Geeklog Site http://www.sdissa.org/pages Another Nifty Geeklog Site admin@sdissa.org admin@sdissa.org Copyright 2008 SDISSA GeekLog Mon, 04 Aug 2008 13:18:48 -0700 en-gb FBI Computer Scientist Position http://www.sdissa.org/pages/article.php?story=20080804120503123 http://www.sdissa.org/pages/article.php?story=20080804120503123 Mon, 04 Aug 2008 12:05:03 -0700 Careers <font face="Arial"><div><strong>Company: </strong>FBI, San Diego, CA</div><div><strong>Contact: </strong>CS Jennifer Kolde - FBI San Diego Division <span></span></div><div><strong>Status:</strong> Position Open</div><div><strong>Type: </strong>Full Time</div></font> <p class="MsoNormal"><span>The FBI, San Diego Field Office, National Security Cyber Squad, will post a position for a Computer Scientist in the near future.&nbsp; The Computer Scientist (CS) is responsible for providing technical support and subject matter expertise to FBI Special Agents and Intelligence Analysts related to sensitive computer network intrusions and intelligence matters.&nbsp; While the CS will perform a variety of duties, his/her primary responsibility is identifying computer network attacks and data compromise using techniques such as malware analysis, forensic analysis, log file analysis, large-scale data analysis (correlation / trending), network traffic analysis, and the development of tools and / or programs to assist with or automate the same.&nbsp; </span></p><p class="MsoNormal"><span>The CS will work in a team environment in the production of relevant written reporting and briefings within the FBI and other U.S. Government entities.&nbsp; As such, strong written and oral communications skills are essential.&nbsp; In addition, as a subject matter expert, the CS is expected to monitor and provide insight into trends in the security community (vulnerabilities, threats, exploits, changing techniques, risks, etc.). </span></p><p class="MsoNormal"><span>The position will be at the GS13 or GS14 level with an adjustment for San Diego locality pay.&nbsp; The salary grade and step are determined from the selected candidate&rsquo;s experience and prior employment.&nbsp; </span></p><p class="MsoNormal"><span>Interested candidates must meet the following minimum requirements to apply:</span></p><ul> <li><span>US Citizen<br /> </span></li> <li><span>Ability to obtain a Top Secret-SCI clearance</span></li> <li><span>Completion of a four-year course of study at an accredited college or university (e.g., Bachelor's degree or higher)</span></li> <li><span>Minimum of 30 semester hours of mathematics, statistics, and computer science</span></li></ul><p class="MsoNormal"><span>Once posted, the position will be open to applicants for only a short window of time (usually 10 days).&nbsp; As such, we encourage you to forward this information to anyone who may be interested in applying so that interested candidates can become familiar with the hiring process, especially the need to apply immediately and completely when the position is posted.&nbsp; The application process requires submission of a current resume, official college / university transcripts, and completion of an online application (to include a set of multiple choice / essay questions describing the candidate's relevant experience).&nbsp; Interested candidates are strongly encouraged to visit the FBI Jobs web site (<a href="http://www.fbijobs.gov/">http://www.fbijobs.gov</a>) to register and review the application process.&nbsp; </span></p><p class="MsoNormal"><span>Additional information about employment with the Federal Bureau of Investigation can be found on the following web sites:</span></p><p class="MsoNormal"><span>1. FBIJobs:&nbsp; <a href="http://www.fbijobs.gov/">www.fbijobs.gov</a></span></p><p class="MsoNormal"><span>&nbsp;&nbsp; - Job posting and application web site.</span></p><p class="MsoNormal"><span>2. Office of Personnel Management:&nbsp; <a href="http://www.opm.gov/">www.opm.gov</a></span></p><p class="MsoNormal"><span>&nbsp;&nbsp; - Salary, benefits, and other information related to Government employment</span></p><p class="MsoNormal"><span>3.&nbsp; FBI:&nbsp; <a href="http://www.fbi.gov/">www.fbi.gov</a></span></p><p class="MsoNormal"><span>&nbsp;&nbsp; - FBI web site</span></p><p class="MsoNormal"><span>Candidates who are interested in applying for the position should register on the FBIJobs web site, and sign up for email notification to receive an alert when the position is posted.</span></p> SDISSA General Membership Meeting 13 August 2008 http://www.sdissa.org/pages/article.php?story=20080620082256664 http://www.sdissa.org/pages/article.php?story=20080620082256664 Fri, 20 Jun 2008 08:22:56 -0700 http://www.sdissa.org/pages/article.php?story=20080620082256664#comments SD ISSA <p><font size="2" face="Arial">Please spread the word and support the security community with your attendance at our next &quot;OPEN&quot; General Membership meeting and bring a friend.</font></p><p><font size="2" face="Arial">Please register for the chapter meeting <a href="http://acteva.com/go/sdissa">ONLINE at Acteva</a>!!!</font></p><p><font size="2" face="Arial"><font size="2" face="Arial"><font size="2" face="Arial">Registration fee for meeting:<br /></font></font></font></p><p><font size="2" face="Arial"><font size="2" face="Arial"><font size="2" face="Arial">&nbsp;&nbsp;&nbsp; &#36;10 &ndash; ISSA Members<br />&nbsp;&nbsp;&nbsp; &#36;20 &ndash; Non-ISSA Members</font></font></font></p><a href="http://www.acteva.com/go/sdissa"> </a><div><a href="http://www.acteva.com/go/sdissa"><img width="80" height="42" border="0" alt="" src="http://www.acteva.com/buttons/2_registernow_80x42.jpg" /> </a></div><p><strong><font>NEW MEETING LOCATION:</font>&nbsp; <a href="http://www.sdissa.org/pages/article.php?story=admiral_baker_clubhouse">Admiral Baker Clubhouse</a></strong></p><p><font size="2" face="Arial"><strong>Presenter:</strong></font></p><span>Faizel Lakhani, </span><span>Vice President of Products and Marketing<br /></span><span>Reconnex</span><span><br /></span><p><font size="2" face="Arial"><font size="2" face="Arial"><strong>Subject:</strong></font></font></p><p><font size="2" face="Arial"><font size="2" face="Arial"><span>Data Loss Prevention: Best Practices</span></font></font></p><p><font size="2" face="Arial"><font size="2" face="Arial"><strong>Presentation Abstract:</strong></font></font></p><p><font size="2" face="Arial"><font size="2" face="Arial"><span>Data loss has garnered headlines with very public breaches recently. These are the breaches that organizations have been forced to disclose; imagine all the leaks occurring that go undetected.