Experienced Security Engineer - Space UnitSolliciteren
Experienced Security Engineer - Space Unit
CGI Nederland
Experienced Security Engineer - Space Unit
IT-consultancy
CC-certificering
Salaris in overleg
Fulltime
CGI Nederland
Amsterdam
Samenvatting
You will work in an international environment where you support the security evaluation and certification of complex, mission-critical systems through structured Common Criteria documentation.
Wat krijg je?
Salaris in overleg
Fulltime
Loondienst (vast)
Direct vast contract
Bonusregeling
Winstdeling
Pensioenregeling
Flexibele werktijden
Extra vakantiedagen
Reiskostenvergoeding
Aandelenopties
Fietsplan
Thuiswerkvergoeding
Vakantiegeld
Wat ga je doen?
- Security Target documentatie opstellen en beoordelen
- Technisch aanspreekpunt voor het evaluatielaboratorium zijn
- Ondersteunen van kwetsbaarheidsanalyses en penetratietesten
- De Target of Evaluation (TOE) definiëren
- Productarchitectuur en beveiligingsmechanismen technisch reviewen
Amsterdam
Wat verwachten wij?
- Degree in Cybersecurity, Computer Science or related engineering
- Professional experience in security assurance or certification
- Practical experience with Common Criteria ISO/IEC 15408
- Experience preparing Security Targets or assurance documentation
Volledige vacaturetekst
At CGI, you will contribute to the security assurance and certification of complex, mission-critical systems. As a Security Engineer, you play a key role in translating technical product capabilities into structured evaluation evidence for European space programs. Beyond joining a global leader, you will become a co-owner of the company from day one, sharing in the success and growth you help create. Dive into a high-security environment and help shape the future of space technology!
Experienced Security Engineer - Space Unit
Functiebeschrijving
Please note that holding an EU passport is mandatory for obtaining an EU Personal Security Clearance, which is part of our selection process. A pre-employment screening is also part of the selection process.
Do you want to contribute to the security assurance and certification of complex, mission-critical systems? As a Security Engineer - Common Criteria Evaluation & Certification, you will play a key role in supporting the security evaluation and certification process, ensuring that products and systems meet applicable Common Criteria requirements.
You will work closely with system architects, developers, security specialists, independent evaluation laboratories, and certification authorities. A central part of your role will be translating technical product capabilities and security mechanisms into structured evaluation evidence, including the preparation and maintenance of Security Targets (STs) and supporting security documentation.
You will support the certification lifecycle from initial evaluation scoping and definition of the Target of Evaluation (TOE), through evidence preparation, evaluation activities, clarification of evaluator findings, vulnerability analysis and testing support, to successful completion of the certification process.
At CGI, you will work in a multidisciplinary and international environment where security assurance, traceability, technical accuracy, and structured documentation are essential.
Your role in our team
•Support the planning, coordination, and execution of Common Criteria evaluation and certification activities.
•Prepare, maintain, and review Security Target (ST) documentation in accordance with applicable Common Criteria requirements.
•Define and document the Target of Evaluation (TOE), its boundaries, interfaces, operational environment, security functions, assumptions, threats, and organisational security policies.
•Define and maintain Security Objectives, Security Functional Requirements (SFRs), Security Assurance Requirements (SARs), and the TOE Summary Specification.
•Ensure consistency and traceability between security requirements, system architecture, security functionality, design documentation, implementation evidence, test evidence, and operational guidance.
•Support the selection and interpretation of applicable Protection Profiles, Evaluation Assurance Levels (EALs), assurance packages, and augmentation requirements, where relevant to the certification.
•Prepare and coordinate evaluation evidence covering relevant Common Criteria assurance areas, such as development documentation, lifecycle processes, configuration management, secure delivery, guidance documentation, testing, and vulnerability assessment.
•Work closely with developers, architects, testers, and product security teams to collect and review the technical evidence required by evaluators.
•Act as a technical interface with the Common Criteria evaluation laboratory, responding to evaluator questions, observations, clarification requests, and findings.
