IT’s Hottest Jobs: Information Security Architect

[Randy Gross]

Job title or job role:

Information Security Architect

Key responsibilities for this individual:

Information security architects plan and carry out security measures to protect an organization’s computer networks and systems. Their responsibilities are continually expanding as the number of cyberattacks increases

The information security architect is responsible for analyzing information security systems and applications, and recommending and developing security measures to protect information against unauthorized data modification or loss. Access control, intrusion detection, virus protection, certification, audit, incident response, security engineering, development and implementation of security policies and procedures are some of the areas that this individual is engaged in on a regular basis. Typical job responsibilities can include:

  • Designing security models; reviewing and approving security configurations and installation of firewall, VPN, routers, IDS scanning technologies and servers.
  • Overseeing security awareness programs; educating staff on information security policies, procedures and practices.
  • Monitoring industry security updates, technologies and best practices to improve security management.
  • Participating in the development of hardware/software/network security procedures and guidelines that support information security policies.

Top industries or markets needing this position:

Demand for information security architects is high. As cyberattacks grow in frequency and sophistication, many organizations find themselves falling behind in their ability to detect these attacks. Security architects are needed to develop innovative solutions to prevent hackers from stealing critical information or creating havoc on computer networks.

The federal government is expected to greatly increase its use of information security architects to protect the nation’s critical IT systems. In addition, as the healthcare industry expands its use of electronic medical records, ensuring patients’ privacy and protecting personal data are becoming more important. More information security architects will likely be needed to develop the safeguards that will satisfy patients’ concerns. Financial services companies also have a growing need for information security architects.

Preferred job roles or work background desired in this job role:

Candidates for the position of an information security architect should have at least eight to 10 years of experience in the IT field, with a broad range of exposure to all aspects of business planning, systems analysis and application development. Additionally, three to five years of experience specifically devoted to information security is advisable.

A bachelor’s degree (or advanced degree) in information technology, information security, computer science, mathematics or a related field is also the norm for this job.

Many employers will also require or prefer that candidates have advanced security-related industry certifications. Examples include CompTIA Security+, CompTIA Advanced Security Practitioner, Certified Information Systems Security Professional (CISSP), Certified Network Security Professional (CNSP) and Certified Hacking Forensics Investigator (CHFI).

Technology, business and soft skills needed for success in this role

Technology skills for an information security architect should include:

  • Knowledge of risk assessment procedures, policy formation, role-based authorization methodologies, authentication technologies and security attack pathologies
  • Technical proficiency in security-related hardware and software, forensics and other security systems and tools.
  • Technical proficiency in broader areas of IT, including networking, servers, desktops and mobile devices.

Desirable business and soft skills should include:

  • Oral and written communication skills with the ability to present and discuss technical information in a way that’s understandable for non-technical audiences.
  • The ability to lead both technical teams and project teams that cross multiple business functions.
  • Problem solving and analytical ability.
  • Strategic thinking and relationship management.

Top challenges of acquiring this talent:

Like many higher-level IT jobs, the role of information security architect is one that currently has more demand than supply. The Bureau of Labor Statistics reports that the employment outlook for security architects is expected to grow about 20 percent through the year 2018 as the need for information security and workers with security skills increases.

Best sources for recruiting individuals into this role:

Because the security architect is responsible for maintaining the security of a company’s computer system, they must think like a hacker would, anticipating the moves and tactics that hackers might use to try and gain unauthorized access to a computer system or network. Some IT experts feel that the best security architects are former hackers, making them very adept at understanding how the hackers will operate.

Best sources for developing internal staff into this role:

Many security architects begin their careers in entry-level positions as IT support specialists. This job provides the training necessary to become familiar with network systems, security and problem solving.

A lower level IT staff member often will demonstrate the aptitude and attitude to be trained and certificated for security-specific jobs. Someone in an entry-level position may operate software to monitor and analyze information, while a more senior-level position could be engaged in investigative work to determine whether a security breach has occurred.

Look for employees who demonstrate good organizational and problem-solving skills. They also need strong problem-solving and analytical skills

Time needed to train and “on-board” an individual into this role:

This is not an entry-level position. Many people venture into the occupation only after working in other IT roles such as computer technician.

Because of the critical nature of the information security architect, several years of experience in advanced security tasks is highly recommended. This experience may be gained by prepping an internal candidate for a senior security position; or recruiting an experienced security architect from another organization.

Candidates for the position of an information security architect should have at least eight to 10 years of experience in the IT field, with a broad range of exposure to all aspects of business planning, systems analysis and application development. Additionally, three to five years of experience specifically devoted to information security is advisable.

