<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Web Application Security Forum - Jobs</title>
        <description>Ever wanted to work as a chief hacker security evangelist? This is a place to post jobs or ask for work. Over time as I hear about job offers, we can consolidate them into this board.</description>
        <link>http://sla.ckers.org/forum/list.php?17</link>
        <lastBuildDate>Sun, 19 May 2013 02:12:08 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,51735,51735#msg-51735</guid>
            <title>Recruitment Firm in Delhi Ncr (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,51735,51735#msg-51735</link>
            <description><![CDATA[New Delhi<br />
http://kaiznhr.com<br />
job consultant in Delhi ncr - job consultant in India - Recruitment firm in Delhi ncr Recruitment firm in India - hr consultant in Delhi Ncr - hr consultant in India - recruitment agency in Delhi - Placement consultant in Delhi Ncr<br />
<br />
<br />
Kaiznhr is a leading consultant in delhi NCR with main focus on providing high quality HR services to the clients. The focused approach, continuous improvement to enhance operational and delivery standards, implementation of best practices and technology has helped Matrix HR in attaining the leading position in the HR Services. We currently employs more than 700 employees in leading MNCs, Corporate Houses, FMCG, Service Industries, KPO, Technologies, Engineering &amp; Manufacturing Companies.<br />
We see HR as a crucial part of any successful business. We believe that people are the single most important asset of any organisation and the role they play both internally and externally is extremely pivotal to the organisation’s success. Kaizn HR acts as a gateway to offer top of the line executive recruitment and selection services to companies.<br />
Central to our approach is the development of close and long term relationships with our clients. Our range of services includes consultation, executive search &amp; selection, executive training, performance management etc. We recruit across various industry segments for multinational corporates as well as for leading and emerging business houses. We have consultants who can quickly understand your business and provide cost-effective yet efficient solutions.<br />
<br />
Why Kaizn HR<br />
(1)	We provide the best staffing solutions ensuring quality, integrity and expertise.<br />
(2)	We are a talent-rich company. <br />
(3)	We enjoy the confidence of leading corporations.<br />
(4)	We offer multiple advantages.<br />
(5)	We have state of the art technologies for total solutions.<br />
(6)	Major costs savings in accounting &amp; overhead work.<br />
(7)	Trained, highly qualified staff readily available at short notices.<br />
(8)	Turn around time is very short depending upon the project.<br />
(9)	Cost effective Staffing Solutions.<br />
<br />
<br />
We deliver customized staffing solutions that make it easier for our clients to achieve their goals at a great value proposition with innovative technology, customized staffing solutions.<br />
We have a broad range of Staffing solutions that help employers to increase their productivity, ensure legal compliance, improve employee retention and minimize the recruitment cost. Our in-house recruitment team and network of recruiters across the country ensure that we meet your staffing  requirements on a long term basis.<br />
<br />
About the author<br />
Managing Director<br />
Kaizn HR<br />
<br />
http://kaiznhr.com/post_your_manpower.php]]></description>
            <dc:creator>rajeshdelhi</dc:creator>
            <category>Jobs</category>
            <pubDate>Tue, 30 Apr 2013 01:29:23 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,51499,51499#msg-51499</guid>
            <title>security,cryptography,reverse engineering,penetration testing (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,51499,51499#msg-51499</link>
            <description><![CDATA[I am loooking for a telecommute job in security,cryptography,reverse engineering,penetration testing.]]></description>
            <dc:creator>cufe</dc:creator>
            <category>Jobs</category>
            <pubDate>Sat, 22 Sep 2012 12:46:03 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,47220,47220#msg-47220</guid>
            <title>Email cracking service (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,47220,47220#msg-47220</link>
            <description><![CDATA[Hello!<br />
<br />
We`re presenting email cracking service.<br />
<br />
We provide:<br />
<br />
- Your full anonymity<br />
- Time of the cracking usually takes from 1 to 5 days (in some cases a bit longer)<br />
- The crack is done without changing the password, so the subject of the crack, continues using his/her mailbox as nothing has changed.<br />
- Without pre-payment, the charge is taken only after you get the evidences.<br />
- The evidences: screenshots, reading of the message that you sent to mailbox, also any evidence you may need on your proposal. We will send the password forward to you, if you pay with the protection code (maximum validity time).<br />
- We crack such mail domains as:<br />
Yahoo.com - $150<br />
Gmail.com - $100<br />
Hotmail.com	- $180<br />
Aol.com - $180<br />
Gmx.de - $180<br />
Russian emails: 	<br />
Mail.Ru - $80<br />
Yandex.ru - $80<br />
Rambler.ru - $80<br />
Other free email service - $120<br />
Any business email - $800 <br />
<br />
<br />
<br />
<br />
- You can order our service by:<br />
Email:support@hackmails.net<br />
Site:http://hackmails.net/]]></description>
            <dc:creator>hackmails</dc:creator>
            <category>Jobs</category>
            <pubDate>Thu, 19 Apr 2012 01:26:45 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,44542,44542#msg-44542</guid>
            <title>XSS on Giant website listed below.Anyone interested can PM me , (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,44542,44542#msg-44542</link>
            <description><![CDATA[Report it to the owner to get What they give.<br />
LIST:<br />
Posting msn vulnerability to microsoft will paste your name on their Hall of fame page. <br />
<br />
msn.com<br />
http://vaibs.comuv.com/msnxss.jpg<br />
http://vaibs.comuv.com/1.jpg<br />
<br />
Yahoo will appreciate and send you T-shirts :P <br />
yahoo.net<br />
http://vaibs.comuv.com/1.jpg<br />
<br />
Mozilla Pays 500$ on reporting.<br />
mozilla.org<br />
http://vaibs.comuv.com/mozilla.jpg<br />
<br />
Baidu too pays .<br />
baidu.com-&gt;http://vaibs.comuv.com/msn22.jpg<br />
<br />
I have 2 to 4 Xss on each listed website listed above.<br />
These were the top site i Xssed.<br />
You can request me for other sites too.<br />
I will find xss for on the sites ranking above 100 on alexa.<br />
Also I will disclose it publicly to all here for these sites. <br />
<br />
I sqlied msn.com<br />
Reporting to microsoft will put your name on Hall of fame like Google but they dont pay.<br />
http://vaibs.comuv.com/msn.png<br />
Guess my name :<br />
http://vaibs.comuv.com/MS.jpg]]></description>
            <dc:creator>Vaibs</dc:creator>
            <category>Jobs</category>
            <pubDate>Thu, 06 Sep 2012 01:30:28 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,37146,37146#msg-37146</guid>
            <title>Paid help! (1 reply)</title>
            <link>http://sla.ckers.org/forum/read.php?17,37146,37146#msg-37146</link>
            <description><![CDATA[Paid help! <br />
Hired to write game plug-in ($ 150,000)]]></description>
            <dc:creator>r0ots</dc:creator>
            <category>Jobs</category>
            <pubDate>Thu, 12 Jan 2012 16:37:25 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,37084,37084#msg-37084</guid>
