
Position: Certifications Analyst
Location: Fairfax, VA
Job Type: Entry-level, Full-time
Corsec is at the forefront of working with top IT Security companies to achieve FIPS 140-3, CC and DoDIN APL certifications. We are looking for an entry-level, full-time Information Security Analyst to join our team.
Product certification support for FIPS 140 Consulting Team.
Responsibilities
•Examine IT products against security certification standards in order to determine and document compliance gaps.
•Understand and analyze cryptography within an IT system.
•Analyze design, architecture and implementation details of IT products and produce technical documentation specific to security certifications.
•Configure IT products to meet compliance requirements and produce certification-specific deployment guidance.
•Author evaluation documentation for submission to testing labs and certifying authorities.
•Produce testing reports by conducting functional, operational, and vulnerability testing of the IT products.
•Communicate effectively with security product vendors, testing facilities personnel, and certifying authorities to address compliance gaps, testing queries and documentation comments.
•Manage project schedules
Required Skills and Experience
•Knowledge of a variety of cryptographic methods, including encryption/decryption, digital signatures and PKI, hashing, random number generation, and key transport/agreement methods
•Knowledge of secure communications protocols, including TLS, SSH, and IPsec
•Bachelor's degree in computer science, information systems, cyber security, computer engineering, or related discipline
•Strong analytical and technical skills - Ability to assess IT products and components with great attention to detail, especially in relation to the uses of cryptography within a system
•Strong technical writing skills
•Strong oral presentation skills - Ability to articulate in technical and non-technical terms to customers, peers, and management
•Strong organizational and prioritization skills
Desired Skills and Experience
•Experience with project management
•Experience with government certification processes, especially FIPS 140-3
•Familiarity with the NIST SP 800 series publications, beyond SP 800-53

For over 25 years Corsec has assisted companies through the IT security certification process for FIPS 140-2/FIPS 140-3, Common Criteria (CC), CSfC, and the DoD’s APL. We are a privately owned company focused on partnering with organizations worldwide to assist with the process of security certifications and validations.
Our certification methodology helps open doors to new markets and increase revenue for clients with products ranging from mobile phones to satellites. Our broad knowledge safeguards against common pitfalls and thwarts delays, translating to a swift and seamless path to certification. Corsec has created the benchmark for providing business leaders with fast, flexible access to industry knowledge on security certifications and validations.
Security Certifications: Done Once, Done Right!
For more information, visit www.corsec.com and follow @CorsecSecurity on Twitter.