•Analyse evaluation findings and coordinate corrective actions with engineering teams to resolve identified gaps or inconsistencies.
•Support vulnerability analysis and penetration testing activities, including the identification and assessment of potential vulnerabilities relevant to the TOE.
•Support evaluator testing by preparing test environments, configurations, documentation, test evidence, and technical explanations.
•Review product architecture and security mechanisms to determine whether they adequately support the security claims made in the Security Target.
•Maintain configuration and version traceability between the evaluated product, evaluation evidence, software releases, and certification baseline.
•Support security impact analyses when changes are introduced to an evaluated or certified product.
•Contribute to improving internal processes, templates, and engineering practices for security assurance and product certification.
How you strengthen our team
•A Bachelor’s or Master’s degree in Cybersecurity, Computer Science, Software Engineering, Telecommunications, Systems Engineering, or a related technical discipline.
•Professional experience in product security, security assurance, security certification, or security engineering.
•Practical experience with the Common Criteria for Information Technology Security Evaluation (ISO/IEC 15408) and the associated evaluation process.
•Experience preparing or contributing to Security Targets (STs) or comparable formal security assurance documentation.
•Good understanding of key Common Criteria concepts, including:
· Target of Evaluation (TOE) and TOE boundary definition
· Security Problem Definition
· Threats, assumptions, and Organisational Security Policies
· Security Objectives
· Security Functional Requirements (SFRs)
· Security Assurance Requirements (SARs)
· TOE Summary Specification
· Protection Profiles and conformance claims
· Evaluation Assurance Levels and assurance packages
•Knowledge of the main Common Criteria assurance domains relevant to an evaluation, including ASE (Security Target Evaluation), ADV (Development), AGD (Guidance Documents), ALC (Life-cycle Support), ATE (Tests), and AVA (Vulnerability Assessment).
•Ability to understand complex system and software architectures and translate technical implementations into clear and structured security assurance arguments.
•Knowledge of security architecture concepts such as authentication, authorisation, access control, cryptographic mechanisms, secure communications, trusted boundaries, secure boot, key management, audit and logging, integrity protection, and secure update mechanisms.
•Experience reviewing technical documentation such as software architecture descriptions, functional specifications, interface descriptions, design documents, configuration-management documentation, test specifications, and operational guidance.
•Understanding of vulnerability analysis, penetration testing, attack scenarios, attack surfaces, and security testing methodologies.
•Ability to assess whether security claims and requirements are correctly implemented and supported by appropriate technical evidence.
•Strong technical writing skills and the ability to produce precise, structured, auditable documentation.
•Strong analytical skills and attention to detail, particularly regarding consistency and traceability across multiple technical documents.
•Strong communication and stakeholder-management skills, with the ability to work effectively with engineers, evaluators, certification bodies, security specialists, and project management.
•Structured, proactive, and quality-focused, with the ability to manage evaluation findings and documentation through multiple review cycles.
Nice to Have
•Previous experience working directly with an accredited Common Criteria evaluation laboratory or national certification scheme.
•Experience supporting a product through a complete Common Criteria evaluation and certification lifecycle.
•Experience with higher-assurance evaluations or augmented assurance requirements.
•Knowledge of the Common Evaluation Methodology (CEM) and practical experience interpreting evaluator work units and evidence expectations.
•Experience working with Protection Profiles, collaborative Protection Profiles, or security-specific assurance packages applicable to the relevant product domain.
•Knowledge of secure software and systems engineering principles, including threat modelling, secure development lifecycle practices, configuration management, and vulnerability management.
•Experience with cryptographic products, secure embedded systems, operating systems, network/security appliances, trusted platforms, or other products subject to formal security certification.
•Familiarity with complementary security standards or assurance frameworks such as ISO/IEC 27001, IEC 62443, FIPS 140, ETSI cybersecurity standards, or NIST guidance, depending on the product domain.
•Experience working in regulated, defence, aerospace, governmental, critical-infrastructure, or other high-assurance environments.
•Experience supporting certification maintenance, product changes, re-evaluation, or security impact analysis after initial certification.
•Relevant cybersecurity or security assurance certifications.
