Penetration tester

AMARIS GROUP SA

Rocester

On-site

GBP 60,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Amaris Consulting, Rocester, UK, is seeking a cybersecurity tester specialized in embedded automotive systems. You will perform penetration testing on ECUs, CAN/J1939 networks, and OTA/update mechanisms, producing precise reports for engineering and compliance teams.

Responsibilities include evidence‑driven testing, applying ISO/SAE 21434 standards, and contributing to vulnerability management triage while staying abreast of automotive threat research and best practices.

Qualifications

  • Hands-on penetration testing experience in embedded systems, OT/ICS, automotive or connected products.
  • Experience with automotive protocols: CAN, J1939, LIN, UDS, OBD‑II.
  • Hardware assessment skills: JTAG/UART, firmware extraction.
  • Familiarity with ISO/SAE 21434 and its verification/validation requirements.
  • Ability to write clear, technically precise test reports for engineers and compliance.
  • Strong analytical, evidence-based, reproducible approach.

Responsibilities

  • Penetration testing on ECUs, telematics, in-vehicle networks, and cloud backends.
  • Produce detailed vulnerability reports with reproduction steps and remediation.
  • Align findings with ISO/SAE 21434 verification requirements and compliance packs.
  • Support vulnerability management with triage and CVSS scoring details.
  • Capture lessons learned to inform internal standards and risk guidance.
  • Stay current on automotive cybersecurity threats and tooling.

Skills

Penetration testing
Embedded systems
Automotive protocols
Hardware assessment
ISO/SAE 21434
Technical reporting

Tools

CANalyzer
Wireshark
IDA Pro
Ghidra
Burp Suite
OpenOCD
GreatFET

Job description

Job description

You will join Amaris Consulting within our Automotive teams in Rocester.

Responsibilities
1) Penetration testing and adversarial assessment
  • Plan and execute penetration tests on the products with digital elements: ECUs, telematics units, in‑vehicle networks (CAN, J1939, LIN), diagnostic interfaces (UDS/OBD), bootloaders, connected services and mobile/cloud backends.
  • Use threat intelligence and TARA outputs to prioritise attack paths and test scenarios.
  • Conduct hardware‑level assessments: JTAG/UART access, debug interface analysis, firmware extraction and analysis, side‑channel awareness.
  • Test software components, APIs, update mechanisms and cryptographic implementations as required.
2) Testing evidence and programme assurance
  • Produce clear, technically detailed reports: vulnerability description, reproduction steps, severity rating, affected products/versions, and recommended remediation.
  • Ensure test outputs meet the coverage and evidence expectations defined by the Senior Engineer – Cybersecurity Compliance for programme assurance.
  • Align findings with ISO/SAE 21434 verification and validation requirements and relevant compliance evidence packs.
3) Collaboration with vulnerability management
  • Feed confirmed findings directly into the vulnerability management process, with sufficient detail for triage, CVSS scoring and remediation tracking.
  • Support the Vulnerability Management Engineer in assessing exploitability of CVEs or supplier‑reported issues where hands‑on validation is needed.
  • Contribute to SBOM‑informed testing priorities as component‑level intelligence evolves.
  • Capture lessons learned from test engagements and feed them into internal standards, TARA guidance and cybersecurity requirements.
  • Stay current with automotive and embedded system attack research, tooling, CVE/CWE trends and threat actor techniques relevant to off‑highway machinery.
  • Support uplift of engineering teams through knowledge sharing on common vulnerability patterns and secure design.
Qualifications and experience
Essential
  • Hands‑on penetration testing experience in embedded systems, OT/ICS, automotive or connected products (3+ years)
  • Practical experience with automotive protocols: CAN, J1939, LIN, UDS, OBD‑II
  • Hardware assessment skills: JTAG, UART, logic analysis, firmware extraction
  • Familiarity with ISO/SAE 21434 and its verification and validation requirements
  • Ability to write clear, technically precise test reports that engineers and compliance stakeholders can both use
  • Strong analytical approach: rigorous, evidence‑based, reproducible
Desired
  • Experience in Tier 1 or OEM sectors (on‑highway or off‑highway)
  • Knowledge of IEC 62443 and CRA requirements, including Article 14 reporting context
  • Familiarity with TARA and threat modelling outputs (attack trees, STRIDE, EVITA)
  • Experience with tools such as CANalyzer, Wireshark, IDA Pro, Ghidra, Burp Suite, OpenOCD, GreatFET or equivalent
  • Awareness of SBOM formats and their role in vulnerability identification
  • Relevant certifications: OSCP, CEH, or automotive/embedded‑specific equivalents (e.g. TÜV Rheinland Cybersecurity)
About you
  • You’re methodical. You document everything and your reports are good enough to hold up in a compliance audit.
  • You’re curious. You read CVE disclosures, follow automotive security research, and probably have test hardware at home.
  • You can work across disciplines. Engineering, compliance, suppliers, sometimes legal. You adapt the message without losing the accuracy.
  • You’re pragmatic. You understand that findings need to land somewhere useful, and you care about closure as much as discovery.
What We Offer
  • An international community bringing together 110+ different nationalities.
  • An environment where trust has a central place: 70% of our key leaders started their careers at the first level of responsibilities.
  • A robust training system with our internal Academy and 250+ available modules.
  • A vibrant workplace that frequently gathers for internal events, including afterworks and team buildings.
  • The opportunity to contribute to high‑impact governance, assurance, and change initiatives for key clients.
  • At Mantu, sustainability is part of everything we do. You’ll have the opportunity to turn your ideas into action and make a tangible impact. Every day, our teams bring our ESG commitments to life, from reducing our footprint to driving positive change within our communities. Through our WeCare Together program, you’ll be empowered to design and lead projects that create real social or environmental impact, with the company’s full support.
Who are we?