&nbsp; This session will provide industry best practices for the processes around data loss prevention and a methodology for identifying and protecting sensitive data that can be applied at any organization.</span></font></font></p> <font size="2" face="Arial"><font size="2" face="Arial"><strong>Presenter's Bio:</strong></font></font><p class="MsoNormal"><font size="2" face="Arial"><font size="2" face="Arial"><span>Faizel Lakhani is responsible for product strategy at Reconnex.&nbsp; Prior to joining Reconnex, Lakhani was Vice President of Products at ConSentry Networks, a leading LAN security company, responsible for overall product strategy and direction. Prior to ConSentry, Faizel was Vice President of Products at Caspian Networks, a flow-based routing company.</span></font></font></p><p class="MsoNormal"><font size="2" face="Arial"><font size="2" face="Arial"><span>Faizel began his career at Nortel Networks holding a number of executive roles in product management for new and emerging products.&nbsp;&nbsp; Faizel holds a Masters Degree In Engineering from Carleton University, an MBA from the University of Ottawa and a Bachelor of Engineering in Electrical Engineering from McMaster University.</span></font></font></p><hr /><p><font size="2" face="Arial"><font size="2" face="Arial"><font size="2" face="Arial"><strong>Date: </strong>Wednesday, 13 August 2008</font></font></font></p><p><font size="2" face="Arial"><font size="2" face="Arial"><font size="2" face="Arial"><strong>Time: </strong>11:30 - 1:00 PM</font></font></font></p><p><font size="2" face="Arial"><font size="2" face="Arial"><font size="2" face="Arial"><strong>Schedule:</strong></font></font></font></p><p><font size="2" face="Arial"><font size="2" face="Arial"><font size="2" face="Arial">11:15 &ndash; 11:45 Networking/Lunch<br />11:45 &ndash; 12:00 Chapter Announcements/Attendee Self-Introductions<br />12:00 &ndash; 12:40 Presentation (write down your questions for Q&amp;A)<br />12:40 &ndash; 12:50 Q&amp;A<br />12:50 -&nbsp; 1:00 Plaque Presentation to Speaker/Raffle (Chapter Members and qualified prospective Members only)</font></font></font></p><p><font size="2" face="Arial"><font size="2" face="Arial"><font size="2" face="Arial"><strong>Location: </strong><a href="http://www.sdissa.org/pages/article.php?story=admiral_baker_clubhouse">Admiral Baker Clubhouse</a>, 2400 Admiral Baker Rd,&nbsp; San Diego, CA 92120&nbsp; (619) 556-5502 </font></font></font></p><hr /><p><font size="2" face="Arial"><font size="2" face="Arial"><font size="2" face="Arial">Registration fee for meeting:<br /></font></font></font></p><p><font size="2" face="Arial"><font size="2" face="Arial"><font size="2" face="Arial">&nbsp;&nbsp;&nbsp; &#36;10 &ndash; ISSA Members<br />&nbsp;&nbsp;&nbsp; &#36;20 &ndash; Non-ISSA Members<br /></font></font></font></p><p><font size="2" face="Arial"><font size="2" face="Arial"><font size="2" face="Arial">Please register or RSVP to (<a href="mailto:secretary@sdissa.org?subject=RSVP%20for%20SDISSA%20General%20Membership%20Meeting%2013%20August%202008&amp;body=I%20will%20be%20in%20attendance.">secretary@sdissa.org</a>) no later than 8 August so that lunch preparations can be made to satisfy the expected audience size. </font></font></font></p><p><font size="2" face="Arial"><font size="2" face="Arial"><font size="2" face="Arial">Remember: If you are a CISSP or SSCP, meeting attendance qualifies for a CPE credit towards recertification.<br /></font></font></font></p><a href="http://www.acteva.com/go/sdissa"> </a><div><a href="http://www.acteva.com/go/sdissa"><img width="80" height="42" border="0" alt="" src="http://www.acteva.com/buttons/2_registernow_80x42.jpg" /> </a></div> http://www.sdissa.org/pages/trackback.php?id=20080620082256664 The Admiral Baker Clubhouse http://www.sdissa.org/pages/article.php?story=admiral_baker_clubhouse http://www.sdissa.org/pages/article.php?story=admiral_baker_clubhouse Wed, 04 Jun 2008 09:15:50 -0700 http://www.sdissa.org/pages/article.php?story=admiral_baker_clubhouse#comments SD ISSA <div><font><strong>NEW MEETING LOCATION</strong></font><br />Located just East of Friars road and Highway 15<br /><br /><strong>The Admiral Baker Clubhouse</strong><br />At 2400 Admiral Baker Rd,&nbsp; San Diego, CA 92120<br />(619) 556-5502<br /></div><br />Take Fairs road east until Santo Road, take a left and very soon veer right onto the Admiral Baker Clubhouse.&nbsp; Then stay left and follow the road around to the clubhouse.&nbsp; No base sticker or government badge is needed.<br /><br />You&rsquo;re going to love the setting, ambiance, and history of the place!<br /><br /><strong>Driving Directions from Highway 15:</strong><br /><br />1) Take Friars Road exit East. Pass through the first stoplight (Rancho Mission).<br />2) Turn left at the second light (Santo Road).<br />3) Make an immediate right turn onto Admiral Baker Road.<br />4) Follow the road to its end at the golf course clubhouse.<br /><br /><img width="442" height="462" src="http://www.sdissa.org/pages/images/library/Image/images/admiral_baker_clubhouse.jpg" alt="" /> http://www.sdissa.org/pages/trackback.php?id=admiral_baker_clubhouse San Diego Chapter of ISSA to Present Student Scholarship http://www.sdissa.org/pages/article.php?story=20080507150052606 http://www.sdissa.org/pages/article.php?story=20080507150052606 Wed, 07 May 2008 15:00:00 -0700 Announcements <p class="MsoNormal" align="center"><em>Scholarship to be presented at the Hoover High School&rsquo;s Academy Awards</em></p><p class="MsoNormal">San Diego, CA &ndash; May 8, 2008 &ndash; The San Diego Chapter of the Information Systems Security Association (ISSA) announced that they will present a &#36;1,500 scholarship at this year&rsquo;s Hoover High School Academy Awards on Thursday, May 15, 2008. The scholarship will be awarded to a student belonging to the Academy of Information Technology (AOIT), an organization emphasizing the importance of technology and integrating its uses in a variety of subjects.