Security Test Engineer
- πΊπΈ United States
- Hybrid
- 9 hours ago
- Devops
- SQL Injection
- XSS
- CSRF
- RBAC
- JWT
- OAuth
- Threat Modeling
- CI/CD
- Jira
- OWASP
- Burp Suite
- OWASP ZAP
- Postman
- Nessus
- Nmap
- Wireshark
- Metasploit
- SonarQube
- Snyk
- Trivy
- Java
- Python
- JavaScript
- Selenium
- Playwright
- Bash
- SOAP
- JSON
- XML
- SQL
- DevSecOps
- SAST
- DAST
- Docker
- Kubernetes
- CEH
- OSCP
- Penetration Testing
- CISSP
- REST API
- Git
- Jenkins
Security Test Engineer β Job Description
Job Title
Security Test Engineer / Application Security Test Engineer
Job Summary
We are looking for a Security Test Engineer to identify, validate, and report security vulnerabilities in web applications, APIs, mobile applications, and enterprise systems. The role involves security testing throughout the SDLC and working with development, QA, DevOps, and security teams to improve application security.
Key Responsibilities
- Analyze requirements and identify security testing scenarios.
- Create security test plans, test cases, and test data.
- Perform Web Application Security Testing.
- Perform API Security Testing.
- Perform mobile application security testing when required.
- Identify vulnerabilities such as:
- SQL Injection
- Cross-Site Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- Broken Authentication
- Broken Authorization
- IDOR
- Session management issues
- Security misconfiguration
- Sensitive data exposure
- File-upload vulnerabilities
- Perform authentication and authorization testing.
- Validate role-based access control (RBAC).
- Test JWT, OAuth, cookies, sessions, and access tokens.
- Perform vulnerability scanning and security assessments.
- Analyze application logs and security findings.
- Reproduce and validate reported vulnerabilities.
- Perform regression security testing after vulnerabilities are fixed.
- Collaborate with developers to understand and remediate security defects.
- Prepare security test reports and vulnerability documentation.
- Participate in threat modeling and risk assessment.
- Integrate security testing into CI/CD pipelines.
- Track vulnerabilities using JIRA or security-management tools.
- Follow OWASP and organizational security standards.
Security Testing Areas
1. Authentication
- Valid/invalid credentials
- Password policy
- Account lockout
- MFA
- Session timeout
- Password reset
- Token expiration
2. Authorization
- Horizontal privilege escalation
- Vertical privilege escalation
- Role-based access
- Unauthorized API access
- IDOR
3. Input Validation
- SQL Injection
- XSS
- Command injection
- Path traversal
- Malicious file uploads
4. API Security
- Authentication
- Authorization
- Token validation
- Rate limiting
- Input validation
- Sensitive information exposure
- API abuse scenarios
Tools
Common tools include:
- Burp Suite
- OWASP ZAP
- Postman
- Nessus
- Nmap
- Wireshark
- Metasploit
- SonarQube
- Snyk
- Trivy
- Checkmarx
- Fortify
Automation / Programming
Knowledge of one or more:
- Java
- Python
- JavaScript
- Selenium / Playwright
- REST Assured
- Bash/Shell scripting
Security automation can include:
CI/CD β Security Scan β Automated Security Tests β Vulnerability Report β Quality/Security Gate β Deployment
API & Database Skills
- REST/SOAP APIs
- HTTP/HTTPS
- JSON/XML
- HTTP headers
- Cookies
- JWT
- OAuth 2.0
- SQL
- Database security basics
DevSecOps Knowledge
Good understanding of:
- Secure SDLC
- CI/CD
- SAST
- DAST
- SCA
- Container security
- Dependency vulnerability scanning
- Secrets scanning
- Security gates
- Docker/Kubernetes security basics
Certifications β Good to Have
- Security+
- CEH
- eJPT
- OSCP β advanced penetration testing
- CISSP β generally for experienced security professionals
Experience
| Experience | Typical Role |
|---|---|
| 0β2 years | Junior Security Test Engineer |
| 2β5 years | Security Test Engineer |
| 5β8 years | Senior Security Test Engineer |
| 8+ years | Security Testing Lead / Security Architect |
Resume Keywords
Security Testing | Application Security | Web Security | API Security | OWASP | OWASP Top 10 | Burp Suite | OWASP ZAP | SQL Injection | XSS | CSRF | IDOR | Authentication | Authorization | JWT | OAuth | SAST | DAST | SCA | DevSecOps | CI/CD | Vulnerability Assessment | Penetration Testing | REST API | Postman | Python | Java | Git | Jenkins
Security Test Engineer Β· Ova Technologies