Talent.com
Senior Security Evaluator
Senior Security EvaluatorSGS Australia • Columbia, MD, US
Senior Security Evaluator

Senior Security Evaluator

SGS Australia • Columbia, MD, US
3 days ago
Job type
  • Full-time
Job description

Company Description

SGS is the global leader and innovator in inspection, verification, testing and certification services. Founded in 1878, SGS is recognized as the global benchmark in quality and integrity. With over 97,000 employees in 130 countries and operating a network of more than 2,400 offices and laboratories, we provide services to almost every industry by assuring quality and safety of products and services.

Trusted all over the world, SGS is a market leader because we put 100% passion, pride and innovation into everything we do. We encourage new ideas. We welcome people who challenge the way we do things. And we will be 100% committed to helping you reach your full potential.

Job Description

A senior engineer must be well versed in, but not limited to, operating systems, data structures, design / analysis of algorithms, database systems, programming languages, computer systems architectures, and networking and will be responsible to work independently as well as lead teams and mentor junior engineers to conduct security compliance analysis or testing of operational, management, and technical controls for IT products, including COTS and GOTS, networks, and systems. This may include :

  • Develop test plans and procedures using applicable security control catalog, including DCID 6 / 3, DoD 8500, or NIST SP 800-53;
  • Perform security testing and vulnerability analysis of product or system designs against applicable security criteria using common tools such as Nessus, NMAP, and WireShark;
  • Perform other evaluation activities, including but not limited to documentation and source code analysis, where applicable;
  • Develop security testing and other evaluation reports to detail the findings noted during testing and other evaluation activities;
  • Develop mitigation strategies to address vulnerabilities uncovered during security testing;
  • facilitate and coordinate development of or updates to security documentation to meet certification and authorization requirements as required;
  • Work effectively and efficiently either alone and with other team members to accomplish the tasks summarized above; and,
  • Work with the organization managers to help identify and implement changes that could improve the overall effectiveness of the organization.

Qualifications

Education and ExperienceEducation Requirement

  • Bachelor’s degree, science or computer degree preferred.
  • 5+ years of experience, training, knowledge, or familiarity in the following areas : 17CAV, 17CMH, and 17CMS
  • Validation Program’s programmatic guidance and management documents
  • The cryptographic algorithms listed in FIPS 140-2 annexes
  • Random bit generators and entropy requirements
  • Key establishment methods and concepts
  • Specification of the module (e.g. hardware, software, hybrid, and / or firmware)
  • Module ports and interfaces;
  • Trusted path and direct entry methods;
  • Specification of roles and services;
  • Authentication methods (role and identity-based) and strengths
  • Bypass mechanisms and concepts
  • Finite state machine model analysis
  • Development of test jigs, software debuggers, binary editors, compilers, and software diagnostic tools
  • Software design specification, including high-level languages
  • Operating system and concepts (e.g., Microsoft, UNIX, LINUX, ARM, Apple, etc.)
  • Key management techniques and concepts
  • Zeroization methods
  • Key entry and output
  • The cryptographic protocols, including, but not limited to, SSL, TLS, IKE, SSH, OTAR, etc.
  • FCC EMI / EMC Class A and Class B requirements and intentional emitters such as radio devices
  • Cryptographic self-test techniques, including, but not limited to, power-up, conditional tests, known answer tests, integrity tests, load and bypass tests, etc.
  • Design assurance, such as configuration management, delivery, operation, and development
  • Mitigation of other attack mechanisms
  • Security policy requirements (e.g. FIPS 140-2 Appendix C)
  • 17 CMH1 Security Levels 1 to 3
  • Production grade, tamper-evident, and tamper detection techniques
  • Hardware implementations and technologies associated with single-chip and multi-chip embodiments
  • Epoxies, potting materials, adhesives (e.g. tamper-evident labels), and their chemical properties
  • Electrical design, schematics, and concepts, including logic design and HDL representations
  • Skills associated with tamper mitigation methods and performing test methods of compromising tamper protection mechanisms
  • 17CMH2 Security Level 4
  • Voltage and temperature measurement (Environmental Failure Protection / Environmental Failure Testing (EFP / EFT))
  • Tamper detection / response envelopes
  • Formal modeling method
  • 17 CMS1 Security Levels 1 to 3
  • Evaluated operating systems under the Common Criteria EAL2 through EAL3 or equivalents
  • 17CMS2 Security Level 4
  • Evaluated operating systems under the Common Criteria EAL4 or equivalent
  • Pay Range : $73,500-$98,000 / year

