All pastes #1742416 Raw Edit

Something

public text v1 · immutable
#1742416 ·published 2010-01-08 07:15 UTC
rendered paste body
I believe I would be the best excellent candidate for your Application Engineer position. Working at a hedge fund site sounds like an exciting opportunity, and my past experience with financial messaging standards would allow me to integrate easily into your environment. I would be thrilled to relocate to Southern California.

I could give you the standard fare about how driven I am, how strong the will to succeed I possess is and how I am the best candidate for your position (and of course, all of this would be true) but I'd rather take the time to tell you about my most fatal flaws of character and why they make me the greatest asset for your enterprise.

SLOTH 
       I live by the old programming adage "laziness is a virtue", applying it to operations and security tasks. Too often have I seen many working frantically to fix failures which should have been anticipated and planned for in advance. I do thorough audits because I know going the extra mile to find all bugs on the outset is easier than doing forensics and compromise scope analysis in the future. I accomplish higher than standard levels of redundancy and monitoring. I believe in working hardest to create the most robust system now, because it is in my best interests to do less later.

GLUTTONY
      I know that memory-hungry, cpu-lite caches like squid and varnish run synergistically beside cpu-hungry, memory-lite httpds. I use every bit of spare disk to redundantly serve files with mogilefs, replicate critical MySQL databases or mirror critical volumes with DRBD.
      I treat machines under my control like a brutal slave master, exacting every grain of performance from them until they are are left empty husks with their lives and souls devoured.

SCHADENFREUDE
      I know how to implement good security because I know how to break bad security. I have an innate understanding of filtering evasion for cross-site scripting attacks and correct abstraction methods for SQL injection. I can perform man-in-the-middle attacks and fuzz for buffer overflows. I know how to prevent MITM via vlans and how to watch for more advanced tactics with arpwatch. I understand the importance of key-based authentication with pre-shared keys. In the event keys may not be pre-shared I always verify fingerprints and I always expire my keys at reasonable intervals.
      I know all the methods to protect the integrity of stored data, from zoning and LUN masking to Tripwire to mounting partitions of mission-critical data (like BIND zone files) from read-only NFS shares. I am adept at implementing disk encryption via Truecrypt, PGP and Loop-AES. I remain vigilant against all threats both internal and external.

VERBOSITY
       I document things. A lot. I use (or start) internal blogs and wikis and tag all posts with relevant keywords. The wiki ends up the essential guide for current and future administrators and the blog is updated up to several times per day 
with reports of progress, how-tos and relevant sections of my ~/.bash_history. I will reference the wiki and blog on each other, and also point to them in ticketing systems. I update company knowledge bases.
       I think it is the duty of security and operations staff to document as much as possible, but also to make important information easily found for those that will search for it in the future.

I'm a solid team player and I'm good at what I do. I'm personable and really fun to work with. I will be a valuable asset to your outfit. Give me a call.