Spyrosoft
4 months ago
Classified Systems Specialist (Defence & Security) @ Spyrosoft
Sign up to save this job, get alerts, and apply with an optimized CV.
Company information
- Company
- Spyrosoft
- Location
- Polska, dolnośląskie, Wrocław Poland
- Posted
- 4 months ago
Job description
System Architecture
- Knowledge and ability to design classified system architectures, including:
Stand-alone systems vs. segregated networks
- Air-gapped environments and controlled data transfers
- Network segmentation
- Defense-in-depth strategies
- Threat modeling
- Secure by design / secure by default approaches
- OS hardening
- System integrity control
- Minimization of the Trusted Computing Base (TCB) in High Assurance Systems (HAS)
- Integration and configuration in closed environments
- Selection of system components (e.g., TEMPEST, EMC emissions, data media protection, etc.)
- Patch and update management in isolated environments
Networking
- Design of high-security networks
- Network traffic analysis
- Network security hardening
Cryptography
- Knowledge of cryptographic techniques
- Key generation and secure storage
- Implementation of cryptography in compliance with government requirements
- Cryptographic key lifecycle management
Physical Security
- Basic knowledge of security zones/protected areas
- Basic knowledge of physical access control systems
- Evaluation of system components
- Knowledge of Secure SDLC
- Dependency management (VM/VA, SBOM)
- Integration of components in isolated environments
- Knowledge of techniques used in cybersecurity testing
- Planning and supervision of tests confirming achievement and maintenance of the required security level for classified systems
- Verification of cybersecurity test reports
- Knowledge of incident management procedures
- Reporting to relevant authorities
- Planning and supervision of incident response (IR) procedures
- Threat identification
- Risk analysis (qualitative and quantitative)
- Selection of security controls
- Residual risk acceptance
- Strong communication skills within project teams
- Communication with clients
- Communication with certification and/or accreditation bodies
- Preparation of customer proposals/offers
- Personal security clearance at the level of:
TAJNE
- NATO SECRET
- SECRET UE / EU SECRET
- or willingness to undergo a security clearance procedure
- Knowledge of:
ISO/IEC 27000 series
- ISO/IEC 15408
- NATO INFOSEC / cryptographic standards
- Security Policy
- NIS2
- CRA
- NIST
- NATO/STANAG
- Polish - C2
- English - C1
- Experience working with public administration, defense, and/or the security sector
At Spyrosoft Solutions, we are expanding our activities in the defence & security sectors at Spyrosoft Defence & Aerospace Business Unit. As we launch new projects and engage with prospective customers, we are looking for experienced professionals who can support the design, accreditation, and operation of highly secure and classified systems in compliance with national and international security standards.
About SpyrosoftSpyrosoft is an authentic, cutting-edge software engineering company, established in 2016. In 2021 and 2022, we were among the fastest growing technology companies in Europe, according to the Financial Times. We were founded by a group of tech experts with established backgrounds in software engineering, who created an ‘engineer-to-engineer’ workplace, powered by enthusiasm, fairness and authentic relationships. Having a unique offering, which bridge the gap between technology and business, we specialise in technology solutions for industry 4.0, automotive, geospatial, healthcare & life sciences, employee experience & education and financial services industries.
Required skills
- english
- automotive
- industry 4.0
- risk analysis
- communication skills
- polish
- financial services
- software engineering
- auditors
- certification
- cybersecurity
- incident management
- cryptography
- threat modeling
- security clearance
- nato secret
- access management
- nis2
- system architecture
- data security
- configuration management
- audits and inspections
- iec
- nist
- patch management
- public administration
- security policy
- cra
- geospatial
- accreditation
- physical security
- information classification
- secure storage
- security zones
- sbom
- network segmentation
- healthcare & life sciences
- government authorities
- key generation
- customer offers
- dependency management
- update management
- cryptographic standards
- nato infosec
- secure sdlc
- iso/iec 27000 series
- os hardening
- secure by design
- defense-in-depth
- iso/iec 15408
- polish regulations
- tempest
- defence & security
- customer proposals
- protected areas
- network traffic analysis
- air-gapped environments
- government requirements
- classified systems
- stand-alone systems
- segregated networks
- controlled data transfers
- secure by default
- system integrity control
- trusted computing base (tcb)
- high assurance systems (has)
- closed environments
- emc emissions
- data media protection
- isolated environments
- high-security networks
- network security hardening
- cryptographic techniques
- cryptography implementation
- cryptographic key lifecycle management
- physical access control systems
- system assessment
- system components evaluation
- vm/va
- cybersecurity testing
- security level maintenance
- cybersecurity test reports
- incident response (ir)
- threat identification
- security controls selection
- residual risk acceptance
- tajne
- secret ue
- eu secret
- nato/stanag
- employee experience & education
- management of classified systems
- protection of classified information
- security accreditation procedures
- documentation of design decisions
- technical solutions justification
- secure systems documentation
- special security requirements (ssr)
- secure operating procedures (sop)
- training integrators
- system users
Interested in this position?
Create your free account and tailor your CV to match this job.