Job Description:
Role: QA Security Engineer
Exp: 4+ Years
Employment Type: C2H
NP: Immediate
Location: Bangalore/Hyderabad/Pune/Mumbai
Job Description
Role Summary
We are looking for a QA Security Engineer with strong application security testing expertise to validate and strengthen the security posture of Microsoft Fabric environments. The role focuses on hands-on security testing, access control validation, and collaboration with DevSecOps teams to ensure secure data platforms and compliant CI/CD pipelines.
Key Responsibilities
- Perform manual and automated security testing across Microsoft Fabric components, including workspaces, data assets, and RBAC configurations.
- Validate authentication and authorization mechanisms, including:
- Role-Based Access Control (RBAC)
- Row-Level Security (RLS)
- Object-Level Security (OLS)
- Column-Level Security (CLS)
- Assess data security controls, including encryption at rest and in transit.
- Identify, analyze, and report security vulnerabilities aligned with OWASP and SANS guidelines.
- Collaborate with DevSecOps teams to integrate security checks into CI/CD pipelines.
- Support regulatory and compliance requirements, including GDPR, CCPA, and ISO 27001.
- Prepare detailed security defect reports, including risk ratings, impact analysis, and actionable remediation guidance.
- Participate in security reviews, threat modeling, and continuous security improvement initiatives.
Must-Have Skills
- Strong experience in Application Security / QA Security Testing.
- Hands-on knowledge of OWASP Top 10 and SANS secure coding practices.
- Proficiency in Python scripting and PySpark for security validation and automation.
- Solid understanding of Microsoft Fabric security model, including:
- Workspace security
- RBAC implementation
- Data access controls
- Familiarity with Microsoft Purview for data governance, classification, and compliance.
- Experience validating identity, access management, and data protection controls.
- Strong documentation and communication skills for security reporting.
Nice to Have
- Experience with security testing tools (SAST, DAST, SCA).
- Exposure to cloud security (Azure security services preferred).
- Knowledge of DevSecOps tools and CI/CD platforms.
- Certifications such as CEH, GWAPT, CSSLP, or equivalent AppSec certifications.