BAE Systems

Senior Common Criteria Certification Specialist

BAE Systems

Doha, Doha Municipality, Qatar · Full Time

Be the first to apply

Experience
8+ yrs
Salary
Openings
1
Posted
1 week ago
Work mode
In office
Education
University degree in IT or Information Security
Resume
Required to apply

Where you'll work

Job description

Role Overview

The Senior Common Criteria Certification Specialist spearheads cybersecurity product and system certification aligned with global standards, mainly Common Criteria. This role entails analyzing security documentation, conducting in-depth technical risk assessments, supervising rigorous testing procedures, and advising on certification verdicts, including Evaluation Assurance Levels (EALs).

Key Duties

  • Manage daily certification, validation, oversight, maintenance of certificates, and mutual recognition activities in compliance with Common Criteria standards.
  • Uphold the highest levels of expertise, impartiality, and consistency across all evaluation and certification tasks.
  • Apply comprehensive knowledge of Common Criteria standards, including Protection Profiles, Security Targets, and EALs.
  • Mentor and guide certification body members and evaluators, assisting with complex evaluation challenges.
  • Oversee review and evaluation of developer-submitted documentation such as Security Targets, design specifications, and test plans.
  • Perform sophisticated technical risk assessments, identifying vulnerabilities and recommending mitigations.
  • Supervise security testing phases to ensure precise and thorough execution.
  • Support development of certification policies, standards, procedures, and guidelines.
  • Collaborate closely with developers, evaluators, and certification authorities to maintain evaluation accuracy and consistency.
  • Continuously monitor and adapt to emerging cybersecurity threats, technologies, and standards.

Required Qualifications and Experience

  • University degree in IT, information security, or related discipline, preferably focused on security.
  • Certification from a recognized Common Criteria certification body; prior certifier experience is advantageous.
  • Formal IT Security Overview and Common Criteria evaluation training and certification.
  • At least eight years of professional experience overall, including minimum four years as a senior IT/information security/cybersecurity auditor, risk manager, or information security manager.
  • Preferred proficiency in both Arabic and English, spoken and written.

Additional Skills and Competencies

  • Strong analytical and problem-solving capabilities.
  • Proven IT and information security assessment expertise.
  • Experience in risk assessment and management alongside audit methodologies.
  • Hands-on experience with information security practices.
  • Understanding ISO27001 certification audit requirements.
  • Excellent communication, documentation, and technical report writing skills.
  • Familiarity with security testing tools and methodologies.
  • Experienced in assessing formal schemes impartially to reach definitive conclusions.
  • Proven ability to plan and deliver training and workshops across governmental and private sectors.

Technical Knowledge

  • Expertise in risk assessment, audit methods, and information security frameworks such as NIST, ISO27001, and NIA.
  • Understanding of NIA controls and implementation needs.
  • Up-to-date awareness of cybersecurity trends.

Behavioral Competencies

  • Excellent multitasking skills, capable of managing multiple project teams and stakeholders.
  • Attention to detail with ability to meet deadlines and work under pressure.
  • Strong interpersonal skills and ability to work independently with enthusiasm.

Specific Role Requirements

  • Proficiency in interpreting certification criteria standards including ISO/IEC 17021, 17024, 27006, and 17065.
  • Knowledge of auditing and assurance standards such as ISA, ITAF, ISO17021, and ISO19011.
  • Experience with third-party audits, certification processes, and cybersecurity audits.
  • Hands-on experience in information security audits or management.

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help