QA Engineer, Security and Multi-Tenant Isolation - Elchai Group

🏢 elchai group
📍 United Arab EmiratesFull-timeOn-site
📅 Posted: 4d ago🔄 Updated: 4d ago
CV%
✨ AI Summary
Elchai Group is seeking a QA Engineer specializing in Security and Multi-Tenant Isolation to join their team in Dubai. The primary responsibility is to ensure absolute data isolation between clients on their AI Governance Orchestration platform, delivering signed audit reports for enterprise deployment. This role involves building and maintaining a dual-client testing environment, actively testing for security vulnerabilities, verifying data isolation across various functions, and ensuring per-client auditability. The position also requires automating successful manual attacks into test suites and documenting findings. The company is looking for candidates with proven experience in web and API security testing, understanding of multi-tenant systems and RBAC, proficiency in test automation, and excellent technical writing skills.
Required Skills
Information Technology
Security TestingTest Automation
Engineering, Construction & Trades
ATS Systems
Other
Role-Based Access Control
Requirements
The ideal candidate will have proven, hands-on experience in Web and API security testing, with the ability to intercept and modify network requests (e.g., using Postman or Burp Suite). A deep architectural understanding of Role-Based Access Control and multi-tenant systems is essential, along with strong proficiency in test automation frameworks. Impeccable, highly organized technical writing skills in English are required for audit reporting, along with a maniacal, detail-oriented methodology.
Description
QA Engineer, Security and Multi-Tenant IsolationLocation: On-site, in DubaiAgent Workflow and Permissions Engineer, Gateway Engineer.The MissionWe are building a highly advanced, centralized AI Governance Orchestration platform. As our Security and Isolation QA, your mission is singular and critical: to prove with repeatable, documented evidence that one client's data can never be accessed by another. Your ultimate deliverable is a signed, unassailable audit report that authorizes our deployment to our first paying enterprise client.What You Will DoBuild the Bench: construct and maintain a permanent dual-client testing environment with strictly segregated users, roles, and databases.Attack the Boundaries: deliberately attack the boundaries between clients across all access points, not just the graphical interface.Vulnerability Hunting: test aggressively for resource ID manipulation, cross-tenant token and ID injection, privilege escalation, cache and queue poisoning, and noisy-neighbor resource exhaustion effects.Expose Hidden Leaks: verify absolute data isolation where it silently breaks: background reports, data exports, search functions, file downloads, push notifications, system logs, backup restorations, and hard deletions.Verify Per-Client Audit and Observability: prove that telemetry, logs, and every human-approval event are separated and attributable to a single client, in line with our governance law of human control and traceability.Automate the Defense: transform every successful manual attack or vulnerability check into an automated test suite that runs on every code release.Audit and Document: draft, update, and maintain the official Data Isolation Audit Report.Mentor the School: train two internal QA interns on your isolation testing methodologies to prepare them for future deployments.What We RequireProven, hands-on experience in Web and API security testing.The ability to read, intercept, and manually modify network requests and payloads, for example Postman or Burp Suite.A deep, architectural understanding of Role-Based Access Control and multi-tenant systems.Strong proficiency in test automation frameworks.Impeccable, highly organized technical writing skills in English for audit reporting.A maniacal, detail-oriented methodology. You do not assume a system works, you prove it.The First 30 DaysDual-client test bench fully active and configured.Comprehensive list of attack vectors and edge cases mapped out.First end-to-end execution of the security suite completed.Version 1 of the Audit Report delivered to the CTO, highlighting any weak points and their severity.
✨ Premium Match Details
Deep-dive CV analysis, customized Cover Letters, and Interview prep!
📊 Match Analysis
Insights against your active CV
📊
Personalized Match Analysis
Upload your CV to see exact matching percentages, detailed skills mapping, and gap analysis for this role.
🎯 Overalli74%
⚡ Skillsi85%
View Breakdown
Ontology Match: 85.0
Matched:✓ Requirements Matching✓ Ontology Skills Mapping
📜 Eligibilityi49%
View Breakdown
Local: 19600%
🏗️ Career Fiti91%
View Breakdown
Seniority: 91.0
📋 Requirementsi67%
View Breakdown
Domain: 67.0
🔥 Motivationi78%
View Breakdown
Title Fit: 78.00