HM Health Solutions Presentation Monday, November 16

HM Health Solutions, a subsidiary of Highmark Health, will be on campus to give a presentation about their company and meet with students in the CIS department.  Please make room in your schedule to attend!

HM Health Solutions (Highmark Health)
Monday, November 16, 2015 (4:00 – 5:45pm)
Wheatley Center Atrium


4 pm – Registration and Pizza

4:15 pm – 5:15 pm – Highmark Presentation

5:15 pm – 5:45 pm – Q&A session


HM Health Solutions is committed to excellence in delivering innovative solutions to enable health plans achieve top-line revenue growth, reduce costs and gain economies of scale. With industry-leading expertise, HM Health Solutions delivers measurable results while increasing customer engagement. It’s extensive portfolio includes enterprise services, infrastructure management, data center housing and print management.

HM Health Solutions is seeking knowledgeable, creative individuals to join them as they continue to power the future of health care. Opportunities exist at all levels, from experienced professionals to internships, and also with our Rotation Program for high-potential recent college graduates.

They currently are looking to fill seats in a COBOL boot camp program that starts the 3rd week in January. Those chosen will be hired and then attend an extensive training that will prepare you for an important role on their team that can make a huge impact. More information on how to apply will be available at the event.

They are also looking to fill multiple roles in the areas of Cyber Security and Information Access Management.

International student sponsorships available.

SET credit is available for attending this event

FBI Internship Information

The FBI has opened the call for applications for the 2015 Honors and Cyber Internship programs and launched a new application process. All intern candidates must go to www.fbijobs.gov, register and complete a profile, and then select their profile to be added to the Intern Talent Network (ID Number 1023) by November 24.

After selecting the Intern Talent Network, intern candidates must attach their resumes and answer suitability questions. Only those candidates in the network by November 24 will be considered for the 2016 program.

All educational backgrounds will be considered for the internships. To qualify for the Honors or Cyber Internship Programs, candidates must:

  • Be a second-semester freshman or above; candidates cannot have graduated before June 13, 2016;
  • Be available 40 hours per week from June 13, 2016 to August 19, 2016 (10 weeks); and
  • Have a minimum cumulative 3.0 GPA.

Professional Web Development Experience Opportunity

A non-profit organization called EyesFree.org is looking for a student to help them with development of their web site:

http://eyesfree.org/pfg/index.htm

This organization works to aid blind and other disabled individuals by finding inexpensive ways for them to access computers and software.  They feature screen readers and email programs along with word processing and web surfing so that people with disabilities will have a way to look for and apply for jobs. 

If you have web development skills and would be interested in aiding this organization for professional experience, please reach out to Dr. Andrea Schwartz at 724-444-0064.

Hacking – Breaches and password dumps

Call it what you want – hacking, cracking, a dump, a data breach, whatever.  The fact is that these events are becoming more and more common, and as IT professionals we need to know how to deal with the fallout.  There is a great visualization that illustrates this recent trend on informationisbeautiful.net.

Often, one of the results of these breaches are that the public gets some insight into the security protections that a company uses (or lack thereof).  In the case of the recent 000Webhost breach, we discovered that passwords for over 13 million of their customers were stored in plaintext; that is to say, with no protection whatsoever.

Also in recent news, users of the Ashley Madison service had a large amount of their information disclosed, including account details and password hashes.  The primary protection mechanism for password storage that was in use here is a technology called bcrypt (a very strong password protection mechanism – you can find more details here and here), however due to a legacy function that had numerous flaws (for all of the details, check out this blog post) some user passwords were also simplified and stored as MD5.  Due to how MD5 functions, hardware like GPUs and ASICs are able to be used to quickly and efficiently crack the passwords, and in this case they were then able to use information gathered from cracking the MD5 hashes to significantly speed up the attacks on bcrypt-stored passwords.

One of the major problems with password hashes getting dumped is that password reuse is a real problem, and without the use of a password safe (like LastPass, KeePass, 1Password, or more enterprise products such as CyberArk or ERPM) it’s not realistic to think that end users will ever fix this on their own.

There are numerous websites and password managers available where you can check if your password has been a part of a breach, where the companies behind those websites seek out and collect password dumps to perform password cracking on them.  Simulating the attacks that malicious individuals use in this way allows them to provide a security monitoring and alerting service to their customers.  Many companies with a significant web presence, including Facebook, Twitter, and LinkedIn, will also scour the Internet for dumps and attempt to crack the passwords, then compare the cracked passwords to the information they have stored for your account.  If they get a match, they can take steps to protect your account by doing things like expiring your sessions, forcing a password reset on your account, etc.