</p><p class="MsoNormal">&ldquo;By supporting organizations in our community such as the AOIT we can help ensure that information technology continues to be an area of continued educational growth, the earlier students are exposed to the capabilities of technology the better prepared they will be for college and the work force&rdquo;, says Peter Bybee, President of the San Diego ISSA chapter, &ldquo;if we want to continue to see advances in the world of technology, we have to invest in its future &ndash; these students are the future&rdquo;.</p> <p class="MsoNormal">The AOIT has been gaining popularity in high schools nationwide, and for good reason; &ldquo;In partnership with the community, the AOIT provides a leading edge, rigorous, career-focused education which prepares students for post-secondary education and an increasingly technology-oriented society&rdquo; says Ellen Towers who heads the academy at Hoover High adding &ldquo;the support from ISSA and their scholarship really helps students get started in college&rdquo;. </p><p class="MsoNormal">The winning student is selected based on GPA, volunteer experience, Internships, technology courses completed, a detailed essay, and a panel interview.<span>&nbsp; </span>The award ceremony will be held at Hoover High School, 4474 El Cajon Blvd San Diego, CA 92115 and begins May 15, 2008 at 5:30 pm with a light dinner and presentation starting at 6:15 pm. </p> IA/Security resources, references, guides http://www.sdissa.org/pages/article.php?story=20071217151212844 http://www.sdissa.org/pages/article.php?story=20071217151212844 Mon, 17 Dec 2007 15:12:12 -0800 SD ISSA <div><strong>Useful web sites&nbsp;&nbsp;&nbsp; (Main ones) </strong></div><div><a href="https://infosec.navy.mil/docs/index.jsp">https://infosec.navy.mil/docs/index.jsp</a></div><div><a href="http://iase.disa.mil/techguid/index.html">http://iase.disa.mil/techguid/index.html</a></div><div>&nbsp;</div><div><strong>&nbsp;And these others</strong></div><div><a href="http://www.sse-cmm.org/lib/lib.asp">http://www.sse-cmm.org/lib/lib.asp</a></div><div><a href="https://www.fleetforces.navy.mil/netwarcom/navycanda">https://www.fleetforces.navy.mil/netwarcom/navycanda</a></div><div><a href="https://www.us.army.mil/suite/portal/index.jsp">https://www.us.army.mil/suite/portal/index.jsp</a></div><div><a href="http://csrc.nist.gov/">http://csrc.nist.gov/</a></div><div><a href="http://www.nsa.gov/ia/index.cfm">http://www.nsa.gov/ia/index.cfm</a></div><div><a href="http://www.iatf.net/">http://www.iatf.net/</a></div><div><a href="void(0);/*1197933050781*/">http://www.cert.org/</a></div><div><a href="http://www.commoncriteriaportal.org/ ">http://www.commoncriteriaportal.org/ </a></div><div><a href="http://www.amc.army.mil/amc/ci/matrix/policy/policy_new.htm">http://www.amc.army.mil/amc/ci/matrix/policy/policy_new.htm</a> </div><div><a href="https://www.sans.org/about/sans.php">https://www.sans.org/about/sans.php</a></div><div><a href="http://iac.dtic.mil/iatac/">http://iac.dtic.mil/iatac/</a></div><div><a href="http://www.cerias.purdue.edu/">http://www.cerias.purdue.edu/</a></div><div><a href="http://security.sdsc.edu/">http://security.sdsc.edu/</a></div> <div><div><strong>Main Statues / Directives / Guidance</strong></div><ul style="MARGIN-TOP: 0in"> <li>Clinger-Cohen Act (CCA), 1996 </li> <li>Government Information Security Reform Act (GISRA), 2000 </li> <li>Federal Information Security Management Act (FISMA), 2002 </li> <li>OMB Circular A-130, 2000 </li> <li>DoDD 8500.01E -&nbsp;Information Assurance (IA), April 2007 (changed from 8500.1) </li> <li>DoDI 8500.2 - IA Implementation, Feb 03 </li> <li>DoDI 8580.1 - IA in the Defense Acquisition System, July 04 </li> <li>Information Assurance Technical Framework (IATF), Sep 2000 (www.iatf.net) </li> <li>GIG IA Architecture, ICD (6 Mar 06) &nbsp;and Strategy &nbsp;(and related GIAP artifacts, plans, priorities) </li> <li>NSTISSP 11 - National Security Telecommunications&nbsp;and Information Systems Security </li> <li>DoDI 8510.bb - DoD Information Assurance Certification and Accreditation Process (DIACAP) </li></ul><div>&nbsp;</div><div>&nbsp;</div><div>&nbsp;</div><div><strong>Also see:</strong></div><div>- DoDD 5000.1 - The Defense Acquisition System, May 03</div><div>- DoDI 5000.2 - Operation of the Defense Acquisition System, May 03</div><div>-&nbsp;&nbsp;&nbsp; Section 2224 of title 10, US Code &ldquo;Defense Information Assurance Program&rdquo;</div><div><strong><span>http://iase.disa.mil/policy-guidance/index.html#DoD</span></strong></div><div>&nbsp;</div></div><span><br /></span><div><strong>Preferred Product Lists (PPL)</strong> -&nbsp;Generally programs should still to using PPL devices / processes in building their systems. Other than the type-1 COMSEC devices, which require individual certification letters held by the companies, the list below is probably the 90% solution without getting industry groups such as ICSA labs.</div><div>&nbsp;</div><div>NIST FIPS 140 certifications: http://csrc.nist.gov/groups/STM/cmvp/index.html</div><div>NIST algorithm certifications: http://csrc.nist.gov/groups/STM/cavp/index.html</div><div>NIAP/Common Criteria: http://niap.bahialab.com/cc-scheme/</div><div>DISA IASE: http://iase.disa.mil/index2.html</div><div>NSA IAD: http://www.nsa.gov/ia/index.cfm</div><div>&nbsp;</div><div>NOTE - A PPL list can range from algorithms to specific equipment configurations. For example, one radio might have FIPS approval when ordered using model number 123 and an NSA type-1 certification when ordered using model number 456.<span>&nbsp;&nbsp; Same is true for a router, IPS,...&nbsp;&nbsp;&nbsp;&nbsp; Yet even if a device has a CC EAL-4 certification, you still need to ensure that the protection profile used and the security target meets your specific application.