SonSoft Inc.
Jobs at SonSoft Inc.
Let Your Resume Do The Work
Upload your resume to be matched with jobs you're a great fit for.
Success! We'll use this to further personalize your experience.
Recently posted jobs
Information Technology • Professional Services • Software • Consulting
Provide cloud and security operations support: run Nessus scans; manage McAfee installs and policy updates; configure Splunk forwarders and dashboards; monitor AWS security configurations; support incident response, vulnerability analysis, remediation, and change control activities.
Information Technology • Professional Services • Software • Consulting
Implement and maintain the organization's risk management framework: perform risk identification, assessment, tracking, third-party supplier risk assessments, document security policies and controls, recommend remediation, report risks to stakeholders, and support security awareness, audits, and continuous improvement.
Information Technology • Professional Services • Software • Consulting
Assess and document security controls, perform risk, vulnerability and business impact assessments, develop test scripts and compliance frameworks, coordinate audits and remediation with business units, and report findings to management while supporting security policy and process development.
Information Technology • Professional Services • Software • Consulting
Implement and maintain enterprise risk management frameworks and processes. Conduct risk assessments and third-party supplier risk reviews, document security policies and control deficiencies, recommend remediations, report risk status, and provide training and governance support.
Information Technology • Professional Services • Software • Consulting
Operate vulnerability scanning (Nessus), manage McAfee and Splunk agents/policies, monitor AWS security controls, support incident response and security operations, assist with security hardening (RHEL), application security tasks, and participate in change control and ACI-related security activities.
Information Technology • Professional Services • Software • Consulting
Design and implement Identity & Access Management solutions (RSA SecurID). Lead process architecture, development/configuration, validation, deployment, and project/talent management. Requires extensive travel and strong communication and analytical skills.
Information Technology • Professional Services • Software • Consulting
Design, configure, validate and deploy Identity & Access Management solutions (RSA SecurID). Provide business process consulting, architecture/design, development/configuration, solution evaluation, and project/talent management in a consulting environment with regular travel.
Information Technology • Professional Services • Software • Consulting
Perform web and network penetration testing and secure code analysis using tools such as HP Fortify, WebInspect, Nessus, Burp, and IBM AppScan. Apply security frameworks (OWASP, NIST, ISO27001, PCI), analyze security NFRs/metrics, coordinate multiple projects, manage stakeholders, and support global delivery. Mobile security and telco domain experience are a plus.
Information Technology • Professional Services • Software • Consulting
Perform web and network penetration testing and secure code analysis using tools like HP Fortify, WebInspect, Nessus, Burp, and IBM AppScan. Apply security frameworks (OWASP, NIST, ISO27001, PCI), collaborate with stakeholders, coordinate projects, and work within global delivery teams. Mobile security and telco domain knowledge are a plus; relevant security certifications encouraged.
Information Technology • Professional Services • Software • Consulting
Lead application security activities including static and dynamic code analysis, penetration testing, and use of tools like Fortify, AppScan, CodeSecure, BurpSuite, Paros, and TemperIE. Perform development/configuration, solution validation and deployment, manage projects and talent, and work in a consulting environment requiring regular travel.
Information Technology • Professional Services • Software • Consulting
Lead application security consulting: define business processes, design secure architectures, perform source-code analysis and penetration testing, use Fortify/AppScan/CodeSecure and proxy tools (BurpSuite/Paros/TemperIE). Configure, validate, deploy solutions, manage projects and talent, and support client engagements requiring regular travel.
Information Technology • Professional Services • Software • Consulting
Lead vulnerability assessment and infrastructure security activities, manage AirWatch MDM and Symantec tools, develop/configure and validate security solutions, perform business process consulting, manage projects and talent, and travel regularly for management consulting engagements.
Information Technology • Professional Services • Software • Consulting
Lead infrastructure vulnerability assessment and security management activities, manage Air-Watch MDM and Symantec solutions, perform development/configuration/validation/deployment, provide business process consulting, and manage projects and talent in a consulting environment that requires regular travel.
Information Technology • Professional Services • Software • Consulting
Lead application security activities including security code reviews, vulnerability assessments, tool-based scanning, and consulting product development teams. Manage project delivery, customer relationships, and documentation while aligning work to OWASP/OSSTMM/SANS standards and security best practices. Work requires travel and project management in a consulting environment.
Information Technology • Professional Services • Software • Consulting
Contract Information Security Consultant to perform PCI assessments for a client in Sacramento through Dec 31, 2017 (possible extension). Requires documented experience conducting PCI assessments and holding CISSP and QSA certifications. Candidates must be authorized to work in the U.S.; employer cannot sponsor visas.
Information Technology • Professional Services • Software • Consulting
Design, configure, operate, and troubleshoot endpoint DLP systems; create and deploy access control rules; monitor and investigate DLP logs and incidents; coordinate testing with business owners; balance data protection with business needs and participate in incident response.
Information Technology • Professional Services • Software • Consulting
Design, implement, and manage large-scale network and security solutions (Cisco/Juniper). Lead incident resolution, stakeholder communications, IPv4 planning, monitoring, and customer-facing technical consulting with regular travel.
Information Technology • Professional Services • Software • Consulting
Lead and deliver Identity & Access Management solutions: design IAM processes, manage privileged accounts across platforms, administer DELL TPAM (PPM/PSM), perform development/configuration/deployment, ensure information security controls, and support project and consulting engagements that require regular travel.
Information Technology • Professional Services • Software • Consulting
Lead application security and business process consulting efforts: design and detail secure architectures, perform source-code analysis and penetration testing, use SAST/DAST tools (Fortify, AppScan, CodeSecure, BurpSuite, Paros, TemperIE), support development/configuration/validation/deployment, manage projects and talent, and travel regularly for consulting engagements.
Information Technology • Professional Services • Software • Consulting
Lead application security activities including static and dynamic analysis, source code review, and penetration testing using Fortify, AppScan, CodeSecure, BurpSuite and related tools. Provide security architecture and process design, manage projects and talent, perform solution validation and deployment, and support consulting engagements that require regular travel.



