RSM US LLP. (McGladrey LLP)
Job Title:Consulting - Senior Associate - Security, Privacy & RiskDescription:In order to address the most critical needs of our clients, RSM US LLP has established the Security, Privacy and Risk group, comprised of more than 100 professionals dedicated exclusively to serving the cyber security needs of our clients. This group includes experienced consultants located throughout the country dedicated to helping clients with preventing, detecting, and responding to security threats that may affect their critical systems and data. We serve a diverse client base within a variety of industries, and we are relied upon to provide expertise within areas of security testing, architecture, governance, compliance, and digital forensics.We are seeking individuals with a variety of skill sets such as performing vulnerability assessments, penetration testing, incident response, governance assessments (HIPAA, NIST, ISO, FISMA, etc.), Payment Card Industry (PCI) assessments, as well as experience in managing or deploying SIEM, DLP, and Identify Management solutions.Responsibilities will be based on background but will typically include:Perform vulnerability assessments and penetration testing to verify the strengths and weaknesses of a variety of operating systems, network devices, web applications, and security architectures utilizing commercial and open source security testing toolsPerform assessments against a variety of regulatory and industry standards such as PCI, FFIEC, ISO 2700X, NIST sp800 series, FISMA, FedRAMP, HIPAA/HITECH, and NERC/CIPAssist clients in improving the capabilities and maturity of their monitoring program by identifying appropriate technologies, policies, organizational structures, and relations with third partiesAssist with the development and delivery of remediation recommendations for identified findingsIdentify and clearly articulate (written and verbal) findings to senior management and clientsHelp identify improvement opportunities for assigned clientsRequired qualifications:This position is for individuals with 2-6 years of experience within the cyber security space, with a preference for prior consulting or professional services backgrounds. Other candidates may be considered based on experience and skill setsBachelor's degree in computer science or related field from an accredited college/universityAbility to travel as neededMust possess a high degree of integrity and confidentiality, as well as the ability to adhere to both company policies and best practicesStrong verbal and written abilitiesStrong multitasking and project management skillsPreferred qualifications that may vary by candidate:Experience with testing and development frameworks such as the Open Web Application Security Project (OWASP), Open Source Security Testing Methodology Manual (OSSTMM), the Penetration Testing Execution Standard (PTES), Information Systems Security Assessment Framework (ISSAF), and NIST SP800-115Experience with discovering and demonstrating web application vulnerabilities such as Cross Site Scripting (XSS), Cross Site Request Forgery (CSRF), Injection Flaws, Remote file inclusion (RFI) and SQL InjectionFamiliar with security testing techniques such as network discovery, port and service identification, vulnerability scanning, network sniffing, penetration testing, configuration reviews, firewall rule reviews, social engineering, wireless penetration testing, fuzzing, and password cracking and can perform these techniques from a variety of adversarial perspectives (white-, grey-, black-box)In-depth knowledge of the security and privacy provisions of a variety of regulations and standards such as PCI, NERC/CIP, HIPAA/HITECH/HITRUST, FFIEC, FDIC, ISO 27000 series, NIST sp800 series, etc.Commercial Application Security tools experience (Nessus , Nexpose, Qualys, Appdetective, Appscan, etc.)Open source and free tools experience (Kali Linux suite, Metasploit, nmap, airsnort, Wireshark, Burp Suite, Paros, etc.)One or more o
RSM US LLP is a leading provider of audit, tax and consulting services focused on the middle market. We guide our clients through business challenges by understanding their needs and bringing together the right team to address them. With 8,000 professionals and associates in 80 cities nationwide and access to more than 38,300 people in 120 countries through our membership in RSM International, we can meet your needs wherever in the world you do business.