This position could be located in either Houston or Kansas City.
In order to address the most critical needs of our clients, RSM US LLP has established the Security and Privacy Risk Consulting group, comprised of more than 150 professionals dedicated exclusively to serving the cyber security needs of our clients. This group includes experienced consultants located throughout the country dedicated to helping clients with preventing, detecting, and responding to security threats that may affect their critical systems and data. We serve a diverse client base within a variety of industries, and we are relied upon to provide expertise within areas of security testing, architecture, governance, compliance, and digital forensics.
This position will work independently and as part of a team to perform security assessments, including internal vulnerability assessments, internal penetration testing, wireless security assessments, social engineering, ISO27000 assessments, Payment Card Industry (PCI) assessments, Federal Information Security Management Act (FISMA) assessments and Health Insurance Portability and Accountability Act (HIPAA) assessments.
- Perform application and network penetration tests for our global clients
- Use commercial scanning tools such as BurpSuite, Nessus, and other commercial products to analyze systems for vulnerabilities, and provide risk reduction recommendations
- Performing manual verification of vulnerabilities to reduce false positives
- Understanding of common regulatory or standards-based control frameworks such as PCI-DSS, ISO 27001/2, NIST 800-53, etc.
- Creating comprehensive security assessment reports
- Interfacing with clients to gather information and investigate security controls
- Maintaining industry credentials/certifications
- Supporting ongoing development of security assessment service offerings
- Basic experience in web application architecture analysis to identify logical flaws and security weaknesses
- Basic understanding of encryption methods and how they are applied in an application environment
- Working knowledge of application security tools such as proxies, fuzzers, scanners, debuggers, simulators, etc.
- Familiarity with common web platforms i.e. Tomcat, .Net, AJAX, HTML5 etc.
- Familiarity with backend databases like MS SQL, Oracle, MySQL, etc.
- Understanding of common web content management systems like Joomla, DotNetNuke etc.
- Experience with various security like Metaspolit, Nmap, Qualys, mimikatz, Nessus, NeXpose, Kali Linux, BurpSuite, OWASP ZAP, WireShark, Tcpdump, etc. to analyze systems for vulnerabilities, and provide risk reduction recommendations.
- Working knowledge of Windows & Linux, TCP/IP, and Web services
- Perform manual verification of vulnerabilities to reduce false positives
- Understand common regulatory or standards-based control frameworks such as PCI-DSS, ISO 27001/2, NIST 800-53, etc.
- Able to create a comprehensive security assessment reports
- Interface with clients to gather information and investigate security weakness and controls
- Bachelor's degree in Computer Science, Computer Engineering, Cyber-Security, Information Security or a related field or equivalent experience
- Minimum 4 years of experience conducting application and network penetration testing
- Ability to travel as needed (up to 35%)
- GIAC GPEN, Offensive Security Certified Professional (OSCP), CISA, CISSP or Offensive Security Certified Expert (OSCE) preferred
- Implementation of vulnerability management programs is a plus
- Prior consulting or professional services background preferred
- Knowledgeable regarding Sarbanes-Oxley Act, Payment Card Industry (PCI), and SOC
- Must possess a high degree of integrity and confidentiality, as well as the ability to adhere to both company policies and best practices
- Experience with an accounting or consulting firm preferred
- Strong verbal and written abilities
- Strong multitasking and project management skills