
Common Criteria Product Tester
- Columbia, MD
- $85,150-153,925 per year
- Permanent
- Full-time
- Work with IT product vendors to determine applicability of IT product security standards to products
- Interpret IT product security standards to determine the compliance or noncompliance of product design based on research of product documentation and interviews with technical personnel
- Devise, execute, and document security functional testing to justify how tested products are compliant with IT security standards
- Conduct product troubleshooting and provide recommendations when noncompliant findings are made
- Conduct vulnerability research to determine if documented security vulnerabilities are adequately mitigated by product configuration and patch level
- Produce documentation that describes how IT products conform to security requirements
- Develop user guidance for instructions on placing products into secure configurations
- Justify completeness, consistency, accuracy, and sufficiency of product test result to third-party quality reviewers
- Familiarity with general IT security products and their operation (e.g., routers/switches, firewalls, IDS, operating systems, software applications, mobile devices)
- General knowledge of the role that various IT products and concepts serve in information security (e.g., full disk encryption, mobile device management, remote access/VPN, etc.)
- Experience with software development lifecycle methods (e.g., agile) and tools (e.g., Subversion, GitLab, Confluence, JIRA)
- Strong applied knowledge of network, transport, and application layer communications and security (e.g., TCP/IP, TLS, IPsec, SSH, LDAP)
- Working knowledge of applied cryptography (e.g. X.509, Diffie-Hellman, PKI)
- Strong customer-facing oral and written communication skills
- Previous experience with Common Criteria or other IT product security evaluation standards (e.g., FIPS 140, FedRAMP, NIST SP 800-53)
- One or more technical professional certifications related to information technology communications or security (e.g., CEH, CCNA, CISSP)
- Knowledge of scripting/programming (e.g., Python) and familiarity with machine-readable data exchange methods (e.g., JSON, REST)