أبلاي إيدج ابدأ البحث عن عمل

QA Engineer, Security and Multi-Tenant Isolation - Elchai Group

Elchai Group · Dubai, Dubai, United Arab Emirates

قدّم وتابع مع أبلاي إيدج
QA Engineer, Security and Multi-Tenant IsolationLocation: On-site, in DubaiAgent Workflow and Permissions Engineer, Gateway Engineer.The MissionWe are building a highly advanced, centralized AI Governance Orchestration platform. As our Security and Isolation QA, your mission is singular and critical: to prove with repeatable, documented evidence that one client's data can never be accessed by another. Your ultimate deliverable is a signed, unassailable audit report that authorizes our deployment to our first paying enterprise client.What You Will DoBuild the Bench: construct and maintain a permanent dual-client testing environment with strictly segregated users, roles, and databases.Attack the Boundaries: deliberately attack the boundaries between clients across all access points, not just the graphical interface.Vulnerability Hunting: test aggressively for resource ID manipulation, cross-tenant token and ID injection, privilege escalation, cache and queue poisoning, and noisy-neighbor resource exhaustion effects.Expose Hidden Leaks: verify absolute data isolation where it silently breaks: background reports, data exports, search functions, file downloads, push notifications, system logs, backup restorations, and hard deletions.Verify Per-Client Audit and Observability: prove that telemetry, logs, and every human-approval event are separated and attributable to a single client, in line with our governance law of human control and traceability.Automate the Defense: transform every successful manual attack or vulnerability check into an automated test suite that runs on every code release.Audit and Document: draft, update, and maintain the official Data Isolation Audit Report.Mentor the School: train two internal QA interns on your isolation testing methodologies to prepare them for future deployments.What We RequireProven, hands-on experience in Web and API security testing.The ability to read, intercept, and manually modify network requests and payloads, for example Postman or Burp Suite.A deep, architectural understanding of Role-Based Access Control and multi-tenant systems.Strong proficiency in test automation frameworks.Impeccable, highly organized technical writing skills in English for audit reporting.A maniacal, detail-oriented methodology. You do not assume a system works, you prove it.The First 30 DaysDual-client test bench fully active and configured.Comprehensive list of attack vectors and edge cases mapped out.First end-to-end execution of the security suite completed.Version 1 of the Audit Report delivered to the CTO, highlighting any weak points and their severity.