Senior Security Certifications Engineer

Fortaegis Technologies

Amsterdam

On-site

EUR 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Fortaegis Technologies is seeking a Senior Security Certifications Engineer to drive the product security certification programme across FIPS 140-3 and Common Criteria. You will collaborate with hardware, firmware and FPGA teams to produce evidence artefacts, manage labs and liaise with certification bodies to ensure on-time, audit-ready outcomes.

You will own the certification engine, advancing security policy, traceability and secure development lifecycle practices while interfacing with

Qualifications

  • 5+ years working directly on product security certifications, with deep hands-on FIPS 140-3 (or 140-2) and Common Criteria experience.
  • Detailed, practical command of the FIPS 140-3 process - CMVP and CAVP, SP 800-90B entropy source validation, algorithm validation, and security policy and evidence requirements.
  • Strong Common Criteria experience, ideally to EAL4 and/or high-assurance vulnerability analysis (AVA_VAN), including the ALC, ADV, ATE and AVA assurance classes.
  • Proven track record producing certification evidence artefacts - design documentation, security policies, assurance mappings and traceability - for hardware or firmware cryptographic products.
  • Experience managing accredited test laboratories and certification bodies, including deficiency cycles and submissions.
  • Solid grasp of applied cryptography and key management (approved algorithms, key lifecycle, entropy) and how these map onto certification requirements.
  • Familiarity with hardware security modules, secure elements, or FPGA/ASIC-based cryptographic designs.
  • Working knowledge of adjacent frameworks - IEC 62443, the EU Cyber Resilience Act, NIST SSDF and ISO/IEC 27001 - is a strong plus.
  • Experience with secure development lifecycle and secure release/signing practices (reproducible builds, HSM-based signing ceremonies) is advantageous.
  • Excellent technical writing - able to turn dense engineering detail into clear, consistent, assessor-ready documentation.
  • Effective communication and teamwork, with the ability to collaborate across engineering, product and external partners.

Responsibilities

  • Run the day-to-day execution of our product security certification projects - FIPS 140-3, Common Criteria (EUCC) and the regulatory obligations our customers depend on - keeping them on schedule and evidence-complete against the overall strategy set by security leadership.
  • Partner with hardware, firmware and FPGA engineers on security-relevant design decisions, translating certification requirements into concrete, testable design and documentation actions.
  • Gather, structure and help author the certification evidence artefacts: detailed design documentation, security policies, assurance/VE mappings, entropy (SP 800-90B) documentation, algorithm and module test evidence, and end-to-end traceability.
  • Act as our primary technical interface to accredited test laboratories and certification schemes (CMVP/CAVP, Common Criteria evaluators), managing queries, deficiency cycles and report submissions.
  • Prepare and coordinate lab engagements across entropy source, algorithm and module validation testing, including planning and hosting test witnessing and data collection on our sites.
  • Operate and continuously improve our Secure Development Lifecycle and Secure Release processes so that engineering work produces audit-ready evidence as a by-product, not an afterthought.
  • Support release-integrity assurance - reproducible builds, artefact verification and HSM-based signing - where it intersects with certification requirements.
  • Track requirements and dependencies across FIPS 140-3, Common Criteria, IEC 62443 and the EU Cyber Resilience Act, and flag design or documentation gaps early enough to fix cheaply.
  • Own the evidence repository and traceability so every product has a complete, retrievable assurance package ready for external assessment.
  • Coach engineering teams so that security and certification thinking becomes part of everyday development.

Skills

FIPS 140-3
Common Criteria
CMVP/CAVP
Entropy validation
Security policy
Assurance mappings
Traceability
Hardware security
Secure development lifecycle

Job description

Job description

Fortaegis is a fast-scaling, highly ambitious and cutting-edge semiconductor company. We are looking for a Senior Security Certifications Engineer to run the day-to-day execution of our product security certification programme across FIPS 140-3, Common Criteria and the regulatory frameworks our customers rely on. This role owns the engine room of certification: working alongside our engineers on security-relevant design decisions, gathering and helping author the evidence artefacts that certifications demand, and acting as our primary technical interface to accredited test laboratories and certification bodies. Overall certification strategy is set by security leadership; you make it happen. We are looking for candidates with not only an exceptional skillset, but also an exceptional mindset, willing to go above and beyond to make our security and certification capability even better.

