🇳🇱 The Randstad, Netherlands · 6h ago
Experienced Security Engineer - Space Unit
CGI Nederland
LinkedInjuniorEnglish-friendly
FunctiebeschrijvingPlease note that holding an EU passport is mandatory for obtaining an EU Personal Security Clearance, which is part of our selection process. A pre-employment screening is also part of the selection process.Do you want to contribute to the security assurance and certification of complex, mission-critical systems? As a Security Engineer – Common Criteria Evaluation & Certification, you will play a key role in supporting the security evaluation and certification process, ensuring that products and systems meet applicable Common Criteria requirements.You will work closely with system architects, developers, security specialists, independent evaluation laboratories, and certification authorities. A central part of your role will be translating technical product capabilities and security mechanisms into structured evaluation evidence, including the preparation and maintenance of Security Targets (STs) and supporting security documentation.You will support the certification lifecycle from initial evaluation scoping and definition of the Target of Evaluation (TOE), through evidence preparation, evaluation activities, clarification of evaluator findings, vulnerability analysis and testing support, to successful completion of the certification process.At CGI, you will work in a multidisciplinary and international environment where security assurance, traceability, technical accuracy, and structured documentation are essential.Your role in our team Support the planning, coordination, and execution of Common Criteria evaluation and certification activities. Prepare, maintain, and review Security Target (ST) documentation in accordance with applicable Common Criteria requirements. Define and document the Target of Evaluation (TOE), its boundaries, interfaces, operational environment, security functions, assumptions, threats, and organisational security policies. Define and maintain Security Objectives, Security Functional Requirements (SFRs), Security Assurance Requirements (SARs), and the TOE Summary Specification. Ensure consistency and traceability between security requirements, system architecture, security functionality, design documentation, implementation evidence, test evidence, and operational guidance. Support the selection and interpretation of applicable Protection Profiles, Evaluation Assurance Levels (EALs), assurance packages, and augmentation requirements, where relevant to the certification. Prepare and coordinate evaluation evidence covering relevant Common Criteria assurance areas, such as development documentation, lifecycle processes, configuration management, secure delivery, guidance documentation, testing, and vulnerability assessment. Work closely with developers, architects, testers, and product security teams to collect and review the technical evidence required by evaluators. Act as a technical interface with the Common Criteria evaluation laboratory, responding to evaluator questions, observations, clarification requests, and findings. Analyse evaluation findings and coordinate corrective actions with engineering teams to resolve identified gaps or inconsistencies. Support vulnerability analysis and penetration testing activities, including the identification and assessment of potential vulnerabilities relevant to the TOE. Support evaluator testing by preparing test environments, configurations, documentation, test evidence, and technical explanations. Review product architecture and security mechanisms to determine whether they adequately support the security claims made in the Security Target. Maintain configuration and version traceability between the evaluated product, evaluation evidence, software releases, and certification baseline. Support security impact analyses when changes are introduced to an evaluated or certified product. Contribute to improving internal processes, templates, and engineering practices for security assurance and product certification.How You Strengthen Our Team A Bachelor’s or Master’s degree in Cybersecurity, Computer Science, Software Engineering, Telecommunications, Systems Engineering, or a related technical discipline. Professional experience in product security, security assurance, security certification, or security engineering. Practical experience with the Common Criteria for Information Technology Security Evaluation (ISO/IEC 15408) and the associated evaluation process. Experience preparing or contributing to Security Targets (STs) or comparable formal security assurance documentation. Good understanding of key Common Criteria concepts, including: Target of Evaluation (TOE) and TOE boundary definition Security Problem Definition Threats, assumptions, and Organisational Security Policies Security Objectives Security Functional Requirements (SFRs) Security Assurance Requirements (SARs) TOE Summary Specification Protection Profiles and conformance claims Evaluation Assurance Levels and assurance packages Knowledge of the main Common Criteria assurance domains relevant to an evaluation, including ASE (Security Target Evaluation), ADV (Development), AGD (Guidance Documents), ALC (Life-cycle Support), ATE (Tests), and AVA (Vulnerability Assessment). Ability to understand complex system and software architectures and translate technical implementations into clear and structured security assurance arguments. Knowledge of security architecture concepts such as authentication, authorisation, access control, cryptographic mechanisms, secure communications, trusted boundaries, secure boot, key management, audit and logging, integrity protection, and secure update mechanisms. Experience reviewing technical documentation such as software architecture descriptions, functional specifications, interface descriptions, design documents, configuration-management documentation, test specifications, and operational guidance. Understanding of vulnerability analysis, penetration testing, attack scenarios, attack surfaces, and security testing methodologies. Ability to assess whether security claims and requirements are correctly implemented and supported by appropriate technical evidence. Strong technical writing skills and the ability to produce precise, structured, auditable documentation. Strong analytical skills and attention to detail, particularly regarding consistency and traceability across multiple technical documents. Strong communication and stakeholder-management skills, with the ability to work effectively with engineers, evaluators, certification bodies, security specialists, and project management. Structured, proactive, and quality-focused, with the ability to manage evaluation findings and documentation through multiple review cycles.Nice to Have Previous experience working directly with an accredited Common Criteria evaluation laboratory or national certification scheme. Experience supporting a product through a complete Common Criteria evaluation and certification lifecycle. Experience with higher-assurance evaluations or augmented assurance requirements. Knowledge of the Common Evaluation Methodology (CEM) and practical experience interpreting evaluator work units and evidence expectations. Experience working with Protection Profiles, collaborative Protection Profiles, or security-specific assurance packages applicable to the relevant product domain. Knowledge of secure software and systems engineering principles, including threat modelling, secure development lifecycle practices, configuration management, and vulnerability management. Experience with cryptographic products, secure embedded systems, operating systems, network/security appliances, trusted platforms, or other products subject to formal security certification. Familiarity with complementary security standards or assurance frameworks such as ISO/IEC 27001, IEC 62443, FIPS 140, ETSI cybersecurity standards, or NIST guidance, depending on the product domain. Experience working in regulated, defence, aerospace, goveSourced from LinkedIn. Relocantly aggregates public job postings; apply on the original site.