Senior Security Test Engineer (Bengaluru)

Senior Security Test Engineer (Bengaluru)

24 Sep
|
Commergence
|
Bengaluru

24 Sep

Commergence

Bengaluru

– Senior Security Test Engineer

Experience: 5–8 Years

Role Level: Senior Engineer / Specialist

Primary Focus: Application Security, Vulnerability Assessment & Penetration Testing (VAPT),

Security Testing

Technology Focus: Adobe Experience Manager (AEM), Edge Delivery Services (EDS), Adobe

Commerce, Web Applications, APIs & Integrations

Role Overview

We are looking for a hands-on Senior Security Test Engineer / Application Security Specialist to support the delivery of security testing services for enterprise digital applications and platforms.

The individual will work closely with the Security Testing Architect / Lead, application architects,

developers, QA engineers, infrastructure teams, and customer stakeholders to execute comprehensive security assessments across web applications, APIs, integrations, and Adobe Digital

Experience solutions.

This is primarily a hands-on technical role requiring strong expertise in vulnerability assessment,

manual penetration testing, security testing tools, vulnerability analysis, reporting, and remediation validation.

The successful candidate should be capable of independently executing security assessments,

investigating potential vulnerabilities beyond automated scanner results, documenting findings with appropriate evidence, and providing practical remediation recommendations.

A key focus will be security testing for enterprise implementations involving Adobe Experience

Manager (AEM), Adobe Edge Delivery Services (EDS), Adobe Commerce, web applications, APIs, and associated integrations.

Key Responsibilities

Vulnerability Assessment & Penetration Testing

- Execute end-to-end Vulnerability Assessment and Penetration Testing (VAPT) for enterprise web applications, APIs, digital platforms, and integrations.
- Perform automated vulnerability scanning followed by manual validation and deep-dive penetration testing.
- Identify security vulnerabilities across authentication, authorization, access control, session management, input validation, application configuration, APIs, and business logic.
- Perform security testing based on industry-standard frameworks and methodologies such as:

o OWASP Top 10

o OWASP Web Security Testing Guide (WSTG)

o OWASP API Security Top 10

o CWE o CVSS

- Investigate vulnerabilities to determine exploitability, severity, technical impact, and potential business impact.
- Validate automated scanner findings and eliminate false positives.
- Perform manual testing to identify vulnerabilities and business-logic issues that may not be detected through automated scanning.
- Conduct remediation verification and re-testing after vulnerabilities have been addressed.

Hands-on Security Testing The candidate will be expected to perform hands-on testing across areas including:

- Authentication and authorization
- Broken access control
- Privilege escalation
- Session management
- Injection vulnerabilities
- Cross-Site Scripting (XSS)
- Server-Side Request Forgery (SSRF)
- Cross-Site Request Forgery (CSRF)
- Insecure Direct Object References (IDOR)
- API security vulnerabilities
- Sensitive data exposure
- Security misconfigurations
- File upload and input-validation vulnerabilities
- HTTP/security header configuration
- TLS and transport security
- REST and GraphQL APIs
- Application and integration endpoints
- Business logic vulnerabilities The candidate should understand how vulnerabilities can be chained together and should be capable of going beyond checklist-driven or scanner-only security testing.

Adobe Digital Experience Security Testing

Perform security testing for enterprise implementations involving:

- Adobe Experience Manager (AEM)
- Adobe Edge Delivery Services (EDS)
- Adobe Commerce
- Enterprise websites and digital portals
- REST/GraphQL APIs and web services
- Third-party and internal integrations
- Authentication, authorization, SSO, and identity integrations
- Cloud-hosted and hybrid application environments

Prior experience with Adobe technologies is desirable but not mandatory. Candidates with strong security testing experience across enterprise CMS, e-commerce,



or comparable web platforms should be able to develop the required Adobe-specific expertise.

Security Testing Tools

Strong hands-on experience with the following tools or equivalent technologies is expected:

Primary Tools

- Burp Suite Professional
- Kali Linux
- OWASP ZAP
- Nmap
- Relevant open-source penetration testing and security assessment utilities

Desirable Enterprise Tool Experience

- HCL AppScan
- OpenText Fortify / Fortify WebInspect
- Invicti / Acunetix
- Qualys
- Tenable / Nessus
- Other SAST, DAST, SCA, or vulnerability management platforms The candidate should understand how to configure and use security testing tools effectively rather than simply executing default scans.

Vulnerability Analysis & Reporting

- Analyze identified vulnerabilities and determine their validity, exploitability, and risk.
- Assign appropriate severity ratings using frameworks such as CVSS, while considering customer-specific business impact.
- Capture appropriate technical evidence, including request/response details, screenshots,

logs, and proof-of-concept information where required.

- Document clear and reproducible steps for validated vulnerabilities.
- Prepare professional security assessment and penetration testing reports.
- Provide practical and technically actionable remediation recommendations.
- Maintain appropriate handling and confidentiality of sensitive vulnerability information.
- Participate in vulnerability review and triage sessions with engineering and customer teams.
- Track identified vulnerabilities through remediation and closure.
- Perform re-testing and document remediation status.

