Senior Certifier is responsible for the conduct of the day to day certification, validation, oversight, certificate maintenance and mutual recognition with the common criteria standards.
Ensuring that the highest standards of competence and impartiality are maintained, and that consistency is achieved across all evaluation and certification activities;
Possess a deep understanding of Common Criteria standards, Protection Profiles, Security Targets, Evaluation Assurance Levels (EALs), and related documentation
Provide guidance and mentorship to CB team members Certifiers and evaluators, ensuring their understanding of the certification process and helping them with complex evaluations.
Lead and oversee the review and assessment of documentation submitted by product developers, including Security Target documents, design specifications, and test plans.
Conduct advanced technical risk assessments, identifying potential security weaknesses or flaws in products or systems and providing expert guidance for mitigation.
Oversee and manage the testing phase, ensuring that security testing is conducted rigorously and accurately.
Conduct of day-to-day certification, certificate maintenance and mutual recognition projects and in compliance with scheme documentations.
Assisting with the development of policies, standards, procedures and guidelines.
Make recommendations regarding certification at specific Evaluation Assurance Levels (EALs) based on extensive evaluation expertise and knowledge of the certification process.
Stay up-to-date with the latest developments in security, emerging threats, and evolving technology to ensure the certification process remains relevant.
Collaborate with stakeholders, such as developers, evaluators, and national certification authorities, to ensure a consistent and accurate evaluation process.
Desired Candidate Profile
Master's degree in IT, Information Security, Cybersecurity, or a related field.
Minimum 10 years of relevant professional experience.
At least 5 years in senior Information Security/Cybersecurity Audit, Risk Management, or Information Security Management roles.
Strong knowledge of Common Criteria, Protection Profiles, Security Targets, and certification processes.
Hands-on experience with ISO 27001, quality management systems, risk assessments, and cybersecurity audits.
Excellent analytical, documentation, technical report writing, and stakeholder communication skills.
Common Criteria certification and previous experience as a Certifier are highly desirable.