Job requirements
  • 5+ years working directly on product security certifications, with deep hands-on FIPS 140-3 (or 140-2) and Common Criteria experience.
  • Detailed, practical command of the FIPS 140-3 process - CMVP and CAVP, SP 800-90B entropy source validation, algorithm validation, and security policy and evidence requirements.
  • Strong Common Criteria experience, ideally to EAL4 and/or high-assurance vulnerability analysis (AVA_VAN), including the ALC, ADV, ATE and AVA assurance classes.
  • Proven track record producing certification evidence artefacts - design documentation, security policies, assurance mappings and traceability - for hardware or firmware cryptographic products.
  • Experience managing accredited test laboratories and certification bodies, including deficiency cycles and submissions.
  • Solid grasp of applied cryptography and key management (approved algorithms, key lifecycle, entropy) and how these map onto certification requirements.
  • Familiarity with hardware security modules, secure elements, or FPGA/ASIC-based cryptographic designs.
  • Working knowledge of adjacent frameworks - IEC 62443, the EU Cyber Resilience Act, NIST SSDF and ISO/IEC 27001 - is a strong plus.
  • Experience with secure development lifecycle and secure release/signing practices (reproducible builds, HSM-based signing ceremonies) is advantageous.
  • Excellent technical writing - able to turn dense engineering detail into clear, consistent, assessor-ready documentation.
  • Effective communication and teamwork, with the ability to collaborate across engineering, product and external partners.
  • Ability to take ownership and solve problems beyond the scope of the job description, with a flexible, solution-oriented mindset.
Job responsibilities
  • Run the day-to-day execution of our product security certification projects - FIPS 140-3, Common Criteria (EUCC) and the regulatory obligations our customers depend on - keeping them on schedule and evidence-complete against the overall strategy set by security leadership.
  • Partner with hardware, firmware and FPGA engineers on security-relevant design decisions, translating certification requirements into concrete, testable design and documentation actions.
  • Gather, structure and help author the certification evidence artefacts: detailed design documentation, security policies, assurance/VE mappings, entropy (SP 800-90B) documentation, algorithm and module test evidence, and end-to-end traceability.
  • Act as our primary technical interface to accredited test laboratories and certification schemes (CMVP/CAVP, Common Criteria evaluators), managing queries, deficiency cycles and report submissions.
  • Prepare and coordinate lab engagements across entropy source, algorithm and module validation testing, including planning and hosting test witnessing and data collection on our sites.
  • Operate and continuously improve our Secure Development Lifecycle and Secure Release processes so that engineering work produces audit-ready evidence as a by-product, not an afterthought.
  • Support release-integrity assurance - reproducible builds, artefact verification and HSM-based signing - where it intersects with certification requirements.
  • Track requirements and dependencies across FIPS 140-3, Common Criteria, IEC 62443 and the EU Cyber Resilience Act, and flag design or documentation gaps early enough to fix cheaply.
  • Own the evidence repository and traceability so every product has a complete, retrievable assurance package ready for external assessment.
  • Coach engineering teams so that security and certification thinking becomes part of everyday development.
Additional information

The successful candidate will have the unique opportunity to participate in shaping the future of our visionary company, taking direct ownership of the certifications that let our ultra-secure, high-performance products reach the world’s most demanding markets. They will work closely with our security leadership and engineering teams in a collaborative and technically rewarding environment at the forefront of secure semiconductor technology.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Certifications Engineer: Lead FIPS 140-3 & CC
Security Certifications Engineer: Lead FIPS 140-3 & CC

Fortaegis Technologies • Amsterdam

On-site
EUR 90,000 - 130,000
Hardware Security Engineer
Hardware Security Engineer

Fortaegis Technologies • Amsterdam

On-site
EUR 70,000 - 110,000
Embedded Security Engineer– Security Certifications
Embedded Security Engineer– Security Certifications

Keysight Technologies SAles Spain SL. • Delft

On-site
EUR 70,000 - 110,000
Embedded Security Engineer- Security Certifications
Embedded Security Engineer- Security Certifications

Keysight Technologies, Inc. • Netherlands

On-site
EUR 70,000 - 110,000
Embedded Security Engineer- Security Certifications
Embedded Security Engineer- Security Certifications

Qabird • Delft

On-site
EUR 90,000 - 120,000
Embedded Security Engineer– Security Certifications
Embedded Security Engineer– Security Certifications

Keysight Technologies • Delft

On-site
EUR 70,000 - 110,000
Applied Cryptographer
Applied Cryptographer

Fortaegis Technologies • Amsterdam

On-site
EUR 110,000 - 180,000
System Integration Architect
System Integration Architect

Fortaegis Technologies • Amsterdam

On-site
EUR 90,000 - 130,000
Solution Engineer – Device Security Hardware (Keysight Device Security)
Solution Engineer – Device Security Hardware (Keysight Device Security)

Keysight Technologies • Delft

On-site
EUR 70,000 - 110,000
PCB Design and Verification Engineer
PCB Design and Verification Engineer

Fortaegis Technologies • Amsterdam

On-site
EUR 60,000 - 90,000