Common Criteria Product Tester
Description
Leidos is searching for a highly motivated product tester to support Common Criteria evaluation efforts with Leidos’ Accredited Testing & Evaluation (AT&E) Laboratory. The ideal candidate is an independent performer who can perform commercial off-the-shelf (COTS) IT product security tests with minimal supervision, including devising product-specific test procedures and performing any configuration procedures necessary to enable the execution of tests. The candidate is also expected to interact with product developers and other technical staff to develop necessary product knowledge and assist in troubleshooting when tests cannot be successfully executed. General IT product knowledge such as networking, operating systems, communications security, identity and access management, and PKI is essential. This is a fast-paced position requiring time management skills to perform multiple product certification efforts in parallel and a thorough understanding of how product security requirements may apply to a wide variety of hardware and software products. The ideal candidate is also able to assist with setup and maintenance of laboratory infrastructure.
This position will be based in Columbia, MD. Part-time telework is acceptable but the selected candidate will be expected to be in-office for regular periods as needed to support efforts that must be performed locally. Therefore, only local candidates will be considered.
Primary Responsibilities:
Work with IT product vendors to determine applicability of IT product security standards to products
Interpret IT product security standards to determine the compliance or noncompliance of product design based on research of product documentation and interviews with technical personnel
Devise, execute, and document security functional testing to justify how tested products are compliant with IT security standards
Conduct product troubleshooting and provide recommendations when noncompliant findings are made
Conduct vulnerability research to determine if documented security vulnerabilities are adequately mitigated by product configuration and patch level
Produce documentation that describes how IT products conform to security requirements
Develop user guidance for instructions on placing products into secure configurations
Justify completeness, consistency, accuracy, and sufficiency of product test result to third-party quality reviewers
Assist in maintenance of the physical and digital infrastructure of the laboratory, including physical setup, server administration, backups, and patching
Basic Qualifications:
Bachelor's degree (or equivalent) and 4+ years of related experience
Familiarity with general IT security products and their operation (e.g., routers/switches, firewalls, intrusion detection/prevention systems, operating systems, software applications, mobile devices)
General knowledge of the role that various IT products and concepts serve in information security (e.g., full disk encryption, mobile device management, remote access/VPN, etc.)
Experience with software development lifecycle methods (e.g., agile) and tools (e.g., Subversion, GitLab, Confluence, JIRA)
Strong applied knowledge of network, transport, and application layer communications and security (e.g., TCP/IP, TLS, IPsec, SSH, LDAP)
Working knowledge of applied cryptography (e.g. X.509, PKI, post-quantum standards)
Strong customer-facing oral and written communication skills
Preferred Qualifications:
Previous experience with Common Criteria certification or related standards (FIPS 140, FedRAMP, NIST SP 800-53) is desirable.
Software development or DevOps experience a plus.
Experience with administration of Windows/Linux systems and version control/ticketing systems (e.g., JIRA, GitLab, Subversion)
One or more technical professional certifications related to information technology communications or security (e.g., CEH, CCNA, CISSP)
Knowledge of scripting/programming (e.g., Python) and familiarity with machine-readable data exchange methods (e.g., JSON, REST)
Please note: while the salary range is wide, the specific salary range for this position is going to be around $120,000.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
Original Posting:
August 28, 2026For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $87,100.00 - $157,450.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
About Leidos
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.
Securing Your Data
Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system – never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at [email protected].
If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.