•Experience working in European space programs such as Galileo, Copernicus, or similar.
•Familiarity with ECSS standards or mission-critical system lifecycles.
•Previous collaboration with ESA, EUSPA, or other space industry stakeholders.
For this role all the work needs to be performed on-site at our CGI office with no hybrid working opportunities.
A pre-employment screening is part of our selection process.
Where you will be working?
You will join a multidisciplinary and international CGI team working on security assurance and certification of complex, mission-critical systems. You will collaborate closely with system architects, developers, security specialists, testers and other engineering disciplines, as well as independent evaluation laboratories and certification authorities.
The environment is technically complex and highly security-sensitive, with a strong focus on Common Criteria evaluation, security assurance, traceability and structured technical documentation. Depending on the project, you may contribute to European space programmes and work with stakeholders within the European space and security ecosystem.
Due to the sensitivity and security requirements of this role, all work must be performed on-site at our CGI office. Hybrid or remote working is not possible for this position.
AI & Futureproof
At CGI, we continuously explore the impact of new technologies on our services and the solutions we develop for our clients. Developments in AI and automation are also playing an increasingly important role.
Why CGI
CGI is one of the world's largest IT and business consulting companies. Our people help keep the Netherlands running. Government organizations, banks, aerospace organizations, infrastructure providers, and companies in the energy, transport and manufacturing sectors are among CGI's clients. We work on meaningful projects that impact the daily lives of millions of people. We combine a strong local presence with global industry expertise, our ecosystem and colleagues around the world.
We are proud of the impactful projects we successfully deliver together with our colleagues.
At CGI, we highly value diversity and inclusion, as this not only strengthens collaboration but also often leads to better results. We look forward to your contribution to our team! You will work in small, self-managing teams consisting of experts in your field.
At CGI, we combine challenging projects with excellent employment conditions:
• Permanent employment contract from day one;
• A competitive salary based on your experience and seniority;
• 8% holiday allowance;
• Bonus and profit-sharing scheme;
• 20 statutory and 5 additional vacation days (based on full-time employment);
• Lease budget / mobility budget;
• NS Business Card;
• Bicycle plan through CGI;
• Opportunity to invest 3% in CGI shares;
• Gross healthcare allowance of €116.35 per month;
• €40 net home-working allowance per month;
• Excellent pension scheme;
• Hybrid working.
Join our team of experts and apply today!
We will contact you as soon as possible! Do you have any questions about the role? Please contact Director Consulting Services, Willie Betancourt via de button "Solliciteer nu" op deze pagina. or +31 6 27402419.
Do you have any questions about the recruitment process? Please contact Recruitment Business Partner, Ferhun Dogan via de button "Solliciteer nu" op deze pagina. or +31 6 11484743.
We do not work with external recruitment agencies. Therefore, unsolicited acquisition is not appreciated.
#LI-FD6
Taken en verantwoordelijkheden
Criteria
Together, as owners, let’s turn meaningful insights into action.
In 1976 opgericht als een familiebedrijf, is CGI vandaag de dag een van de grootste onafhankelijke zakelijke en ICT-dienstverleners ter wereld. Bij ons draait het om ownership, teamwork en respect. Je krijgt de ruimte om al je talenten volledig te ontplooien.
Vanaf je eerste werkdag ben je mede-eigenaar van CGI. We profiteren samen van ons succes en je krijgt de kans én verantwoordelijkheid om actief bij te dragen aan de koers en strategie van ons bedrijf.
Jouw inzet voegt waarde toe. Je werkt aan innovatieve oplossingen en bouwt aan je netwerk van collega's en klanten. Je hebt toegang tot wereldwijde kansen om je ideeën te realiseren, mogelijkheden te benutten en te profiteren van onze kennis van de industrie en technologische expertise.
Ontdek bij ons de mogelijkheden voor jouw persoonlijke ontwikkeling en zet de volgende stap in je carrière. Hier staat jouw succes centraal!
J1026-0323
Meer tonenFunctiebeschrijving
Please note that holding an EU passport is mandatory for obtaining an EU Personal Security Clearance, which is part of our selection process. A pre-employment screening is also part of the selection process.
