Senior Consultant - Enhanced Security Admin Environment (ESAE) - Non Location Specifi Job
Job Field: Legal Jobs
Location: REDMOND, WA
Salary: $-
Job Type: Part Time
JOB SUMMARY:
</tr>
</table>
<table border="0" bgColor="#F5F5F5" cellpadding="5" cellspacing="0" style="border-collapse: collapse" width="100%">
<tr>
<td align="left"><font style="font-size: 100%;">Job Category:Services & Consulting<BR>Location:, , US<BR>Job ID:814104-95451<BR>Division:Services & Support<BR><BR><BR>Do you have a passion for helping Microsoft''s clients defend themselves against targeted exploitation? Are you interested in being intimately involved in the latest, cutting-edge developments in the security industry, communicating with security industry leaders, and having a direct impact on the security of all Microsoft customers? Do you want to be on the front lines of helping our customers go toe-to-toe against advanced adversaries? Are you interested in a fast-paced job full of new opportunities? If so, you might be a candidate for the Microsoft Cybersecurity Team. The team is looking for a strong, experienced systems engineer/consultant to join our client-facing practice. Ideal candidates should meet the following skill requirements:<BR>Required:<BR>- Solid understanding of authentication protocols and mechanisms<BR>o Basic traffic flow of Kerberos and NTLM<BR>o Trusts types and configuration options<BR>o Configuration options (scope of impact, side effects, appcompat, etc.)<BR>o Protocol fallback, etc.<BR>o Advanced authentication protocols configuration<BR>o Pass the Hash - 300-400 level understanding of the common methodologies used to traverse laterally and elevate to higher privilege accounts<BR>- Experience using Network Monitor (NetMon) to troubleshoot connectivity, authentication, and IPsec issues<BR>- Solid understanding of Windows Firewall Policy and IP Security (IPsec)<BR>o Concepts<BR>o Troubleshooting (failure recognition and categorization)<BR>? - IPsec negotiation failure<BR>? - Host firewall block<BR>? - Network firewall block<BR>? - Use of NetMon in troubleshooting<BR>- General Active Directory Skills<BR>o AD Architecture<BR>o Replication configuration and troubleshooting<BR>o Group Types and Inheritance implications (UGLP, nesting, token bloat, etc.)<BR>- Group Policy<BR>o Security Compliance Manager<BR>o Group Policy Architecture (CSEs, user context of operations, etc.)<BR>o GPO Components, Sysvol contents, AD Objects<BR>o Familiarity with Logon Rights and Security Options settings<BR>- PKI/Smartcards<BR>o Windows PKI architecture<BR>o PKINIT modification of Kerberos<BR>o Configurations and Enforcement (policy, account, computers)<BR><BR>Desired:<BR>- Familiarity with deploying, configuring, and interpreting the output of Attack Surface analyzer (ASA)<BR>- Familiarity with deploying, configuring and handling crashes that could be due to the protections of the Enhanced Mitigation Experience Toolkit (EMET)<BR>- System Center (Forefront) Endpoint Protection configuration with GPOs and WSUS/SCCM updates<BR>- WSUS<BR>o Installation and Configuration<BR>o Configuration of auto-approval rules<BR>o Configuration of upstream/downstream WSUS<BR>- SCOM<BR>o Basic installation and maintenance<BR>o Configuring rules and unsealed management packs<BR>o Configuration of Agents across trust boundary<BR>o Specific solution configuration for solution (security management pack)<BR>o How to respond to security related events<BR>- Experience using MDT and troubleshooting depl </font></td>
</tr>
</table>
<table border="0" bgColor="#F5F5F5" cellpadding="0" cellspacing="0" style="border-collapse: collapse" width="100%">
<tr>