Competitive salary and benefits required to hire this individual:

The average pay for an information security architect is $106,974 per year, according to PayScale, a provider of data and insights around salary and career topics. Total pay for this position (salary and benefits) ranges from $82,714 to $157,556. Factors such as geographic location, known technologies, certifications and practical field experience can affect the salary level.

Best ways to measure success of the individual in this role:

The Information Security and Control Association has developed high-level guidance for information security governance and evaluation of security performance. They propose six areas that organizations should focus on when measuring the performance of security personnel and programs:

  1. The strategic alignment of information security in support of business objectives.
  2. Executing appropriate measures to mitigate risks and reduce potential impacts on information resources to an acceptable level.
  3. Integration of all relevant assurance functions to maximize the effectiveness and efficiency of security activities.
  4. Optimizing security investments in support of business objectives to achieve the best return on security investments.
  5. Using information security knowledge and infrastructure efficiently and effectively.
  6. Monitoring and reporting on information security processes to ensure that objectives are achieved.

About the author: Randy Gross is the Chief Information Officer for CompTIA, the ICT Industry Trade Association.

The Latest Kuluoz Spam Campaign Kicks Off

At 06:47 PST on May 20 Palo Alto Networks WildFire detected the start of the latest Kuluoz spam campaign. The total number of e-mails detected quickly rose to over 30,000 per hour around noon PST and had not begun to slow down as of 1:30PM PST.

 

Kuluoz is a descendant of the Asprox malware and spreads by sending copies of itself as an e-mail attachment. As the malware infects more systems, the systems begin sending more e-mails which leads to more infections. Kuluoz makes money for its owner by installing other malware, such as crimeware or fake antivirus programs.

Kuluoz e-mails often trick the reader into thinking they are delivery notifications (such as UPS or Fedex), or notices from airlines or payment processors. In this case the e-mails claim to contain a document about a court case.

Subject: Hearing of your case in Court
From: Notice of Appearance

Pretrial Notice,
Please, download the copy of the court notice attached herewith to read the details.
Note: The case may be heard by the judge in your absence if you do not come.

Truly yours,
Clerk to the Court.
Olivia Smith

Each e-mail carries one of the following attachments:

  • Court_Notice_May-20_Date_IN-FN_2014.exe
  • Court_Notice_May-20_Date_EN-RM_2014.exe
  • DC_Court_Notice_ER_NSER[4 Random Numbers].zip

These attachments are different versions of the malware that has been packed to evade antivirus engines. Twelve of the 53 scanners on virustotal.com now detect the first variant of the malware, but only three detect the latest version.

To determine where the highest number of infected nodes are, we mapped the sending IP address for each of the attach e-mails to their rough geographic location. While there are infected systems around the world, the largest concentration is in North America, particularly the United Stats and Canada.


Geographic Distribution of Koluoz Spam Nodes in North America

Thus far we’ve detected the following command and control servers in use.

  • 192.69.192. 178:443
  • 59.106.185. 11:443
  • 173.203.113. 94:443
  • 69.60.8. 88:8080
  • 205.186.156. 218:8080

The network traffic generated by each Trojan uses the HTTP protocol, and despite its use of port 443, is not encrypted with SSL.

As with most fast-spreading malware, antivirus engines will typically begin detecting the files a day or two after the spread has begun. While we haven’t seen any indication that the spam volume has begun to slow down, we do expect the campaign to wind down in the next 24 hours, but a new campaign will probably be close behind. WildFire users can rest assured that they’ll be protected from whatever Kuluoz has in-store next.

[Source: Palo Alto Networks]

Palo Alto Networks News of the Week – May 16

Interested in the top Palo Alto Networks news from this past week? It’s all right here.

Palo Alto Networks researchers identified a new Trojan, Funtasy, that targets Spanish Android users with sneaky SMS charges.

For the Record: We recently asked several Palo Alto Networks customers to describe the benefits of WildFire, and why adding a WildFire subscription to their Palo Alto Networks deployment is a better option than buying a standalone detection product or service.

Sharat Sinha, Palo Alto Networks VP, detailed 3 security priorities for the Asia Pacific region.

Kevin Magee, Palo Alto Networks Regional Sales Manager for Ontario, Public Sector, shared his perspective on the success of the Palo Alto Networks Expert Forums held recently in Ontario’s unique public sector community.

We hosted our third annual EMEA Expert Tour under the sun this week in Marbella, Spain with NextWave partner sales engineers and technicians across the EMEA region.

We talked at our Federal Expert Forum about tackling the government’s toughest cybersecurity challenges.

As a continuing part of our government and public sector activities, we are featured on Federal News Radio/WTOP in the United States over the next few months. Check it out to hear Rick and Steve Hoffman, VP, U.S. Federal, talk about what advanced government security teams are doing today.

