SG

Junior Security Evaluator

Sgs

Clackamas · Posted 6h ago

$46k–$62k/yr Other Onsite
Apply now

Location: Clackamas, OR, us Department: Laboratory & Testing Employment Type: {'id': 'permanent', 'label': 'Full-time'}

Company Description

SGS is the global leader and innovator in inspection, verification, testing and certification services. Founded in 1878, SGS is recognized as the global benchmark in quality and integrity. With over 97,000 employees in 130 countries and operating a network of more than 2,400 offices and laboratories, we provide services to almost every industry by assuring quality and safety of products and services.

Trusted all over the world, SGS is a market leader because we put 100% passion, pride and innovation into everything we do. We encourage new ideas. We welcome people who challenge the way we do things. And we will be 100% committed to helping you reach your full potential.

Job Description

Position Overview

SGS-Penumbra is seeking a Junior Security Evaluator to support the testing and validation of cryptographic modules under the FIPS 140-3 Cryptographic Module Validation Program (CMVP). This position is ideal for an early-career technical professional interested in cybersecurity, cryptography, and security compliance.

The successful candidate will work alongside experienced evaluators to assess hardware, software, and firmware products against FIPS 140-3 requirements, while developing expertise in NIST standards, cryptographic testing, and security evaluations.

Key Responsibilities

FIPS Evaluation Activities

Assist with the development and execution of FIPS 140-3 test plans in accordance with CMVP requirements.

Review cryptographic module documentation, including security policies, design documentation, finite state models, and vendor evidence packages.

Perform hands-on testing of cryptographic modules, including operational testing, physical security testing, and algorithm validation activities.

Conduct Cryptographic Algorithm Validation Program (CAVP) testing using NIST-approved test methodologies and vectors.

Document test procedures, test results, observations, and findings in accordance with laboratory quality procedures.

Support preparation of validation reports and submission packages for CMVP review.

Physical Security Testing

Perform physical security assessments of cryptographic modules in accordance with applicable FIPS 140-3 security level requirements.

Evaluate enclosure construction, tamper evidence mechanisms, tamper response features, and other physical security controls.

Assist in documenting physical security findings and test results.

Customer and Project Support

Serve as a day-to-day technical point of contact for assigned customer projects.

Coordinate evidence requests, documentation updates, and technical questions with customers.

Provide project status updates and communicate risks, issues, and schedule impacts to senior staff.

Track assigned project milestones and deliverables to support successful project completion.

Professional Development

Develop working knowledge of FIPS 140-3, the NIST SP 800-140 series, CMVP implementation guidance, and related validation requirements.

Participate in internal technical training and mentoring activities.

Continuously build expertise in cryptography, cybersecurity, and security testing methodologies.

Qualifications

Required Qualifications

College degree in an IT discipline, or a related technical discipline; or equivalent practical experience.

Foundational understanding of computer systems and information security principles.

Basic understanding of cryptographic concepts, including symmetric and asymmetric cryptography, hashing, digital signatures, and key management.

Strong analytical and problem-solving abilities.

Excellent written documentation and technical communication skills.

Strong attention to detail and ability to follow structured test procedures.

Ability to manage multiple tasks and deadlines in a professional services environment.

Ability to communicate effectively with customers and technical stakeholders.

Preferred Qualifications

Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, Cybersecurity, Information Technology, or a related technical discipline; or equivalent practical experience.

Familiarity with FIPS 140-2, FIPS 140-3, Common Criteria, or other security certification programs.

Experience with Linux operating systems and command-line tools.

Experience with Python, Bash, or other scripting languages.

Exposure to embedded systems, firmware, hardware security modules (HSMs), or secure hardware development.

Familiarity with cryptographic libraries such as OpenSSL, BoringSSL, wolfSSL, or similar implementations.

Knowledge of software development, secure coding practices, or vulnerability analysis.

Additional Requirements

Ability to obtain any required background checks or security clearances.

Occasional travel may be required to customer locations.

Ability to perform hands-on hardware testing activities in a laboratory environment.

Additional Information

Compensation

The expected salary for this position is $46,000 to $62,000 per year. This range represents the minimum and maximum base salary we reasonably expect to pay for this role. Actual compensation within the range will depend on skills, experience, and qualifications.

Our Benefits

We care about your total well-being and will support you with the following, subject to your location and role.

Health: Medical, dental and vision insurance, life insurance, employee assistance programs.

Wealth: In addition to base pay, we offer 401(k) with company match (immediate vesting upon enrollment).

Happiness: Professional Growth: Online training courses, virtual and classroom development experiences, tuition reimbursement program

Work-Life Balance: Paid-time off and family leave

In compliance with applicable state and local pay transparency laws, we provide clear and equitable compensation information for all applicants.

Position anticipate

What they are looking for

Linux Python Bash Openssl Firmware

Details

Work type
Onsite
Compensation
Paid
Remote eligible
No

Get new internships by email

Free daily digest, matched to what you pick. Unsubscribe anytime.