            <title>15 sites to work, $1000~$5000 per site. (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,37084,37084#msg-37084</link>
            <description><![CDATA[Hi <br />
<br />
I'm lookin' for a black hat to co-operate.<br />
I'm runnin' casino, horse racin' and loan sites in ASIA.<br />
I want permanant or part-time partner who got skill to hack sites that I'm askin' to.<br />
Please reply me if u r interested in makin' money with ur skill.<br />
Let's talk 'bout details on messanger.<br />
GJHGGJHG@HOTMAIL.COM]]></description>
            <dc:creator>gjhg</dc:creator>
            <category>Jobs</category>
            <pubDate>Tue, 15 Nov 2011 04:51:13 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,36635,36635#msg-36635</guid>
            <title>APPLICATION SECURITY GURU REQUIRED - London UK - Up to £150k (1 reply)</title>
            <link>http://sla.ckers.org/forum/read.php?17,36635,36635#msg-36635</link>
            <description><![CDATA[Are you considered to be one of the best in Application Security?  If you believe so - and there are others that would support that - then I'd really like to hear from you if you are potentially interested in the job below:<br />
<br />
APPLICATION SECURITY PRINCIPAL up to GBP£150k in London, UK<br />
<br />
We are assisting a leading technology driven &amp; dependent client to find an Application Security Principal to oversee the security assessment of applications and development processes/technologies within this fast moving, E-commerce environment.<br />
<br />
You will need to be a and highly skilled Application Security expert who has a background in security and application development. Defines ongoing continuous improvements. Makes business recommendations and can present and articulate business cases for improvement/action at company-level.<br />
<br />
&quot; Large scale co-ordination of incident response and incident management.<br />
<br />
&quot; Sets technical direction for managing incidents.<br />
<br />
&quot; Responsible for maintaining integrity of process and approach, as well as controls, for the whole incident management process. Able to coordinate and manage major/highly sensitive investigations with potential for business wide impact/reputational damage. <br />
<br />
&quot; Regarded as an expert on forensics. Can use in-depth analysis methods (such as binary analysis) and can trace an attack footprint for all leading-edge attacks.<br />
<br />
&quot; Considered an expert in complex testing techniques across multiple domains.<br />
<br />
&quot; Designs test methodologies and improvements to the testing process. <br />
Candidates should be comfortable mentoring a team of security experts, analysing complex systems, able to identify application risks and threats, and recommend appropriate countermeasures and remediation.<br />
<br />
The role owns and operates the Secure Software Development Lifecycle, which involves interacting with development teams to ensure that production applications are implemented securely. Typical engagements involve conducting architectural/design reviews, code reviews, penetration tests, tracking new requirements and recommending improvements.<br />
<br />
Key Skills and Attributes - Essential:<br />
&quot; Expert understanding of the Web Application threats. <br />
&quot; Expert knowledge of software development security principles and best practices <br />
&quot; Strong analytical and diagnostic skills <br />
&quot; Expert knowledge of Java, JSP, Struts, .Net, Java Patterns, Spring, HTTP SQL <br />
&quot; Strong understanding of three tier web applications. <br />
&quot; 10+ years working in the software/security industry <br />
&quot; Considered an expert in one or more areas of application security <br />
&quot; Code review knowledge or development experience <br />
&quot; Ability to get the job done. <br />
<br />
If you are interested in an initial discussion then please contact me in the UK on 0044(0) 207 618 0965 or via email at emmah@propriusrecruitment.com<br />
<br />
You may still be considered if you require a VISA to work in the UK]]></description>
            <dc:creator>EmmaHunwick</dc:creator>
            <category>Jobs</category>
            <pubDate>Sat, 24 Dec 2011 10:21:58 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,34243,34243#msg-34243</guid>
            <title>Cigital is hiring pen-testers (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,34243,34243#msg-34243</link>
            <description><![CDATA[Folks,<br />
Cigital (www.cigital.com) is looking to hire few pen-testers in NoVa, NYC or west coast. If interested send me a mail.<br />
<br />
We are looking for motivated people, it's best if you have experience in the field, but the most important is to show interest.<br />
<br />
Even if the positions are mostly for web pen-testers, you might be doing many different things. In fact, I've done online games (MMORPG, etc.) pen-tests, mobile applications and few other cool stuff :)<br />
Also if you are interested in other area such as code review and architectural analysis, you'll be able to learn a lot with us, so don't hesitate!]]></description>
            <dc:creator>nEUrOO</dc:creator>
            <category>Jobs</category>
            <pubDate>Mon, 20 Aug 2012 10:20:55 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,34033,34033#msg-34033</guid>
            <title>Jr. Application Security Engineer needed in the DC area (1 reply)</title>
            <link>http://sla.ckers.org/forum/read.php?17,34033,34033#msg-34033</link>
            <description><![CDATA[Target Labs is searching, on behalf of its client, for a Junior Application Security Engineer who is interested in working in the DC area.<br />
<br />
Client: TBD<br />
Location: Washington, DC Metro. area <br />
Position: Jr. Application Security Engineer<br />
Duration: 6 months to start (possibly contract-to-permanent if the right ‘fit’)  <br />
Pay rate: TBD<br />
<br />
In sort: If you have a few years of development and a few years of secrutiy, we should talk!<br />
<br />
Formal position description:<br />
<br />
Jr. Application Security<br />
The Jr. Application Security Engineer (Jr. ASE) is responsible for helping design security for all aspects of the application life cycle. The ASE ensures security risks of applications are known and evaluated for significance and effective security products and techniques are identified, implemented, and applied. Position serves as subject matter expert on production security technologies.<br />
 <br />
Essential Job Functions: <br />
•	Researches new information security technologies (in the areas of application and application infrastructure components).<br />
•	 Participates in teams with security SMEs, in all application lifecycle phases, including: requirements gathering, architecture development, product/service selection and procurement, functional &amp; QA testing, detailed technical design, technology infrastructure implementation and deployment, migration from existing services, operational process and procedure documentation, operations staff training)<br />
•	Advises and consults internal clients on appropriate application of existing security services to solve problems or enable new business opportunities.<br />
•	Recommends, customizes, implements, documents, and transitions to operations, reusable technical security service components including: application level intrusion detection systems, authentication systems, authorization systems, audit trail management systems, cryptographic systems, and others as defined by management.<br />
