CGI Nederland logo

Experienced Security Engineer - Space Unit

CGI Nederland

Almere
Full-time
5-10 years experience
On-site

Key Skills

Common Criteria Evaluation and Certification
Security Target Documentation
Target of Evaluation Definition
Security Requirements Analysis
Security Assurance Evidence
Security Architecture Review
Vulnerability Analysis
Penetration Testing Support
Technical Documentation
Requirements Traceability
Configuration Management
Evaluator and Certification Authority Liaison
Secure Systems Engineering
Stakeholder Management
Technical Writing

Job Description

Functiebeschrijving Please note that holding an EU passport is mandatory for obtaining an EU Personal Security Clearance, which is part of our selection process. A pre-employment screening is also part of the selection process. Do you want to contribute to the security assurance and certification of complex, mission-critical systems? As a Security Engineer – Common Criteria Evaluation & Certification, you will play a key role in supporting the security evaluation and certification process, ensuring that products and systems meet applicable Common Criteria requirements. You will work closely with system architects, developers, security specialists, independent evaluation laboratories, and certification authorities. A central part of your role will be translating technical product capabilities and security mechanisms into structured evaluation evidence, including the preparation and maintenance of Security Targets (STs) and supporting security documentation. You will support the certification lifecycle from initial evaluation scoping and definition of the Target of Evaluation (TOE), through evidence preparation, evaluation activities, clarification of evaluator findings, vulnerability analysis and testing support, to successful completion of the certification process. At CGI, you will work in a multidisciplinary and international environment where security assurance, traceability, technical accuracy, and structured documentation are essential. Your role in our team Support the planning, coordination, and execution of Common Criteria evaluation and certification activities. Prepare, maintain, and review Security Target (ST) documentation in accordance with applicable Common Criteria requirements. Define and document the Target of Evaluation (TOE), its boundaries, interfaces, operational environment, security functions, assumptions, threats, and organisational security policies. Define and maintain Security Objectives, Security Functional Requirements (SFRs), Security Assurance Requirements (SARs), and the TOE Summary Specification. Ensure consistency and traceability between security requirements, system architecture, security functionality, design documentation, implementation evidence, test evidence, and operational guidance. Support the selection and interpretation of applicable Protection Profiles, Evaluation Assurance Levels (EALs), assurance packages, and augmentation requirements, where relevant to the certification. Prepare and coordinate evaluation evidence covering relevant Common Criteria assurance areas, such as development documentation, lifecycle processes, configuration management, secure delivery, guidance documentation, testing, and vulnerability assessment. Work closely with developers, architects, testers, and product security teams to collect and review the technical evidence required by evaluators. Act as a technical interface with the Common Criteria evaluation laboratory, responding to evaluator questions, observations, clarification requests, and findings. Analyse evaluation findings and coordinate corrective actions with engineering teams to resolve identified gaps or inconsistencies. Support vulnerability analysis and penetration testing activities, including the identification and assessment of potential vulnerabilities relevant to the TOE. Support evaluator testing by preparing test environments, configurations, documentation, test evidence, and technical explanations. Review product architecture and security mechanisms to determine whether they adequately support the security claims made in the Security Target. Maintain configuration and version traceability between the evaluated product, evaluation evidence, software releases, and certification baseline. Support security impact analyses when changes are introduced to an evaluated or certified product. Contribute to improving internal processes, templates, and engineering practices for security assurance and product certification. How You Strengthen Our Team A Bachelor’s or Master’s degree in Cybersecurity, Computer Science, Software Engineering, Telecommunications, Systems Engineering, or a related technical discipline. Professional experience in product security, security assurance, security certification, or security engineering. Practical experience with the Common Criteria for Information Technology Security Evaluation (ISO/IEC 15408) and the associated evaluation process. Experience preparing or contributing to Security Targets (STs) or comparable formal security assurance documentation. Good understanding of key Common Criteria concepts, including: Target of Evaluation (TOE) and TOE boundary definition Security Problem Definition Threats, assumptions, and Organisational Security Policies Security Objectives Security Functional Requirements (SFRs) Security Assurance Requirements (SARs) TOE Summary Specification Protection Profiles and conformance claims Evaluation Assurance Levels and assurance packages Knowledge of the main Common Criteria assurance domains relevant to an evaluation, including ASE (Security Target Evaluation), ADV (Development), AGD (Guidance Documents), ALC (Life-cycle Support), ATE (Tests), and AVA (Vulnerability Assessment). Ability to understand complex system and software architectures and translate technical implementations into clear and structured security assurance arguments. Knowledge of security architecture concepts such as authentication, authorisation, access control, cryptographic mechanisms, secure communications, trusted boundaries, secure boot, key management, audit and logging, integrity protection, and secure update mechanisms. Experience reviewing technical documentation such as software architecture descriptions, functional specifications, interface descriptions, design documents, configuration-management documentation, test specifications, and operational guidance. Understanding of vulnerability analysis, penetration testing, attack scenarios, attack surfaces, and security testing methodologies. Ability to assess whether security