Job Title: QA Security Engineer
Experience Required: Minimum 3 Years
Location: Mohali (work from office)
Employment Type: Full-Time
Position Overview
We are seeking a skilled and detail-oriented Security Testing Engineer with proven expertise in Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) for mobile (Android/iOS) and web applications. The ideal candidate will have hands-on experience in identifying, validating, and remediating vulnerabilities across multiple platforms, working closely with development and QA teams in a global, multi-market environment.
Key Responsibilities
Application Security Testing
- Conduct SAST and DAST on various API versions for mobile (Android/iOS) and web applications.
- Perform backend code testing (SAST) to identify security vulnerabilities and risks.
- Retest vulnerabilities reported by external sources and validate fixes.
- Perform security testing on critical features/modules across platforms such as Mobile, Web, and KIOSK.
Collaboration & Compliance
- Work closely with development and QA teams across multiple countries to ensure adherence to security standards.
- Document all security findings, prepare detailed reports, and recommend remediation steps.
- Integrate security testing into the CI/CD pipeline for proactive vulnerability detection.
Research & Continuous Improvement
- Stay updated on emerging security threats, vulnerabilities, and trends relevant to mobile and web platforms.
Required Skills & Qualifications
- Minimum 3 years of experience in security testing, with a focus on SAST and DAST for mobile (Android/iOS) and web applications.
- Hands-on experience testing backend code using SAST tools.
- Experience working in multi-market, multi-country environments.
- Proficiency with tools such as Burp Suite, OWASP ZAP, Fortify, Checkmarx, or similar.
- Strong knowledge of mobile app security testing methodologies and tools.
- Understanding of Single Sign-On (SSO) security principles and testing.
- Experience testing APIs and backend services using both SAST and DAST.
- Knowledge of encryption, data protection, and secure coding practices.
- Strong communication and collaboration skills for working with cross-functional, global teams.