Common Criteria / FIPS Security Engineer
Remote, North Carolina
Job Id:
171516
Job Category:
Job Location:
Remote, North Carolina
Security Clearance:
No Clearance
Business Unit:
Piper Companies
Division:
Piper Enterprise Solutions
Position Owner:
Katie Iverson
Piper Companies is seeking a Common Criteria / FIPS Security Engineer to support the design, development, validation, and certification of security-focused products under the Common Criteria (CC) and FIPS 140 frameworks. This role will be responsible for partnering with engineering teams to ensure products meet security certification requirements, regulatory standards, and compliance obligations throughout the development lifecycle.
The Common Criteria / FIPS Security Engineer will play a key role in certification readiness activities, security documentation, technical reviews, compliance testing, and collaboration with evaluation laboratories. This is an excellent opportunity for an engineer who understands security certifications, regulatory compliance, and secure product development, and can effectively bridge the gap between engineering and certification requirements.
Responsibilities of the Common Criteria / FIPS Security Engineer:
- Partner with engineering teams to design and develop products that meet Common Criteria and FIPS certification requirements.
- Support Common Criteria certification efforts, including Security Target (ST) development, evidence collection, and certification documentation.
- Assist with FIPS 140 validation activities related to cryptographic modules, libraries, and security functions.
- Review product architectures, security controls, and technical documentation for certification readiness.
- Translate certification and compliance requirements into engineering tasks, testing activities, and product requirements.
- Evaluate products against regulatory, security, and certification standards to ensure compliance.
- Support threat modeling, security design reviews, vulnerability assessments, and remediation planning.
- Collaborate with Common Criteria evaluation labs, FIPS testing laboratories, product managers, and security teams throughout certification projects.
- Assist with addressing findings identified during certification and validation assessments.
- Support certification maintenance, recertification efforts, and evolving regulatory compliance requirements.
- Develop detailed technical documentation, reports, and written communications for internal and external stakeholders.
- Contribute to Secure Development Lifecycle (SDLC) processes and security best practices across product teams.
Qualifications of the Common Criteria / FIPS Security Engineer:
- Bachelor's degree in Computer Science, Cybersecurity, Engineering, Information Technology, or a related field.
- 3+ years of experience in security engineering, systems engineering, software engineering, product security, compliance, or a related technical discipline.
- Experience supporting regulatory compliance, certification programs, audit activities, or security assessment initiatives.
- Understanding of secure software development practices and security architecture principles.
- Ability to interpret technical requirements and evaluate products against defined compliance standards.
- Experience reviewing code, configurations, and technical designs to assess alignment with certification requirements.
- Strong written communication and technical documentation skills.
- Ability to work independently while collaborating with senior engineers and cross-functional teams.
Experience in one or more of the following areas:
- Cryptography
- Network Security
- Identity and Access Management (IAM)
- Cloud Security
- Operating Systems
- Embedded Systems
Preferred Qualifications:
- Experience with Common Criteria (ISO/IEC 15408) certification programs.
- Familiarity with:
- Security Targets (STs)
- Protection Profiles (PPs)
- Evaluation Assurance Levels (EALs)
- EUCC or SOG-IS frameworks
- Experience supporting FIPS 140 validation efforts involving cryptographic modules and libraries.
- Experience testing products against compliance and certification requirements.
- Experience working with Cisco networking, security, or router products.
- Experience within government, defense, telecommunications, or other regulated industries.
- Industry certifications such as CISSP, CCSP, Security+, or equivalent.
- Experience working directly with third-party testing laboratories and certification bodies.
Compensation & Benefits for the Common Criteria / FIPS Security Engineer:
- Base salary: $95,000 - $120,000 annually
- Fully remote opportunity for candidates located on the U.S. East Coast.
- Comprehensive benefits package including medical, dental, vision, and sick leave as required by law.
- Opportunity to work on high-impact security certification and compliance initiatives.
- Exposure to Common Criteria, FIPS validation, product security, and regulatory compliance programs.
- Collaborative team environment with mentorship from senior security and compliance professionals.
Key Words:
Common Criteria, CC, FIPS 140, Security Engineer, Product Security, Security Compliance, Regulatory Compliance, Certification Engineer, ISO 15408, Security Target, ST, Protection Profile, PP, Evaluation Assurance Level, EAL, EUCC, SOG-IS, Cryptography, Cryptographic Modules, Network Security, Security Validation, Security Certification, Security Architecture, SDLC, Vulnerability Assessment
Applications for this role will be accepted for at least 30 days after the publication date (08/03).
#LI-REMOTE
#LI-KI1