وصف المشروع يتوسع عميلنا، وهو شركة رائدة في تصنيع الأجهزة المنزلية الراقية، في خطوط منتجات ذكية جديدة. وكجزء من هذه المبادرة الاستراتيجية، يتم تنفيذ برنامج عالمي واسع النطاق عبر محفظة الملكية الفكرية للشركة. ويتضمن ذلك تطوير برامج مدمجة جديدة، وتحسينات على البنية التحتية السحابية، وإنشاء واجهات مبتكرة داخل تطبيق الهاتف المحمول.
المسؤوليات: عضو في فريق الاختبار، وإجراء تصميم الاختبار، وتنفيذ الاختبار وإعداد التقارير، وصيانة حالات الاختبار. والتحقق من صحة TARA ونمذجة التهديدات. وتطوير وثائق الاختبار رفيعة المستوى. وتنفيذ أتمتة الاختبارات المتقدمة (اختياري، التفكير في إطار عمل الأتمتة ونشره، وإنشاء/صيانة اختبارات الأتمتة). ومراجعة والتحقق من صحة تقرير TARA ونمذجة التهديدات لمختلف مكونات البرامج/الأجهزة. ومراجعة وتحليل وإنشاء حالات اختبار الأمن السيبراني لمتطلبات وسيناريوهات العميل/البرامج الشاملة. والمشاركة في اختيار الأدوات وإنشاء وصيانة بيئة اختبار الأمان والبنية التحتية. وصيانة حالات الاختبار وفقًا لتطور المنتج والمتطلبات وتتبع حالات الاختبار. وإنشاء/تشغيل سكريبتات أتمتة الاختبار (اختياري). والتفاعل (مثل المكالمات الجماعية والبريد الإلكتروني) مع العميل إذا لزم الأمر. وإنشاء وثائق الاختبار وتقارير الاختبار. ومعرفة قوية بالمنتج/النظام، وتحليل أسباب العيوب، والمناقشات والتفاعل القوي مع فريق التطوير. والمساعدة في تصحيح الأخطاء وتحديد أنواع الأعطال (جمع تتبع تصحيح الأخطاء، وتسريبات الذاكرة، والعثور على الثغرات البرمجية المحتملة). وتزويد مدير الاختبار بتقديرات دقيقة لمدة المهام المعينة. والمسؤولية عن التحقق والاعتماد لمتطلبات الأمن السيبراني على جميع المستويات (المكونات / الوحدة / النظام الفرعي / مستوى النظام). والتأكد من أن جميع متطلبات الأمن السيبراني مع ضوابط الأمن السيبراني مغطاة بحالات الاختبار؛ وتطبيق جميع حالات الاختبار، وإعادة سجلات الاختبار الآلية إلى حالات الاختبار؛ وتطبيق أساليب تصميم حالات الاختبار المتعلقة بالأمن السيبراني. والتحقق من المتطلبات ذات الصلة بالأمن السيبراني (أي الاختبار القائم على المتطلبات الوظيفية). ومراجعة موجزات استخبارات التهديدات دوريًا، وتصفية الثغرات الأمنية الحرجة الجديدة المتعلقة بقطاع السيارات وإعداد تقارير عنها. والمشاركة في إنشاء خط أنابيب CI/CD لتغطية الاختبارات الوظيفية المؤتمتة للأمن السيبراني (DevSecOps).
المهارات المتطلبات الأساسية: الحصول على درجة البكالوريوس في علوم الحاسوب أو مجال ذي صلة، و5 سنوات على الأقل من الخبرة السابقة ذات الصلة، مثل: اختبار الأمن السيبراني (السيارات/ تكنولوجيا المعلومات/ تكنولوجيا التشغيل/ إنترنت الأشياء)، اختبار الاختراق، بنية الأمن السيبراني. يجب أن تتضمن خبرته/خبرتها سنتين على الأقل في قيادة أحد الأنشطة التالية: تصميم/بنية البرمجيات، اختبار السيارات / اختبار إنترنت الأشياء، اختبار الاختراق للمشاريع المتعلقة بالأجهزة. مهارات يفضل وجودها: معرفة بالعمليات التي تحدد معايير ISO/SAE 21434 وASPICE للأمن السيبراني. لغات أخرى: الإنجليزية: C1 متقدم. المستوى الوظيفي: سينيور.
