Security Test Engineer - Job DescriptionJob Title Security Test Engineer / Application Security Test Engineer
Job Summary We are looking for a Security Test Engineer to identify, validate, and report security vulnerabilities in web applications, APIs, mobile applications, and enterprise systems. The role involves security testing throughout the SDLC and working with development, QA, DevOps, and security teams to improve application security.
Key Responsibilities - Analyze requirements and identify security testing scenarios.
- Create security test plans, test cases, and test data.
- Perform Web Application Security Testing.
- Perform API Security Testing.
- Perform mobile application security testing when required.
- Identify vulnerabilities such as:
- SQL Injection
- Cross-Site Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- Broken Authentication
- Broken Authorization
- IDOR
- Session management issues
- Security misconfiguration
- Sensitive data exposure
- File-upload vulnerabilities
- Perform authentication and authorization testing.
- Validate role-based access control (RBAC).
- Test JWT, OAuth, cookies, sessions, and access tokens.
- Perform vulnerability scanning and security assessments.
- Analyze application logs and security findings.
- Reproduce and validate reported vulnerabilities.
- Perform regression security testing after vulnerabilities are fixed.
- Collaborate with developers to understand and remediate security defects.
- Prepare security test reports and vulnerability documentation.
- Participate in threat modeling and risk assessment.
- Integrate security testing into CI/CD pipelines.
- Track vulnerabilities using JIRA or security-management tools.
- Follow OWASP and organizational security standards.
Security Testing Areas 1. Authentication
- Valid/invalid credentials
- Password policy
- Account lockout
- MFA
- Session timeout
- Password reset
- Token expiration
2. Authorization
- Horizontal privilege escalation
- Vertical privilege escalation
- Role-based access
- Unauthorized API access
- IDOR
3. Input Validation
- SQL Injection
- XSS
- Command injection
- Path traversal
- Malicious file uploads
4. API Security
- Authentication
- Authorization
- Token validation
- Rate limiting
- Input validation
- Sensitive information exposure
- API abuse scenarios
Tools Common tools include:
- Burp Suite
- OWASP ZAP
- Postman
- Nessus
- Nmap
- Wireshark
- Metasploit
- SonarQube
- Snyk
- Trivy
- Checkmarx
- Fortify
Automation / Programming Knowledge of one or more:
- Java
- Python
- JavaScript
- Selenium / Playwright
- REST Assured
- Bash/Shell scripting
Security automation can include:
CI/CD 12 Security Scan 12 Automated Security Tests 12 Vulnerability Report 12 Quality/Security Gate 12 Deployment
API & Database Skills - REST/SOAP APIs
- HTTP/HTTPS
- JSON/XML
- HTTP headers
- Cookies
- JWT
- OAuth 2.0
- SQL
- Database security basics
DevSecOps Knowledge Good understanding of:
- Secure SDLC
- CI/CD
- SAST
- DAST
- SCA
- Container security
- Dependency vulnerability scanning
- Secrets scanning
- Security gates
- Docker/Kubernetes security basics
Certifications - Good to Have - Security+
- CEH
- eJPT
- OSCP - advanced penetration testing
- CISSP - generally for experienced security professionals
Experience Experience Typical Role 0-2 years Junior Security Test Engineer 2-5 years Security Test Engineer 5-8 years Senior Security Test Engineer 8+ years Security Testing Lead / Security Architect
Resume Keywords Security Testing | Application Security | Web Security | API Security | OWASP | OWASP Top 10 | Burp Suite | OWASP ZAP | SQL Injection | XSS | CSRF | IDOR | Authentication | Authorization | JWT | OAuth | SAST | DAST | SCA | DevSecOps | CI/CD | Vulnerability Assessment | Penetration Testing | REST API | Postman | Python | Java | Git | Jenkins