</span></div><div><strong>&nbsp;</strong></div><div><strong>&nbsp;</strong></div><div><strong><em>DoDD 8500.01E, October 24, 2002</em></strong><em>&nbsp;&nbsp; &nbsp;&nbsp;(</em> ENCLOSURE 1, REFERENCES (Continued))</div><div>(e) DoD CIO Memorandum 6-8510, &quot;Guidance and Policy for Department of Defense Global Information Grid Information Assurance,&quot; June 16, 2000 (<em><span>hereby canceled</span></em>)</div><div>(f) DoD 5025.1-M, &quot;DoD Directives System Procedures,&quot; <em>March 5, 2003</em></div><div>(g) Executive Order 12333, &quot;United States Intelligence Activities,&quot; December 4, 1981</div><div>(h) DoD Directive <em>5144.1, &ldquo;Assistant Secretary of Defense for Networks and Information Integration/DoD Chief Information Officer (ASD(NII)/DoD CIO),&rdquo; May 2, 2005</em></div><div>(i) National Security Telecommunications and Information Systems Security Instruction (NSTISSI) No. 4009, &quot;National Information Systems Security Glossary,&quot; September 20002</div><div>(j) OMB Circular A-130, &quot;Management of Federal Information Resources, Transmittal 4,&quot; November 30, 2000</div><div>(k) DoD Directive 5000.1, &quot;The Defense Acquisition System,&quot; <em>May 12, 2003</em></div><div>(l) Sections 1423 and 1451 of title 40, United States Code, &quot;Division E of the Clinger-Cohen Act of 1996&quot;</div><div>(m) DoD Directive O-8530.1, &quot;Computer Network Defense,&quot; January 8, 2001</div><div>(n) DoD 5200.2-R, &quot;DoD Personnel Security Program,&quot; <em>December 16, 1986</em></div><div>(o) DoD 5200.1-R, &quot;DoD Information Security Program Regulation,&quot; January 14, 1997</div><div>(p) DoD Directive 5230.11, &quot;Disclosure of Classified Military Information to Foreign Governments and International Organizations,&quot; June 16, 1992</div><div>(q) DoD Directive 5230.20<em>E</em>, &quot;Visits <em>and </em>Assignments of Foreign Nationals,&quot; <em>June 22, 2005</em></div><div>(r) DoD Instruction 5230.27, &quot;Presentation of DoD-Related Scientific and Technical Papers at Meetings,&quot; October 6, 1987</div><div>(s) DoD Directive 5230.9, &quot;Clearance of DoD Information for Public Release,&quot; April 9, 1996</div><div>(t) DoD Instruction 5230.29, &quot;Security and Policy Review of DoD Information for Public Release,&quot; August 6, 1999</div><div>(u) DoD Instruction 5200.40, &quot;DoD Information Technology Security Certification and Accreditation (C&amp;A) Process (DITSCAP),&quot; December 30, 1997</div><div>(v) DoD Directive C-5200.5, &quot;Communications Security (COMSEC),&quot; (U) April 21, 1990</div><div>(w) National Security Telecommunications and Information Systems Security Policy (NSTISSP) No. 11, &quot;National Policy Governing the Acquisition of Information Assurance (IA) and IA-enabled Information Technology Products,&quot; January 2000</div><div>(x) DoD Directive <em>3020.40, &ldquo;Defense Critical Infrastructure Program (DCIP),&rdquo; August 19, 2005</em></div><div>(y) DoD 5220.22-M, &quot;National Industrial Security Program Operating Manual,&quot; January 1995 and &quot;National Industrial Security Program Operating Manual Supplement,&quot; February 1995</div><div>&nbsp;</div><div><strong>&nbsp;</strong></div><div><strong>&nbsp;</strong></div><div><strong>****&nbsp;<a name="OLE_LINK1">CJSCSI 6510.1E, </a>Information Assurance And Computer Network Defense</strong>.</div><div>a. Joint Pub 1-02 Series, &ldquo;Department of Defense Dictionary of Military and Associated Terms&rdquo;</div><div>b. CNSS Instruction No. 4009 Series, &ldquo;National Information Assurance (IA) Glossary&rdquo;</div><div>c. DOD Directive 8500.1 Series, &ldquo;Information Assurance (IA)&rdquo;</div><div>d. DOD Directive O-8530.1 Series, &ldquo;Computer Network Defense (CND)&rdquo;</div><div>e. DOD Instruction 8500.2 Series, &ldquo;Information Assurance (IA) Implementation&rdquo;</div><div>f. DOD Instruction O-8530.2, 9 March 2001, &ldquo;Support to Computer Network Defense (CND)&rdquo;</div><div>g. CJCSM 6510.01 Series, &ldquo;Defense-in-Depth: Information Assurance (IA) and Computer Network Defense (CND)&rdquo;</div><div>h. DOD Directive 8100.1 Series, &ldquo;Global Information Grid (GIG) Overarching Policy&rdquo;</div><div>i. DOD CIO Memorandum, 6 July 2006, &rdquo;Department of Defense (DoD) Information Assurance (IA) and Certification and Accreditation (C&amp;A) Process Guidance&rdquo;</div><div>j. DOD Instruction 8551.1 Series, &ldquo;Ports, Protocols and Services Management (PPSM)&rdquo;</div><div>k. CJCSI 6211.02 Series, &ldquo;Defense Information System Network (DISN): Policy, Responsibilities and Processes&rdquo;</div><div>l. CNSSP-1 Series, &ldquo;National Policy for Safeguarding and Control of Communications Security Materials&rdquo;</div><div>m. DOD Regulation 5200.1-R Series, &ldquo;Information Security Program&rdquo;</div><div>n. National Security Agency, 2003/2004, &ldquo;Information Assurance Manual&rdquo;</div><div>o. Title 10, United States Code, Section 2315</div><div>p. NSTISSP No. 11 Revised, June 2003, &ldquo;National Policy Governing the Acquisition of Information Assurance (IA) and IA-Enabled Information Technology Products&rdquo;</div><div>q. Title 15, United States Code, Section 278g-3</div><div>r. ASD(NII) memorandum, 28 May 2003, &quot;Open Source Software in the Department of Defense&quot;</div><div>s. NIST Special Publication 800-59, August 2003, &ldquo;Guidelines for Identifying an Information System as a National Security System&rdquo;</div><div>t. DOD Instruction 8552.01 Series, &quot;Use of Mobile Code Technologies in DoD Information Systems&quot;</div><div>u. NTISSP No. 200, 15 July 1987, &ldquo;National Policy on Controlled Access Protection&rdquo;</div><div>v. DOD Regulation 5200.2-R Series, &ldquo;Personnel Security Program&rdquo;</div><div>w. ASD(C3I) memorandum with amendment, 11 January 2002, &ldquo;Web Site Administration, Policies and Procedures&rdquo;</div><div>x. DOD Directive 5230.9 Series, &ldquo;Clearance of DOD Information for Public Release&rdquo;</div><div>y. DOD Instruction 5230.29 Series, &ldquo;Security and Policy Review of DOD Information for Public Release&rdquo;</div><div>z. DOD CIO Memorandum, 25 April 2006, &quot;Guidance to Facilitate Information Sharing on DoD Information Technology Systems (U)&quot;</div><div>aa. DOD Directive 1035.1 Series, &ldquo;Telework Policy for Department of Defense&rdquo;</div><div>bb. DOD Directive 5200.1 Series, &ldquo;DOD Information Security Program&rdquo;</div><div>cc. DOD Directive 5200.2, 9 April 1999, &ldquo;DOD Personnel Security Program&rdquo;</div><div>dd. CJCSI 3213.01 Series, &ldquo;Joint Operations Security&rdquo;</div><div>ee. NTISSD No. 600, 10 April 1990, &ldquo;Communications Security (COMSEC) Monitoring&rdquo;</div><div>ff. DOD Directive 4640.6, 26 June 1981, &ldquo;Communications Security Telephone Monitoring and Recording&rdquo; </div><div>gg. Title 18, United States Code, Section 2510, et seq.</div><div>hh. Title 50, United States Code, Section 1801, et seq.</div><div>ii. DISA, 4 October 2002, &ldquo;Application Security Developer&rsquo;s Guide, Version 1.0&rdquo;</div><div>jj. ASD(C3I) memorandum, 16 January 1997, &ldquo;Policy on Department of&nbsp;Defense Electronic Notice and Consent Banner&rdquo;</div><div>kk. DOD General Counsel memorandum, 27 March 1997, &ldquo;Communications&nbsp;Security (COMSEC) and Information Systems Monitoring&rdquo;</div><div>ll. DOD Directive 8520.2, 1 April 2004, &ldquo;Public Key Infrastructure (PKI) and Public Key (PK) Enabling&rdquo;</div><div>mm. DOD Directive 8570.1 Series, &quot;Information Assurance Training, Certification, and Workforce Management&quot;</div><div>nn. DOD 8570.01-M Series, &quot;Information Assurance Workforce Improvement Program&quot;</div><div>oo. NSTISSP No. 101, 14 September 1999, &ldquo;National Policy on Securing Voice Communications&rdquo;</div><div>pp. FIPS 140-2, 25 May 2001, &ldquo;Security Requirements for Cryptographic Modules&rdquo;</div><div>qq. DOD CIO memorandum, 3 July 2007, &quot;Encryption of Sensitive Unclassified Data at Rest on Mobile Computing Devices and Removable Storage Media&quot;</div><div>rr. USSTRATCOM, 11 August 2006, &quot;Joint Concept of Operations for Global Information Grid NetOps&quot;</div><div>ss. DOD Directive 3020.40, 19 August 2006, &quot;Defense Critical Infrastructure Program&quot;</div><div>tt. DCID 6/3, 5 June 1999, &ldquo;Protecting Sensitive Compartmented Information Within Information Systems&rdquo;</div><div>uu. CJCSI 3213.01 Series, &quot;Joint Operations Security&quot;</div><div>vv. CJCSI 3121.01 Series, &ldquo;Standing Rules of Engagement/Standing Rules for the Use of Force&rdquo;</div><div>ww. CJCSI 6510.06 Series, &ldquo;Communications Security Releases to Foreign Nations&rdquo;</div><div>xx. CJCSI 6212.01 Series, &ldquo;Interoperability and Supportability of Information Technology and National Security Systems&rdquo;</div><div>yy. CJCSI 3137.01 Series, &ldquo;The Joint Warfighting Capabilities Assessment Process&rdquo;</div><div>zz. CJCSI 3170.01 Series, &ldquo;The Functional Capabilities Board Process&rdquo;</div><div>aaa. ASD(C3I) memorandum, 26 February 2003, &ldquo;Guidance for Computer Network Defense Response Actions&rdquo;</div><div>bbb. DOD Directive 8581.1E Series, &quot;Information Assurance (IA) Policy for Space Systems Used by the Department of Defense &quot;</div><div>ccc. Strategic Command Instruction (SI) 1009-01, 1 August 2006, &quot;Information Assurance (IA) Implementation for Space Systems Used by the Department of Defense&quot;</div><div>ddd. CJCSI 2300.01 Series, &rdquo;International Agreements&rdquo;</div><div>eee. CJCSI 5130.01 Series, &ldquo;Relationships Between Commanders of Combatant Commands and International Commands and Organizations&rdquo;</div><div>fff. CJCSI 5221.01 Series, &ldquo;Delegation of Authority to Commanders of Combatant Commands to Disclose Classified Military Information to Foreign Governments and International Organizations&rdquo;</div><div>ggg. DOD Directive 4630.5, 5 May 2004, &ldquo;Interoperability and Supportability of Information Technology (IT) and National Security Systems (NSS)&rdquo;</div><div>hhh. DOD 000-151-94, 24 May 1994, &ldquo;Department of Defense Intelligence Production Program (DoDIPP)&rdquo;</div><div>iii. DIA message 021727Z JUN 98, &ldquo;Indications and Warning for Information&nbsp;Warfare/Information Operations (CNA-WATCHCON)&rdquo;</div><div>jjj. NSD-42, 5 July 1990, &ldquo;National Policy for the Security of National Security Telecommunications and Information Systems&rdquo;</div><div>kkk. Initial Capabilities Document (ICD), 6 March 2006, &quot;Initial Capabilities Document (ICD) for Global Information Grid (GIG) Information Assurance (IA)&quot;</div><div>lll. NSTISSD No. 503, 30 August 1993, &ldquo;Incident Response and Vulnerability Reporting for National Security Systems&rdquo;</div><div>mmm. Strategic Command Directive (SD) 527-1, 27 January 2006, &quot;Department of Defense (DOD) Information Operations Condition (INFOCON) System Procedures&quot;</div><div>nnn. CJCSM 3402.01 Series, &ldquo;Alert System of the Chairman of the Joint Chiefs of Staff&rdquo;</div><div>ooo. Military Extraterritorial Jurisdiction Act of 2000, 18 U.S.C. 3261, et seq.</div><div>ppp. DOD Instruction 3020.41 Series, &ldquo;Contractor Personnel Authorized to Accompany the U.S. Armed Forces.&rdquo;</div><div>qqq. JTF-GNO Technical Bulletin 06-005, 191500Z May 2006, &quot;Coordinating Authorized Scanning Activity Across DOD Networks&quot;</div><div>rrr. CJCSI 3401.01 Series, &ldquo;Chairman&rsquo;s Readiness System&rdquo;</div><div>sss. CJCSI 3401.03 Series, &ldquo;Information Assurance (IA) and Computer Network Defense (CND) Joint Quarterly Readiness Review (JQRR) Metrics&rdquo;</div><div>ttt. CJCSI 6731.01 Series, &ldquo;Global Command and Control System Security Policy&rdquo;</div><div>uuu. Deputy Secretary of Defense memorandum, July 2000, &ldquo;Use and Protection of Portable Computing Devices&rdquo;</div><div>vvv. DOD Directive 8100.2 Series, &quot;Use of Commercial Wireless Devices, Services, and Technologies in the Department of Defense (DOD) Global Information Grid (GIG)&quot;</div><div>www. DOD Directive, C-5200.19, 16 May 1995, &ldquo;Control of Compromising Emanations&rdquo;</div><div>xxx. ASD(NII) memorandum, 2 June 2006, &quot;Use of Commercial Wireless Local-Area Network (LAN) Devices, Systems and Technologies in Department of Defense (DoD) Global Information Grid (GIG)&quot;</div><div>yyy. PL 104-191, 21 August 1996, Health Insurance Portability and Accountability Act of 1996&quot;</div><div>zzz. Title 5, U.S.C., Section 552a, et seq.</div><div>aaaa. DOD Directive C-5200.5 Series, &ldquo;Communications Security (COMSEC)&rdquo;</div><div>bbbb. CJCSI 6510.02 Series, &quot;Cryptographic Modernization Planning&quot;</div><div>cccc. CJCSN 6510 Series, &quot;Information Assurance Cryptographic Equipment Modernization Requirements&quot;</div><div>dddd. Special Publication 800-34 Series, &ldquo;Contingency Planning Guide for Information Technology Systems&rdquo;</div><div>eeee. DOD Directive 5200.8, 25 April 1991, &ldquo;Security of DoD Installations and Resources&rdquo;</div><div>ffff. Title 44, U.S.C. Section 3542, Federal Information Security Management Act of 2002</div><div>gggg. American National Standard for Telecommunications, 28 February 2001, &ldquo;Telecom Glossary&rdquo;</div><div>hhhh. National Military Strategy for Cyberspace Operations, November 2006</div> Information Systems Auditor Sr. http://www.sdissa.org/pages/article.php?story=20071029105647201 http://www.sdissa.org/pages/article.php?story=20071029105647201 Mon, 29 Oct 2007 10:56:00 -0700 Careers <font face="Arial"><div><strong>Company: </strong>Scripps Health, San Diego, CA</div><div><strong>Contact:</strong> <font face="Arial">Human Resources - <a href="mailto:esparza.veronica@scrippshealth.org">esparza.veronica@scrippshealth.org</a></font></div><div><strong>Status:</strong> Position Open</div><div><strong>Type: </strong>Full Time</div></font> <div><div><span>Join a dynamic organization where you will be challenged and grow with a fast-paced, technology driven, leading healthcare organization with over 11,000 employees. </span><span>This position is a key member of a nationally prominent Audit &amp; Compliance Services Department and Information Security Team. Responsibilities will include, but are not limited to: reviews of implemented clinical and business application system controls, IT general controls for key infrastructure components, and new implementation projects.</span></div></div><div>&nbsp;</div><div><font size="2">The position will lead team reviews and oversee activities or other auditors, conduct audits and review processes and safeguards to protect the organization&rsquo;s information system resources and their data confidentiality, integrity, and availability, as well as assess related security system vulnerabilities for: application software systems, operating systems, telecommunication networks, disaster recovery, as well as Scripps policies, Information Technology procedures, and standards. Also, the position will provide support for compliance and investigative audit projects that are part of the annual audit plan or initiated based on new implementation projects, develop plans for remediation of internal control gaps and deficiencies, reducing costs, and or improving operational efficiency and effectiveness.</font></div><div>&nbsp;</div><div><font size="2"><strong>Basic Qualifications:</strong> Bachelor&rsquo;s degree required in Accounting, Management Information Systems, Computer Engineering, Computer Science, or a related discipline.&nbsp;At least two of the certifications of CISA, CIA, and CPA designations in good standing at the time of hire are required or successful active pursuit of these designations within 12 months of hire. Required experience/Specialized Skills:&nbsp;Ability to evaluate and audit complex information systems and related information security safeguards.&nbsp;Technical knowledge of information security concepts, information technology internal controls and safeguards, technologies, system vulnerabilities, and applicable rules and regulations.&nbsp;Understanding of key clinical information systems and processes in an integrated healthcare delivery environment.&nbsp;Knowledge of the IIA professional auditing standards, as well as internal and information security control frameworks and principles. Demonstrated effective interpersonal, written, and verbal communication skills.&nbsp;High level of personal accountability for accuracy, attention to detail, task prioritization, and timely completion.&nbsp;Ability to work independently under conditions of changing priorities due to investigations and special requests; important deadlines; and rapid response to security incidents.&nbsp;Strong technical skills and ability to learn and deploy computer assisted audit techniques (CAAT) through ACL audit software and other tools. </font></div><div>&nbsp;</div><div><font size="2"><strong>Preferred Qualifications:</strong> Master's preferred.</font></div><div>&nbsp;</div><div><font size="2">Please send your resume together with your salary requirements. Initial salary will be commensurate with experience and qualifications. The position will remain open until filled. To apply, visit us online at: </font></div><div><strong><font size="2">Website: </font><a href="http://www.scripps.org/"><span><font size="2">www.scripps.org</font></span></a></strong></div><div>&nbsp;</div><div><font size="2">For further information, please contact:</font></div><div><strong><a href="mailto:esparza.veronica@scrippshealth.org"><span><font size="2">esparza.veronica@scrippshealth.org</font></span></a><font size="2"> &ndash; Human Resources</font></strong></div><div><strong><font size="2">Address: Scripps Health-CP2</font></strong></div><div><font size="2"><strong>4275 Campus Point Court</strong></font></div><div><font size="2"><strong>San Diego</strong><strong>, CA 92121</strong></font></div><div><strong><font size="2">EEO/ AA</font></strong></div><div>&nbsp;</div> Where do I get a copy of the presentation from last month’s meeting? http://www.sdissa.org/pages/article.php?story=20070921082531585 http://www.sdissa.org/pages/article.php?story=20070921082531585 Fri, 21 Sep 2007 08:25:31 -0700 SD ISSA <ul> <li><font face="Arial">Did you attend last month&rsquo;s meeting and wish you had gotten a copy of the PowerPoint presentation?</font> </li> <li><font face="Arial">Are you looking to network with other local security professionals and peers?</font> </li> <li><font face="Arial">Are you looking to improve your own career opportunities or are trying to fill a security position within your department?</font> </li> <li><font face="Arial">Do you want to get a discount at the next annual security conference?</font> </li> <li><font face="Arial">Would you like a forum to discuss with your peers the latest trends in technology, Information Assurance, governance, and risk management?&nbsp;</font>&nbsp; </li></ul><p><font face="Arial">These are all reasons why you should consider joining the San Diego Chapter of the ISSA.&nbsp; There are of course lots more benefits, so what we&rsquo;ve listed here only scratches the surface.&nbsp; Once you become a member, you can receive a logon access to the secure portion of our chapter website where you can have full access to all of the resources described in the questions above.&nbsp; <a href="http://www.sdissa.org/pages/staticpages/index.php?page=membership">Click here</a> to get more information about becoming a member.</font></p> Security Engineer http://www.sdissa.org/pages/article.php?story=20070920165149641 http://www.sdissa.org/pages/article.php?story=20070920165149641 Thu, 20 Sep 2007 16:51:00 -0700 Careers <p><strong>Company:</strong> Network Vigilence<br /><strong>Contact:</strong> Network Vigilence Human Relations <a href="mailto:hr@netvig.com?subject=Security%20Engineer%20position%20posted%20at%20SDISSA.org">hr@netvig.com</a><br /><strong>Status:</strong>&nbsp; Position OPEN</p> <div><strong><span>Title: &nbsp;Security Engineer - Step Up your Career into Network Security</span></strong></div><div>&nbsp;</div><div><span>Do you want to step up your career into one of the most challenging and rapidly growing IT professions?&nbsp;</span></div><div>&nbsp;</div><div><span>Are you an experienced Network Engineer that understands how to be consultative and personable with clients? </span></div><div>&nbsp;</div><div><span>Can work under a time crunch, figure just about anything out, and quickly learn new technologies even if it means doing it on your own time?</span></div><div>&nbsp;</div><div><span>Have you been looking for that perfect career growth opportunity that will allow you to go to the next level, building upon your solid network experience with security expertise?&nbsp;</span></div><div>&nbsp;</div><div><span>Do you have a deep interest in the world of IT security including hacking/cracking, risk assessments, penetration testing, computer forensics, Network Access Control, Firewalls, intrusion detection, security incident management, encryption, honeypots, and other security technology?</span></div><div>&nbsp;</div><div><span>Then, this might be the perfect opportunity for you.&nbsp;Network Vigilance is a nationally known, 17 year-old information security firm based in San Diego, California.&nbsp;We excel in providing security consulting/guidance, IT risk assessments, Firewall/VPN implementations, IDS/IDP NAC, endpoint, remote access and wireless security solutions, forensic analysis, and managed security services.</span></div><div>&nbsp;</div><div><span>We are seeking an a Senior Network Engineer, who we can develop into a competent Security Engineer, one who has excellent troubleshooting skills, is motivated to learn the security trade, can give great customer service and can perform implementation of various security products, including Check Point Cisco, Juniper, Symantec, Secure Computing, Websense, SourceFire, and others.</span></div><div>&nbsp;</div><div><span>This individual would ideally assist with risk assessments, provide technical product support to existing clients, roll out new security deployments, baseline and tune security devices and systems, implement anti-spam and Web filtering technologies, provide end-user network technical support including occasional weekend and after hours support if necessary.</span></div><div>&nbsp;</div><div><span>Ideal certifications would include MCSE, CCNA, CCNP, A+, N+, MCP, Citrix, VMWare, GIAC, or other security certifications, however experience is more important than certs.&nbsp;</span></div><div>&nbsp;</div><div><span>An excellent background for this role would include high level network administration/network support on Microsoft Server based products, (Windows 2000/2003 Server, IIS, SQL Server, Exchange, ISA, etc.), high level system troubleshooting, Linux/Unix servers, routing and switching, deployment of enterprise firewalls, IDS/IPS, and past deployment or consulting experience with network/security products or services.</span></div><div>&nbsp;</div><div><span>If this seems like appears like the perfect opportunity for you and please send us your resume at <a href="mailto:hr@netvig.com?subject=Security%20Engineer%20position%20posted%20at%20SDISSA.org">hr@netvig.com</a>.&nbsp;Please note that there is no relocation assistance offered for this position.&nbsp;Also, an in-person interview if not multiple interviews in San Diego will also be required, including a technical assessment.</span></div> Security Engineer http://www.sdissa.org/pages/article.php?story=20070920115011163 http://www.sdissa.org/pages/article.php?story=20070920115011163 Thu, 20 Sep 2007 11:50:11 -0700 Careers <font size="2"><div><font size="2"><strong>Company:</strong> Cardinal Health</font></div><div><font size="2"><strong>Contact:</strong>&nbsp;Cardinal Health Staffing&nbsp;&nbsp;<a href="mailto:chris.price@cardinalhealth.com?subject=Security%20Engineer%20position%20posted%20at%20SDISSA.org">chris.price@cardinalhealth.com</a></font></div><div><font size="2"><strong>Status:</strong> </font><font size="2">Position OPEN</font></div></font> <div><div><strong><font size="2">I.</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></strong><strong><font size="2">Basic Function:&nbsp;</font></strong></div></div><div><strong>&nbsp;</strong></div><div><font size="2">This candidate will be a member of a cross functional security team that is responsible for the Certification and Accreditation (e.g., DITSCAP/DIACAP) of products deployed in a government setting as well as for implementing and monitoring of the Company&rsquo;s information security policies and procedures to ensure that electronic protected health information (ePHI) is handled in an appropriate manner and meets all legislative requirements, such as those required by HIPAA.</font></div><div>&nbsp;</div><table style="BORDER-COLLAPSE: collapse" cellspacing="0" cellpadding="0" border="0"> <tbody> <tr> <td valign="top"> <div><strong>&nbsp;</strong></div> <div><strong><font size="2">II. Specific Duties, Activities, and Responsibilities:</font></strong></div> </td> <td valign="top"> <div><strong>&nbsp;</strong></div> <div><strong><font size="2">% of time</font></strong></div> </td> <td> <div><font size="2">&nbsp;</font></div> </td> </tr> <tr> <td valign="top"> <div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Develop and maintain company information security policies and procedures ensuring compliance with HIPAA security rules as well as government specific (e.g., DIACAP) rules and regulations</font></div> <div><span><font size="2">o</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Perform security scans and audits of various systems in order to ensure all compliance regulations are met</font></div> </td> <td valign="top"> <div><strong><font size="2">30%</font></strong></div> </td> <td> <div><font size="2">&nbsp;</font></div> </td> </tr> <tr> <td valign="top"> <div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Reviews updates and provides compliant specifications for operating systems, databases, and