Do you want to contribute to the security assurance and certification of complex, mission-critical systems? As a Security Engineer - Common Criteria Evaluation & Certification, you will play a key role in supporting the security evaluation and certification process, ensuring that products and systems meet applicable Common Criteria requirements.
You will work closely with system architects, developers, security specialists, independent evaluation laboratories, and certification authorities. A central part of your role will be translating technical product capabilities and security mechanisms into structured evaluation evidence, including the preparation and maintenance of Security Targets (STs) and supporting security documentation.
You will support the certification lifecycle from initial evaluation scoping and definition of the Target of Evaluation (TOE), through evidence preparation, evaluation activities, clarification of evaluator findings, vulnerability analysis and testing support, to successful completion of the certification process.
At CGI, you will work in a multidisciplinary and international environment where security assurance, traceability, technical accuracy, and structured documentation are essential.
Your role in our team
•Support the planning, coordination, and execution of Common Criteria evaluation and certification activities.
•Prepare, maintain, and review Security Target (ST) documentation in accordance with applicable Common Criteria requirements.
•Define and document the Target of Evaluation (TOE), its boundaries, interfaces, operational environment, security functions, assumptions, threats, and organisational security policies.
•Define and maintain Security Objectives, Security Functional Requirements (SFRs), Security Assurance Requirements (SARs), and the TOE Summary Specification.
•Ensure consistency and traceability between security requirements, system architecture, security functionality, design documentation, implementation evidence, test evidence, and operational guidance.
•Support the selection and interpretation of applicable Protection Profiles, Evaluation Assurance Levels (EALs), assurance packages, and augmentation requirements, where relevant to the certification.
•Prepare and coordinate evaluation evidence covering relevant Common Criteria assurance areas, such as development documentation, lifecycle processes, configuration management, secure delivery, guidance documentation, testing, and vulnerability assessment.
•Work closely with developers, architects, testers, and product security teams to collect and review the technical evidence required by evaluators.
•Act as a technical interface with the Common Criteria evaluation laboratory, responding to evaluator questions, observations, clarification requests, and findings.
•Analyse evaluation findings and coordinate corrective actions with engineering teams to resolve identified gaps or inconsistencies.
•Support vulnerability analysis and penetration testing activities, including the identification and assessment of potential vulnerabilities relevant to the TOE.
•Support evaluator testing by preparing test environments, configurations, documentation, test evidence, and technical explanations.
•Review product architecture and security mechanisms to determine whether they adequately support the security claims made in the Security Target.
•Maintain configuration and version traceability between the evaluated product, evaluation evidence, software releases, and certification baseline.
•Support security impact analyses when changes are introduced to an evaluated or certified product.
•Contribute to improving internal processes, templates, and engineering practices for security assurance and product certification.
How you strengthen our team
•A Bachelor’s or Master’s degree in Cybersecurity, Computer Science, Software Engineering, Telecommunications, Systems Engineering, or a related technical discipline.
•Professional experience in product security, security assurance, security certification, or security engineering.
•Practical experience with the Common Criteria for Information Technology Security Evaluation (ISO/IEC 15408) and the associated evaluation process.
•Experience preparing or contributing to Security Targets (STs) or comparable formal security assurance documentation.
•Good understanding of key Common Criteria concepts, including:
· Target of Evaluation (TOE) and TOE boundary definition
· Security Problem Definition
· Threats, assumptions, and Organisational Security Policies
· Security Objectives
· Security Functional Requirements (SFRs)
· Security Assurance Requirements (SARs)
· TOE Summary Specification
· Protection Profiles and conformance claims
· Evaluation Assurance Levels and assurance packages
•Knowledge of the main Common Criteria assurance domains relevant to an evaluation, including ASE (Security Target Evaluation), ADV (Development), AGD (Guidance Documents), ALC (Life-cycle Support), ATE (Tests), and AVA (Vulnerability Assessment).
•Ability to understand complex system and software architectures and translate technical implementations into clear and structured security assurance arguments.