Security Testing Delivery

- Work under the guidance of the Security Testing Architect / Lead to execute security testing engagements.
- Understand customer requirements, application architecture, testing scope, and security assessment objectives.
- Prepare testing prerequisites, test plans, checklists, test data, and required environments.
- Execute assigned security assessments independently and within agreed timelines.
- Escalate critical and high-risk vulnerabilities promptly to the Security Testing Architect / Lead.
- Maintain high-quality testing documentation and evidence.
- Contribute to reusable security testing checklists, methodologies, templates, scripts, and accelerators.
- Support continuous improvement of the organization's security testing service offering.
- Collaborate with other security engineers and contribute to peer reviews of vulnerabilities and reports.

Collaboration & Remediation Support

- Work closely with application developers, QA engineers, architects, DevOps teams,

infrastructure teams, and security stakeholders.

- Explain identified vulnerabilities and associated risks to engineering teams.
- Assist developers in understanding the root cause of security issues.
- Recommend appropriate mitigation and remediation approaches.
- Support teams in validating security fixes.
- Participate in security review meetings, vulnerability triage sessions, and customer discussions as required.
- Promote secure development and shift-left security practices within delivery teams.

Required Skills & Experience

- 5–8 years of experience in cybersecurity, application security, penetration testing, security testing, or related areas.
- Robust hands-on experience in web application Vulnerability Assessment and Penetration

Testing (VAPT).

- Strong practical knowledge of web application and API security.
- Experience conducting both automated vulnerability scanning and manual penetration testing.
- Strong understanding of:

o OWASP Top 10

o OWASP API Security Top 10

o OWASP WSTG o CWE o CVE o CVSS

- Strong hands-on experience with Burp Suite Professional, Kali Linux, and OWASP ZAP or comparable tools.




- Ability to manually validate vulnerabilities and identify false positives.
- Understanding of HTTP/HTTPS, cookies, sessions, browser security mechanisms, REST APIs,

GraphQL, authentication, and authorization mechanisms.

- Experience testing modern enterprise web applications and integrations.
- Ability to analyze security findings and provide appropriate remediation recommendations.
- Strong security assessment documentation and report-writing skills.
- Good analytical, troubleshooting, and problem-solving capabilities.
- Ability to work independently while operating within the security testing methodology defined by the Security Testing Architect / Lead.

Preferred Skills

- Security testing experience with Adobe Experience Manager (AEM), Adobe Edge Delivery

Services (EDS), and/or Adobe Commerce.

- Experience with enterprise CMS, digital experience, or e-commerce platforms.
- Experience testing REST and GraphQL APIs.
- Familiarity with modern authentication technologies such as OAuth 2.0, OpenID Connect,

SAML, SSO, and JWT.

- Familiarity with cloud platforms such as AWS, Azure, or Google Cloud.
- Understanding of CI/CD pipelines and DevSecOps practices.
- Experience with SAST, DAST, SCA, secrets scanning, and vulnerability management technologies.
- Basic understanding of threat modeling and secure architecture principles.
- Scripting knowledge using Python, Bash, PowerShell, or similar technologies would be advantageous.
- Experience working in customer-facing consulting, professional services, or enterprise delivery environments.

Preferred Certifications

One or more security certifications would be desirable, such as:

- OSCP – Offensive Security Certified Professional
- CEH – Certified Ethical Hacker
- eJPT / eCPPT or equivalent practical penetration testing certifications
- GIAC security certifications
- CREST penetration testing certifications
- Other recognized application security, ethical hacking, or penetration testing certifications

Practical hands-on penetration testing capability will be an important consideration in addition to certifications.

Key Competencies The ideal candidate should demonstrate:

- Strong hands-on security testing skills
- Curiosity and an attacker's mindset
- Ability to investigate beyond automated scanner findings
- Strong attention to detail
- Ability to differentiate genuine vulnerabilities from false positives
- Good understanding of application architecture and web technologies
- Strong technical documentation and reporting skills
- Ability to clearly communicate vulnerabilities and remediation recommendations
- Strong collaboration and teamwork
- Ability to manage assigned assessments independently
- Willingness to continuously learn new attack techniques, tools, platforms, and technologies
- Strong ownership and accountability for assigned security testing activities

Expected Outcomes The Senior Security Test Engineer / Application Security Specialist will be expected to:

1.

Execute high-quality VAPT assessments across web applications, APIs, Adobe solutions, and enterprise integrations.

- Perform both automated and deep-dive manual security testing rather than relying solely on vulnerability scanners.
- Identify, validate, risk-rate, document, and communicate security vulnerabilities with appropriate technical evidence.
- Produce clear, professional, and customer-ready security assessment reports.
- Provide practical remediation recommendations and work with engineering teams through vulnerability closure.
- Perform re-testing to validate remediation and ensure identified vulnerabilities have been appropriately addressed.

7.

Support the Security Testing Architect / Lead in executing multiple customer security testing engagements.

- Contribute reusable test cases, methodologies, scripts, checklists, templates, and security testing accelerators.
- Build expertise in security testing of AEM, EDS, Adobe Commerce, APIs, and enterprise digital experience implementations.
- Contribute to the continuous improvement and scaling of the organization's Security Testing

/ VAPT service offering.

📌 Senior Security Test Engineer (Bengaluru)
🏢 Commergence
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior security test engineer (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: senior security test engineer (bengaluru) / bengaluru