ملف المرشح المطلوب
المتطلبات الأساسية: الحصول على درجة البكالوريوس في علوم الحاسوب أو مجال ذي صلة، و5 سنوات على الأقل من الخبرة السابقة ذات الصلة، مثل: اختبار الأمن السيبراني (السيارات/ تكنولوجيا المعلومات/ تكنولوجيا التشغيل/ إنترنت الأشياء)، اختبار الاختراق، بنية الأمن السيبراني. يجب أن تتضمن خبرته/خبرتها سنتين على الأقل في قيادة أحد الأنشطة التالية: تصميم/بنية البرمجيات، اختبار السيارات / اختبار إنترنت الأشياء، اختبار الاختراق للمشاريع المتعلقة بالأجهزة.
مهارات يفضل وجودها: معرفة بالعمليات التي تحدد معايير ISO/SAE 21434 وASPICE للأمن السيبراني
لغات أخرى: الإنجليزية: C1 متقدم
Project description Our client, a leading manufacturer of high-end household appliances, is expanding into new smart product lines. As part of this strategic initiative, a large-scale global program is being implemented across the company's IP portfolio. This includes the development of new embedded software, enhancements to cloud infrastructure, and the creation of innovative interfaces within the mobile application.
Responsibilities Member of test team, perform test design, test execution and reporting, test cases maintenance. TARA and Threat modeling validation. High-level test documentation development. Advanced test automation (optional, considering, and deployment of automation framework, creation/maintenance automation tests) execution. Review and validate TARA report and threat modeling for various SW/HW components Review, analysis, and create cybersecurity test case for comprehensive Customer/Software Requirements and scenarios Participate in tool selection, creation, and maintenance of security testing environment and infrastructure Test case maintenance in compliance with product evolution, requirements, and test cases traceability tracking Test automation scripts creation/run (optional) Interactions (e.g, call conf, emails) with Client if required. Testing documentation creation & test reports Strong product/system knowledge, defect causes analysis, discussions and strong interaction with Development team. Help in debugging & identifying crash types (collect debugging traces, memory leaks, find potential software vulnerabilities) Provide the Test Manager with accurate estimates for assigned task duration Responsible for Cybersecurity Requirements Verification and Validation at all levels (components / module / sub-system / system level) Ensure that all Cybersecurity requirements with Cybersecurity controls are covered by test cases; All test cases are executed, and automated test logs refer back to the test cases; Cybersecurity-related test case design methods have been applied. Verify Cybersecurity-relevant requirements (i.e. functional requirements-based testing) Review periodically Threat Intelligence feeds, Filter and report the critical new vulnerabilities related to automotive sector Participate in CI/CD pipeline creation to cover automated functional cybersecurity testing (DevSecOps)
Skills Must have Bachelor's Degree in Computer science or related field, AND At least 5 year of previous relevant experience, such as: Cybersecurity testing (Automotive/ IT/ OT/IOT) Penetration testing Cybersecurity architecture At Least 2 Years of his/her experiences includes leading one of the following activities: SW Design/Architecture Automotive Testing / IoT Testing HW related project penetration testing Nice to have Knowledge of processes defining standards ISO/SAE 21434 and ASPICE for Cybersecurity Other Languages English: C1 Advanced Seniority Senior
Desired Candidate Profile
Must have Bachelor's Degree in Computer science or related field, AND At least 5 year of previous relevant experience, such as: Cybersecurity testing (Automotive/ IT/ OT/IOT) Penetration testing Cybersecurity architecture At Least 2 Years of his/her experiences includes leading one of the following activities: SW Design/Architecture Automotive Testing / IoT Testing HW related project penetration testing
Nice to have Knowledge of processes defining standards ISO/SAE 21434 and ASPICE for Cybersecurity
Other Languages English: C1 Advanced