•Knowledge of security architecture concepts such as authentication, authorisation, access control, cryptographic mechanisms, secure communications, trusted boundaries, secure boot, key management, audit and logging, integrity protection, and secure update mechanisms.
•Experience reviewing technical documentation such as software architecture descriptions, functional specifications, interface descriptions, design documents, configuration-management documentation, test specifications, and operational guidance.
•Understanding of vulnerability analysis, penetration testing, attack scenarios, attack surfaces, and security testing methodologies.
•Ability to assess whether security claims and requirements are correctly implemented and supported by appropriate technical evidence.
•Strong technical writing skills and the ability to produce precise, structured, auditable documentation.
•Strong analytical skills and attention to detail, particularly regarding consistency and traceability across multiple technical documents.
•Strong communication and stakeholder-management skills, with the ability to work effectively with engineers, evaluators, certification bodies, security specialists, and project management.
•Structured, proactive, and quality-focused, with the ability to manage evaluation findings and documentation through multiple review cycles.
Nice to Have
•Previous experience working directly with an accredited Common Criteria evaluation laboratory or national certification scheme.
•Experience supporting a product through a complete Common Criteria evaluation and certification lifecycle.
•Experience with higher-assurance evaluations or augmented assurance requirements.
•Knowledge of the Common Evaluation Methodology (CEM) and practical experience interpreting evaluator work units and evidence expectations.
•Experience working with Protection Profiles, collaborative Protection Profiles, or security-specific assurance packages applicable to the relevant product domain.
•Knowledge of secure software and systems engineering principles, including threat modelling, secure development lifecycle practices, configuration management, and vulnerability management.
•Experience with cryptographic products, secure embedded systems, operating systems, network/security appliances, trusted platforms, or other products subject to formal security certification.
•Familiarity with complementary security standards or assurance frameworks such as ISO/IEC 27001, IEC 62443, FIPS 140, ETSI cybersecurity standards, or NIST guidance, depending on the product domain.
•Experience working in regulated, defence, aerospace, governmental, critical-infrastructure, or other high-assurance environments.
•Experience supporting certification maintenance, product changes, re-evaluation, or security impact analysis after initial certification.
•Relevant cybersecurity or security assurance certifications.
•Experience working in European space programs such as Galileo, Copernicus, or similar.
•Familiarity with ECSS standards or mission-critical system lifecycles.
•Previous collaboration with ESA, EUSPA, or other space industry stakeholders.
For this role all the work needs to be performed on-site at our CGI office with no hybrid working opportunities.
A pre-employment screening is part of our selection process.
Where you will be working?
You will join a multidisciplinary and international CGI team working on security assurance and certification of complex, mission-critical systems. You will collaborate closely with system architects, developers, security specialists, testers and other engineering disciplines, as well as independent evaluation laboratories and certification authorities.
The environment is technically complex and highly security-sensitive, with a strong focus on Common Criteria evaluation, security assurance, traceability and structured technical documentation. Depending on the project, you may contribute to European space programmes and work with stakeholders within the European space and security ecosystem.
Due to the sensitivity and security requirements of this role, all work must be performed on-site at our CGI office. Hybrid or remote working is not possible for this position.
AI & Futureproof
At CGI, we continuously explore the impact of new technologies on our services and the solutions we develop for our clients. Developments in AI and automation are also playing an increasingly important role.
Why CGI
CGI is one of the world's largest IT and business consulting companies. Our people help keep the Netherlands running. Government organizations, banks, aerospace organizations, infrastructure providers, and companies in the energy, transport and manufacturing sectors are among CGI's clients. We work on meaningful projects that impact the daily lives of millions of people. We combine a strong local presence with global industry expertise, our ecosystem and colleagues around the world.
We are proud of the impactful projects we successfully deliver together with our colleagues.
At CGI, we highly value diversity and inclusion, as this not only strengthens collaboration but also often leads to better results. We look forward to your contribution to our team! You will work in small, self-managing teams consisting of experts in your field.
