Magnet.me  -  The smart network where students and professionals find their internship or job.

The smart network where students and professionals find their internship or job.

Security Engineer – Common Criteria Evaluation & Certification

Posted 8 Oct 2026
Share:
Work experience
2 to 10 years
Full-time / part-time
Full-time
Job function
Degree level
Required language
English (Fluent)

Build your career on Magnet.me

Create a profile and receive smart job recommendations based on your liked jobs.

Do you want to contribute to the security assurance and certification of complex, mission-critical systems? As an Experienced Security Engineer - Space Unit (Security Engineer – Common Criteria Evaluation & Certification), you will play a key role in supporting the security evaluation and certification process, ensuring that products and systems meet applicable Common Criteria requirements.

Please note that holding an EU passport is mandatory for obtaining an EU Personal Security Clearance, which is part of our selection process. A pre-employment screening is also part of the selection process.

  • Categorie: Cyber Security
  • Hoofdlokatie: Nederland, Zuid-Holland, Randstad
  • Type dienstverband: Full Time

You will work closely with system architects, developers, security specialists, independent evaluation laboratories, and certification authorities. A central part of your role will be translating technical product capabilities and security mechanisms into structured evaluation evidence, including the preparation and maintenance of Security Targets (STs) and supporting security documentation.

You will support the certification lifecycle from initial evaluation scoping and definition of the Target of Evaluation (TOE), through evidence preparation, evaluation activities, clarification of evaluator findings, vulnerability analysis and testing support, to successful completion of the certification process.

At CGI, you will work in a multidisciplinary and international environment where security assurance, traceability, technical accuracy, and structured documentation are essential.

Your role in our team

  • Support the planning, coordination, and execution of Common Criteria evaluation and certification activities.
  • Prepare, maintain, and review Security Target (ST) documentation in accordance with applicable Common Criteria requirements.
  • Define and document the Target of Evaluation (TOE), its boundaries, interfaces, operational environment, security functions, assumptions, threats, and organisational security policies.
  • Define and maintain Security Objectives, Security Functional Requirements (SFRs), Security Assurance Requirements (SARs), and the TOE Summary Specification.
  • Ensure consistency and traceability between security requirements, system architecture, security functionality, design documentation, implementation evidence, test evidence, and operational guidance.
  • Support the selection and interpretation of applicable Protection Profiles, Evaluation Assurance Levels (EALs), assurance packages, and augmentation requirements, where relevant to the certification.
  • Prepare and coordinate evaluation evidence covering relevant Common Criteria assurance areas, such as development documentation, lifecycle processes, configuration management, secure delivery, guidance documentation, testing, and vulnerability assessment.
  • Work closely with developers, architects, testers, and product security teams to collect and review the technical evidence required by evaluators.
  • Act as a technical interface with the Common Criteria evaluation laboratory, responding to evaluator questions, observations, clarification requests, and findings.
  • Analyse evaluation findings and coordinate corrective actions with engineering teams to resolve identified gaps or inconsistencies.
  • Support vulnerability analysis and penetration testing activities, including the identification and assessment of potential vulnerabilities relevant to the TOE.
  • Support evaluator testing by preparing test environments, configurations, documentation, test evidence, and technical explanations.
  • Review product architecture and security mechanisms to determine whether they adequately support the security claims made in the Security Target.
  • Maintain configuration and version traceability between the evaluated product, evaluation evidence, software releases, and certification baseline.
  • Support security impact analyses when changes are introduced to an evaluated or certified product.
  • Contribute to improving internal processes, templates, and engineering practices for security assurance and product certification.

