Find Jobs
Find Jobs Near You – Available Work in Your Location
Common Criteria Engineer
Career Insights for Vulnerability Analyst / Penetration Tester
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on North Carolina data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.
$118,018 / year median in North Carolina
+8% projected growth
Job Description
- Execute
FIPS 140-3
compliance initiatives and Common criteria for networking, security, and cloud-managed products.- Support certification efforts under the Cryptographic Module Validation Program (CMVP) by applying NIST, CMVP, and FIPS guidance to product architectures and development processes..
- Participate in gap assessments and compliance reviews under the guidance of senior engineers.
- Review product configurations and cryptographic implementations to support certification readiness.
- Partner with accredited test laboratories throughout pre-validation, testing, remediation, and certification activities.
- Analyze cryptographic algorithms, key management practices, and secure communications protocols.
- Create and maintain technical documentation, validation artifacts, and certification packages.
- Improve certification readiness processes and internal compliance tools. Qualifications for the Common Criteria Engineer include:
- Bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, Information Technology, Electrical Engineering, or a related technical discipline..
- Basic knowledge of cybersecurity concepts and secure development practices.
- Familiarity with Linux operating systems and command-line tools.
- Exposure through coursework, internships, projects, or professional experience related to cybersecurity, cryptography, networking, or secure software development.
- Exposure to Python, Java, C, or C++
- Familiarity with Git and source control systems.
- Experience with Linux administration and network protocols such as TLS, SSH, and IPsec.
- Familiarity with security standards including
FIPS 140-3, NIST SP 800
Series, Common Criteria, and FedRAMP.- Security-related certifications such as Security+, CyberOps Associate, or equivalent are a plus. Compensation for the Common Criteria Engineer includes:
Salary Range:
$100,000 - $140,000/yearComprehensive Benefits:
Medical, Dental, Vision, 401(k), and applicable sick leaveKeywords:
Common Criteria, FIPS 140-3, CMVP, NIST, cybersecurity, cryptography, cryptographic modules, cryptographic algorithms, key management, TLS, SSH, IPsec, compliance, regulatory compliance, certification, validation, compliance assessments, gap analysis, security testing, validation testing, remediation, certification readiness, technical documentation, compliance evidence, design reviews, code reviews, secure software development, Linux, networking, cloud security, product security, Python, Java, C, C++, Git, FedRAMP, Common Criteria initiatives, Security+, CyberOps, security engineering, risk management, security controls, audit readiness, automation, test automation, security architecture, vulnerability management, stakeholder communication, project coordination, cross-functional collaboration, accreditation labs, cybersecurity compliance. #LI-BH1 #HYBRID This job is open for applications on 9/10/2026 and will remain open for at least 30 days from the posting date.Benefits
- Sick Leave
- 401(k) Plans
- Health Insurance
- Dental Insurance