Test Analyst
  • Sanlam
1 year before
31.12.2023
Protect and Defend
Cyber Defense Analysis
Job Description

Who are we?


Sanlam Group Technology is responsible for the provision of a digitally enabled technology service as a group COE, drive business and transformation and provide group-wide digital and data architecture. We operate the various technology platforms and shared services, ensure Cyber and Information Security resilience, and act as technology governance and risk orchestrator for technology across Sanlam.


What will you do?


The successful candidate will provide Test Analyst services to the Client Portal team as part of a squad in an agile release train.


What will make you successful in this role?

Analyse system and business specification to provide inputs and estimates
Liaising with business and or technical representatives to ensuring the highest quality outcomes
Integration impact test analysis
Defining the appropriate tests required
Gathering and managing the Test Data
Set up and adjust test plans for all types of testing (functional and non-functional testing)
Comprehensive documentation of test results according to standards
Perform defect logging and reporting
Post implementation production support (after care)
Identify and suggest areas for growth and improvement within the team
Systems or tools used to execute tasks:
Client Portal web, Unified Experience (UEX), Group Portfolio Management (GPM), Native mobile app for Sanlam Portfolio
Postman
Jira
Quality Centre
SQLSMS
Bamboo


Qualification


Successfully completed Grade 12
IT Degree advantageous
ISTQB CTAL Foundation Test Analyst Certificate or other relevant qualification


Experience

3-5 years working experience
Automated testing experience preferable
Working knowledge of:
webservices and back end scrutinisation
SQL
Integration and security testing
API testing
Understanding of:
Software quality and agile methodologies, tools and techniques (black box, white box and automated testing experience)
Agile methodologies (scrum)
SQL
Software failures and faults
Active participation in team to improve the testing process/define the team’s test strategy
Technical knowledge (HTML) and solid experience in WEB Application testing would be to your advantage
Testing experience of mainframe applications recommended
Experience in the financial services industry would be advantageous
Working knowledge of the following Testing Platforms:
API Testing (Postman,SoapUI)
SQL
Jira
Strong technical skills
Test Automation (Java, Selenium)


Build a successful career with us


We’re all about building strong, lasting relationships with our employees. We know that you have hopes for your future – your career, your personal development and of achieving great things. We pride ourselves in helping our employees to realise their worth. Through its four business clusters – Sanlam Life and Savings, Sanlam Investment Group, Sanlam Emerging Markets, Santam, as well as MiWay and the Group Office – the group provides many opportunities for growth and development.


Core Competencies


Cultivates innovation - Contributing independently


Customer focus - Contributing independently


Drives results - Contributing independently


Collaborates - Contributing independently


Being resilient - Contributing independently


Turnaround time


The shortlisting process will only start once the application due date has been reached. The time taken to complete this process will depend on how far you progress and the availability of managers.


Our commitment to transformation


The Sanlam Group is committed to achieving transformation and embraces diversity. This commitment is what drives us to achieve a diverse, inclusive and equitable workplace as we believe that these are key components to ensuring a thriving and sustainable business in South Africa. The Group's Employment Equity plan and targets will be considered as part of the selection process.


Quick response

Required Knowledge
  • K0001   Knowledge of computer networking concepts and protocols, and network security methodologies.
  • K0004   Knowledge of cybersecurity and privacy principles.
  • K0005   Knowledge of cyber threats an`d vulnerabilities.
  • K0007   Knowledge of authentication, authorization, and access control methods.
  • K0040   Knowledge of vulnerability information dissemination sources (e.g., alerts, advisories, errata, and bulletins).
  • K0060   Knowledge of operating systems.
  • K0061   Knowledge of how traffic flows across the network (e.g., Transmission Control Protocol [TCP] and Internet Protocol [IP], Open System Interconnection Model [OSI], Information Technology Infrastructure Library, current version [ITIL]).
  • K0070   Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, return-oriented attacks, malicious code).
  • K0301   Knowledge of packet-level analysis using appropriate tools (e.g., Wireshark, tcpdump).
  • K0339   Knowledge of how to use network analysis tools to identify vulnerabilities.

Required Skills
  • S0027   Skill in determining how a security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes.
  • S0057   Skill in using protocol analyzers.
  • S0063   Skill in collecting data from a variety of cyber defense resources.
  • S0147   Skill in assessing security controls based on cybersecurity principles and tenets. (e.g., CIS CSC, NIST SP 800-53, Cybersecurity Framework, etc.).
  • S0167   Skill in recognizing vulnerabilities in security systems. (e.g., vulnerability and compliance scanning).

Required Abilities
  • A0015  Ability to conduct vulnerability scans and recognize vulnerabilities in security systems.
  • A0123  Ability to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).