Security Certification Engineer, FIPS/CC - Mobile Devices
Location:
Remote or Mountain View, CA
Lab Summary:
Are you passionate about transforming bleeding-edge technologies into services that will impact millions in our daily lives? At Mobile Platform Solutions (MPS), we are looking for passionate product managers to share their creative vision and to build applications and services for Samsung's array of devices spanning mobile, wearables, IoT, TVs, appliances, etc. In this position, you will join a collaborative team of world-class designers, researchers, and engineers in the field of AI/ML, blockchain, IAM, computer vision, AR/VR/XR, IOT technologies, with emphasis on mobile B2B services, security and privacy, Enterprise AI, etc.
Come join the Samsung MPS team and be a leader in bringing futuristic services to life!
Position Summary:
We are looking for an individual who has experience in the common criteria evaluations of IT products and who has experience with FIPS validation of cryptographic modules (FIPS 140-3). They will be responsible for the end-end validation of the products (performing initial assessment of the security functions and specifications; consult with various teams in the development of the process, design, and documentation required for the common criteria evaluations of our Mobile Device products and the FIPS 140-2/3 accreditation of our cryptographic modules.
Position Responsibilities:
- Develop the security target for our products, assist with the testing, documentation and working with the necessary engineering teams during the evaluation
- Develop plans and procedures using applicable security controls, including NIAP Protection Profiles (MDFPP, VPN, WLAN, Biometric enrollment, and verification), assist with the CAVP algorithm testing, drafting and review of the security policies for our cryptographic modules according to the FIPS 140-3 specifications, possess information around the DCID 6/3, DoD 8500, or NIST SP 800-53
- Assist in the development and review of all test reports and required certification documentation for all the Common Criteria evaluations and FIPS 140-2/3 accreditation
- Experience building testing environments, performing testing and reporting results (technical writing) for all of the common criteria and FIPS evaluations
- Develop mitigation strategies to address vulnerabilities uncovered during security testing; and assist with completing all the required documentation to meet the specifications and certification requirements, as required
- Perform vulnerability analysis of product or system designs against applicable security criteria using common tools, including Nessus, NMAP, and Wireshark
- Project POC with Internal/External audience when required
Required Skills:
- Bachelor's Degree in Electrical Engineering, Computer/Information Science, Information Assurance/Cybersecurity, or equivalent degree (Master's Degree preferred), or equivalent combination of education, training, and experience
- 5+ years of technical experience in Common Criteria evaluations NIAP-managed Common Criteria Evaluation and Validation Scheme (CCEVS or Scheme) of any product in the US scheme. Mobile device and Software knowledge highly preferred
- Knowledge of common security related protocols and their design (i.e., SSH, IPsec, TLS, etc.)
- Be highly proficient in FIPS 186-4/5, SP 800-186, SP800-90B and the FIPS 140-3 requirements and have knowledge around the cryptographic encryption algorithms, key exchange algorithms, hashing/message authentication algorithms, PKI, random number generators
Special Attributes:
- Self-motivated individual with the ability to thrive in a team-based or independent environment
- Detail-oriented with strong organization skills
- Ability to work in a fast-paced environment
- Limited supervision and the exercise of discretion
- Ability to comprehend security standard requirements and specifications and apply them to products
- Excellent communication (written/verbal) skills and analytical skills
Base Pay Range
$158,800 - $218,100 USD
Additional Information
Disclosure of Trade Secrets
Samsung has a strict policy on trade secrets. In applying to Samsung and progressing through the recruitment process, you must not disclose any trade secrets of a current or previous employer.
Essential Job Functions
This position will be performed in an office setting. The position will require the incumbent to sit and stand at a desk, communicate in person and by telephone, and frequently operate standard office equipment, such as telephones and computers.
Samsung Research America is committed to complying with all Federal, State and local laws related to the employment of qualified individuals with disabilities. If you are an individual with a disability and would like to request a reasonable accommodation as part of the employment selection process, please contact the recruiter or email sratalent@samsung.com.
Equal Employment Opportunity
At Samsung, we believe that innovation and growth are driven by an inclusive culture and a diverse workforce. We aim to create a global team where everyone belongs and has equal opportunities, inspiring our talent to be their true selves. Together, we are building a better tomorrow for our customers, partners, and communities.
Samsung Research America is committed to employing a diverse workforce, and provide Equal Employment Opportunity for all individuals regardless of race, color, religion, gender, age, national origin, marital status, sexual orientation, gender identity, status as a protected veteran, genetic information, status as a qualified individual with a disability, or any other characteristic protected by law.
For more information regarding protection from discrimination under Federal law for applicants and employees, please refer to this link: Pay Transparency
Apply for this job
*
indicates a required field