Cyber Security Penetration Test Engineer

Tata Technologies Europe Ltd
Lighthorne Heath, UK
2 days ago
Apply on www.adzuna.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
£45,000.0 - £64,000.0
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Cyber Security Software Debugging Embedded Software Fuzz Testing Hardware Design Python (Programming Language) Scripting CAPL Software Security

Job description

  • We are responsible for developing the cyber security penetration test lab.
  • We create and review penetration test scopes, penetration test plans, and penetration test reports.
  • We execute penetration tests and support the creation of vulnerabilities and related CSMS artefacts.
  • We support Product Engineering teams to understand and deliver penetration test-related activities.
  • We manage the delivery of penetration test activities as per CSMS (ISO 21434) according to scope, time, budget, and quality.
  • We build and review vulnerability reports.
  • We create penetration test scopes and plans for ECUs, systems, and vehicles.
  • We review penetration test reports for ECUs, systems, and vehicles.
  • We assess cyber security penetration test scopes and plans for customer products and run penetration tests as per the approved scope for ECUs, systems, and vehicles.
  • We manage and lead external penetration test suppliers and their activities.
  • We maintain and develop penetration test scripts and tools for penetration testing and fuzz testing.
  • We support external penetration test activities for ECUs, systems, and vehicles.
  • We support vulnerability resolution and VSOC by demonstrating vulnerabilities, attacks, and PoCs.
  • We support the sign-off of penetration test-related artefacts and type approval activities.

Technologies:

  • Embedded
  • Hardware
  • Support
  • Python
  • Security

Requirements

  • We require knowledge of at least one scripting language, including Python, CAPL, and others.
  • We require knowledge of TARA, security concepts, and other cyber security artefacts mentioned in ISO 21434.
  • We require knowledge of cyber security technologies used to protect embedded systems.
  • We require knowledge of at least two automotive technologies, such as in-vehicle networks, safety-critical embedded software and hardware, low-level debug interfaces for embedded hardware, complex onboard computers, and vehicle connectivity.
  • We require understanding of high-integrity systems and secure software and/or hardware design principles in an embedded environment.
  • We require the ability to engineer in a way that is demonstrably compliant with standards and technical specifications.
  • We require excellent collaborative skills.

Benefits & conditions

We are Tata Technologies, and we design, engineer, and validate products for the worlds leading manufacturers. Our Engineering Research and Development department is a fast-growing global function working across Automotive, Aerospace, and Industrial Heavy Machinery. This role is based at our customers office in Gaydon, and you will be part of Product Engineering teams delivering secure products while helping improve our cyber security posture and respond to emerging threats. We offer a competitive salary and excellent benefits, including a pension scheme with employee contributions matched up to 5%, 25 days holiday, private health care, the Tata Jaguar Land Rover privilege scheme with up to 20% off new JLR vehicles, group income protection, Health Assured Employee Assistance Program, group life assurance, and a Health Shield private health cash plan. We are committed to innovation and to engineering a better world.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

3:40 min

Integrating mutation testing and fuzzing into software workflows

Michael Contento · World Congress 2023

3:20 min

Certifying safety-critical automotive software and deploying progressive testing strategies

David Romić · World Congress 2023

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

3:52 min

Sending malformed inputs to applications using fuzzing

Michael Contento · World Congress 2023

Videos

See all

Related articles

See all