The Senior Common Criteria Certification Specialist is responsible for leading and executing cybersecurity product and system certification activities in alignment with internationally recognized standards, particularly Common Criteria. The role involves evaluating security documentation, conducting technical risk assessments, overseeing testing processes, and providing expert recommendations on certification decisions (e.g., EAL levels).
This position plays a critical role in ensuring the integrity, consistency, and credibility of the certification process, while collaborating with developers, evaluators, and regulatory stakeholders. The specialist also contributes to the development of certification policies and stays current with emerging cybersecurity threats, technologies, and standards.
Key Responsibilities:
Senior Certifier is responsible for the conduct of the day to day certification, validation, oversight, certificate maintenance and mutual recognition with the common criteria standards.
Ensuring that the highest standards of competence and impartiality are maintained, and that consistency is achieved across all evaluation and certification activities;
Possess a deep understanding of Common Criteria standards, Protection Profiles, Security Targets, Evaluation Assurance Levels (EALs), and related documentation
Provide guidance and mentorship to CB team members Certifiers and evaluators, ensuring their understanding of the certification process and helping them with complex evaluations.
Lead and oversee the review and assessment of documentation submitted by product developers, including Security Target documents, design specifications, and test plans.
Conduct advanced technical risk assessments, identifying potential security weaknesses or flaws in products or systems and providing expert guidance for mitigation.
Oversee and manage the testing phase, ensuring that security testing is conducted rigorously and accurately.
Conduct of day-to-day certification, certificate maintenance and mutual recognition projects and in compliance with scheme documentations.
Assisting with the development of policies, standards, procedures and guidelines.
Make recommendations regarding certification at specific Evaluation Assurance Levels (EALs) based on extensive evaluation expertise and knowledge of the certification process.
Stay up-to-date with the latest developments in security, emerging threats, and evolving technology to ensure the certification process remains relevant.
Collaborate with stakeholders, such as developers, evaluators, and national certification authorities, to ensure a consistent and accurate evaluation process.
Desired Candidate Profile
A university degree-level qualification in IT, information security or a related field. ideally with a focus on security domains.
Certification from a recognized Common Criteria certification body and previous experience as a Certifier is desired
IT Security Overview Training and certification
Common Criteria for IT Security Evaluation Training and certification
Minimum 8 years
Minimum 4 years of work experience as a Senior IT / Information Security / Cyber Security Auditor and/or Risk Management and/or Cyber Security/Information Security Management.
Proficiency in Arabic and English (spoken and written) is preferred
Other Required Qualifications:
General:
Analytical and problem-solving skills
Proven experience in IT and Information Security Assessment
Common Criteria for IT Security Evaluation Training
Experience in Risk Assessment and management.
Should have hands on experience in information security
Understanding of ISO27001 certification audit requirements
Excellent communication, documentation, and report-writing skills.
In-depth knowledge of security testing methodologies and tools.
Have analytical & assessment experience of formal schemes and can assess a situation in a fair and objective manner in order to arrive at a firm conclusion.
Have training, workshops planning and delivery experience across Government & private sector.
Technical:
Experience in Risk Assessment and management including audit methodologies and risk assessment methodologies.
Understanding of NIA controls and implementation requirements
Proficiency in security frameworks and standards like NIST, ISO27001, NIA.
Strong awareness of Information Security / Cyber Security trends.
Behavioural:
Ability to multitask and work effectively with multiple project teams, sponsors, and customers.
Ability to pay close attention to detail, meet deadlines and work under pressure.
Interpersonal skills
Work autonomously with a high degree of enthusiasm
Specific:
Excellent technical report writing skills.
Have capabilities to understand and interpret the Certification Criteria (ISO/ IEC 17021, ISO/ IEC 17024, ISO/ IEC 27006 and ISO/IEC 17065).
Knowledge of auditing and information assurance standards like ISA, ITAF, ISO17021, ISO19011.
Proficiency in security frameworks and standards like, ISO27001, NIA, CSF Q2022.
Familiarity with third-party audit, Certification and Information Security / Cyber Security audits.
Proven, hands on, experience in Information Security Audit or Information Security Management.
المتخصص الأول في تقييم معايير Common Criteria مسؤول عن قيادة وتنفيذ أنشطة الاعتماد الخاصة بمنتجات وأنظمة الأمن السيبراني بما يتوافق مع المعايير المعترف بها دوليًا، ولا سيما Criteria Common. تشمل المهام تقييم وثائق الأمان، إجراء تقييمات مخاطر تقنية، الإشراف على عمليات الاختبار، وتقديم توصيات خبراء حول قرارات الاعتماد (على سبيل المثال مستويات EAL).
يلعب هذا المنصب دورًا حاسمًا في ضمان نزاهة الاتساق ومصداقية عملية الاعتماد، مع التعاون مع المطورين والمقيّمين والجهات التنظيمية. كما يساهم الاختصاصي في تطوير سياسات الاعتماد والبقاء على اطلاع بتهديدات الأمن السيبراني الناشئة والتقنيات والمعايير المستحدثة.