•	Researches and implements new security technologies as point solutions for Technology initiatives unqualified under reusable enterprise security services. Based on accumulated knowledge of project-specific security implementations, recommend new security service development ideas to the Security Technology R&amp;D process.<br />
•	Assess applications to identify security risks using appropriate automated tools and other manual techniques. Provide viable recommendations for minimizing or eliminating identified security risks. Advise and assist with implementing recommendations where needed.<br />
•	Work with Application team and help them in closing out security issues in their application.<br />
•	Perform other duties and responsibilities as assigned.<br />
•	 <br />
Education/Experience Requirements:<br />
 <br />
•	Bachelor’s of Science in Computer Science or equivalent work experience plus CISSP certification or obtainment of within 18 months of start date and a minimum of six years experience in applications engineering focusing on the delivery of secure systems.<br />
•	Experience developing in a some of the following languages: VBA, ASP, ASP.NET, Perl, C#, Java, XML, Python, Ajax, Google GWT or Yahoo YUI.<br />
•	Inner workings and security aspects of variety of Applications such as: Servers (Weblogic), Web Servers (Apache, IIS), Database Servers (Oracle, MS SQL).<br />
•	Strong knowledge of Microsoft Office products especially MS Excel, MS Word and Visio is desired.<br />
•	Preferred that the candidate have hands-on experience performing application security assessments using business-class assessment tools including static code analyzers                (e.g. Fortify, Ounce), web vulnerability analyzers (e.g. AppScan, WebInspect), platform vulnerability scanners (e.g. Qualys), Nessus, as well as manual techniques for evaluating logic flaws. Manual code reviews would be nice.<br />
•	Excellent technical writing, documentation development, process mapping, and visual communication skills.<br />
•	Excellent interpersonal and verbal communication skills.<br />
•	Strong knowledge of Microsoft Office products especially MS Excel, MS Word and Visio is desired.<br />
<br />
If you are interested in discussing these positions, please reply to this message with a convenient time and number to call for a brief conversation about what Target Labs can do for you..  Please attach a copy of your resume, in Word, to your reply.  <br />
<br />
Please send me an invitation to link on LinkedIn:  http://www.linkedin.com/in/kellybcollier<br />
<br />
Again, please also consider friends and colleagues who may benefit from receiving this announcement.<br />
<br />
Thank you for your interest in Target Labs, I look forward to speaking with you soon.<br />
<br />
Regards,<br />
<br />
Kelly Collier<br />
Account Manager<br />
Target Labs, Inc.<br />
Specialized IT Consulting Services<br />
Direct: 202-422-8766 | Fax: 703-891-9091 <br />
www.targetlabs.net<br />
The Green IT Services Firm,<br />
100% Wind Powered, Carbon Free IT Professionals]]></description>
            <dc:creator>kbrydc</dc:creator>
            <category>Jobs</category>
            <pubDate>Tue, 06 Apr 2010 04:18:27 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,34032,34032#msg-34032</guid>
            <title>Sr. Security Engingeer needed in the DC area (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,34032,34032#msg-34032</link>
            <description><![CDATA[Target Labs, Inc. is searching, on behalf of its client, for two Security Engineers who are interested in positions in the Washington, DC Metro. area.  If you are not interested in these positions, please consider friends and colleagues who may benefit from seeing this announcement.<br />
 <br />
&quot;One of the Top 100 Companies&quot; Forbes <br />
 <br />
Client: TBD<br />
Location: DC Metro. area<br />
Position: Sr. IT Security Engineer<br />
Duration: 6 months to start (possibly contract-to-permanent if the right ‘fit’)  <br />
Pay rate: TBD<br />
<br />
CISSP’s preferred for both positions<br />
<br />
Sr. Security Engineer:<br />
AV &amp; Malware Management (McAfee ePO)<br />
•	Vulnerability Management &amp; Pen test (Qualys). VM Program management experience.<br />
•	IDS tuning &amp; design (ISS Proventia)<br />
•	Written Skills<br />
•	Ability to work with people<br />
•	Detecting security vulnerabilities and issues (MS/Oracle/Solaris)<br />
•	DLP Data@ Rest, DLP Data@motion, Data@EndPoint<br />
•	Security Infr Architecture &amp; Design (need examples)<br />
•	Exposure to different environments (Virtualization, Unix, Windows, Linux, netezza, greenplum, SANs, FCoE)<br />
•	SME on VMWare/Unix/Linux (vSphere)<br />
•	SEM: Correlation, Building a program (enVISION)<br />
•	Policy (27001, 800-53)  &amp; Standards (CIS, NIST, SCAP)<br />
•	Qualys and McAfee ePO essential<br />
<br />
Jr. Application Security<br />
The Jr. Application Security Engineer (Jr. ASE) is responsible for helping design security for all aspects of the application life cycle. The ASE ensures security risks of applications are known and evaluated for significance and effective security products and techniques are identified, implemented, and applied. Position serves as subject matter expert on production security technologies.<br />
 <br />
Essential Job Functions: <br />
•	Researches new information security technologies (in the areas of application and application infrastructure components).<br />
•	Participates in teams with security SMEs, in all application lifecycle phases, including: requirements gathering, architecture development, product/service selection and procurement, functional &amp; QA testing, detailed technical design, technology infrastructure implementation and deployment, migration from existing services, operational process and procedure documentation, operations staff training)<br />
•	Advises and consults internal clients on appropriate application of existing security services to solve problems or enable new business opportunities.<br />
•	Recommends, customizes, implements, documents, and transitions to operations, reusable technical security service components including: application level intrusion detection systems, authentication systems, authorization systems, audit trail management systems, cryptographic systems, and others as defined by management.<br />
•	Researches and implements new security technologies as point solutions for Technology initiatives unqualified under reusable enterprise security services. Based on accumulated knowledge of project-specific security implementations, recommend new security service development ideas to the Security Technology R&amp;D process.<br />
•	Assess applications to identify security risks using appropriate automated tools and other manual techniques. Provide viable recommendations for minimizing or eliminating identified security risks. Advise and assist with implementing recommendations where needed.<br />
•	Work with Application team and help them in closing out security issues in their application.<br />
•	Perform other duties and responsibilities as assigned.<br />
 <br />
Education/Experience Requirements:<br />
 <br />
•	Bachelor’s of Science in Computer Science or equivalent work experience plus CISSP certification or obtainment of within 18 months of start date and a minimum of six years experience in applications engineering focusing on the delivery of secure systems.<br />
•	Development languages: VBA, ASP, ASP.NET, Perl, C#, Java, XML, Python, Ajax, Google GWT or Yahoo YUI.<br />
•	Inner workings and security aspects of variety of Application Servers (Weblogic), Web Servers (Apache, IIS), Database Servers (Oracle, MS SQL).<br />