I recently developed a lab focused on how to perform these password cracking attacks for a local security group called Steel City InfoSec.  The lab is available here on my GitHub, and if you aren’t familiar with password cracking, I suggest trying out the Beginner lab.  That difficulty level includes additional details about how to complete the lab, including a hints area that contains explanations and commands to run for each the steps of password cracking.  There is also a recording of my presentation and my slides available (along with additional information on the Steel City InfoSec message boards) if you are interested in a bit more background.

If you’ve done this sort of thing before and want to experiment with different tools or just download a bunch of word lists, feel free to try out the Intermediate lab.  Specifically, take a look at the downloads readme file to get a clean listing of everything that I’ve provided as a part of the lab.

If you have a GPU cracking rig or a cluster of machines at your disposal, and you’ve done this sort of things a few times in the past, take a crack at the competition.  It’s important to note that with the competition you will need to be a bit more creative about how you create a word list than just using the dumps that I’ve provided, and GPUs/ASICs will not help you as much as if you were cracking something stored with MD5 or even SHA-256.  Also, please note that the competition prizes were for the Steel City InfoSec event is are no longer available.

While working on the lab, if you find anything that isn’t clear or may be incorrect, please feel free to reach out to me directly (via a GitHub issue or pull request) and I can either lend a hand or fix any bugs as appropriate.  In addition, I will be available on RMU campus on November 10th in the evening in Hale 304, presenting this material to Dr. Paullet’s class.

Jon Zeolla

Mainframe Technology Job Opening for Black Knight Financial Services in Jacksonville, Florida!

Black Knight Financial Services, located in Jacksonville, Florida, is currently looking for candidates for an entry level position in their CICS Systems Programming group. Black Knight is looking for candidates that have been exposed to IBM Mainframe Technology and are interested in pursuing a career in IBM Enterprise Technical Support. Candidates that have participated in the IBM Master the Mainframe Contest have an advantage over candidates that have not. All candidates should have experience in application programming and exposure to the REXX programming language would be highly beneficial. Ideally, candidates should have exposure to COBOL or System 370 Assembler. The position can be applied for at Black Knight Financial Services website
( http://www.bkfs.com/CorporateInformation/Careers/Pages/WorkwithUs.aspx ).

Good luck and happy job hunting!

Seeking Students Interested in Building a Social Media Site

A student innovation group, Enactus RMU, is looking for people interested in developing a social media webpage that will allow students to create a network for studying collaboratively.  This project will cover the entire development lifecycle: from requirements definition, to deployment and maintenance.  Developers will be able to work at their own pace using online collaborative tools. They are looking for anyone who is interested and willing to learn however ideal candidates will have some of the following skills:

1) All developers should have knowledge of the agile development method, knowledge of software documentation best practices, and a willingness to thoroughly document all code.

2) Developers who wish to work on the webpage design should be familiar with web design best practices,  and have knowledge of HTML 5, JavaScript, and CSS.

3) Developers who wish to work on the servers should know how to work with Ubuntu Linux (or any Debian based Linux distribution), have skills in JAVA programming, knowledge of MySQL, be familiar with the TCP/IP model, and have an understanding of distributed file system concepts.

Anyone interested should contact Michael Arturo at mdast12@mail.rmu.edu

FREE Women Learn Coding Event in November

Interested in coding, but do not know where to start?  You are in luck ladies!

What is this?  This is an event perfect for all the women out there who want to learn how to code.  It is a free weekend workshop for women of all skill ranges – from never coded to professionals.  This event allows you to learn Ruby on Rails.

“Rails is the most well thought-out web development framework I’ve ever used.  And that’s in a decade of doing web applications for a living.  I’ve built my own frameworks, helped develop the Servlet API, and have created more than a few web servers from scratch.  Nobody has done it like this before.” – James Duncan Davidson, Creator of Tomcat and Ant

When/where is this?  November, in Pittsburgh’s very own Carnegie Museum of Art and Natural History.  4400 Forbes Ave Pittsburgh, PA 15213

InstallFest starts on Friday November 13th, 2015, from 7 – 9:30 PM, the Workshop starts on Saturday November 14th, 2015, from 8:30 – 5 PM, and Sunday November 15th, 2015, even has an after-party for those who attend the event.

Why do this? Why not??  It is free.  It is also an experience that may change your life forever.

“A lot of graduates love it so much that they decided to learn how to code, and even came back as teachers and TAs” – Professor John C. Turchek

How to sign up?  Go online to https://www.bridgetroll.org/events/223 to register.  **Only 22 students can attend this event so sign up fast!

