Junior Security Evaluator

  • Full-time
  • Compensation: USD 56000 - USD 75000 - yearly

Company Description

SGS is the global leader and innovator in inspection, verification, testing and certification services. Founded in 1878, SGS is recognized as the global benchmark in quality and integrity. With over 97,000 employees in 130 countries and operating a network of more than 2,400 offices and laboratories, we provide services to almost every industry by assuring quality and safety of products and services.

Trusted all over the world, SGS is a market leader because we put 100% passion, pride and innovation into everything we do. We encourage new ideas. We welcome people who challenge the way we do things. And we will be 100% committed to helping you reach your full potential.

Job Description

Position Overview

SGS-Penumbra is seeking a Junior Security Evaluator to support the testing and validation of cryptographic modules under the FIPS 140-3 Cryptographic Module Validation Program (CMVP). This position is ideal for an early-career technical professional interested in cybersecurity, cryptography, and security compliance.

The successful candidate will work alongside experienced evaluators to assess hardware, software, and firmware products against FIPS 140-3 requirements, while developing expertise in NIST standards, cryptographic testing, and security evaluations.

Key Responsibilities

FIPS Evaluation Activities

  • Assist with the development and execution of FIPS 140-3 test plans in accordance with CMVP requirements.
  • Review cryptographic module documentation, including security policies, design documentation, finite state models, and vendor evidence packages.
  • Perform hands-on testing of cryptographic modules, including operational testing, physical security testing, and algorithm validation activities.
  • Conduct Cryptographic Algorithm Validation Program (CAVP) testing using NIST-approved test methodologies and vectors.
  • Document test procedures, test results, observations, and findings in accordance with laboratory quality procedures.
  • Support preparation of validation reports and submission packages for CMVP review.

Physical Security Testing

  • Perform physical security assessments of cryptographic modules in accordance with applicable FIPS 140-3 security level requirements.
  • Evaluate enclosure construction, tamper evidence mechanisms, tamper response features, and other physical security controls.
  • Assist in documenting physical security findings and test results.

Customer and Project Support

  • Serve as a day-to-day technical point of contact for assigned customer projects.
  • Coordinate evidence requests, documentation updates, and technical questions with customers.
  • Provide project status updates and communicate risks, issues, and schedule impacts to senior staff.
  • Track assigned project milestones and deliverables to support successful project completion.

Professional Development

  • Develop working knowledge of FIPS 140-3, the NIST SP 800-140 series, CMVP implementation guidance, and related validation requirements.
  • Participate in internal technical training and mentoring activities.
  • Continuously build expertise in cryptography, cybersecurity, and security testing methodologies.

Qualifications

Required Qualifications

  • College degree in an IT discipline, or a related technical discipline; or equivalent practical experience.
  • Foundational understanding of computer systems and information security principles.
  • Basic understanding of cryptographic concepts, including symmetric and asymmetric cryptography, hashing, digital signatures, and key management.
  • Strong analytical and problem-solving abilities.
  • Excellent written documentation and technical communication skills.
  • Strong attention to detail and ability to follow structured test procedures.
  • Ability to manage multiple tasks and deadlines in a professional services environment.
  • Ability to communicate effectively with customers and technical stakeholders.

Preferred Qualifications

  • Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, Cybersecurity, Information Technology, or a related technical discipline; or equivalent practical experience.
  • Familiarity with FIPS 140-2, FIPS 140-3, Common Criteria, or other security certification programs.
  • Experience with Linux operating systems and command-line tools.
  • Experience with Python, Bash, or other scripting languages.
  • Exposure to embedded systems, firmware, hardware security modules (HSMs), or secure hardware development.
  • Familiarity with cryptographic libraries such as OpenSSL, BoringSSL, wolfSSL, or similar implementations.
  • Knowledge of software development, secure coding practices, or vulnerability analysis.

Additional Requirements

  • Ability to obtain any required background checks or security clearances.
  • Occasional travel may be required to customer locations.
  • Ability to perform hands-on hardware testing activities in a laboratory environment.

Additional Information

Compensation

The expected salary for this position is $46,000 to $62,000 per year. This range represents the minimum and maximum base salary we reasonably expect to pay for this role. Actual compensation within the range will depend on skills, experience, and qualifications.

Our Benefits

We care about your total well-being and will support you with the following, subject to your location and role.

  • Health: Medical, dental and vision insurance, life insurance, employee assistance programs.
  • Wealth: In addition to base pay, we offer 401(k) with company match (immediate vesting upon enrollment).
  • Happiness:
    • Professional Growth: Online training courses, virtual and classroom development experiences, tuition reimbursement program
    • Work-Life Balance: Paid-time off and family leave

In compliance with applicable state and local pay transparency laws, we provide clear and equitable compensation information for all applicants.

Position anticipated to close November 2, 2026.

Additional information

SGS is an Equal Opportunity Employer, and as such we recruit, hire, train, and promote persons in all job classifications without regard to race, color, religion, sex, national origin, disability, age, marital status, sexual orientation, gender identity or expression, genetics, status as a protected veteran, or any other characteristics protected by law.

To perform this job successfully, an individual must be able to perform each essential duty satisfactorily with or without reasonable accommodations. The requirements listed above are representative of the knowledge, skills, and/or abilities required.

This job description should not be construed as an exhaustive statement of duties, responsibilities or requirements, but a general description of the job. Nothing contained herein restricts the company’s rights to assign or reassign duties and responsibilities to this job at any time.

If you are applying for a position within the United States and you have difficulty completing the on-line employment application because of a disability, please call 201-508-3149 for assistance and leave a message. You will receive a callback.  Please note, this phone number is not for general employment information but is only for individuals who are experiencing difficulty applying for a position due to a disability.

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

Privacy Notice