WHO we’re looking for:
We are looking for a Security Engineer - FIPS/CC (Mobile Devices) who will be responsible for performing initial assessment of the security functions and specifications; consult various teams in the development of the process, design, and documentation required for the FIPS 140-2/3 accreditation of our cryptographic modules and common criteria evaluations of our security products. You will at times be responsible for security compliance analysis and testing of operational, management, and technical controls for products. Ideally you have deep mobile device expertise. You will be a part of FIPS 140-2/3 and Common Criteria evaluations team.
Role and Responsibilities:
- Develop plans and procedures using applicable security controls, FIPS 140-2/3 validation of Cryptographic Modules, Common Criteria Evaluation of any IT product familiar with NIAP Protection Profiles (MDFPP, VPN, WLAN, TLS ,Biometric enrollment, and verification), DCID 6/3, DoD 8500, or NIST SP 800-53. Help with CAVP algorithm testing using ACVP/ACVTS, assist with review and writing of review of security policies for the modules.
- Develop and review the required certification documentation for all the FIPS 140-2/3 validation and Common Criteria evaluations.
- Develop mitigation strategies to address vulnerabilities uncovered during security testing; and assist with completing the required reports and documentation to meet certification and authorization requirements, as required.
- Perform vulnerability analysis of product or system designs against applicable security criteria using common tools, including Nessus, NMAP, and WireShark.
- Project POC with Internal/External audience when required.
Required Experience and Education:
- 5+ years of technical experience in FIPS 140-2/3 validation of Cryptographic Modules and Common Criteria evaluation of any IT product in the US CC scheme . Mobile Device Product Evaluation experience is preferred.
- Bachelor's Degree in Electrical Engineering, Computer/Information Science, Information Assurance/Cybersecurity, or equivalent degree (Master's Degree preferred).
- Proficiency in FIPS 140-2 and FIPS 140-3 validation of Cryptographic modules - Understanding of standards like FIPS 186-4/5, SP 800-186, SP800-90B is desirable.
- Experience building test environments, performing testing and reporting results (technical writing).
- Knowledge of general software product security architecture , design principles of protocols (i.e., SSH, IPsec, TLS, Wi-Fi etc.) is preferred.