•	Strong knowledge of Microsoft Office products especially MS Excel, MS Word and Visio is desired.<br />
•	Preferred that the candidate have hands-on experience performing application security assessments using business-class assessment tools including static code analyzers (e.g. Fortify , Ounce), web vulnerability analyzers (e.g. AppScan, WebInspect), platform vulnerability scanners (e.g. Qualys), Nessus, as well as manual techniques for evaluating logic flaws. Manual code reviews would be nice.<br />
•	Excellent technical writing, documentation development, process mapping, and visual communication skills.<br />
•	Excellent interpersonal and verbal communication skills.<br />
•	Strong knowledge of Microsoft Office products especially MS Excel, MS Word and Visio is desired.<br />
<br />
If you are interested in discussing these positions, please send resume to Kellybcollier@gmail.com or, if you would prefer: kelly.collier@targetlabs.com, along with a telephone-number and convenient time for me to call for a brief conversation about what Target Labs can do for you.  Please attach a copy of your resume, in Word, to your reply.  <br />
<br />
Please send me an invitation to link on LinkedIn:  http://www.linkedin.com/in/kellybcollier<br />
<br />
Thank you for your interest in Target Labs, I look forward to speaking with you soon.]]></description>
            <dc:creator>kbrydc</dc:creator>
            <category>Jobs</category>
            <pubDate>Fri, 02 Apr 2010 04:10:34 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,33600,33600#msg-33600</guid>
            <title>QA Engineer - HP Application Security Center (HP Software) Alpharetta, GA (Pipeline)-392594 (1 reply)</title>
            <link>http://sla.ckers.org/forum/read.php?17,33600,33600#msg-33600</link>
            <description><![CDATA[Job Description<br />
The HP Application Security Center group (HP ASC) is in search of a full-time Quality Assurance Engineer who is available to begin immediately.  HP ASC provides software and services to help enterprises protect against the loss of confidential data through the web application layer.  The company's flagship product line, WebInspect, assesses the security of an organization's applications and web services, the most vulnerable yet least secure IT infrastructure component.  Software developers, quality assurance professionals, corporate security auditors and security practitioners use WebInspect products throughout the application lifecycle to identify security vulnerabilities that would otherwise go undetected by traditional measures such as automated application testing tools, network firewalls, intrusion detection systems, or manual code reviews.<br />
 <br />
The ideal candidate for this position is someone who has a strong web application security background and an interest in performing technical quality assurance on commercial grade applications, and component and network-based enterprise applications.  A solid knowledge of HTTP and HTTPS protocols is required. The ideal candidate will have a web application development background. The position will include building test cases, configuring test environments, tracking defects, and performing regression testing in an independent environment. The ideal candidate must thrive in a fast-paced, hard-working development team and have a passion for keeping up to date on the latest technologies.  Mercury test tool experience is a plus.<br />
<br />
<br />
Qualifications<br />
-          Internet security background (including Web application security). <br />
-          Experience With Web Technologies (Javascript, HTML, PHP, ASP, JSP, Ruby, Python,XML, Flash, Silverlight …)<br />
-          Solid knowledge of HTTP and HTTPS protocols.<br />
-          Experience with SQL Server and/or SQL Express.<br />
-          Experience providing quality assurance in a Microsoft environment (.NET, Windows 2003, Windows XP, IIS.) is a plus.<br />
-          Experience using the Mercury Interactive test tools is a plus.<br />
-          Strong communication skills, both written and verbal.<br />
-          Independent, self-motivated worker requiring little supervision.<br />
-          Strong problem solving skills.<br />
-          Degree in computer science, computer information systems or related field of study.<br />
<br />
<br />
To apply online, visit https://hp.taleo.net/careersection/2/jobdetail.ftl?lang=en&amp;job=1909227<br />
Job Code: 392594<br />
<br />
<br />
<br />
*Disclaimer: Taleo shall not be liable for the content or any errors or omissions in the information provided in the Comments section, and conclusions drawn from such information are the responsibility of the user.]]></description>
            <dc:creator>cmcelvy</dc:creator>
            <category>Jobs</category>
            <pubDate>Thu, 19 Jan 2012 05:32:00 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,33591,33591#msg-33591</guid>
            <title>TCP/IP (3 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,33591,33591#msg-33591</link>
            <description><![CDATA[how to setup TCP/IP of a CCTV Recorder?]]></description>
            <dc:creator>vanflyhigh</dc:creator>
            <category>Jobs</category>
            <pubDate>Wed, 24 Feb 2010 16:44:30 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,33288,33288#msg-33288</guid>
            <title>Ollydbg/IDA PRO *.dll for game hack analysys JOB (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,33288,33288#msg-33288</link>
            <description><![CDATA[It's eimple.<br />
Not that hard.<br />
<br />
First one might take some time.<br />
However, after that, it might be easier than first one.<br />
<br />
Just wanna get some analysis report how they work.<br />
<br />
Ollydbg screen capture and explanation should be enough.<br />
<br />
just part time job.<br />
work from home<br />
thanks.]]></description>
            <dc:creator>tigerclavv</dc:creator>
            <category>Jobs</category>
            <pubDate>Fri, 05 Feb 2010 14:22:56 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,33029,33029#msg-33029</guid>
            <title>need a quote for vps service (1 reply)</title>
            <link>http://sla.ckers.org/forum/read.php?17,33029,33029#msg-33029</link>
            <description><![CDATA[need vps for windows2003, need 1-3 months. quote to e-mail: log8656@gmail.com<br />
or add me on log8656@hotmail.com]]></description>
            <dc:creator>jlw</dc:creator>
            <category>Jobs</category>
            <pubDate>Thu, 14 Jan 2010 07:35:01 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,33028,33028#msg-33028</guid>
            <title>looking for a ddos tester (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,33028,33028#msg-33028</link>
            <description><![CDATA[wrok at home, attrictive bornes. if u interest, pm... or add me on msn log8656@hotmail.com]]></description>
            <dc:creator>jlw</dc:creator>
            <category>Jobs</category>
            <pubDate>Thu, 14 Jan 2010 06:21:51 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,32962,32962#msg-32962</guid>
            <title>Sr. Application Security Engineer Opportunity (Santa Clara, CA) (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,32962,32962#msg-32962</link>
            <description><![CDATA[Sr. Application Security Engineer - Build/Enhance our Application Security Controls and Processes<br />
<br />
