedwithcompanygoals.TheInformationSecurityConsultant–PenetrationTesterwillgainexperienceinanalysis,documentation,troubleshootingprocessimprovementandtechnicaltroubleshootingforprojectimplementations.Previousinformationsecurityexperienceisaplus.

Qualifications:

• Bachelor'sdegreeinComputerScience,InformationSystems,orequivalent• Experienceininformationsystems,specificallynetworkadministrationorinfrastructure,informationsecurity,audit,

and/orriskassessmentspreferred• ExperiencewithnetworkvulnerabilityscanningtoolssuchasTenable’sNessusand/orBeyondTrust’sRetinarequired• Experiencewithinternalandexternalpenetrationtestingmethodologiesandtoolsrequired• Criticalthinkingandinitiativetolearnnewareasarequirement• ProficiencywithMicrosoftOfficesuiterequired;advancedproficiencywithExcelandplus• Experienceincustomer-facingprojectsaplus• Understandingof/experienceinthehealthcareindustryaplus• CertifiedEthicalhackercertificationaplus• CISSP,CISM,CRISC,HCISPP,orSSCPhighlypreferred(currentorpursuing)• Excellentcommunicationskillsrequired• FamiliaritywithsecurityframeworkssuchasNIST,ISO27001,andHITRUSThighlydesired• Abilitytotravelupto20%

Location:WestChester,PA