    Additional Information

    Benefits

  • Competitive salary.
  • Comprehensive health, dental, and vision insurance for full time employees.
  • Retirement savings plan.
  • Continuous professional development and training opportunities.
  • A dynamic, collaborative work environment.
  • Access to cutting-edge cryptographic technology and tools.
  • Physical Demands of the Job

  • Stand : Occasionally
  • Move or traverse : Frequently
  • Sit : Constantly
  • Use hands : Constantly
  • Reach with hands and arms : Occasionally
  • Climb or balance : Occasionally
  • Stoop, kneel, crouch or crawl : Occasionally
  • Talk / hear : Constantly
  • Taste / Smell : Occasionally
  • Lift / carry / push or pull : Occasionally 30 lbs
  • Additional information

    SGS is an Equal Opportunity Employer, and as such we recruit, hire, train, and promote persons in all job classifications without regard to race, color, religion, sex, national origin, disability, age, marital status, sexual orientation, gender identity or expression, genetics, status as a protected veteran, or any other characteristics protected by law.

    To perform this job successfully, an individual must be able to perform each essential duty satisfactorily with or without reasonable accommodations. The requirements listed above are representative of the knowledge, skills, and / or abilities required.

    This job description should not be construed as an exhaustive statement of duties, responsibilities or requirements, but a general description of the job. Nothing contained herein restricts the company’s rights to assign or reassign duties and responsibilities to this job at any time.

    If you are applying for a position within the United States and you have difficulty completing the on-line employment application because of a disability, please call 201-508-3149 for assistance and leave a message. You will receive a callback.  Please note, this phone number is not for general employment information but is only for individuals who are experiencing difficulty applying for a position due to a disability.

    Create a job alert for this search

    Evaluator • Columbia, MD, US

    Related jobs
    Senior Security Engineer

    Senior Security Engineer

    NetImpact Strategies • Bethesda, MD, United States
    Full-time
    We are seeking a highly skilled Security Engineer to join our team, specializing in implementing secure and resilient infrastructural modifications and advanced IT security enhancements to join our...Show more
    Last updated: 30+ days ago • Promoted
    Sr. Security Engineer, WAF

    Sr. Security Engineer, WAF

    Warner Bros. Discovery • Silver Spring, MD, United States
    Full-time
    When we say, "the stuff dreams are made of," we're not just referring to the world of wizards, dragons and superheroes, or even to the wonders of Planet Earth. Behind WBD's vast portfolio of iconic ...Show more
    Last updated: 6 days ago • Promoted
    Senior Security Engineer II (DevSecOps)

    Senior Security Engineer II (DevSecOps)

    Aledade, Inc. • Bethesda, MD, United States
    Full-time
    As a Senior Security Engineer II at Aledade, we play a central role in helping secure our enterprise, cloud native environments, and applications. We’re looking for security engineers that understan...Show more
    Last updated: 10 days ago • Promoted
    Senior eDiscovery Technical Advisor

    Senior eDiscovery Technical Advisor

    EmergencyMD • Washington, DC, United States
    Full-time
    Evolver Federal, a Converged Security Solutions company, is an information technology company serving the Federal, Commercial, and Legal markets that addresses client challenges in the present and ...Show more
    Last updated: 13 hours ago • Promoted • New!
    Senior Security Engineer

    Senior Security Engineer

    Tad PGS • Washington, DC, United States
    Full-time
    We have an outstanding Contract position for aSenior Security Engineerto join a leading Company located in theWashington, DCsurrounding area. Candidate must possess an Active Top Secret or Top Secre...Show more
    Last updated: 6 days ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    CoStar Realty Information, Inc. • Arlington, VA, United States
    Full-time
    CoStar Group (NASDAQ : CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index and the NASDAQ 100, ...Show more
    Last updated: 6 days ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    Anduril • Washington, DC, United States
    Full-time
    Washington, District of Columbia, United States.Anduril Industries is a defense technology company with a mission to transform U. By bringing the expertise, technology, and business model of the 21s...Show more
    Last updated: 1 day ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    DirectViz Solutions, LLC • Washington, DC, USA
    Full-time
    Quick Apply
    DirectViz Solutions, (DVS) is a rapidly growing government contractor that provides strategic services that meet mission IT needs for government customers. DVS provides innovative information techno...Show more
    Last updated: 30+ days ago
    Senior Security Engineer (Compliance)

    Senior Security Engineer (Compliance)

    Versar • Washington, DC, United States
    Full-time
    Senior Security Engineer (Compliance) to support the Department of Homeland Security's Enterprise Engineering Division (EED) within the Office of the Chief Information Officer (OCIO).This candidate...Show more
    Last updated: 6 days ago • Promoted
    Lead Adversarial Security Engineer

    Lead Adversarial Security Engineer

    Trellix • Washington, DC, United States
    Full-time
    Lead Adversarial Security Engineer.Trellix, the trusted CISO ally, is redefining the future of cybersecurity and soulful work. Our comprehensive, GenAI-powered platform helps organizations confronte...Show more
    Last updated: 6 days ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    Executive Recruiting • Washington, DC, United States
    Full-time
    Washington, DC | (Hybrid - 3 days in office with travel as required).Must be eligible to obtain a DoD security clearance. This role is critical in securing mission-critical cloud applications and ma...Show more
    Last updated: 6 days ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    Network Designs Inc. • Washington DC, DC, USA
    Full-time
    Quick Apply
    NDi) is a leading Federal contractor that specializes in designing, developing, and delivering information technology and network solutions for government customers. Founded in 1985, NDi's firmly de...Show more
    Last updated: 30+ days ago
    Lead Cyber Evaluation Expert

    Lead Cyber Evaluation Expert

    SilverEdge • Columbia, MD, United States
    Full-time
    SilverEdge is a premier provider of innovative cyber, software, and intelligence solutions, addressing mission-critical challenges for the Department of Defense (DoD), Intelligence Community (IC), ...Show more
    Last updated: 6 days ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    ECS Limited • Suitland, MD, United States
    Full-time +2
    ECS Federal is a leading information security and information technology company in Washington, DC.We are looking to hire a Senior Security Engineer to support a full range of cyber security servic...Show more
    Last updated: 4 days ago • Promoted
    Senior Systems Security Engineer

    Senior Systems Security Engineer

    AnaVation LLC • Washington, DC, United States
    Full-time
    Be Challenged and Make a Difference.In a world of technology, people make the difference.We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched va...Show more
    Last updated: 6 days ago • Promoted
    Zero Trust Security Engineer - Senior

    Zero Trust Security Engineer - Senior

    DecisionPoint Corporation • Washington, DC, United States
    Full-time
    The Government Publishing Office (GPO) SecDevOps program provides advanced security, development, and operations support to safeguard federal information systems and infrastructure.This initiative ...Show more
    Last updated: 30+ days ago • Promoted
    Senior Application Security Engineer (WAF) 3956

    Senior Application Security Engineer (WAF) 3956

    Tier4 Group • Washington, DC, United States
    Full-time +1
    Senior Application Security Engineer (WAF) 3956.Get AI-powered advice on this job and more exclusive features.Direct message the job poster from Tier4 Group. Greater DC Area (2 days per week onsite ...Show more
    Last updated: 30+ days ago • Promoted
    Senior FIPS 140 Security Engineer

    Senior FIPS 140 Security Engineer

    DanSources • Silver Spring, MD, United States
    Full-time
    Senior FIPS 140 Security Engineer.Seeking a Senior FIPS 140 Security Engineer to join an Accredited Testing and Evaluation (AT&E, Common Criteria / FIPS) team. This role provides an exciting opportuni...Show more
    Last updated: 6 days ago • Promoted