
How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Job Description
You will join Amaris Consulting within our Automotive teams in Rocester.
Your Responsibilities
-
Penetration Testing and Adversarial Assessment
- Plan and execute penetration tests on products with digital elements: ECUs, telematics units, in-vehicle networks (CAN, J1939, LIN), diagnostic interfaces (UDS/OBD), bootloaders, connected services and mobile/cloud backends.
- Use threat intelligence and TARA outputs to prioritise attack paths and test scenarios.
- Conduct hardware-level assessments: JTAG/UART access, debug interface analysis, firmware extraction and analysis, side-channel awareness.
- Test software components, APIs, update mechanisms and cryptographic implementations as required.
-
Testing Evidence and Programme Assurance
- Produce clear, technically detailed reports: vulnerability description, reproduction steps, severity rating, affected products/versions, and recommended remediation.
- Ensure test outputs meet the coverage and evidence expectations defined by the Senior Engineer – Cybersecurity Compliance for programme assurance.
- Align findings with ISO/SAE 21434 verification and validation requirements and relevant compliance evidence packs.
-
Collaboration with Vulnerability Management
- Feed confirmed findings directly into the vulnerability management process, with sufficient detail for triage, CVSS scoring and remediation tracking.
- Support the Vulnerability Management Engineer in assessing exploitability of CVEs or supplier-reported issues where hands-on validation is needed.
- Contribute to SBOM-informed testing priorities as component-level intelligence evolves.
-
Continuous Improvement
- Capture lessons learned from test engagements and feed them into internal standards, TARA guidance and cybersecurity requirements.
- Stay current with automotive and embedded system attack research, tooling, CVE/CWE trends and threat actor techniques relevant to off-highway machinery.
- Support uplift of engineering teams through knowledge sharing on common vulnerability patterns and secure design.
Essential
Qualifications and Experience
- Hands-on penetration testing experience in embedded systems, OT/ICS, automotive or connected products (3+ years)
- Practical experience with automotive protocols: CAN, J1939, LIN, UDS, OBD-II
- Hardware assessment skills: JTAG, UART, logic analysis, firmware extraction
- Familiarity with ISO/SAE 21434 and its verification and validation requirements
- Ability to write clear, technically precise test reports that engineers and compliance stakeholders can both use
- Strong analytical approach: rigorous, evidence-based, reproducible
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Desired
- Experience in Tier 1 or OEM sectors (on-highway or off-highway)
- Knowledge of IEC 62443 and CRA requirements, including Article 14 reporting context
- Familiarity with TARA and threat modelling outputs (attack trees, STRIDE, EVITA)
- Experience with tools such as CANalyzer, Wireshark, IDA Pro, Ghidra, Burp Suite, OpenOCD, GreatFET or equivalent
- Awareness of SBOM formats and their role in vulnerability identification
- Relevant certifications: OSCP, CEH, or automotive/embedded-specific equivalents (e.g. TÜV Rheinland Cybersecurity)
About You
- You're methodical. You document everything and your reports are good enough to hold up in a compliance audit.
- You're curious. You read CVE disclosures, follow automotive security research, and probably have test hardware at home.
- You can work across disciplines. Engineering, compliance, suppliers, sometimes legal. You adapt the message without losing the accuracy.
- You're pragmatic. You understand that findings need to land somewhere useful, and you care about closure as much as discovery.
What We Offer
- An international community bringing together 110+ different nationalities.
- An environment where trust has a central place: 70% of our key leaders started their careers at the first level of responsibilities.
- A robust training system with our internal Academy and 250+ available modules.
- A vibrant workplace that frequently gathers for internal events, including afterworks and team buildings.
- The opportunity to contribute to high-impact governance, assurance, and change initiatives for key clients.
- At Mantu, sustainability is part of everything we do. You’ll have the opportunity to turn your ideas into action and make a tangible impact. Every day, our teams bring our ESG commitments to life, from reducing our footprint to driving positive change within our communities. Through our WeCare Together program, you’ll be empowered to design and lead projects that create real social or environmental impact, with the company’s full support.
Amaris Consulting is proud to be an equal-opportunity workplace. We are committed to promoting diversity within the workforce and creating an inclusive working environment. For this purpose, we welcome applications from all qualified candidates regardless of gender, sexual orientation, race, ethnicity, beliefs, age, marital status, disability, or other characteristics.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Who Are We?
Amaris Consulting is an independent technology consulting firm providing guidance and solutions to businesses. With more than 1,000 clients across the globe, we have been rolling out solutions in major projects for over a decade – this is made possible by an international team of 7,600 people spread across 5 continents and more than 60 countries. Our solutions focus on four different Business Lines: Information System & Digital, Telecom, Life Sciences and Engineering. We’re focused on building and nurturing a top talent community where all our team members can achieve their full potential. Amaris is your steppingstone to cross rivers of change, meet challenges and achieve all your projects with success.
At Amaris, we strive to provide our candidates with the best possible recruitment experience. We like to get to know our candidates, challenge them, and be able to give them proper feedback as quickly as possible. Here's what our recruitment process looks like:
Brief Call
Our process typically begins with a brief virtual/phone conversation to get to know you! The objective? Learn about you, understand your motivations, and make sure we have the right job for you!
Interviews
The average number of interviews is 3 - the number may vary depending on the level of seniority required for the position. During the interviews, you will meet people from our team: your line manager of course, but also other people related to your future role. We will talk in depth about you, your experience, and skills, but also about the position and what will be expected of you. Of course, you will also get to know Amaris: our culture, our roots, our teams, and your career opportunities!
Case Study
Depending on the position, we may ask you to take a test. This could be a role play, a technical assessment, a problem-solving scenario, etc.
As you know, every person is different and so is every role in a company. That is why we have to adapt accordingly, and the process may differ slightly at times. However, please know that we always put ourselves in the candidate's shoes to ensure they have the best possible experience.
We look forward to meeting you!
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills