网络安全服务 - 渗透测试与漏洞评估
Cyber Security Services - Penetration Testing and Vulnerability Assessments
仅限在澳大利亚居住的澳大利亚公民回复。
- 合同开始时间:2023年11月1日,为期12个月,可延长两次,每次12个月。
- 澳大利亚公民,堪培拉,非现场(偶尔需要面对面会议)职位。
请将您的回复发送至
概述
需要聘请合格且有经验的候选人,以开展组合项目中的安全测试活动,帮助了解安全漏洞、风险和/或问题,并在适当的情况下推荐修复漏洞和减轻任何风险和问题的措施。
NDIA正在开展多项涉及关键业务系统开发以及基于云的桌面环境的项目。
成功的候选人将提供混合的漏洞评估、渗透测试和代码审查服务。所提供的服务和所需细节将根据NDIA的需求而变化。
· 关键交付成果和验收标准
需要聘请合格且有经验的候选人,对项目组合进行多项漏洞评估、渗透测试和代码审查活动,并记录结果,以帮助理解未解决的风险或问题,并在适当的情况下建议缓解这些风险和问题的措施。每个任务都需要以下两个交付成果:
成功的候选人将补充NDIA项目团队(包括NDIA聘用的资源和外部供应商);并期望能够与位于NDIA总部274 Reed St, Greenway, ACT的NDIA网络安全团队进行面对面会议。在堪培拉远程办公是可接受的。
候选人必须展示其人员适当的的技术能力,以执行网络安全测试。这可能包括:
· 持有认证信息系统安全专家(CISSP)和/或安全经理(CISM)资质的员工,
· 在复杂云和多供应商环境中工作的经验,
· 应用信息安全手册的经验,
· 使用安全工具的经验,
每份申请都需在申请提交时针对选拔标准进行说明。
必备条件
1. 有组织经验进行漏洞评估和渗透测试,包括Salesforce和基于云的环境(例如微软Azure和亚马逊网络服务),占40%
2. 相关技术能力(包括对ASD基本8项控制措施和信息安全管理的了解)
查看英文原文
Australian Citizens residing in Australia only respond.
- Contract start 01 November 2023 to 12 months, 2 x 12 months extensions.
- Australian Citizen, Canberra, Offsite(Occasional face to face meetings will be required) role.
Send your responses to
Overview
The services of a suitably qualified and experience Candidates are required to undertake security testing activities across the portfolio of projects to help understand security vulnerabilities, risks and/or issues, and where appropriate recommend actions to remediate vulnerabilities and mitigate any risks and issues.
The NDIA is undertaking a number of projects involving development of critical business systems as well as a cloud-based desktop environment.
The successful Candidate will provide a mix of vulnerability assessments, penetration teste and code reviews. The mix of services and detail required will vary with NDIA needs.
· Key Deliverables and Acceptance
The services of a suitably qualified and experience candidates are required to conduct and document a number of Vulnerability Assessments, Penetration Testing and Code Review activities across the portfolio of projects to help understand any unresolved risks or issues, and where appropriate recommend steps to mitigate those risks and issues. The following two deliverables will be required for each assignment:
The successful candidates will augment the NDIA project team (comprising NDIA engaged resources and external suppliers); and are expected to be available for face-to-face meetings with the NDIA Cyber Security team located in NDIAs premises at 274 Reed St, Greenway, ACT. Remote work offsite in Canberra would be acceptable.
The Candidate must demonstrate appropriate technical capability of their personnel to perform cyber security testing. This may include:
· Certified Information Systems Security Professional (CISSP) and/or Security Manager (CISM) accredited staff,
· Experience in a complex cloud and multi-vendor environment,
· Experience applying the Information Security Manual,
· Experience using security tools,
Every application requires to address selection criteria as part of application submission.
Essential Criteria
1. Relevant organisational experience undertaking Vulnerability Assessments and Penetration Testing including Salesforce and cloud-based environment (i.e such as Microsoft Azure & Amazon Web Services) 40%
2. relevant technical capability (including working knowledge of ASDs Essential 8 controls and the Information Security Manual) and experience in delivering similar services 25%
Originally posted on Himalayas