For the application security focused software engineer who enjoys a wide variety of work and owning projects from start to finish, this Sr. Applications Security Engineer role with LiveOps is a great fit.  We are a leader in the outsourced contact center market providing both the technology (contact center in the cloud) and virtual workforce that enables companies to scale their contact center support as needed.  With us, you’ll play the vital role of ensuring that not only our applications, but also our products, meet the highest security standards.  This is a high profile position reporting directly to the company’s CISO, and you will enjoy working with the latest technologies and seeing your ideas quickly implemented as we use Scrum methodology.  Bring your passion for security and best practice security mindset to LiveOps and thrive in our team environment.<br />
<br />
Based out of our Santa Clara, CA headquarters, your primary mission will be to ensure the security of LiveOps applications and products by designing secure products and architectures, performing secure code reviews, leading penetration testing and vulnerability assessments, helping define secure coding standards, and more.  Current and superior Perl and Java development skills are crucial to this role, as well as having strong and focused application security experience including strong knowledge of security best practices.  Experience with Ruby scripting/programming and Scrum would also be highly beneficial in your coding responsibilities although these are not required.  As the owner of applications security for our company you will be responsible for handling projects from the initial information gathering stage, through to implementation and ongoing monitoring.  One of your initial projects will be to build our authentication systems so any previous experience you have with projects involving the authentication of users would be highly valuable.  You will be working with our engineering, development and product teams on technical security issues and documenting your work for future reference thus your ability to communicate effectively and strong documentation skills will be important.  If you are excited by the prospect of driving on major security projects, working with interesting technology, and growing your career with an industry leader, then apply today and join a great team!<br />
<br />
About LiveOps:<br />
<br />
LiveOps is revolutionizing the world of work, starting with the virtual call center. Our company has a world-class management team that includes leaders from Genesys, eBay, Salesforce.com, Siebel, and Tellme - and an amazing and enthusiastic engineering team that includes original founders and engineers from Netscape/Mosaic, AOL, eBay and Microsoft. We have built the most advanced on-demand call center platform anywhere to help companies make their existing call centers more virtual. We've not only established the future of distributed work, we've made it a reality today.<br />
<br />
A privately held company backed by Menlo Ventures and Benchmark Capital, LiveOps has been consistently growing revenue rapidly and is led by one of the top visionaries in Silicon Valley Maynard Webb, the former COO of eBay. Come join one of the most exciting companies in the Bay Area and be part of a world class team building the next eBay and Salesforce.com.<br />
<br />
We are financially and strategically backed by Menlo Ventures, Benchmark and CMEA. We have been profitable since 2006 with a solid financial track record, and on a sound growth path to becoming a major player in the contact center space.<br />
<br />
Related Keywords:<br />
    security analyst, security consultant, enterprise security, application security, source code analysis, runtime protection, scope, scoping, application security product, vulnerability, source code audit, build environment, software build, Java, Ruby, Perl, Unix, Linux, CISSP, CISA, CPP, authentication system, authenticate, clients, secure code, enterprise, Saas, best practices<br />
<br />
To apply for this position or refer someone you know, please use our online interview system managed by Accolo.<br />
<br />
Apply Online Now: http://hiring.accolo.com/job.htm?id=233921496<br />
<br />
Once you have completed the interview, your information will be forwarded to the hiring authority for decisions on next steps.]]></description>
            <dc:creator>jsaunders</dc:creator>
            <category>Jobs</category>
            <pubDate>Mon, 11 Jan 2010 15:27:36 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,32865,32865#msg-32865</guid>
            <title>Quote needed (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,32865,32865#msg-32865</link>
            <description><![CDATA[Trying to create a global flowchart for first time VPS startups for programmers at my plant. Need quote for someone to just compile a list of steps to secure a linux distro. So far, here is what I got. If you can improve on it, please tell price.<br />
<br />
yum upgrade<br />
add new user<br />
remove root access from ssh<br />
installed apf firewall<br />
installed brute force detection<br />
install rkhunter<br />
install mod_security<br />
move tmp to different partition, noexec nosuid<br />
disable non-root access to unsafe binaries (no user can run wget)]]></description>
            <dc:creator>lukethedrifter</dc:creator>
            <category>Jobs</category>
            <pubDate>Thu, 31 Dec 2009 23:59:12 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,31767,31767#msg-31767</guid>
            <title>good job if you want (6 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,31767,31767#msg-31767</link>
            <description><![CDATA[Hi, <br />
<br />
I am looking for investigators/ hackers for projects on the Internet. <br />
<br />
Looking for people who are able to hack/ track and investigate certain websites, selling counterfeit/ infringing products online and able to reveal evidence/ information on the person(s)/ group behind the specific websites. <br />
<br />
Able to work from home. <br />
<br />
No special skills required, as long as you can track them down ;-) <br />
<br />
Please email me if you are interested, looking for people asap! <br />
<br />
email at: hackmuzi@hotmail.com<br />
<br />
Thanks. <br />
<br />
muzi]]></description>
            <dc:creator>hackmuzi</dc:creator>
            <category>Jobs</category>
            <pubDate>Wed, 04 Nov 2009 14:48:42 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,31422,31422#msg-31422</guid>
            <title>Product Security Engineer (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,31422,31422#msg-31422</link>
            <description><![CDATA[Salesforce.com has positions available for qualified software security professionals.  Email rfly (at) salesforce [dot] com if you are interested.<br />
<br />
This role will provide security support for salesforce.com's cloud computing service. You'll work closely with the technology organization to educate our team on secure application development and help in creating innovative security solutions for our product. Additionally, you will play a key role providing both strategic and tactical security advice and help in developing technology solutions which promote securing our customer's data and users.<br />
<br />
Responsibilities include identifying and understanding the development practices, networks and infrastructure that make salesforce.com successful and then recommending and/or building solutions and mitigations to help resolve risks to that success. Guide the Salesforce.com technology organization's security by participating in design reviews, Threat Modeling, and in depth security penetration testing of our code and systems. These responsibilities extend to providing input on application design, secure coding practices, log forensics, log design and application code security. The ideal candidate will have in-depth experience protecting against web and web services security vulnerabilities including cross-site scripting, sql injection, DoS attacks, XML/SOAP and API attacks, email security flaws and more. Also included is performing cutting edge research on new attacks, writing white papers and presenting on those findings to internal audiences. In addition this individual will hold responsibilities for evaluating or building application security tools for internal consumption and driving usage of these tools. <br />
