Your task:
1. Carrying out penetration tests and vulnerability assessments across a wide variety of platforms and technologies (web, mobile, networking, IoT devices, etc.), including targeted attack simulations to identify weaknesses and exploitability. (40%)
2. Performing specialised penetration tests on automotive electronic systems – covering in-vehicle infotainment, telematics boxes (T Box), ADAS, ECUs, CAN/CAN FD, in-vehicle Ethernet, etc. – to validate vehicle network security protections, while ensuring that test procedures and results comply with regulatory standards such as UN R155, UN R156, and GB44495. (20%)
3. Helping evolve the knowledge of adversarial TTPs and applying that knowledge when evaluating and testing corporate resources. Adherence to the highest standards of safety, ethics, and professional conduct is a critical requirement. (15%)
4. Keeping up to date with tools, countermeasures, threats, and technologies. (15%)
5. Interpreting vulnerabilities, identifying weaknesses, exploiting them, and escalating access. (10%)
Your qualifications:
1. Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, or a related field.
2. Understanding of at least one relevant penetration testing domain (e.g., web, networking, medical devices, automotive, mobile applications, etc.).
3. Comprehension of OWASP Top 10 (both web and IoT), OSSTMM, PTES, NIST, and ISSAF technical controls and standards, with the ability to understand and communicate how these standards and controls relate to risk management strategies.
4. Knowledge of reverse engineering for Windows, Unix/Linux, and Android/iOS based applications is a plus.
5. Knowledge of JTAG/UART and on chip debuggers is a plus.
6. Knowledge of wireless protocols such as WiFi, Bluetooth, Zigbee, etc. is a plus.
7. Familiarity with UN R155 (Vehicle Cybersecurity Regulation), UN R156 (Software Update Regulation), and GB44495 (China’s automotive vehicle cybersecurity technical requirements), and an understanding of their specific testing and compliance assessment processes.
8. Working knowledge of automotive E/E architectures, in vehicle communication protocols (e.g., CAN, LIN, FlexRay, MOST, in vehicle Ethernet), and diagnostic protocols (e.g., UDS), with the ability to identify and exploit potential security risks within vehicle networks.
9. Experience in planning, setting up, and managing an automotive penetration testing laboratory – including test equipment (e.g., CANoe, Vector toolchain), environment configuration, and security test process management – is highly preferred.