ABOUT PROTIVITI
Protiviti is a global consulting firm that delivers deep expertise, objective insights, a tailored approach, and unparalleled collaboration to help leaders confidently face the future. Protiviti and our independently owned Member Firms provide consulting solutions in finance, technology, operations, data, analytics, governance, risk and internal audit to our clients through our network of more than 85 offices in over 25 countries. We have served more than 60 percent of Fortune 1000® and 35 percent of Fortune Global 500® companies. We also work with smaller, growing companies, including those looking to go public, as well as with government agencies. Protiviti is a wholly owned subsidiary of Robert Half (NYSE: RHI). Founded in 1948, Robert Half is a member of the S&P 500 index.
JOB RESPONSIBILITES
• Reviewing, documenting, evaluating and testing cyber security controls in a wide range of environments.
• Conduct comprehensive penetration tests on the organization's digital infrastructure, including but not limited to web applications, networks, and endpoint systems.
• Communicating control strengths and weaknesses to the client or internal audit engagement team and developing effective solutions.
• Ensure timely completion of assigned project phases.
• Develop and maintain effective client relationships.
•Apply understanding of Protiviti policies and proficiency in Protiviti methodologies.
•Apply understanding of business processes and technical skills to successful completion of project assignments.
•Develop understanding of project requirements and client’s business.
•Preparing reports on findings and recommendations to both senior management and technical audience. General knowledge and Technical Skills.
•Understanding of security architecture principles.
REQUIRED EXPERIENCE
•4+ years in a related field, preferably gained in a “Big 4” environment or professional cyber security servicing firms.
•Experienced in performing vulnerability assessments and penetration testing.
•Proficient in Microsoft Windows scripting (WSH, PowerShell), Linux shell scripting, Python/Perl/Ruby, C/C++, .NET, SOAP/Rest API.
•Understanding of leading IT security control frameworks (ISO 27001/2, NIST CSF, COBiT).
•Understanding of cyber security risk assessment approaches and deliverables.
REQUIRED INDUSTRY / TECHNICAL KNOWLEDGE & SKILLS
• Understanding of leading IT security control frameworks (ISO 27001/2, NIST CSF, COBiT). Candidate should have multiple successfully accomplished IT Security assessment, IT Audit engagements.
• Understanding of cyber security risk assessment approaches and deliverables.
• Understanding of security architecture principles.
• Practical hands-on experience with security solutions in multi-layered “defense-in-depth” security model (EDR, NGFW, IPS/IDS/FW, SEIM, MDM, DB Protection, DLP, Web proxies, WAF, Wireless security, Patch and vulnerability management, Forensic tools, etc).
• Practical hands-on experience with technical security assessment (configuration, source code, mobile), vulnerability assessment and penetration testing methodologies and tools (Nexpose, Qualys, Nessus, Burp Suite, NetSparker, Acunetix, Metasploit, Powersploit, Empire, Kali linux tools etc.) for networks and applications.
• Proficient in Microsoft Windows scripting (WSH, PowerShell), Linux shell scripting, Python/Perl/Ruby, C/C++, .NET, SOAP/Rest API.
• Experience in Financial sector will be a plus.
REQUIRED GENERAL KNOWLEDGE & SKILLS
•Strong interpersonal, communication and writing skills.
•Highly analytical, creative in thinking and tenacious with a “take charge” attitude.
•Able to work independently as well as in teams of varying sizes.
EDUCATIONAL & PROFESSIONAL CREDENTIALS
· Bachelor’s Degree in Computer Science, Information System, or related discipline
· Strong knowledge on different parts of IT environment, i.e. operation systems, network, database, etc.
· Professional certifications, i.e. CREST, CISSP, CISM, CISA, CBCP, CIA, CFE, ISO 27001 leader auditor, PMP, or ITIL, are preferred
· Knowledge of CyberArk, Netskope, PaloAlto Network, Microsoft Products