New Positions Available at Heartland Campus Solutions ECSI

Heartland Campus Solutions ECSI is well-known for its ability to deliver forward-thinking solutions, service excellence, and over 40 years of experience to the Higher Education Community.  Their 2200+ college and university partners all will vouch for their role as the industry’s trusted partner, as well as their ability to educate the industry.  Heartland’s SelectSm solutions are about delivering a custom fit to all institutions, and include loan servicing, payment processing, refund disbursements, tax document management, tuition payment plans, campus cards, account recovery, and many other outsource services.


Project Manager:

Job Summary: The role of the Project Manager is to plan, execute, and finalize projects according to strict deadlines and within budget. This includes acquiring resources and coordinating the efforts of team members and third-party contractors or consultants in order to deliver projects according to plan.

Key Responsibilities: 

  • Take full ownership of project execution, and define its scope, goals, and deliverables
  • Identify and mange project dependencies proactively
  • Delegate tasks and responsibilities
  • Coach, Mentor, and motivate project team members

Qualifications:

  • Bachelor’s degree or equivalent, or four to ten years work experience, or training or equivalent combination of education and experience
  • Direct work experience in a project management capacity
  • Working knowledge of current internet technologies and various software programs
  • React efficiently to adjustments promptly
  • Strong communication skills
  • Ability to present to senior and management personal

Senior Software  Engineer: 

Purpose: The role of the programmer is to engage in a variety of analytical and programming assignments that provide for the development, enhancement, and maintenance of application programs, application systems, and operating systems software within our client server and web environments.

Key Duties and Responsibilities: 

  • Participate in the analysis effort to derive system requirements to meet business objectives as defined by customers
  • Develop code in accordance with the design to meet customer requirements
  •  Creates program ‘builds’ to implement new programs and program changes into the Production environment

Qualifications:

  • Bachelor’s Degree or equivalent or four to ten years related experience and/or training, or equivalent combination of education and experience
  • Experience with Microsoft Windows environment, HTML, Java Script, C# Programming Language, MVC5 framework, Microsoft Reporting Services, Visual Studio, Team
    Foundation Server
  • Ability to read, analyze, and interpret scientific and technical journals as well as finance reports, and other legal documents

Technology Support Specialist:

Job Summary: 

  • Provide technical support for all standard hardware, software, and applications
  • Assume responsibility for care, regular maintenance, and cleaning of computer hardware and other equipment
  • Documents and identifies equipment for inventory, maintain delivery records, installation, and call records

Qualifications:

  • Bachelor’s Degree or equivalent or two to four years related experience and/or training, or equivalent combination of education and experience
  • Customer service abilities
  • Presentation and speech writing skills

To Apply: Fill out this information sheet

For application or other additional information, contact Bobbi Englert by phone at 855-800-6558 Ext. 6051 or email at bobbi.englert@e-hps.com

USS Open Co-Op Positions for January or June 2016 in IT

United States Steel Corporation is currently recruiting Co-Ops in their IT Division for 2016. These assignments would begin in Jan or June 2016.  Students local to the USS facility are able to attend class and work the Co-Op assignment. These assignments offer a competitive pay and an exceptional learning opportunity.

Below is the list of open positions and work locations. If you interested in one of these positions, please apply directly to the USS careers website at http://www.ussteel.com.

Job # Posting Title Work Location No. of Positions
6876BR Application Developer Co-Op/Intern Southside – Pittsburgh 10
6878BR IT Infrastructure Co-Op Southside – Pittsburgh 15
6879BR Plant Process Control Co-Op West Mifflin, PA 1
6880BR Plant Process Control Co-Op West Mifflin, PA 1
6881BR Plant Process Control Co-Op Gary, IN 2
6882BR Plant Process Control Co-Op Gary, IN 1
6883BR Plant Process Control Co-Op Ecorse, MI (Detroit) 2
6885BR Plant Infrastructure Co-Op West Mifflin, PA 1
6886BR Plant Application Developer Co-Op Gary, IN 2
6888BR Cyber Security Co-Op/Intern Southside – Pittsburgh 1

General Qualifications:

– Candidates must be a full-time student pursuing a Bachelor’s or Master’s Degree in Computer Science, Computer Information Systems, Management Information Systems, or other IT-related discipline.

– Candidates must have completed or be working towards completion of their sophomore year and be in good academic standing.

– Candidates must be willing to work one of two schedules: two semesters at 16-20 hours per week followed by one summer of 40 hours per week or one semester of 40 hours per week plus one summer of 40 hours per week.

If you would like to speak about these openings or have any questions, please contact Barbara Santella at 412-433-6677.