third party software as required</font></div> <div><span><font size="2">o</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Ensures that all CTS products maintain status as DITSCAP/DIACAP accredited and adhere to HIPAA regulatory standards, rules, or regulations with respect to technical security of product and information within the product</font></div> <div><span><font size="2">o</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Tests systems and ensures that all certified product security related issues are identified, and issues corrective actions as necessary</font></div> </td> <td valign="top"> <div><strong><font size="2">25%</font></strong></div> </td> <td> <div><font size="2">&nbsp;</font></div> </td> </tr> <tr> <td valign="top"> <div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Advises appropriate business units on current technical security regulation</font></div> <div><span><font size="2">o</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Conducts appropriate reviews, audits, and metrics of accredited products</font></div> <div><span><font size="2">o</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Coordinates completion/updates for product certification and accreditation</font></div> </td> <td valign="top" colspan="2"> <div><strong><font size="2">25%</font></strong></div> </td> </tr> <tr> <td valign="top"> <div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Establishes/maintains appropriate QMS policies and guidelines for product teams</font></div> <div><span><font size="2">o</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Maintains on-going lifecycle accreditation for certified products</font></div> <div><span><font size="2">o</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Conducts assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information (ePHI)</font></div> </td> <td valign="top" colspan="2"> <div><strong><font size="2">15%</font></strong></div> </td> </tr> <tr> <td valign="top"> <div><a name="OLE_LINK1"><span><span><font size="2">&sect;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><font size="2">Performs special projects, assists in problem solving and quality initiatives as required</font></span></a></div> </td> <td valign="top" colspan="2"> <div><strong><font size="2">5%</font></strong></div> </td> </tr> </tbody></table><div><strong>&nbsp;</strong></div><div><strong><font size="2">III. &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Position Requirements:</font></strong></div><div><font size="2"><strong>Reports to:&nbsp;</strong><strong><span>Sr. Security Engineer</span></strong>&nbsp;&nbsp;&nbsp;&nbsp; </font></div><div><font size="2"><strong>Supervises: &nbsp;</strong>Self</font></div><div><font size="2"><strong>Education or Equivalent:&nbsp;</strong>BA/BS in related field</font><span> or equivalent combination of education and experience.</span></div><div>&nbsp;</div><div><strong><font size="2">Experience/Knowledge/Skills Requirements:</font></strong></div><div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span><font size="2">Bachelors degree in Information Systems or equivalent experience</font></span></div><div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span><font size="2">6 years experience in information systems with at least 2 years focus on network security</font></span></div><div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span><font size="2">Experience with network/system security scanning tools</font></span></div><div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span><font size="2">Healthcare experience and CISSP is highly desirable</font></span></div><div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span><font size="2">At least two years experience administering or directing security risk management and network compliance programs</font></span></div><div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span><font size="2">Knowledge and expertise in Federal government regulations (DITSCAP/DIACAP, NICAP, OMB 130, DoD 5800.2 NIST 800-37, FIPS 140-1, &amp;2, FIPS 199, HIPAA, etc).</font></span></div><div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span><font size="2">Being a highly motivated self-starter with the ability to handle multiple tasks</font></span></div><div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span><font size="2">Possess excellent conflict resolution and negotiation skills</font></span></div><div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span><font size="2">Demonstrate strong decision-making and problem-solving skills</font></span></div><div><span><font size="2">&middot;</font><span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><span><font size="2">Excellent verbal and written communication skills</font></span></div><div>&nbsp;</div><div><font size="2">These are only minimum qualifications for this position at this grade level.&nbsp;Other factors taken into consideration when deciding what position and grade level to place an employee such as performance level, capable contribution and company need.</font></div><div>&nbsp;</div><div><font size="2"><strong>Work Environment:&nbsp;</strong>Works out of and performs primary duties in the San Diego Corporate Office.</font></div><div><font size="2"><strong>Compensation:&nbsp;</strong>Competitive compensation based upon experience with an excellent benefits package.</font></div><div><strong>&nbsp;</strong></div> Seeking Subject Matter Experts http://www.sdissa.org/pages/article.php?story=20070514174621628 http://www.sdissa.org/pages/article.php?story=20070514174621628 Mon, 14 May 2007 17:46:00 -0700 SD ISSA Are you a Subject Matter Expert (SME)?&nbsp; Would you like to assist the chapter answering questions on your subject of expertise?&nbsp; From time-to-time SD ISSA receives calls from local media, schools, and businesses for our opinion, judgment, discernment on various information security topics.&nbsp; If you would like to be included on our SME Listing <a href="http://www.sdissa.org/pages/fckeditor/editor/president@sdissa.org?subject=SME%20Listing&amp;body=Contact%20Peter%20Bybee%20for%20consideration%20to%20be%20included%20on%20the%20SD%20ISSA%20SME%20Listing.">please contact Peter Bybee</a>.&nbsp; <span><font size="2" face="Arial">Peter will follow up with you on your SME nomination.</font></span>&nbsp; We need you're expertise to service our community.