Hiring Security Testing Engineer
# Hiring Security Testing Engineer **Haparz** · Bangalore City, Bengaluru, Karnataka · `On-site` 🕒 **Статус:** *Опубликовано: сегодня* · *Источник: Indeed* --- ### About the Role Security Testing Engineer Experience: 5+ Years Location: Chennai / Bangalore / Hyderabad / Pune / Gurgaon Work Mode: Hybrid – 3 Days WFO Work Time: 2:00 PM – 11:00 PM IST Payroll: Haparz Budget: Up to 19 LPA Notice Period: Immediate / Short Notice Preferred Role Overview We are looking for an experienced Security Testing Engineer with strong hands-on experience in application security testing, vulnerability assessment, penetration testing, and security automation. The candidate will work closely with development and DevOps teams to identify security vulnerabilities, improve application security, and integrate security checks into CI/CD pipelines. The ideal candidate should have practical experience with tools such as Black Duck, OWASP ZAP, Fortify, and Veracode , along with a solid understanding of OWASP security practices, SAST, DAST, vulnerability management, and secure coding principles. What You'll Do Design and execute security testing strategies for enterprise applications covering vulnerabilities, threats, and security risks. Perform application vulnerability assessments and penetration testing across web applications and APIs. Use Black Duck to identify open-source component vulnerabilities, license risks, and dependency-related security issues. Perform web application security testing using OWASP ZAP Proxy and analyze vulnerabilities identified during testing. Use Fortify for Static Application Security Testing (SAST) and support remediation of code-level security vulnerabilities. Work with Veracode for automated application security analysis and vulnerability reporting. Integrate SAST, DAST, and software composition analysis into CI/CD and DevSecOps pipelines . Review security findings with development teams and provide practical recommendations for remediation. Develop and maintain security test plans, test cases, scripts, reports, and supporting documentation. Track security vulnerabilities through remediation and perform validation/retesting of fixes. Monitor security testing results and provide actionable insights to engineering and security stakeholders. Support security audits and compliance activities by maintaining appropriate testing evidence and documentation. Stay updated with emerging application security threats, vulnerabilities, tools, and testing methodologies. Technical Expectations Strong understanding of application security testing and vulnerability assessment . Hands-on experience with Black Duck, OWASP ZAP, Fortify, and Veracode . Practical knowledge of SAST, DAST, SCA, penetration testing, and vulnerability management . Good understanding of OWASP Top 10 and common web application/API vulnerabilities. Experience integrating security testing tools into DevOps/CI/CD environments . Understanding of secure coding principles and vulnerability remediation. Knowledge of security testing documentation and reporting standards. Familiarity with security frameworks such as OWASP and NIST . Ability to work with development, QA, DevOps, and security teams in an Agile environment. Good to Have Exposure to container security tools such as Aqua or Twistlock . Experience with security testing across AWS, Azure, or GCP environments. Knowledge of threat modeling and risk assessment . Scripting experience using Python or Bash for security-test automation. Experience implementing SAST/DAST/SCA controls within DevSecOps pipelines. Security certifications such as CEH, OSCP, CSSLP , or equivalent are an advantage. Work Location: Hybrid remote in Bangalore City, Bengaluru, Karnataka
Наблюдалась 2026-09-15, впервые 2026-09-15, источник — Indeed.