<br />
Job Requirements:	<br />
BS degree or equivalent experience<br />
<br />
Minimum of 5 years working in application security<br />
<br />
Ability to demonstrate strategic thinking<br />
<br />
Extensive problem solving and analytical skills<br />
<br />
Experience working in 24x7xforever support for security in production systems<br />
<br />
Extensive knowledge of the OWASP Top 10 and CWE Top 25<br />
<br />
Extensive programming and application development experience in multiple languages such as Java, C, and scripting languages]]></description>
            <dc:creator>rfly</dc:creator>
            <category>Jobs</category>
            <pubDate>Mon, 14 Sep 2009 18:01:29 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,30199,30199#msg-30199</guid>
            <title>h (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,30199,30199#msg-30199</link>
            <description><![CDATA[i]]></description>
            <dc:creator>Anonymous User</dc:creator>
            <category>Jobs</category>
            <pubDate>Fri, 12 Feb 2010 23:34:40 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,29755,29755#msg-29755</guid>
            <title>Professionals are seeking for competent hackers for work in a team (1 reply)</title>
            <link>http://sla.ckers.org/forum/read.php?17,29755,29755#msg-29755</link>
            <description><![CDATA[Professionals are seeking for competent hackers for work in a team/ <br />
If you consider yourself to be a competent worker, if you are sure of your abilities or you just want to try yourself out we are always glad to talk to you. <br />
<br />
What is aquired:<br />
 - Breaking of European and American(USA) Internet-shops<br />
 - Leaking of DB<br />
<br />
What you will get:<br />
 - Good work conditions<br />
 - High salary(Good payments)<br />
 - Serious partners<br />
<br />
All additional information is in pm. <br />
<br />
If you work hard and with a serious approach, we garantee timely payments. <br />
If you are interested in this topic, leave your contacts in pm. <br />
I'll contact and talk to everyone.]]></description>
            <dc:creator>dht</dc:creator>
            <category>Jobs</category>
            <pubDate>Sun, 09 Aug 2009 13:41:32 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,28876,28876#msg-28876</guid>
            <title>Network Reverse Eng./Forensics position in NoVa - clearance required (4 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,28876,28876#msg-28876</link>
            <description><![CDATA[The hiring company specializes in instant intelligence across the enterprise, enabling right-time responses to threats or opportunities. With their solutions, data is processed and analyzed as it is received from all incoming sources, reducing the time required To Detect and Respond - to seize hidden opportunities and eliminate imminent and unforeseen risks.<br />
<br />
Software Developer (III) position (Network Reverse Eng./Forensics)<br />
<br />
* Clearance requirements: TS/SCI with lifestyle or full-scope polygraph required (Must be current)<br />
* Applied knowledge/experience performing C/C++ programming <br />
* Coding experience on Intel and AMD platforms. <br />
* Understanding of end-to-end software development &amp; delivery cycle, documentation development. <br />
* Computer/network hacker techniques/methods to include application and mitigation techniques. <br />
* Experience using intrusion detection programs, firewalls and standard operating systems features such as Kaspersky,Norton/Symantec,McAFee, Zone Alarm,and AVG-AV. <br />
* Applied knowledge of Hardware/Firmware reverse engineering techniques. <br />
* Experience in network programming and supporting network software. <br />
* Expertise in network communication protocols. <br />
* Applied knowledge/experience with Network Security Appliances (e.g. Snort, Bluecoat, Cisco ASA, etc). <br />
* Familiarity with Cisco IOS and JUNOS. <br />
* Compensation: BOM (Based On Merit) <br />
<br />
The Software Developer (III) position (Network Reverse Eng. / Forensics) will create customized low-level solutions at government location located in Northern Virginia. This position requires a strong background in networks and network security.<br />
<br />
If you are not interested in this position...can you refer me to a person who might be interested? I would be glad to pay you for a referral fee, if they get hired. Please let me know if you are interested in hearing more.]]></description>
            <dc:creator>CPI</dc:creator>
            <category>Jobs</category>
            <pubDate>Thu, 18 Jun 2009 09:26:04 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,28875,28875#msg-28875</guid>
            <title>NY, NJ, MD, DC, VA, GA, IL - work along side the brightest (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,28875,28875#msg-28875</link>
            <description><![CDATA[Software Security Consultant needed immediately<br />
<br />
This hiring company has positions available for graduating college students, graduate students and experienced hires. Work with and be part of a passionate and energetic team that is backed by a world-class experts from academia and industry. Requires working closely with company's customers.<br />
<br />
Responsibilities of a Software Security Consultant vary but are not limited to: <br />
<br />
    * Scanning customer source code, auditing results with development and/or security teams and offering plans for remediation of vulnerabilities.<br />
    * Installing and configuring company products onsite for customers<br />
    * Communicating technical application security concepts to customer staff including developers, architects, and managers.<br />
    * Training customer staff on application security and company's products.<br />
    * Assessing and scoping of customer's application security needs.<br />
    * Contributing to project planning and other project deliverables.<br />
    * Customizing the implementation of companies production and test products.<br />
    * Collaborating with Product Management and Engineering to enhance products.<br />
    * Represent company's technical, business, and professional values to customers, partners, and peers.<br />
    * Work is conducted mostly at customer sites; extensive travel is required. <br />
<br />
Technical Qualifications<br />
<br />
    * The ideal candidate should have: A Technical Bachelor's degree is required.<br />
    * 5+ years experience in role of software or security consulting.<br />
    * 5+ years experience in software development using Java, Microsoft .NET (C# or VB), or C/C++.<br />
    * Experience using build tools (e.g. ant, make, maven, msbuild, nant, etc.).<br />
    * Experience in developing and/or deploying web applications is strongly desired.<br />
    * Experience with multiple operating systems is strongly desired.<br />
    * Fundamental understanding of software, computer, and network architectures.<br />
    * Experience in the enterprise security or application security is a plus.<br />
    * CISSP, CISA, CCP MCP/MCSE and SANS certifications are a plus. <br />
<br />
Characteristics<br />
<br />
    * The ideal candidate will: Be highly motivated, competitive, entrepreneurial and attracted to challenging opportunities.<br />
