More jobs:
Penetration tester
Job in
Rocester, Uttoxeter, Staffordshire, ST14, England, UK
Listed on 2026-07-24
Listing for:
AMARIS GROUP SA
Full Time
position Listed on 2026-07-24
Job specializations:
-
Security
Cybersecurity
Job Description & How to Apply Below
Job description
You will join Amaris Consulting within our Automotive teams in Rocester.
Responsibilities1) Penetration testing and adversarial assessment
- Plan and execute penetration tests on the products with digital elements: ECUs, telematics units, in‑vehicle networks (CAN, J1939, LIN), diagnostic interfaces (UDS/OBD), bootloaders, connected services and mobile/cloud backends.
- Use threat intelligence and TARA outputs to prioritise attack paths and test scenarios.
- Conduct hardware‑level assessments: JTAG/UART access, debug interface analysis, firmware extraction and analysis, side‑channel awareness.
- Test software components, APIs, update mechanisms and cryptographic implementations as required.
- Produce clear, technically detailed reports: vulnerability description, reproduction steps, severity rating, affected products/versions, and recommended remediation.
- Ensure test outputs meet the coverage and evidence expectations defined by the Senior Engineer – Cybersecurity Compliance for programme assurance.
- Align findings with ISO/SAE 21434 verification and validation requirements and relevant compliance evidence packs.
- Feed confirmed findings directly into the vulnerability management process, with sufficient detail for triage, CVSS scoring and remediation tracking.
- Support the Vulnerability Management Engineer in assessing exploitability of CVEs or supplier‑reported issues where hands‑on validation is needed.
- Contribute to SBOM‑informed testing priorities as component‑level intelligence evolves.
- Capture lessons learned from test engagements and feed them into internal standards, TARA guidance and cybersecurity requirements.
- Stay current with automotive and embedded system attack research, tooling, CVE/CWE trends and threat actor techniques relevant to off‑highway machinery.
- Support uplift of engineering teams through knowledge sharing on common vulnerability patterns and secure design.
- Hands‑on penetration testing experience in embedded systems, OT/ICS, automotive or connected products (3+ years)
- Practical experience with automotive protocols: CAN, J1939, LIN, UDS, OBD‑II
- Hardware assessment skills: JTAG, UART, logic analysis, firmware extraction
- Familiarity with ISO/SAE 21434 and its verification and validation requirements
- Ability to write clear, technically precise test reports that engineers and compliance stakeholders can both use
- Strong analytical approach: rigorous, evidence‑based, reproducible
- Experience in Tier 1 or OEM sectors (on‑highway or off‑highway)
- Knowledge of IEC 62443 and CRA requirements, including Article 14 reporting context
- Familiarity with TARA and threat modelling outputs (attack trees, STRIDE, EVITA)
- Experience with tools such as CANalyzer, Wireshark, IDA Pro, Ghidra, Burp Suite, OpenOCD, GreatFET or equivalent
- Awareness of SBOM formats and their role in vulnerability identification
- Relevant certifications: OSCP, CEH, or automotive/embedded‑specific equivalents (e.g. TÜV Rheinland Cybersecurity)
- You’re methodical. You document everything and your reports are good enough to hold up in a compliance audit.
- You’re curious. You read CVE disclosures, follow automotive security research, and probably have test hardware at home.
- You can work across disciplines. Engineering, compliance, suppliers, sometimes legal. You adapt the message without losing the accuracy.
- You’re pragmatic. You understand that findings need to land somewhere useful, and you care about closure as much as discovery.
- An international community bringing together 110+ different nationalities.
- An environment where trust has a central place: 70% of our key leaders started their careers at the first level of responsibilities.
- A robust training system with our internal Academy and 250+ available modules.
- A vibrant workplace that frequently gathers for internal events, including after works and team buildings.
- The opportunity to contribute to high‑impact governance, assurance, and change initiatives for key clients.
- At Mantu, sustainability is part of everything we do. You’ll have the…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×