Since 1985, Qualcomm has been an innovator in the wireless telecommunications industry with more than 13,000 patents in the United States. Today, Qualcomm provides a variety of pro
Senior Security Certification Analyst
Location
France
Posted
21 days ago
Salary
0
Seniority
Senior
Job Description
Senior Security Certification Analyst
Qualcomm
Role Description We are seeking a senior security certification engineer with a strong hands-on background in FIPS 140-2 and FIPS 140-3 validations. You will join our Security Certification team supporting Qualcomm product certifications across hardware and software domains. In this role, you will apply 5-8 years of experience to ensure Qualcomm cryptographic modules achieve FIPS 140 compliance, working closely with worldwide engineering teams, product managers, corporate security, third-party evaluation labs, and government validation authorities. The role offers exposure to all aspects of product security—especially cryptography, certification requirements, and the development of FIPS documentation—ultimately enabling Qualcomm to meet global customer security needs and deploy trusted, compliant solutions. Qualifications - Bachelor's degree in Electrical Engineering, Computer Science, Information Security, Mathematics or equivalent - Preferred: Master's in Computer Engineering, Mathematics, Computer Science, or Electrical Engineering Requirements - 5+ years of experience in embedded product’s security, cryptography, and security certification (e.g. Secure Processor or secure element, Cryptographic libraries, hardware cryptography, and embedded security software) in the context of FIPS 140-2/-3, Common Criteria (CC), SESIP or banking standards such as EMVCo, MasterCard, VISA, etc. - 3+ years of embedded security/cryptography experience with direct involvement in FIPS 140-2/-3 cryptographic module validations (e.g. cryptographic library or secure hardware module validation) - 2+ years of experience in project management - Intermediate knowledge of cryptography (symmetric, asymmetric, hashes, RNG) and associated standards Preferred Qualifications - 8+ years total experience in secure embedded systems or product security roles (beyond FIPS) – indicating deeper expertise - 5+ years of experience working in or with accredited FIPS 140 evaluation labs (e.g. ATSEC) or in product teams that achieved FIPS validations – provides valuable perspective on the testing and certification process - 5+ years of experience in project management - Advanced cryptography knowledge (e.g. various standards, entropy sources) and familiarity with security architecture (ARM TrustZone, hardware cryptographic engines, etc.) Principal Duties and Responsibilities - Coordinate and execute FIPS 140-3 validation projects from planning through lab submission and certification, working under guidance from senior team members as needed. - Prepare, review, and maintain detailed FIPS certification documentation (e.g. security policies, design documentation), ensuring strict compliance with NIST requirements. - Collaborate closely with third-party labs and certification authorities to facilitate evidence collection, testing, and resolve any issues throughout the validation process. - Advise and support internal engineering teams on FIPS 140 requirements and best practices, helping integrate compliance into product development. - Work independently on assignments with moderate supervision, and effectively plan and prioritize tasks to meet project milestones. - Communicate clearly with cross-functional stakeholders (engineers, managers, external evaluators), conveying technical details and progress. Minimum Qualifications - Bachelor's degree in Engineering, Computer Science, or related field and 4+ years of Security Engineering or related work experience. - OR Master's degree in Engineering, Computer Science, or related field and 3+ years of Security Engineering or related work experience. - OR PhD in Engineering, Computer Science, or related field and 2+ years of Security Engineering or related work experience.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Cybersecurity Engineer – Clearance Required
LMILMI is a nonprofit business that was established in 1961 to address complex issues throughout the federal government of the United States. LMI is headquartered in McLean, Virginia
• Lead Risk Management Framework (RMF) activities for the LIGER deployment at CBP, including system categorization, control selection and tailoring, implementation, assessment, and continuous monitoring • Own and maintain authorization artifacts: System Security Plan (SSP), Security Assessment Plan (SAP), Security Assessment Report (SAR), Plan of Action and Milestones (POA&M), and supporting documentation aligned to CBP and DHS requirements • Coordinate directly with CBP ISSOs, Authorizing Officials, and cyber working groups to advance ATO and continuous authorization activities • Interpret NIST 800-53 controls in the context of the LIGER platform and translate them into actionable engineering requirements • Run and review vulnerability scans across CI/CD pipelines and runtime environments, triage findings, and drive remediation through the engineering team • Validate secure configurations and hardening baselines (e.g., CIS Benchmarks, DISA STIGs) on containers, hosts, and cloud resources • Partner with platform engineers on cloud and container security in AWS GovCloud, including IAM, network controls, secrets management, logging, and runtime protection • Develop and maintain security policies, procedures, and standard operating procedures (SOPs) specific to LIGER on CBP infrastructure • Track audit findings, remediation actions, and POA&M items to closure • Support FedRAMP-aligned control implementation and inheritance where applicable • Advise senior LIGER and CBP leadership on system risk levels, control effectiveness, and emerging compliance considerations for AI/LLM systems in federal environments.
Role Description This Protection Advisor opportunity is ideal for experienced individuals near South Coast seeking a proposition with leads provided. You will be joining a business based along the South Coast, who are producing a high number of leads, which they can share with you. As such, little need for self-generation. This is a home based role with occasional meetings with the Principal to discuss business, cases etc, as such you should be within 1 – 2 hours of the Southampton / Bournemouth area. Qualifications - You should have experience as a Protection Advisor. - Ideally, you should have R05 or equivalent. - You should have a desire to be self-employed. Benefits - Self-employed role with OTE of £50,000 - £85,000+. - Healthy commission splits with tiered rates on self-generation and company leads. - Fully home based role with occasional get-togethers. - Ability to earn additional income through various referral schemes. Company Description
Especialista em Segurança da Informação
Unimed Grande FlorianópolisConheça todos os benefícios de ser Unimed em: https://linktr.ee/unimedflorianopolis
• Participar ativamente do ciclo de melhoria contínua em segurança da informação, identificando gaps, oportunidades de melhorias, propondo e executando planos de ação, bem como definir políticas de segurança da informação e indicadores de segurança.
• Build & Harden Secure Pipelines • Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before they reach production. • Systematically, consistently and automatically capture the risk exposure of Chainguards products. • Implement and enforce software supply chain security controls: signed artifacts, SBOMs, provenance attestation (SLSA, Sigstore / Cosign). • Proactively identify emerging customer security needs, and build solutions to meet these. • Cloud-Native Product Hardening • Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS. • Harden container images, Kubernetes cluster configurations, and cloud IAM postures — minimising attack surface across our product stack. • Define and drive adoption of baseline security standards: pod security standards, network policies, workload identity, secrets management. • Evaluate and operationalise CNAPP / CSPM tooling to maintain continuous visibility into cloud-native risk.