How you strengthen our team

  • A Bachelor’s or Master’s degree in Cybersecurity, Computer Science, Software Engineering, Telecommunications, Systems Engineering, or a related technical discipline.
  • Professional experience in product security, security assurance, security certification, or security engineering.
  • Practical experience with the Common Criteria for Information Technology Security Evaluation (ISO/IEC 15408) and the associated evaluation process.
  • Experience preparing or contributing to Security Targets (STs) or comparable formal security assurance documentation.
  • Good understanding of key Common Criteria concepts, including Target of Evaluation (TOE) and TOE boundary definition; Security Problem Definition; Threats, assumptions, and Organisational Security Policies; Security Objectives; Security Functional Requirements (SFRs); Security Assurance Requirements (SARs); TOE Summary Specification; Protection Profiles and conformance claims; Evaluation Assurance Levels and assurance packages.
  • Knowledge of the main Common Criteria assurance domains relevant to an evaluation, including ASE (Security Target Evaluation), ADV (Development), AGD (Guidance Documents), ALC (Life-cycle Support), ATE (Tests), and AVA (Vulnerability Assessment).
  • Ability to understand complex system and software architectures and translate technical implementations into clear and structured security assurance arguments.
  • Knowledge of security architecture concepts such as authentication, authorisation, access control, cryptographic mechanisms, secure communications, trusted boundaries, secure boot, key management, audit and logging, integrity protection, and secure update mechanisms.
  • Experience reviewing technical documentation such as software architecture descriptions, functional specifications, interface descriptions, design documents, configuration-management documentation, test specifications, and operational guidance.
  • Understanding of vulnerability analysis, penetration testing, attack scenarios, attack surfaces, and security testing methodologies.
  • Ability to assess whether security claims and requirements are correctly implemented and supported by appropriate technical evidence.
  • Strong technical writing skills and the ability to produce precise, structured, auditable documentation.
  • Strong analytical skills and attention to detail, particularly regarding consistency and traceability across multiple technical documents.
  • Strong communication and stakeholder-management skills, with the ability to work effectively with engineers, evaluators, certification bodies, security specialists, and project management.
  • Structured, proactive, and quality-focused, with the ability to manage evaluation findings and documentation through multiple review cycles.

Nice to Have

  • Previous experience working directly with an accredited Common Criteria evaluation laboratory or national certification scheme.
  • Experience supporting a product through a complete Common Criteria evaluation and certification lifecycle.
  • Experience with higher-assurance evaluations or augmented assurance requirements.
  • Knowledge of the Common Evaluation Methodology (CEM) and practical experience interpreting evaluator work units and evidence expectations.
  • Experience working with Protection Profiles, collaborative Protection Profiles, or security-specific assurance packages applicable to the relevant product domain.
  • Knowledge of secure software and systems engineering principles, including threat modelling, secure development lifecycle practices, configuration management, and vulnerability management.
  • Experience with cryptographic products, secure embedded systems, operating systems, network/security appliances, trusted platforms, or other products subject to formal security certification.
  • Familiarity with complementary security standards or assurance frameworks such as ISO/IEC 27001, IEC 62443, FIPS 140, ETSI cybersecurity standards, or NIST guidance, depending on the product domain.
  • Experience working in regulated, defence, aerospace, governmental, critical-infrastructure, or other high-assurance environments.
  • Experience supporting certification maintenance, product changes, re-evaluation, or security impact analysis after initial certification.
  • Relevant cybersecurity or security assurance certifications.
  • Experience working in European space programs such as Galileo, Copernicus, or similar.
  • Familiarity with ECSS standards or mission-critical system lifecycles.
  • Previous collaboration with ESA, EUSPA, or other space industry stakeholders.

For this role all the work needs to be performed on-site at our CGI office with no hybrid working opportunities.

Where you will be working?

You will join a multidisciplinary and international CGI team working on security assurance and certification of complex, mission-critical systems. You will collaborate closely with system architects, developers, security specialists, testers and other engineering disciplines, as well as independent evaluation laboratories and certification authorities.

The environment is technically complex and highly security-sensitive, with a strong focus on Common Criteria evaluation, security assurance, traceability and structured technical documentation. Depending on the project, you may contribute to European space programmes and work with stakeholders within the European space and security ecosystem.

Due to the sensitivity and security requirements of this role, all work must be performed on-site at our CGI office. Hybrid or remote working is not possible for this position.

CGI is one of the world's largest IT and business consulting companies. Our people help keep the Netherlands running. Government organizations, banks, aerospace organizations, infrastructure providers, and companies in the energy, transport and manufacturing sectors are among CGI's clients. We work on meaningful projects that impact the daily lives of millions of people. We combine a strong local presence with global industry expertise, our ecosystem and colleagues around the world.

At CGI, we combine challenging projects with excellent employment conditions:

  • Permanent employment contract from day one;
  • A competitive salary based on your experience and seniority;
  • 8% holiday allowance;
  • Bonus and profit-sharing scheme;
  • 20 statutory and 5 additional vacation days (based on full-time employment);
  • Lease budget / mobility budget;
  • NS Business Card;
  • Bicycle plan through CGI;
  • Opportunity to invest 3% in CGI shares;
  • Gross healthcare allowance of €116.35 per month;
  • €40 net home-working allowance per month;
  • Excellent pension scheme.

CGI is een van ’s werelds grootste IT-bedrijven. Onze mensen houden Nederland draaiende. Overheidsinstellingen, banken, infrastructurele organisaties en productiebedrijven zijn klanten van CGI. Projecten die het alledaagse leven van miljoenen mensen raken. Groei mee met ons en maak je ambitie waar.

IT
Rotterdam
Active in 40 countries
77,500 employees
90% men - 10% women
Average age is 40 years