Amaris Consulting is an independent technology‑consulting firm providing guidance and solutions to businesses. With more than 1000 clients across the globe, we have been rolling out solutions in major projects for over a decade – this is made possible by an international team of 7,600 people spread across 5 continents and more than 60 countries. Our solutions focus on four different Business Lines: Information System & Digital, Telecom, Life Sciences and Engineering. We’re focused on building and nurturing a top talent community where all our team members can achieve their full potential. Amaris is your stepping stone to cross rivers of change, meet challenges and achieve all your projects with success.

Amaris Consulting is proud to be an equal‑opportunity workplace. We are committed to promoting diversity within the workforce and creating an inclusive working environment. For this purpose, we welcome applications from all qualified candidates regardless of gender, sexual orientation, race, ethnicity, beliefs, age, marital status, disability, or other characteristics.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Penetration tester
Penetration tester

Amaris Consulting • Rochester

On-site
GBP 70,000 - 90,000
Automotive Penetration Tester - Embedded & CAN Focus
Automotive Penetration Tester - Embedded & CAN Focus

Amaris Consulting • Rochester

On-site
GBP 70,000 - 90,000
Cybersecurity Governance & Assurance Specialist
Cybersecurity Governance & Assurance Specialist

AMARIS GROUP SA • Greater London

On-site
GBP 50,000 - 70,000
Automotive Embedded Security Penetration Tester
Automotive Embedded Security Penetration Tester

AMARIS GROUP SA • Rocester

On-site
GBP 60,000 - 90,000
AIT Lead Engineer
AIT Lead Engineer

AMARIS GROUP SA • Guildford

On-site
GBP 60,000 - 90,000
International team
Internal Academy with modules
Team events and gatherings
+1
AIT Integration Engineer
AIT Integration Engineer

AMARIS GROUP SA • Guildford

On-site
GBP 45,000 - 70,000
Internal Academy with 250+ training
International community
Team events & ESG initiatives
Senior Test Engineer
Senior Test Engineer

Amach • Greater London

Hybrid
GBP 50,000 - 70,000
Options for career advancement
Learning and development opportunities
Flexible working environment
+1
Senior Engineer - Defence
Senior Engineer - Defence

UTAC group • Bedford

On-site
GBP 55,000 - 85,000
Life Cover
Contributory Pension
Flexible Working
+2
IT/OT Penetration Tester
IT/OT Penetration Tester

PA Consulting • Greater London

Hybrid
GBP 60,000 - 80,000
Health and lifestyle perks with private healthcare
25 days annual leave with the option to buy 5 additional days
Generous company pension scheme
+2
Engineer - Systems & Components
Engineer - Systems & Components

Utaceram • Bedford

On-site
GBP 35,000 - 50,000
Life Cover
Access to discounts through the Perkz reward scheme
Recognition awards
+2