> Markdown version of [/jobs/ext/361230-senior-security-evaluator-hardware](https://www.wearedevelopers.com/jobs/ext/361230-senior-security-evaluator-hardware). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Evaluator - Hardware - **Company:** Keysight Technologies, Inc. - **Location:** Delft, Netherlands - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** C (Programming Language), Software System Penetration Testing, Booting (BIOS), C++ (Programming Language), Static Program Analysis, Computer Engineering, Embedded Software, Firmware, Hardware Design, Hardware Security Module, Reverse Engineering, Smart Cards, Verilog, VHSIC Hardware Description Language (VHDL), Scripting, Vulnerability Analysis - **Published:** June 19, 2026 - **Apply:** https://nl.indeed.com/viewjob?jk=8f84e0d850887b21 ## About the Role Do you have experience in Verilog?, Do you have a Master's degree?, * A completed academic degree (BSc/MSc) in Electrical Engineering, Embedded Systems, or Computer Engineering. * At least 5 years of technical, hands-on experience in hardware security evaluations, including: * + Security assessments on Smart Cards, Secure ICs, and Secure Sub-Systems in SoC (PP0117). + Leading and performing fault injection and side-channel analysis, including attack potential rating and threshold testing as per JIL or EMVCo requirements. + Deep familiarity with Common Criteria (PP0084, PP0117), JIL hardware attack methods, or EMVCo Security Evaluation Process. + Experience in evaluating bootloaders, embedded code, and proprietary protocols. * Expert-level skills in: * + Embedded programming: Assembly, C, C++ + Hardware design review: PCB schematics, layout files, protection mechanisms + RTL code analysis: Verilog, VHDL + Working with hardware security lab equipment: oscilloscopes, lasers, EM probes, FI tooling * Strong technical documentation and reporting skills; able to translate complex technical findings into certification-ready reports. * Comfortable working with multidisciplinary teams (hardware, software, crypto, compliance) and interfacing with both technical and scheme-level stakeholders. * Willing to travel occasionally to customer locations or certification authority meetings across Europe, North America, or Asia ## Description * Lead and execute vulnerability analysis and penetration testing campaigns on secure hardware products (e.g., Secure ICs, Secure Sub-Systems in SoCs) in accordance with certification schemes like Common Criteria (PP0084, PP0117) and EMVCo. * Design, plan, and document test strategies and test plans aligned with scheme-specific requirements (e.g., JIL, AVA_VAN.5, EMVCo attack paths). * Perform and guide fault injection (FI) and side-channel analysis (SCA) testing (e.g., laser, EM, voltage, glitching), and analyze collected traces for vulnerability identification. * Conduct in-depth hardware design reviews, including schematics, layout, and countermeasure analysis, to assess resistance against physical and logical attacks. * Analyze and reverse-engineer bootloaders, embedded software, and firmware using Assembly, C/C++, and scripting tools. * Review and assess RTL code (e.g., Verilog, VHDL) to identify potential architectural and implementation-level weaknesses. * Document findings in technical reports and certification deliverables in a clear, structured, and evidence-driven manner, suitable for submission to certification bodies and scheme owners. * Technically lead evaluation teams by assigning tasks, reviewing technical deliverables, and ensuring conformance with certification expectations and project timelines. * Act as a subject-matter expert for hardware-based evaluations, engaging with customers and certification authorities to explain findings and defend evaluation results. * Provide guidance and mentoring to junior colleagues by reviewing their analysis results and offering coaching rooted in certification scheme expectations. * Maintain and share up-to-date knowledge on certification scheme developments, vulnerability classes, and evaluation methodologies relevant to the secure product certification domain. * Translate vulnerability analysis findings into clear and actionable input for the security testing team, aligning results with applicable scheme thresholds and evaluation metrics. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [Cybersecurity for Software Defined Vehicles](https://www.wearedevelopers.com/videos/725-cybersecurity-for-software-defined-vehicles) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)