المهام الأساسية:
يتولى المعتمد الأول إجراء الاعتماد اليومي، والتحقق، والإشراف، وصيانة الشهادات والتعرف المتبادل مع معايير Criterion الشائعة.
ضمان الحفاظ على أعلى معايير الكفاءة والحياد، وتحقيق الاتساق عبر جميع أنشطة التقييم والاعتماد;
امتلاك فهم عميق لمعايير Common Criteria، وملفات الحماية، وأهداف الأمان، ومستويات ضمان التقييم (EALs)، والوثائق ذات الصلة
تقديم الإرشاد والتوجيه لأعضاء فريق CB من Certifiers ومُقيّمين، لضمان فهمهم لعملية الاعتماد ومساعدتهم في التقييمات المعقدة.
قيادة ومتابعة مراجعة وتقييم الوثائق المقدمة من مطوري المنتجات، بما في ذلك وثائق أهداف الأمان، ومواصفات التصميم، وخطط الاختبار.
إجراء تقييمات مخاطر تقنية متقدمة، وتحديد نقاط الضعف الأمنية المحتملة في المنتجات أو الأنظمة وتقديم التوجيه الخبراء للتخفيف منها.
الإشراف وإدارة مرحلة الاختبار، والتأكد من إجراء اختبارات الأمان بصرامة ودقة.
تنفيذ مهام الاعتماد اليومية، وصيانة الشهادات والتعرف المتبادل وفق وثائق النظام.
المساعدة في تطوير السياسات والمعايير والإجراءات والإرشادات.
إصدار توصيات بشأن الاعتماد عند مستويات Assurance محددة (EALs) بناءً على خبرة تقييمية واسعة ومعرفة بعملية الاعتماد.
البقاء مطلعًا على أحدث التطورات في الأمن، والتهديدات الناشئة، والتقنيات المتطورة لضمان بقاء عملية الاعتماد ذات صلة.
التعاون مع أصحاب المصلحة، مثل المطورين والمقيّمين والجهات الوطنية للاعتماد، لضمان عملية تقييم متسقة ودقيقة.
الملف المرغوب للمرشح
درجة جامعية في تكنولوجيا المعلومات أو الأمن المعلوماتي أو مجال ذي صلة، ويفضل مع تركيز على مجالات الأمن.
شهادة من جهة اعتماد Common Criteria مع خبرة سابقة كمعتمد مرغوبة
تدريب وشهادة في عرض Security IT Overview
تدريب وشهادة في Common Criteria لتقييم أمان تكنولوجيا المعلومات
حد أدنى 8 سنوات
حد أدنى 4 سنوات من الخبرة العملية كمدقق أمني للمعلومات أو معني بالأمن السيبراني/إدارة المخاطر و/أو إدارة الأمن السيبراني للمعلومات.
إتقان العربية والإنجليزية (شفوياً وكتابة) مفضل
المؤهلات الأخرى المطلوبة:
عام:
مهارات تحليلية وحل المشكلات
خبرة مثبتة في تقييم تكنولوجيا المعلومات والأمن المعلوماتي
تدريب في Common Criteria لتقييم أمان تكنولوجيا المعلومات
خبرة في تقييم وإدارة المخاطر.
يجب أن يمتلك خبرة عملية في الأمن المعلوماتي
فهم لمتطلبات تدقيق ISO27001 للاعتماد
مهارات تواصل وتوثيق وكتابة تقارير ممتازة.
معرفة عميقة مناهج وأدوات اختبار الأمان.
امتلاك خبرة تحليلية وتقييمية في الأطر الرسمية والقدرة على تقييم الوضع بشكل عادل وموضوعي للوصول إلى نتيجة حازمة.
لدية خبرة في التدريب وورش العمل والتخطيط والتقديم عبر الحكومة والقطاع الخاص.
تقني:
خبرة في تقييم وإدارة المخاطر بما في ذلك منهجيات التدقيق وتقييم المخاطر.
فهم لضوابط NIA ومتطلبات التطبيق
إتقان أُطر ومعايير الأمان مثل NIST و ISO27001 و NIA.
وعي قوي باتجاهات الأمن المعلوماتي / الأمن السيبراني.
السلوكي:
القدرة على تعدد المهام والعمل بفعالية مع فرق مشاريع متعددة، والجهات الراعية والعملاء.
القدرة على الانتباه للتفاصيل والالتزام بالمواعيد والعمل تحت الضغط.
مهارات التعامل بين الأشخاص
العمل بشكل مستقل بشغف عالي
خاص:
مهارات كتابة تقارير فنية ممتازة.
قدرات على فهم وتفسير معايير الاعتماد (ISO/ IEC 17021، ISO/ IEC 17024، ISO/ IEC 27006 وISO/IEC 17065).
معرفة بمعايير التدقيق وضمان المعلومات مثل ISA و ITAF و ISO17021 و ISO19011.
إتقان أُطر ومعايير الأمان مثل ISO27001 و NIA و CSF Q2022.
الاعتياد على تدقيق الطرف الثالث واعتماد ومراجعة الأمان المعلوماتي / الأمن السيبراني.
خبرة عملية مثبتة في تدقيق الأمن المعلوماتي أو إدارة الأمن المعلوماتي.