Danelle Au discussed the massive challenge of securing the Internet of Things.

Our own James Sherlow commented on whether it is time to kill OpenSSL post-Heartbleed.

Join fellow IT Managers & Security Experts at the Palo Alto Networks Customer Forum on May 21 in The Netherlands. If you attend, you could win a great prize.

Here are more upcoming events you should know about:

[Source: Palo Alto Networks]

IT Security: It’s Time to Change the Game – And Here’s How

Summary: After several major security breaches, is there’s another way to do things?

We do IT differently these days, with users bringing their own devices into our networks, with our apps in the cloud, and our users wirelessly connected — from anywhere at any time. But we still do security the same old ways, with firewalls the mediaeval fortresses guarding the gates around our walled city datacentres.

So how can we rethink the ways we protect our changing IT world? We’ve already started to understand that what’s most important is the data and information we use, not the software, nor even our PCs and smartphones. We’ve started to encrypt data, at rest and in motion, and we’re also ensuring our users and apps work with the least possible set of privileges.

But, as the news headlines show, it’s not enough. With millions of us having to replace credit cards and deal with the fallout from recent major data losses, the failings of current security practices have been put in sharp relief. It’s time to do something different, to move from detecting attacks and clearing up after them, to preventing those attacks in the first place.

In the shadow of those high-profile intrusions, I spent some time with Palo Alto Networks, to try to understand how the security company is going beyond the traditional firewall, and coming up with an alternate way of looking at security.

Detecting malware is a complex piece of the puzzle. It’s no longer a matter of looking for malware signatures — for one thing, malware authors have long been able to create software that changes from download to download, and the targeted malware used by state actors and sophisticated cyber criminals is often designed to penetrate a specific network.

New malware that’s never been analysed won’t be blocked by conventional tools: someone must have been infected and lost data for that malware to be found, analysed and its signature added to the daily download of signature files. And while in many cases that someone is a honeypot system on some vendor’s network, there’s still a chance that that someone is you, and that it’s your data that’s been lost.

The risk may be small, but it’s still a risk: and the higher profile you are, the higher the risk. Home PCs might well be safe with a traditional signature-based approach, but that’s an approach that’s risky for businesses running cloud services, or hosting APIs for their apps.

What’s really important is understanding just how malware works. It turns out that while malware apps differ, the attack paths and methods they use are identical. To monitoring software, a buffer overflow or a SQL injection looks the same; so instead of protecting the operating systems of modern network endpoints, we need to monitor the applications and services they’re using, looking for the signatures of attacks, and blocking those attack paths rather than the malware. That’s the approach taken by Israeli security company Cyvera, recently bought by Palo Alto.

By analysing the attack patterns of thousands of pieces of malware, Cyvera has been able to identify fewer than thirty actual attacks. It’s then able to sit between your applications and those attacks, monitor for suspicious activity, and then block and report the code that’s trying to penetrate your network.

If malware can’t attack, no matter what the underlying code might be, we’re starting to focus on prevention, rather than detection. That’s an important distinction, as it’s an approach that, if implemented at an OS-level, would mean that Microsoft wouldn’t have had to issue a patch for IE in Windows XP, as it would have been protected automatically.

Changing the way we think about protecting our networks from malware changes the game. It lets us focus on understanding the software engineering implications of malware, and allows us to harden the areas of our OSes and software that need hardening by using those common attack patterns as part of our software test procedures. However we shouldn’t become complacent.

Just because malware uses a set of common attack patterns doesn’t mean that they’re the only possible attack patterns: it’s just that they’re the easiest or most effective routes into someone’s network. There are always going to be other ways in; just harder and more expensive. However, by continuing to analyse attack signatures it will still always be easier to prevent attacks than to detect malware and then remediate its effects.

These are tools that can be used alongside next generation firewalls, monitoring for unusual network traffic and unknown applications. Bringing the two together turns security into a proactive, rather than reactive, technology, one that’s much more in tune with modern IT and the rapid changes in how we work. They’re also techniques that don’t need to be associated with physical hardware, and can be implemented as part of the software control plane of a software defined network, or even as virtual machines in a virtualised infrastructure — as Palo Alto Networks is doing in conjunction with VMware.

It’s a brave new world out there, and it’s good to see that the security industry is thinking about how it needs to react, taking advantage of the same new tools and techniques we’re using in our private, hybrid, and public clouds. Now it’s up to us to think about how we can move to preventing attacks on our infrastructure, and keeping that vital data right where it belongs.

Simon Bisson is a freelance technology journalist. He specialises in architecture and enterprise IT. He ran one of the UK’s first national ISPs and moved to writing around the time of the collapse of the first dotcom boom. He still writes code.

[Source: ZDNet]

English
Exit mobile version