What are the responsibilities and job description for the FIPS Certifications Consultant position at Corsec Security, Inc.?
Position: Certifications Consultant
Location: Herndon, VA 20171
Job Type: mid-level, Full-time
Corsec is at the forefront of working with top IT Security companies to achieve FIPS 140-3, CC and DoDIN APL certifications. We are looking for an entry-level, full-time Information Security Analyst to join our team.
Job Description: Product certification support for FIPS 140 Consulting Team.
Responsibilities
Location: Herndon, VA 20171
Job Type: mid-level, Full-time
Corsec is at the forefront of working with top IT Security companies to achieve FIPS 140-3, CC and DoDIN APL certifications. We are looking for an entry-level, full-time Information Security Analyst to join our team.
Job Description: Product certification support for FIPS 140 Consulting Team.
Responsibilities
- Examine IT products against security certification standards in order to determine and document compliance gaps.
- Understand and analyze cryptography within an IT system.
- Analyze design, architecture and implementation details of IT products and produce technical documentation specific to security certifications.
- Configure IT products to meet compliance requirements and produce certification-specific deployment guidance.
- Author evaluation documentation for submission to testing labs and certifying authorities.
- Produce testing reports by conducting functional, operational, and vulnerability testing of the IT products.
- Communicate effectively with security product vendors, testing facilities personnel, and certifying authorities to address compliance gaps, testing queries and documentation comments.
- Manage project schedules
- Knowledge of a variety of cryptographic methods, including encryption/decryption, digital signatures and PKI, hashing, random number generation, and key transport/agreement methods
- Knowledge of secure communications protocols, including TLS, SSH, and IPsec
- Bachelor's degree in computer science, information systems, cyber security, computer engineering, or related discipline
- Strong analytical and technical skills - Ability to assess IT products and components with great attention to detail, especially in relation to the uses of cryptography within a system
- Strong technical writing skills
- Strong oral presentation skills - Ability to articulate in technical and non-technical terms to customers, peers, and management
- Strong organizational and prioritization skills
- Experience with project management
- Experience with government certification processes, especially FIPS 140-3
- Familiarity with the NIST SP 800 series publications, beyond SP 800-53