Computer Incident Response Team Job

From: Erik Ginorio (eginorioat_private)
Date: Mon Oct 14 2002 - 13:57:55 PDT

  • Next message: Gabriel Coelho-Kostolny: "Strong Security/Software Engineer needed @ Intruvert"

      Cisco Systems internal Infosec team is looking to fill a position in 
    their Incident Response Team. We would like to see someone who is 
    experienced in forensics and investigations, and with strong host based 
    skills (unix, windows). A firm understanding of protocols, and networks, 
    experience with risk assessments and programming experience is a big plus. 
    Experience with EnCase, TcT, etc, is a must.
    
      To spare everyone the long dry job description, if you are an experienced 
    *technical* incident handler and/or investigator, and want to relocate to 
    Cisco's HQ at San Jose, California or to our mirror site at Research 
    Triangle Park, North Carolina, send in your resume.
    
    Below is the "official" dry job listing babble, so I'll let people read it 
    at their leisure.
    
    Thanks!
    
    --------------------------------------------------------------------------
    
    
    Incident Response Team Member:
    Inventory seized computers for identifiable information and duplicate 
    magnetic media. Delete or neutralize computer viruses and file password 
    protection. Print directory listing of active system, and hidden files. 
    Detect and recover erased files, file slack, and file fragments. Execute 
    files and view data contents as well as perform keyword/string searches. 
    Provide testimony on evidence examination and handling as expert witness in 
    judicial proceedings. Some travel required. Perform Risk Assessments and 
    security posture assessments. Assist with security tool selection and 
    strategic direction of security tools, systems and software packages. Lead 
    small team of digital security investigators.
    
    Skills required:
    Recognized expert in particular or multiple technological fields of 
    specialization within and outside of the organization. Must have performed 
    multiple forensics examinations for law enforcement purposes. Must have 
    solid knowledge of DOS, Windows, Unix, and Linux operating systems as well 
    as hard drive, diskette, data tape, and data cartridge storage media. Must 
    have experience with NCase Functions as the highest level technical 
    resource. Certifications in the following a plus - Encase, IACIS. Cross-IT 
    leadership in all technical disciplines focused on Incident Response and 
    investigations.
    
    IT Engineer IV:
    Proactively anticipates framework and infrastructure requirements for 
    security application needs. Receives assignments in the form of objectives 
    towards long-range goals and objectives. Work is reviewed in terms of 
    meeting IT specific initiatives. Strong understanding of all current 
    security technologies and good understanding of emerging technologies. 
    Focus on technology and how to use it. Leadership and mentoring skills. 
    Drives and oversees the implementation of company wide projects. Provides 
    leadership and direction on projects for maximum business impact. Typically 
    reports to Sr Mgr IT or above. Goals set by overall Manager with assistance 
    of group Director. Interfaces with all levels of IT and Business Partners 
    in all areas of the company. Thorough understanding of applying technology 
    to reach desired goal. Solves complex, cross-functional issues that cross 
    many groups. Can apply good analytic process to any issue to help come to 
    resolution. Accountable to highest levels of senior management to ensure 
    project commitments and deliverables are met. Recommends and initiates 
    projects to benefit cross-group and Cisco wide objectives. Identify and 
    document design and architecture best practices for global adoption. Owns 
    responsibility for driving worldwide architecture for global projects.
    
    --------------------------------------------------------------------------
    
    
    best regards,
        Erik Ginorio
    
    Corporate Information Security
    Cisco Systems
    eginorioat_private
    direct:408.853.6313
    fax:408.525.1484
    PGP Key ID:0x070AB400
    



    This archive was generated by hypermail 2b30 : Mon Oct 14 2002 - 20:00:41 PDT