QA - Security Testing
BestQ · Bengaluru ·
- Category
- QA
- Experience
- 1+ years
BestQ · Bengaluru ·
Nucleus Labs · Europe
Millennium IT ESP · Colombo, Sri Lanka
Encrytpedge Labs Limited · St Lukes, Central London
TrustedSec · Remote - US Only
Compensation: ₹2L – ₹3L • No equity
About the Role We are looking for a detail-oriented QA Engineer – Security Testing with strong application security fundamentals to support a cloud-based security testing product. The role involves validating web and API vulnerabilities, ensuring accurate vulnerability detection, improving automated security testing capabilities, and collaborating closely with engineering teams to deliver reliable and secure products.
Key Responsibilities Design, execute, and maintain test cases for web and API security testing features Validate vulnerability findings, including identifying false positives and false negatives Perform functional, negative, regression, and stress testing Analyze test results, debug issues, and collaborate with developers for resolution Create and maintain test environments simulating real-world attack scenarios Support automated DAST and security testing workflows Contribute to improving test coverage, automation, and product reliability Document test cases, findings, and security validation reports
Required Skills & Experience 1–3 years of experience in application security, security testing, or penetration testing Strong understanding of common web vulnerabilities including SQL Injection (SQLi), XSS, CSRF, SSRF, etc. Good knowledge of OWASP Top 10 vulnerabilities and secure testing practices Hands-on experience with tools such as Burp Suite, Nmap, OWASP ZAP, or similar vulnerability scanners Basic scripting knowledge (preferably Python) Familiarity with Linux environments and command-line tools Strong analytical, debugging, and problem-solving skills Good communication and collaboration abilities
Nice to Have Knowledge of network protocols, APIs, and databases Experience with automated security testing or DAST tools Familiarity with CI/CD pipelines and DevSecOps practices Security certifications such as CEH, OSCP, Security+, or equivalent
What We Offer Opportunity to work on cutting-edge security testing products Collaborative and learning-focused environment Exposure to modern cloud and security technologies Career growth in cybersecurity and product quality engineering
Embark GCC · Pan - India, India