Security Engineer
Park Hudson International - New York, NY

Concise Description of Position: Responsible for the Security Data Loss prevention tool, Intruder Detection and Auditing tools Security testing, penetration and vulnerability testing. This position requires hands on experience with secure coding practices, ethical hacking, web application firewalls and vulnerability assessment methodologies. In the role of Information Security Engineer, the candidate will also be responsible for designing, developing, and implementing the Enterprise SIMM security tool, two factor authentication and end point authentication for the mobile devices. The Security Engineer will be part of the Security team that does all the security design, development and testing for the corporate enterprise Security tools. General Description of Duties (What will associate do?): •Oversee installation and maintenance of data Loss Prevention in the Internet DMZ •Oversee installation and maintenance of the Auditing Compliance security tool •Domain expert in the scanning tools (Nessus or Metasploit or other tools)to assess external and internal network and applications for security risks •Domain expert in firewalls and Intruder Detection systems •Translate business and technical requirements into extensible, scalable, and maintainable security solutions •Protect mission critical applications and corresponding databases in the public domain •Work with state-of-the-art intrusion/prevention technology •Monitor threats and provide mitigation when threats for the enterprise Internet DMZ •As new Internet DMZ equipment is deployed, add any additional security permissions and roles that may be needed in the DLP or IDS. •Update any additional security settings for the enterprise firewalls •Work with Vendor for implementation of enterprise Auditing and SIMM infrastructure •Monitor alerts and coordinate patch management with corresponding teams •Demonstrate best-practice knowledge and apply skills to deliver an effective solution specific to client needs •Provide front-end development and build web interfaces. •Provide DMZ application security if needed. Technical Skills Required (please note required proficiency level): •Expertise in DLP (Data Loss prevention) tools •Expertise in Auditing tools •Experience with an application/database layer IDS Intrusion detection/ prevention appliance •Experience with ethical hacking and remediation efforts •Experience with firewalls, including application firewalls • •Knowledge of secure coding principles and practices •application security assessment methodologies and tools •Knowledge in optimizing Web Application Firewall •Knowledge of security standards and techniques for network and applications •Understand browser-specific compatibility issues •Expertise in the design, implementation, and deployment of user-centric security tools with focus on usability • Other Qualifications: Knowledge of hospital information systems is a plus. •Ability to work effectively as an individual, within a team, or as a team lead •Maintain current technical knowledge to support rapidly changing technology, always on a look out for new technologies and work with management and security team in bringing new technologies Education Requirements: Qualifications: BS in computer science or equivalent work experience CISSP, or other Security certificates is a plus