claims and requirements are correctly implemented and supported by appropriate technical evidence. Strong technical writing skills and the ability to produce precise, structured, auditable documentation. Strong analytical skills and attention to detail, particularly regarding consistency and traceability across multiple technical documents. Strong communication and stakeholder-management skills, with the ability to work effectively with engineers, evaluators, certification bodies, security specialists, and project management. Structured, proactive, and quality-focused, with the ability to manage evaluation findings and documentation through multiple review cycles. Nice to Have Previous experience working directly with an accredited Common Criteria evaluation laboratory or national certification scheme. Experience supporting a product through a complete Common Criteria evaluation and certification lifecycle. Experience with higher-assurance evaluations or augmented assurance requirements. Knowledge of the Common Evaluation Methodology (CEM) and practical experience interpreting evaluator work units and evidence expectations. Experience working with Protection Profiles, collaborative Protection Profiles, or security-specific assurance packages applicable to the relevant product domain. Knowledge of secure software and systems engineering principles, including threat modelling, secure development lifecycle practices, configuration management, and vulnerability management. Experience with cryptographic products, secure embedded systems, operating systems, network/security appliances, trusted platforms, or other products subject to formal security certification. Familiarity with complementary security standards or assurance frameworks such as ISO/IEC 27001, IEC 62443, FIPS 140, ETSI cybersecurity standards, or NIST guidance, depending on the product domain. Experience working in regulated, defence, aerospace, governmental, critical-infrastructure, or other high-assurance environments. Experience supporting certification maintenance, product changes, re-evaluation, or security impact analysis after initial certification. Relevant cybersecurity or security assurance certifications. Experience working in European space programs such as Galileo, Copernicus, or similar. Familiarity with ECSS standards or mission-critical system lifecycles. Previous collaboration with ESA, EUSPA, or other space industry stakeholders. For this role all the work needs to be performed on-site at our CGI office with no hybrid working opportunities. A pre-employment screening is part of our selection process. Where you will be working? You will join a multidisciplinary and international CGI team working on security assurance and certification of complex, mission-critical systems. You will collaborate closely with system architects, developers, security specialists, testers and other engineering disciplines, as well as independent evaluation laboratories and certification authorities. The environment is technically complex and highly security-sensitive, with a strong focus on Common Criteria evaluation, security assurance, traceability and structured technical documentation. Depending on the project, you may contribute to European space programmes and work with stakeholders within the European space and security ecosystem. Due to the sensitivity and security requirements of this role, all work must be performed on-site at our CGI office. Hybrid or remote working is not possible for this position. AI & Futureproof At CGI, we continuously explore the impact of new technologies on our services and the solutions we develop for our clients. Developments in AI and automation are also playing an increasingly important role. Why CGI CGI is one of the world's largest IT and business consulting companies. Our people help keep the Netherlands running. Government organizations, banks, aerospace organizations, infrastructure providers, and companies in the energy, transport and manufacturing sectors are among CGI's clients. We work on meaningful projects that impact the daily lives of millions of people. We combine a strong local presence with global industry expertise, our ecosystem and colleagues around the world. We are proud of the impactful projects we successfully deliver together with our colleagues. At CGI, we highly value diversity and inclusion, as this not only strengthens collaboration but also often leads to better results. We look forward to your contribution to our team! You will work in small, self-managing teams consisting of experts in your field. At CGI, we combine challenging projects with excellent employment conditions: Permanent employment contract from day one; A competitive salary based on your experience and seniority; 8% holiday allowance; Bonus and profit-sharing scheme; 20 statutory and 5 additional vacation days (based on full-time employment); Lease budget / mobility budget; NS Business Card; Bicycle plan through CGI; Opportunity to invest 3% in CGI shares; Gross healthcare allowance of €116.35 per month; €40 net home-working allowance per month; Excellent pension scheme; Hybrid working. Join our team of experts and apply today! We will contact you as soon as possible! Do you have any questions about the role? Please contact Director Consulting Services, Willie Betancourt via [email protected] or +31 6 27402419. Do you have any questions about the recruitment process? Please contact Recruitment Business Partner, Ferhun Dogan via [email protected] or +31 6 11484743. We do not work with external recruitment agencies. Therefore, unsolicited acquisition is not appreciated. Taken en verantwoordelijkheden Criteria Together, as owners, let’s turn meaningful insights into action. In 1976 opgericht als een familiebedrijf, is CGI vandaag de dag een van de grootste onafhankelijke zakelijke en ICT-dienstverleners ter wereld. Bij ons draait het om ownership, teamwork en respect. Je krijgt de ruimte om al je talenten volledig te ontplooien. Vanaf je eerste werkdag ben je mede-eigenaar van CGI. We profiteren samen van ons succes en je krijgt de kans én verantwoordelijkheid om actief bij te dragen aan de koers en strategie van ons bedrijf. Jouw inzet voegt waarde toe. Je werkt aan innovatieve oplossingen en bouwt aan je netwerk van collega's en klanten. Je hebt toegang tot wereldwijde kansen om je ideeën te realiseren, mogelijkheden te benutten en te profiteren van onze kennis van de industrie en technologische expertise. Ontdek bij ons de mogelijkheden voor jouw persoonlijke ontwikkeling en zet de volgende stap in je carrière. Hier staat jouw succes centraal!

