Bradley-Morris offers exclusive career opportunities to professionals with U.S. military experience only. If you are able to start your new career within 90 days and meet the position requirements listed in the job description, feel free to apply. If you are not available to work within the next 90 days, but would like to work with Bradley-Morris on finding your next career, please complete an application here https://mapp.bradley-morris.com to get started.
Director-Cyber Security Services
They are looking for a Practice Leader or Director for their Cyber Security Services Group in their Chicago office who wants to join us in Improving Society Through the Built Environment. Collectively, they apply their knowledge, expertise, and critical thinking skills to develop solutions impacting people's health, comfort, productivity, safety, and connectivity.
They are able to make a difference for their clients and society-at-large within a framework of regulations, budget and schedule realities, and at the speed of change. This requires their team to collaborate, continuously improve, and innovate to earn trust among their colleagues and clients.
If you are a person who enjoys making a difference for your colleagues and clients through excellence - this is an opportunity for you to apply your knowledge, work with some of the world's highest-profile clients, enjoy social and charitable activities, and build your career.
Essential duties and responsibilities:
They are seeking a world class security expert to build the business strategy and lead a team of ethical hackers to conduct application security/penetration tests of their clients as it relates to their building's infrastructure systems (HVAC, Lighting, and so on), internal/external web, mobile and web service applications, leveraging both manual techniques as well as automated tools in order to uncover and report security vulnerabilities that exist.
You will be knowledgeable with business risks associated to common security vulnerabilities and to be able to effectively communicate security vulnerabilities to their clients through presentations and reports.
Experience conducting vulnerability assessments, code reviews and Manual penetration tests against web/mobile application technologies, services, platforms and languages to find flaws and exploits (for example, SQL Injection, Cross-Site Scripting, Cross-Site Request Forgery, Clickjacking, Authentication/Authorization, Privilege Escalation, Business Logic Bypass, OWASP Top 10, SANS Top 25 and so on).
Knowledge of network and Web related protocols/technologies especially as it relates to building systems such as HVAC controls, lighting controls, and building operating systems.
Ability to demonstrate manual web application testing experience.
Experience with web application vulnerability scanning tools (for example, IBM AppScan, HP Webinspect, Accuntix, NTO Spider, Burpsuite Pro and so on).
Experience with vulnerability assessment tools and penetration testing techniques (for example, web application proxies, packet capture analysis software, browser extensions, advanced penetration testing Linux distributions, static source code analyzers, SoapUI and so on).
Experience of penetration testing on mobile platforms such as iOS, Android, Windows and RIM.
Expert-level experience and very details technical knowledge in at least 3 of the following areas: general information security; security engineering; application architecture; authentication and security protocols; application session management; applied cryptography; common communication protocols; mobile frameworks, single sign-on technologies; exploit automation platforms; RESTful web services.
Demonstrated ability to learn and apply critical thinking to a variety of situations.
Bonuses + full comprehensive benefits