Security Testing Engineer
Infosys · State of Karnataka, India
Infosys · State of Karnataka, India
## **Job Description:** - We are seeking a highly skilled Automation Security Test Engineer with 3 years of experience in test automation and application security testing - The ideal candidate should possess strong expertise in Selenium Automation using Java or C test framework development CI CD integration and security testing methodologies including vulnerability assessment and DAST - Experience in secure application testing and quality engineering practices is highly desirable ## **Key Responsibilities:** - Key Responsibilities - Automation Testing - Design develop and maintain automation frameworks using Selenium WebDriver with Java or C - Develop and execute automated test scripts for Web API and Enterprise applications - Build reusable automation libraries and utilities - Integrate automation suites with CI CD pipelines - Perform regression smoke sanity and functional testing using automated frameworks - Analyze test results and provide detailed defect reports - Collaborate with developers business analysts and QA teams to ensure quality deliverables - Participate in test planning estimation and test strategy discussions - Security Testing - Perform comprehensive Security Testing and Assessment activities across applications APIs cloud environments and supporting infrastructure - Execute Dynamic Application Security Testing DAST Vulnerability Assessments and Security Validation activities using industry standard tools and methodologies - Conduct manual and automated security testing to identify vulnerabilities related to authentication authorization session management encryption access controls and business logic flaws - Assess applications against industry standards and frameworks such as OWASP Top 10 OWASP API Security Top 10 CWE NIST and SANS - Identify analyze prioritize and document security vulnerabilities with detailed risk ratings business impact analysis and remediation guidance - Perform false positive analysis vulnerability validation and retesting to verify remediation effectiveness - Collaborate closely with Development Architecture QA and DevSecOps teams to promote secure coding practices and integrate security into the Software Development Life Cycle SDLC - Perform security reviews threat assessments and risk based security evaluations for new and existing applications - Participate in vulnerability management activities including triage tracking risk acceptance reviews and remediation validation - Prepare detailed security assessment reports and effectively communicate findings risks and recommendations to technical and non technical stakeholders - Conduct false positive analysis and provide remediation recommendations - Validate authentication authorization session management encryption and access control mechanisms - Support compliance initiatives and security governance requirements ## **Technical Requirements:** - 3 years of experience in Application Security Testing Vulnerability Assessment and Security Validation - Strong hands on experience with DAST tools such as Burp Suite Pro HCL AppScan Acunetix Netsparker or equivalent - Solid understanding of Web API and Cloud Security concepts - Knowledge of OWASP Top 10 OWASP API Security Top 10 CVSS CWE and Secure SDLC practices - Experience in vulnerability reporting risk analysis remediation validation and stakeholder communication - Understanding of authentication protocols such as OAuth 2 - 0 OpenID Connect OIDC SAML JWT and MFA - Experience with Cloud Security Azure AWS GCP and container security assessments - Exposure to SAST SCA OSS Security Testing API Security Testing and Threat Modeling methodologies ## **Additional Responsibilities:** - Preferred Skills - Experience in IAM Security Testing Saviynt SailPoint Access Governance testing - Exposure to Performance Testing tools such as JMeter or LoadRunner - Experience working in DevSecOps environments - Knowledge of container technologies such as Docker and Kubernetes - Scripting knowledge in Python PowerShell or Shell scripting ## **Preferred Skills:** Technology->Security Testing->Security Testing - ALL,Technology->Testing Technologyes->Test Automation Technology,Technology->Java->Core Java,Technology->Automated Testing->Selenium-Java