Tuesday, June 21, 2011

XIRING Products & Solutions Security Qualification Engineer France
The Security Qualification Engineer
Tasks (technical, management, human ressource, scheduling)
· Survey, state of the art about security of smart card readers
o Establish, maintain relationships with recognised professionals of security community:
labs, CESTIs, experts, free-lance, forum, research, etc…
o Through different contacts and different information sources, establish, maintain and
regularly publish an internal document stating :
State of art of hacking techniques for any products connected to a computer
New trends in terms of attacks
New preventing techniques
· Application to our products and solutions
o Study the applicability & portability of above techniques
· Establish, maintain and publish to R&D development teams, a book describing :
o recommendations to avoid known design vulnerabilities
o descriptions of identified attack mechanisms
· Technical support to development teams as regard to attack resistance
· Bring the security qualification tasks & expertise in all relevant projects in all phases of the
product development cycle.
· Develop and maintain tests suites to check & qualify that our products & solutions are resistant
to identified attacks
· Specify tests suites when it is not possible to develop them internally and manage the related
subcontracted design
Responsibilities (HR, financial, technical)
· Guarantee the knowledge of state of the art related to XIRING products & solutions in terms of
logical security.
· Guarantee the actual prevention of identified “state of the art” attacks onto XIRING Products &
Solutions
· Ensure to R&D Design Teams the communication of information and recommendations related
to identified attacks.
· Guarantee the applicability and efficiency of all security tests suites
Team Management
· Not applicable. However, resource management could be a possibility depending on work load
Mission of the managed team (inputs, outputs)
· Not applicable
Functional interfaces
· The Product Qualification Manager
· R&D Teams
Reporting
· Report to its team leader
· Weekly update of all activities and actions

Candidate Skills and Profile
· Recently graduated of a PhD in the field of science & technology of computing security
· High interest into the security of small embedded systems
· Practical sense, in terms of being easily able to convert concepts into clear, usable, repeatable
models
· Highly autonomous with excellent team working spirit and transparency about all undertaken
actions
· Open minded to other team members & ideas
· Good analysis skills, Fond of electronics, Curious, Wide-ranging interest to new technologies
· Ability to chair the « club » or “network” of experts external to XIRING
· Fluent in English.
Job starting date
· As soon as possible
Contract type
· CDI « Contrat à Durée Indéterminée »
Contact:
Mr Durand c.durand(at)xiring.com
Or
Mr Pagot l.pagot(at)xiring.com
Job Title Products & Solutions Security Qualification Engineer
POST DETAILS
Org Name XIRING
City Suresnes Cedex
State/Province N
Country France
Application Deadline 2011-Sep-17