Core Responsibilities

Plan and support Common Criteria evaluation and certification activities, including defining the TOE, preparing Security Targets and assurance evidence, and coordinating with engineering teams, evaluation laboratories, and certification authorities. Analyze evaluator findings and vulnerabilities, support testing and corrective actions, and maintain traceability between security claims, product versions, evidence, and certification baselines.

Requirements

A bachelor’s or master’s degree in a relevant technical discipline and professional experience in product security, security assurance, security certification, or security engineering are required. Candidates should have practical Common Criteria and Security Target experience, strong understanding of assurance concepts and security architecture, and excellent analytical, documentation, communication, and stakeholder-management skills.

Benefits

  • Permanent Employment Contract
  • Competitive Salary
  • Holiday Allowance
  • Bonus and Profit-Sharing Scheme
  • Vacation Days
  • Lease or Mobility Budget
  • Public Transport Business Card
  • Bicycle Plan
  • Employee Share Purchase Plan
  • Healthcare Allowance
  • Home-Working Allowance
  • Pension Scheme

About CGI Nederland

Industry: IT Services and IT Consulting

Company size: 1,001-5,000 employees

Insights you can act on CGI, opgericht in 1976, behoort tot de grootste IT en business consultancy bedrijven ter wereld. Wij werken op basis van inzichten en resultaat om het rendement van uw investeringen te maximaliseren. In 21 bedrijfstakken op 400 locaties wereldwijd bieden we uitgebreide, schaalbare en duurzame IT- en business consultancy diensten die wereldwijd worden gevormd en lokaal worden geleverd.

Added Today