Cybersecurity Engineer (Common Criteria, FIPS 140-3)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Cybersecurity Engineer (Common Criteria, FIPS 140-3): Perform product security testing and penetration testing for ICT products and cryptographic modules with an accent on Common Criteria frameworks, FIPS 140-3, and ISO/IEC 19790 compliance. Focus on threat modeling, vulnerability assessment and exploit testing, and producing audit-ready documentation and reports.
Location: Shenzhen Office, CN
Company
provides testing and certification services across multiple future-focused industries, including product security and cybersecurity.
What you will do
- Perform security testing and penetration testing based on Common Criteria frameworks.
- Support ICT product and cryptographic module certification projects and assist in security certification/compliance work.
- Create security testing and penetration testing plans using threat modeling and security frameworks.
- Analyze security risks and propose mitigation/remediation solutions.
- Conduct vulnerability assessments, exploit testing, and reporting for targets of evaluation.
- Audit cryptographic algorithm implementations and key management policies against FIPS 140-3 requirements, including DRBG entropy source verification.
Requirements
- Onsite work from the Shenzhen office (CN).
- Bachelor’s degree or above in IT, cybersecurity, software engineering, or a related field.
- At least 5 years of experience in IT/cybersecurity/software engineering, including at least 2 years in security or penetration testing.
- Proficiency in security and penetration testing for Web, App, IoT, or Android systems.
- Knowledge of Common Criteria, FIPS 140-3, ISO/IEC 19790, and cybersecurity best practices.
- Strong English communication and documentation skills.
Nice to have
- Experience with ICT product Common Criteria projects or cryptographic module certification.
- Certifications such as CISSP, OSEP, or OSCE.
Culture & Benefits
- Culture of trust, collaboration, and continuous learning.
- Secure, future-oriented employer focused on personal and professional growth.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →