Job 1000 van 1000


Postuler



Senior Security Evaluation & Certification Consultant


🏢 Who are we?

Internet of Trust is a cybersecurity consulting and expertise company specializing in digital trust, security evaluation, certification, and regulatory compliance for connected systems.

We help our customers design, evaluate, certify, and secure connected products throughout their lifecycle, from security architecture and risk assessment to certification and compliance with European cybersecurity regulations.

Our expertise spans embedded systems, semiconductors, IoT, industrial systems, telecommunications, cloud, edge computing, and other emerging technologies.

Founded in 2014, Internet of Trust brings together recognized experts who actively contribute to international standardization initiatives, cybersecurity assurance frameworks, and the development of future European cybersecurity certification schemes.

As part of our continued growth, we are looking for a Senior Security Evaluation & Certification Consultant to help our customers address complex cybersecurity, certification, and regulatory challenges.


🚀 Mission

As a Senior Security Evaluation & Certification Consultant, you will act as a trusted technical advisor, combining deep technical expertise with customer-facing consulting activities.

You will advise customers on security evaluation, certification strategies, cybersecurity assurance, and regulatory compliance while contributing to technically challenging projects across multiple industries.

Working with a high level of autonomy, you will lead customer engagements from technical analysis through project delivery. Approximately 40% of your time will be dedicated to customer interactions, including technical workshops, architecture reviews, certification planning, and technical steering meetings.

In addition to customer projects, you will dedicate approximately 10 to 15% of your time to supporting the growth of Internet of Trust through pre-sales activities, proposal writing, service development, technical publications, and participation in industry and standardization initiatives.


Your responsibilities will include:

  • Certification and assurance consulting
  • Advise customers on European cybersecurity certification schemes, including Common Criteria, EUCC, and other certification frameworks.
  • Guide customers throughout software, hardware, and cryptographic security evaluations, working closely with evaluation laboratories and certification bodies.
  • Define, review, and assess cybersecurity requirements, security architectures, and security controls.
  • Lead technical workshops, architecture reviews, and certification discussions with customers, evaluation laboratories, certification bodies, and other stakeholders.
  • Cybersecurity expertise
  • Conduct cybersecurity risk assessments for connected products, embedded systems, and software platforms.
  • Identify threats, vulnerabilities, attack paths, and security gaps across products, software, firmware, hardware, and system architectures.
  • Support customers in defining practical compliance strategies for the Cyber Resilience Act (CRA), NIS2, the Cybersecurity Act, and other applicable cybersecurity regulations.
  • Challenge customer security architectures and provide pragmatic, risk-based recommendations.
  • Build trusted relationships with customers by acting as their technical advisor throughout consulting and certification engagements.
  • Produce high-quality technical documentation, security assessments, assurance evidence, and certification deliverables.
  • Monitor emerging cybersecurity technologies, regulations, standards, and certification schemes, translating technical and regulatory developments into practical guidance for customers.
  • Contribute to proposal writing, pre-sales activities, new service development, and the continuous evolution of Internet of Trust's technical expertise.
  • Share your expertise with colleagues and contribute to the continuous development of our technical capabilities.


💻 Profile

We are looking for a self-driven consultant who combines technical excellence with strong communication and customer-facing skills. You enjoy solving complex cybersecurity challenges, engaging with customers, and transforming technical and regulatory requirements into practical, effective solutions.

Rather than focusing on a specific number of years of experience, we value demonstrated expertise, sound judgement, curiosity, and the ability to lead technical assignments independently.


You should have:

  • Strong experience in cybersecurity, security evaluation, certification, or security assurance.
  • Experience in a Common Criteria evaluation laboratory or certification body is strongly preferred. Candidates with significant hands-on Common Criteria experience gained in industry or consulting are also encouraged to apply.
  • Practical experience with software, firmware, hardware, or cryptographic security evaluation, or security testing within Common Criteria or equivalent evaluation frameworks.
  • Excellent communication and presentation skills, with the ability to lead technical workshops, facilitate customer discussions, and confidently present complex cybersecurity topics to both technical and management audiences.
  • Strong knowledge of embedded security technologies, including secure software architectures, cryptographic mechanisms, Secure Elements, HSMs, Roots of Trust, secure boot, Trusted Execution Environments (TEE), and secure firmware.
  • Ability to manage technical assignments independently while collaborating effectively with a team of highly skilled experts.
  • Curiosity, technical rigor, and a collaborative mindset.

 

Knowledge of the following technologies, standards, or certification schemes would be considered a plus:

  • Cyber Resilience Act (CRA), NIS2, the Cybersecurity Act, and European cybersecurity certification schemes;
  • ISO/IEC 19790 and FIPS 140-3;
  • Post-Quantum Cryptography (PQC);
  • SESIP;
  • PSA Certified;
  • FITCEM schemes: CSPN, LINCE, BSZ,…,
  • EMVCo;
  • PCI security standards;
  • Trusted Execution Environments (TEE);
  • Confidential Computing;
  • IEC 62443;
  • ISO/SAE 21434;
  • ISO 27000 series.


Languages

  • English: Professional proficiency is mandatory. You are comfortable leading technical meetings, facilitating workshops, producing technical documentation, and interacting confidently with international customers, partners, evaluation laboratories, and certification bodies.
  • French: Professional proficiency is highly desirable, as many of our customers and stakeholders are French-speaking.


🎁 Benefits

  • Work on challenging projects across semiconductors, embedded systems, IoT, industrial systems, telecommunications, cloud, and critical infrastructures.
  • Collaborate in an environment built on technical excellence, curiosity, humility, and knowledge sharing.
  • Continuously develop your expertise through customer projects, research activities, and collaboration with recognized experts.
  • Contribute to the evolution of European cybersecurity certification through ENISA projects, standardization activities, technical working groups, and emerging certification schemes.
  • Travel occasionally for customer engagements, conferences, and technical workshops.
  • Work from offices located in the heart of Paris.
  • Benefit from a hybrid working model.
  • Receive attractive Alan health insurance.
  • Receive €9.50 meal vouchers, funded at 50%.
  • Participate in team events within a friendly, expert-driven working environment.


Postuler