    * Have demonstrated the ability to work in a fast-paced environment where organizational skills are essential and will have strong problem solving, analytical, interpersonal, and ownership skills.<br />
    * Possess excellent collaboration skills with a wide variety of internal team members.<br />
    * Be an intelligent, self-starting, self-confident individual with integrity and accountability.<br />
    * Possess strong written and verbal communication skills as well as presentation skills.<br />
    * Qualify for a security clearance. <br />
PM me if interested.]]></description>
            <dc:creator>Guthrie</dc:creator>
            <category>Jobs</category>
            <pubDate>Wed, 17 Jun 2009 14:48:30 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,28556,28556#msg-28556</guid>
            <title>security expert (JOB) (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,28556,28556#msg-28556</link>
            <description><![CDATA[Traduci testo o pagina web<br />
	<br />
hi,<br />
important Italian Company looking for expert security about operating system, server and security websites (like hacker).<br />
<br />
E 'offered work as a freelancer or company under contract.<br />
<br />
For information,<br />
<br />
send an email to: b.federico @ gmail.com<br />
also attached your resume<br />
<br />
<br />
otherwise contact me on<br />
<br />
msn: b.federico @ gmail.com<br />
skype: federico.bucchi]]></description>
            <dc:creator>federicobucchi</dc:creator>
            <category>Jobs</category>
            <pubDate>Mon, 04 Jan 2010 12:56:30 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,28550,28550#msg-28550</guid>
            <title>Hack for the Government! (3 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,28550,28550#msg-28550</link>
            <description><![CDATA[Huge Government Account in the Kansas City area (or Denver area) has 2 immediate positions available for CISSP's.  Must have experience with developing or redefining security standards for database &amp; application development.  <br />
<br />
Requirements - CISSP.  CEH &amp; CASS preferred.  <br />
<br />
These are Direct Hire positions that need to be filled immediately.  They will not pay for relocation.  Excellent benefits are available!<br />
<br />
Email me at lwible@adaptivesg.com for details - please include your resume in a MS Word Doc.]]></description>
            <dc:creator>lwible</dc:creator>
            <category>Jobs</category>
            <pubDate>Sun, 07 Jun 2009 10:32:12 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,28483,28483#msg-28483</guid>
            <title>IDS Analyst- Swing Shift, Arlington, VA (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,28483,28483#msg-28483</link>
            <description><![CDATA[Apptis is an innovative, forward-thinking information technology services and solutions provider.  We take great pride in supplying, designing, and supporting technology solutions to the government and commercial marketplace. Our steadfast goal is to deliver inspired solutions that are agile, cost effective, and reliable. To learn more about working at Apptis, visit our Web site at www.apptis.com.<br />
<br />
IDS Analyst- Swing Shift 3-11 and an average of 1 weekend per month.<br />
Must be able to obtain a DOD Secret clearance. Must have a good knowledge of principles and techniques applied in securing operating systems with proficiency specifically in both UNIX and Windows. Must have some experience in shell scripting and the use of regular expressions for parsing through data for pertinent information relating to security events.<br />
<br />
Must have a good understanding of network operations, installation and network monitoring procedures. Experience with various types of Intrusion Detection Systems (IDS) and knowledge of best practices regarding IDS architecture and signature development. Knowledge of CERT procedures and NOC operations.<br />
<br />
Participates as a member of the Enterprise IDS team and receives direction from the team leader.<br />
<br />
All Operating System installations, hardening, administration, upgrades and patching<br />
<br />
COTS and open-source IDS installations, administration, upgrades and patching<br />
<br />
Ensuring IDS uptime, availability and the integrity of the IDS systems<br />
<br />
Documenting processes and procedures of all infrastructure operations <br />
An in-depth knowledge of TCP/IP<br />
<br />
Desirable Qualifications:<br />
<br />
Experience with Security Information Management Solutions<br />
<br />
Must also be able to:<br />
<br />
Demonstrate an ability to work independently with minimal supervision<br />
<br />
Demonstrate an ability to handle concurrent projects and assignments<br />
<br />
Continue to expand area of knowledge in Network Security technologies and best practices<br />
<br />
Focus under pressure and respond appropriately to critical situations or incidents <br />
<br />
<br />
For immediate consideration, please submit your resume to our career page at: www.apptis.com/careers.sec. - Reference req # VA VA 290406. U.S. Citizenship is required for most positions.<br />
<br />
An Equal Opportunity Employer. M/F/D/V.]]></description>
            <dc:creator>becmilten</dc:creator>
            <category>Jobs</category>
            <pubDate>Tue, 02 Jun 2009 12:36:11 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,28136,28136#msg-28136</guid>
            <title>Senior Security Engineer @ WEB 2.0 company in London (UK) (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,28136,28136#msg-28136</link>
            <description><![CDATA[Hello ~ <br />
<br />
I am working with a WEB 2.0 company in London (UK) that are looking to recruit a permanent senior security engineer that has basic experience of *nix from a security perspective, xss and sql injection.<br />
<br />
If anybody might be interested in discussing with me, please drop me a line using james@security.camalyn.org<br />
<br />
Thanks, JAMES]]></description>
            <dc:creator>camalyn</dc:creator>
            <category>Jobs</category>
            <pubDate>Thu, 28 May 2009 12:19:11 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,28003,28003#msg-28003</guid>
            <title>Video Algorithm Architect - Toronto, Canada (3 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,28003,28003#msg-28003</link>
            <description><![CDATA[If your interest is cutting edge video algorithms and if you want to see <br />
your invention implemented, this is a fantastic opportunity for you.<br />
<br />
Job Description:<br />
Working in a team of video algorithm experts, you will build next generation <br />
implementation of cutting-edge video compression codecs.  You will develop <br />
new methods to improve video compression in an existing line of shipping <br />
ASICs as well as provide guidance on further ASIC implementations for future <br />
products.<br />
<br />
Requirements:<br />
As a successful candidate, you will have a strong mathematical and <br />
algorithmic background and be comfortable with digital video concepts as <br />
well meet as the following requirements:<br />
<br />
MSc or PhD in Computer Engineering or Computer Science or equivalent<br />
Strong interest in video processing<br />
5+ years experience in video compression algorithms<br />
 In-depth understanding of MPEG2 and MPEG4 video algorithms<br />
<br />
To Apply:<br />
If you are interested in applying for this position, please email your <br />
resume to recruiting@klanderson.com]]></description>
            <dc:creator>khristine</dc:creator>
