المسؤوليات عضو في فريق الاختبار، إعداد تصميم الاختبارات، وتنفيذها، والإبلاغ عنها، وصيانة حالات الاختبار. التحقق من نماذج تحليل المخاطر (TARA) ونمذجة التهديدات. تطوير وثائق اختبار عالية المستوى. تنفيذ اختبار الأتمتة المتقدمة (اختياري، النظر في ونشر إطار عمل الأتمتة، إنشاء/صيانة اختبارات الأتمتة). مراجعة والتحقق من تقرير TARA ونمذجة التهديدات لمختلف مكونات البرامج/الأجهزة. مراجعة وتحليل وإنشاء حالات اختبار أمن سيبراني للمتطلبات/سيناريوهات العملاء الشاملة. المشاركة في اختيار الأدوات، وإنشاء وصيانة بيئة واختبارات أمن البنية التحتية. صيانة حالات الاختبار وفقاً لتطور المنتج، والمتطلبات، وتتبع قابلية التتبع لحالات الاختبار. إنشاء/تشغيل نصوص أتمتة الاختبار (اختياري). تفاعلات (مثل مؤتمرات الهاتف، رسائل البريد الإلكتروني) مع العميل عند الضرورة. إعداد وثائق الاختبار وتقارير الاختبار. معرفة قوية بالمنتج/النظام، تحليل أسباب العيوب، مناقشات وتفاعلات قوية مع فريق التطوير. المساعدة في تصحيح الأخطاء وتحديد أنواع الأعطال (جمع آثار التصحيح، تسرب الذاكرة، العثور على نقاط الضعف المحتملة في البرامج). تقديم تقديرات دقيقة لمديري الاختبار لمدة المهام الموكلة. المسؤول عن التحقق والتحقق من متطلبات الأمن السيبراني على جميع المستويات (المكونات/الوحدة/النظام الفرعي/النظام). ضمان تغطية جميع متطلبات الأمن السيبراني مع ضوابط الأمن السيبراني بواسطة حالات الاختبار؛ تنفيذ جميع حالات الاختبار، وتسجيلات الاختبار الأوتوماتيكي تشير إلى حالات الاختبار؛ تطبيق طرق تصميم حالات اختبار ذات صلة بالأمن السيبراني. التحقق من متطلبات الأمن السيبراني ذات الصلة (أي اختبار متطلبات وظيفية). مراجعة دورية لمصادر معلومات التهديدات، تصفية والإبلاغ عن الثغرات الحرجة الجديدة المتعلقة بقطاع السيارات. المشاركة في إنشاء خط أنابيب CI/CD لتغطية اختبار الأمن السيبراني الوظيفي الأوتوماتيكي (DevSecOps).
الملف الشخصي المرغوب للمرشح
المهارات يجب أن يكون حاصلاً على درجة البكالوريوس في علوم الكمبيوتر أو مجال ذي صلة، و
على الأقل 5 سنوات من الخبرة السابقة ذات الصلة، مثل: اختبار الأمن السيبراني (سيارات/تكنولوجيا المعلومات/تشغيل تقنيات/إنترنت الأشياء) اختبار الاختراق هندسة الأمن السيبراني
على الأقل سنتان من خبراته تشمل قيادة إحدى الأنشطة التالية: تصميم/هندسة البرمجيات اختبار السيارات/إنترنت الأشياء مشاريع متعلقة بالأجهزة اختبار الاختراق
Nice to have المعرفة بعمليات تحديد المعايير ISO/SAE 21434 وASPICE للأمن السيبراني
اللغات الإنجليزية: C1 المتقدمة
المستوى الوظيفي كبير
Responsibilities Member of test team, perform test design, test execution and reporting, test cases maintenance. TARA and Threat modeling validation. High-level test documentation development. Advanced test automation (optional, considering, and deployment of automation framework, creation/maintenance automation tests) execution. Review and validate TARA report and threat modeling for various SW/HW components Review, analysis, and create cybersecurity test case for comprehensive Customer/Software Requirements and scenarios Participate in tool selection, creation, and maintenance of security testing environment and infrastructure Test case maintenance in compliance with product evolution, requirements, and test cases traceability tracking Test automation scripts creation/run (optional) Interactions (e.g, call conf, emails) with Client if required. Testing documentation creation & test reports Strong product/system knowledge, defect causes analysis, discussions and strong interaction with Development team. Help in debugging & identifying crash types (collect debugging traces, memory leaks, find potential software vulnerabilities) Provide the Test Manager with accurate estimates for assigned task duration Responsible for Cybersecurity Requirements Verification and Validation at all levels (components / module / sub-system / system level) Ensure that all Cybersecurity requirements with Cybersecurity controls are covered by test cases; All test cases are executed, and automated test logs refer back to the test cases; Cybersecurity-related test case design methods have been applied. Verify Cybersecurity-relevant requirements (i.e. functional requirements-based testing) Review periodically Threat Intelligence feeds, Filter and report the critical new vulnerabilities related to automotive sector Participate in CI/CD pipeline creation to cover automated functional cybersecurity testing (DevSecOps)
Desired Candidate Profile
Skills Must have Bachelor's Degree in Computer science or related field, AND At least 5 year of previous relevant experience, such as: Cybersecurity testing (Automotive/ IT/ OT/IOT) Penetration testing Cybersecurity architecture At Least 2 Years of his/her experiences includes leading one of the following activities: SW Design/Architecture Automotive Testing / IoT Testing HW related project penetration testing Nice to have Knowledge of processes defining standards ISO/SAE 21434 and ASPICE for Cybersecurity Other Languages English: C1 Advanced Seniority Senior