Konijn Jobs

Open role

Senior Security Certifications Engineer

Fortaegis Technologies B.V.

IND sponsorAmsterdamFull-time

About the role

Fortaegis is a fast-scaling, highly ambitious and cutting-edge semiconductor company. We are looking for a Senior Security Certifications Engineer to run the day-to-day execution of our product security certification programme across FIPS 140-3, Common Criteria and the regulatory frameworks our customers rely on. This role owns the engine room of certification: working alongside our engineers on security-relevant design decisions, gathering and helping author the evidence artefacts that certifications demand, and acting as our primary technical interface to accredited test laboratories and certification bodies. Overall certification strategy is set by security leadership; you make it happen. We are looking for candidates with not only an exceptional skillset, but also an exceptional mindset, willing to go above and beyond to make our security and certification capability even better.

What you'll do

Run the day-to-day execution of our product security certification projects — FIPS 140-3, Common Criteria (EUCC) and the regulatory obligations our customers depend on — keeping them on schedule and evidence-complete against the overall strategy set by security leadership. Partner with hardware, firmware and FPGA engineers on security-relevant design decisions, translating certification requirements into concrete, testable design and documentation actions. Gather, structure and help author the certification evidence artefacts: detailed design documentation, security policies, assurance/VE mappings, entropy (SP 800-90B) documentation, algorithm and module test evidence, and end-to-end traceability. Act as our primary technical interface to accredited test laboratories and certification schemes (CMVP/CAVP, Common Criteria evaluators), managing queries, deficiency cycles and report submissions. Prepare and coordinate lab engagements across entropy source, algorithm and module validation testing, including planning and hosting test witnessing and data collection on our sites. Operate and continuously improve our Secure Development Lifecycle and Secure Release processes so that engineering work produces audit-ready evidence as a by-product, not an afterthought. Support release-integrity assurance — reproducible builds, artefact verification and HSM-based signing — where it intersects with certification requirements. Track requirements and dependencies across FIPS 140-3, Common Criteria, IEC 62443 and the EU Cyber Resilience Act, and flag design or documentation gaps early enough to fix cheaply. Own the evidence repository and traceability so every product has a complete, retrievable assurance package ready for external assessment. Coach engineering teams so that security and certification thinking becomes part of everyday development.

What you'll bring

5+ years working directly on product security certifications, with deep hands-on FIPS 140-3 (or 140-2) and Common Criteria experience. Detailed, practical command of the FIPS 140-3 process — CMVP and CAVP, SP 800-90B entropy source validation, algorithm validation, and security policy and evidence requirements. Strong Common Criteria experience, ideally to EAL4 and/or high-assurance vulnerability analysis (AVA_VAN), including the ALC, ADV, ATE and AVA assurance classes. Proven track record producing certification evidence artefacts — design documentation, security policies, assurance mappings and traceability — for hardware or firmware cryptographic products. Experience managing accredited test laboratories and certification bodies, including deficiency cycles and submissions. Solid grasp of applied cryptography and key management (approved algorithms, key lifecycle, entropy) and how these map onto certification requirements. Familiarity with hardware security modules, secure elements, or FPGA/ASIC-based cryptographic designs. Working knowledge of adjacent frameworks — IEC 62443, the EU Cyber Resilience Act, NIST SSDF and ISO/IEC 27001 — is a strong plus. Experience with secure development lifecycle and secure release/signing practices (reproducible builds, HSM-based signing ceremonies) is advantageous. Excellent technical writing — able to turn dense engineering detail into clear, consistent, assessor-ready documentation. Effective communication and teamwork, with the ability to collaborate across engineering, product and external partners. Ability to take ownership and solve problems beyond the scope of the job description, with a flexible, solution-oriented mindset.

What's on offer

The successful candidate will have the unique opportunity to participate in shaping the future of our visionary company, taking direct ownership of the certifications that let our ultra-secure, high-performance products reach the world’s most demanding markets. They will work closely with our security leadership and engineering teams in a collaborative and technically rewarding environment at the forefront of secure semiconductor technology.

More open roles at Fortaegis Technologies B.V.