            <category>Jobs</category>
            <pubDate>Mon, 23 Nov 2009 22:39:26 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,27528,27528#msg-27528</guid>
            <title>Rapid7 Info Sec Engineer - El Segundo, CA (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,27528,27528#msg-27528</link>
            <description><![CDATA[Hi, I lead the Vuln R&amp;D team at Rapid7 and we have a job opening (see below). No going through recruiters, no battling with HR, you just contact me directly. Simple !<br />
<br />
Thanks,<br />
-marc<br />
<br />
<br />
Job Title: Info Sec Engineer<br />
Position based in: El Segundo, CA<br />
<br />
Rapid7 provides network security software and related research. We develop NeXpose, a unified vulnerability management solution that is primarily sold to large companies and government agencies as a standalone Linux/Windows application or as a pre-configured appliance.<br />
<br />
The Vulnerability R&amp;D Team is responsible for the core feature of NeXpose: its ability to scan hosts and networks to remotely detect all kinds of security vulnerabilities, e.g.: remote arbitrary code execution, weak SSH password, unapplied security update, world-readable /etc/shadow, authentication bypass, infection by well-known backdoor, predictable TCP ISN, insecure configuration of a network server, XSS on a web page, obsolete operating system version, SQL injection, directory traversal in an FTP server, JSP source code disclosure, memory exhaustion denial of service in an RPC service, unused built-in account not disabled, privilege escalation, etc.<br />
<br />
Rapid7 is looking for a Software Engineer to become part of this Vulnerability R&amp;D Team. Requirements:<br />
<br />
 o Minimum 2+ years of professional software development experience, preferably in an IT security field.<br />
 o Demonstrated interests in the computer and network security field, low-level and internals aspects of technologies, and vulnerability research and exploitation.  <br />
 o Excellent coding skills in Java, C, or C++.<br />
 o Perl, Python, shell scripting, Jess (Java expert system shell) a plus.<br />
 o Good foundation in networking, have developed networking code, knowledge of the design of at least some common network protocols (IP, TCP, UDP, ICMP, HTTP, FTP, etc). <br />
 o Experience in a Unix/Linux environment.<br />
 o Ability to understand technical subjects and technologies you might not be familiar with.<br />
 o Experience in working in a team of 5-10 developers on a medium-to- large-scale project (100k-1M lines of code) project a plus.<br />
 o Skills in resource organization, project/task prioritization and schedule development.<br />
<br />
Please contact Marc Bevand &lt;marc_bevand at rapid7 dot com&gt;]]></description>
            <dc:creator>mrb</dc:creator>
            <category>Jobs</category>
            <pubDate>Wed, 08 Apr 2009 12:36:55 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,26725,26725#msg-26725</guid>
            <title>Looking for Security Associate Consultants (3 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,26725,26725#msg-26725</link>
            <description><![CDATA[Hi, we are looking for Security Associate Consultants at Cigital. This is an entry level position, mostly for fresh out of college students. Cigital is a Software Security Consulting firm. Please check out our website at www.cigital.com.<br />
if you are interested, please contact me at timam@cigital.com<br />
Following is the job description: <br />
<br />
<br />
At Cigital, people are our biggest asset.  We select our people carefully; we train them, mentor them and enable them to succeed with our customers.  Cigital offers a competitive benefits and salary package with an opportunity to work in an exciting, fast-paced environment.<br />
<br />
Associate Consultant Responsibilities<br />
The Associate Consultant is responsible for applying software engineering skills to assist teams in the completion of client engagements.  Typical tasks span activities in the software development lifecycle including requirements analysis, development, testing, debugging, and analysis of software.  Associates will employ sound communication skills interacting with clients to understand problems and provide solutions.  Associates will often be responsible for writing analysis results in sections of final reports as part of deliverables to clients.<br />
<br />
Cigital Associate Consultants Apprenticeship Program<br />
As the entry role into our organization, Associate Consultants enroll into a fast paced apprenticeship program to learn what it takes to become a practicing software engineer and a consultant to other software engineers.  Associates work directly with more senior consultants in a mentorship model to learn on the job.<br />
The objectives for the Associate Consultant apprenticeship program include teaching the new employ to:<br />
•	Critically analyze software for discover security and quality risks<br />
•	Apply proprietary risk management techniques to make intelligent choices about addressing software risks that affect everyday business<br />
•	Use practical software engineering practices to build more robust, secure software<br />
•	Build expertise in cutting edge technologies used by the leading companies in industries such as financial, healthcare, telecommunications, defense, and so on.<br />
•	Perform as a consultant and trusted advisor to other software engineers for doing all of the above<br />
<br />
Qualifications<br />
Associate Consultants require strength in the following skills for success: <br />
•	Consulting skills – ability to undertake and complete tasks independently, meet schedules and delivery timelines, and to move swiftly from concepts and theory to action <br />
•	Team-oriented skills – ability to collaborate with project team members, take direction from the project lead and execute tasks consistently<br />
•	Communication skills – strong capabilities writing and presenting technical ideas as well as interacting with teams<br />
•	Demeanor – enthusiasm and commitment with professional interpersonal skill and an entrepreneurial drive<br />
<br />
Associate Consultant Education and Experience<br />
•	BS in Computer Science, Computer Engineering, or equivalent. <br />
•	Training in Software Engineering and Object Oriented Analysis and Design<br />
•	2-5 years of programming experience (or equivalent) in Java, .NET, C#, VB, C++, and/or C++, preferably in a web-based or client-server development environment<br />
•	Familiarity with database management systems like Oracle, MS SQL Server, and MySQL<br />
Experience with the following is beneficial:<br />
•	Software Quality Assurance, Software Security Fundamentals, Source Code Analysis, Test Automation, Penetration Testing<br />
•	Security tools such as Fortify, Coverity, Watchfire, Spidynamics, Tamper Data, Fiddler, Cookie editors, and so on<br />
•	Service Oriented Architecture (SOA), Web Application, and Web Services development<br />
•	Technologies such as JavaEE, Hibernate, Spring, Struts, Servlets, Log4J, JSP, JAAS, XML, AJAX, JavaScript, JavaSE, ACEGI, EJB, .NET, C#, VB, C++, Perl, Unix scripting <br />
•	In-depth usage and administration of Windows, Linux, and other Unix operating systems<br />
•	Java Security Features, .NET Security Model, Cryptography, Digital Certificates<br />
•	Configuration and deployment of web applications using IBM WebSphere, BEA WebLogic, JBoss, Apache Tomcat, and IIS]]></description>
            <dc:creator>recruiter25</dc:creator>
            <category>Jobs</category>
            <pubDate>Tue, 03 Mar 2009 16:21:06 -0600</pubDate>
        </item>
    </channel>
</rss>