At CGI, we combine challenging projects with excellent employment conditions:
• Permanent employment contract from day one;
• A competitive salary based on your experience and seniority;
• 8% holiday allowance;
• Bonus and profit-sharing scheme;
• 20 statutory and 5 additional vacation days (based on full-time employment);
• Lease budget / mobility budget;
• NS Business Card;
• Bicycle plan through CGI;
• Opportunity to invest 3% in CGI shares;
• Gross healthcare allowance of €116.35 per month;
• €40 net home-working allowance per month;
• Excellent pension scheme;
• Hybrid working.
Join our team of experts and apply today!
We will contact you as soon as possible! Do you have any questions about the role? Please contact Director Consulting Services, Willie Betancourt via de button "Solliciteer nu" op deze pagina. or +31 6 27402419.
Do you have any questions about the recruitment process? Please contact Recruitment Business Partner, Ferhun Dogan via de button "Solliciteer nu" op deze pagina. or +31 6 11484743.
We do not work with external recruitment agencies. Therefore, unsolicited acquisition is not appreciated.
#LI-FD6
Taken en verantwoordelijkheden
Criteria
Together, as owners, let’s turn meaningful insights into action.
In 1976 opgericht als een familiebedrijf, is CGI vandaag de dag een van de grootste onafhankelijke zakelijke en ICT-dienstverleners ter wereld. Bij ons draait het om ownership, teamwork en respect. Je krijgt de ruimte om al je talenten volledig te ontplooien.
Vanaf je eerste werkdag ben je mede-eigenaar van CGI. We profiteren samen van ons succes en je krijgt de kans én verantwoordelijkheid om actief bij te dragen aan de koers en strategie van ons bedrijf.
Jouw inzet voegt waarde toe. Je werkt aan innovatieve oplossingen en bouwt aan je netwerk van collega's en klanten. Je hebt toegang tot wereldwijde kansen om je ideeën te realiseren, mogelijkheden te benutten en te profiteren van onze kennis van de industrie en technologische expertise.
Ontdek bij ons de mogelijkheden voor jouw persoonlijke ontwikkeling en zet de volgende stap in je carrière. Hier staat jouw succes centraal!
J1026-0323
Over de werkgever
CGI Nederland
AmsterdamIT-consultancy
119 vacatures
CGI is een van de grootste zakelijke en IT-dienstverleners ter wereld. Bij ons draait het om ownership, teamwork en respect. En je krijgt de ruimte om al je talenten te ontwikkelen.
Bij CGI werk je in kleine, zelfsturende teams, samen met onze klanten aan opdrachten die het alledaagse leven van miljoenen mensen raken. Daarnaast maak je deel uit van een wereldwijde community van CGI-experts die werken aan de nieuwste technologieën. Dit geeft je de mogelijkheden en inspiratie om te werken aan duurzame oplossingen voor de toekomst. Denk aan verbeteringen aan het spoor en onze (vaar)wegen, betrouwbare waterkeringen, klantvriendelijke chatbots en allerlei oplossingen die de energietransitie faciliteren. Impactvolle projecten om zichtbaar trots op te zijn. Dat is werken bij CGI.
Vanaf dag één heb je de ruimte om je eigen carrièrepad vorm te geven. Je krijgt de kans om opleidingen te volgen en de mogelijkheid om bij te blijven op jouw vakgebied. Daarnaast hebben we oog voor je welzijn, vitaliteit en een gezonde balans tussen werk en privé.
Kiezen voor CGI is kiezen voor een wereldbedrijf én voor jezelf.
Meer weten? Kijk op www.werkenbijcgi.nl
Dit bedrijf werft al sinds 2013 via ICTerGezocht.nl, je sollicitatie is in goede handen.
Zo werkt solliciteren
- Snel en eenvoudig via je mobiel
- Solliciteer in 1 minuut
- CV niet verplicht
- Volg je sollicitatie via Track & Trace
- Volg je sollicitatie via Track & Trace
Goed om te weten
C
Rechtstreeks contact
CGI van CGI Nederland ontvangt jouw sollicitatie.
Makkelijk solliciteren Solliciteren