الوصف الوظيفي
وصف المشروع
يتوسع عميلنا، وهو شركة رائدة في تصنيع الأجهزة المنزلية الراقية، في خطوط منتجات ذكية جديدة. وكجزء من هذه المبادرة الاستراتيجية، يتم تنفيذ برنامج عالمي واسع النطاق عبر محفظة الملكية الفكرية للشركة. ويتضمن ذلك تطوير برمجيات مدمجة جديدة، وتحسينات في البنية التحتية السحابية، وإنشاء واجهات مبتكرة داخل تطبيق الهاتف المحمول.
المسؤوليات
عضو في فريق الاختبار، وإجراء تصميم الاختبار، وتنفيذ الاختبار وإعداد التقارير، وصيانة حالات الاختبار.
التحقق من صحة تقييم المخاطر وتحليل التهديدات (TARA) ونمذجة التهديدات. تطوير وثائق اختبار عالية المستوى. تنفيذ أتمتة الاختبار المتقدمة (اختياري، دراسة ونشر إطار عمل الأتمتة، وإنشاء/صيانة اختبارات الأتمتة).
مراجعة والتحقق من صحة تقرير TARA ونمذجة التهديدات لمختلف مكونات البرمجيات/الأجهزة
مراجعة وتحليل وإنشاء حالات اختبار الأمن السيبراني لمتطلبات وسيناريوهات العملاء/البرمجيات الشاملة
المشاركة في اختيار الأدوات، وإنشاء وصيانة بيئة وبنية اختبار الأمان
صيانة حالات الاختبار بما يتوافق مع تطور المنتج والمتطلبات وتتبع إمكانية تتبع حالات الاختبار
إنشاء/تشغيل نصوص أتمتة الاختبار (اختياري)
التفاعل (مثل المكالمات الجماعية والبريد الإلكتروني) مع العميل إذا لزم الأمر.
إنشاء وثائق الاختبار وتقارير الاختبار
معرفة قوية بالمنتج/النظام، وتحليل أسباب العيوب، والمناقشات والتفاعل القوي مع فريق التطوير.
المساعدة في تصحيح الأخطاء وتحديد أنواع الأعطال (جمع آثار تصحيح الأخطاء، وتسريبات الذاكرة، والعثور على الثغرات البرمجية المحتملة)
تزويد مدير الاختبار بتقديرات دقيقة للمدة الزمنية للمهام الموكلة
مسؤول عن التحقق والاعتماد لمتطلبات الأمن السيبراني على جميع المستويات (مستوى المكونات / الوحدة / النظام الفرعي / النظام)
ضمان تغطية جميع متطلبات الأمن السيبراني مع ضوابط الأمن السيبراني بحالات الاختبار؛ وتنفيذ جميع حالات الاختبار، وربط سجلات الاختبار المؤتمتة بحالات الاختبار؛ وتطبيق أساليب تصميم حالات الاختبار المتعلقة بالأمن السيبراني.
التحقق من المتطلبات ذات الصلة بالأمن السيبراني (أي الاختبار القائم على المتطلبات الوظيفية)
المراجعة الدورية لمصادر معلومات التهديدات، وتصفية والإبلاغ عن الثغرات الأمنية الجديدة الحرجة المتعلقة بقطاع السيارات
المشاركة في إنشاء مسار CI/CD لتغطية اختبارات الأمن السيبراني الوظيفية المؤتمتة (DevSecOps)
المهارات
المتطلبات الأساسية
درجة البكالوريوس في علوم الحاسوب أو مجال ذي صلة، و
خبرة ذات صلة لا تقل عن 5 سنوات، مثل:
اختبار الأمن السيبراني (السيارات/ تكنولوجيا المعلومات/ التكنولوجيا التشغيلية/ إنترنت الأشياء)
اختبار الاختراق
هندسة الأمن السيبراني
أن تتضمن خبرته/خبرتها سنتين على الأقل في قيادة أحد الأنشطة التالية:
تصميم/هندسة البرمجيات
اختبار السيارات / اختبار إنترنت الأشياء
اختبار الاختراق للمشاريع المتعلقة بالأجهزة
يفضل أن توجد
معرفة بالعمليات التي تحدد معايير ISO/SAE 21434 و ASPICE للأمن السيبراني
أخرى
اللغات
الإنجليزية: مستوى متقدم C1
مستوى الخبرة
مستوى أقدم (Senior)
Job description
Project description
Our client, a leading manufacturer of high-end household appliances, is expanding into new smart product lines. As part of this strategic initiative, a large-scale global program is being implemented across the company's IP portfolio. This includes the development of new embedded software, enhancements to cloud infrastructure, and the creation of innovative interfaces within the mobile application.
Responsibilities
Member of test team, perform test design, test execution and reporting, test cases maintenance.
TARA and Threat modeling validation. High-level test documentation development. Advanced test automation (optional, considering, and deployment of automation framework, creation/maintenance automation tests) execution.
Review and validate TARA report and threat modeling for various SW/HW components
Review, analysis, and create cybersecurity test case for comprehensive Customer/Software Requirements and scenarios
Participate in tool selection, creation, and maintenance of security testing environment and infrastructure
Test case maintenance in compliance with product evolution, requirements, and test cases traceability tracking
Test automation scripts creation/run (optional)
Interactions (e.g, call conf, emails) with Client if required.
Testing documentation creation & test reports
Strong product/system knowledge, defect causes analysis, discussions and strong interaction with Development team.
Help in debugging & identifying crash types (collect debugging traces, memory leaks, find potential software vulnerabilities)
Provide the Test Manager with accurate estimates for assigned task duration
Responsible for Cybersecurity Requirements Verification and Validation at all levels (components / module / sub-system / system level)
Ensure that all Cybersecurity requirements with Cybersecurity controls are covered by test cases; All test cases are executed, and automated test logs refer back to the test cases; Cybersecurity-related test case design methods have been applied.
Verify Cybersecurity-relevant requirements (i.e. functional requirements-based testing)
Review periodically Threat Intelligence feeds, Filter and report the critical new vulnerabilities related to automotive sector
Participate in CI/CD pipeline creation to cover automated functional cybersecurity testing (DevSecOps)
Skills
Must have
Bachelor's Degree in Computer science or related field, AND
At least 5 year of previous relevant experience, such as:
Cybersecurity testing (Automotive/ IT/ OT/IOT)
Penetration testing
Cybersecurity architecture
At Least 2 Years of his/her experiences includes leading one of the following activities:
SW Design/Architecture
Automotive Testing / IoT Testing
HW related project penetration testing
Nice to have
Knowledge of processes defining standards ISO/SAE 21434 and ASPICE for Cybersecurity
Other
Languages
English: C1 Advanced
Seniority
Senior