01 Oct
|
Cyber1Armor
|
India
Sr. Security Test Engineer
Location- Remote
Key Responsibilities
- Perform application penetration testing, with focus on authentication and session management.
- Develop abuse cases, security scenarios, and automated end-to-end journeys.
- Lead security testing for regulated, customer-facing systems, including traceability and evidence management.
- Support UAT, security workshops, defect management, and stakeholder engagement.
- Execute functional, regression, performance, accessibility, and security testing.
- Design and execute passcode/OTP security tests, including entropy, randomness, concurrency, timing, and telemetry validation.
Required Skills & Experience
- 6+ years in application penetration testing or security test engineering.
- 4+ years hands-on functional, regression, performance, and accessibility testing.
- OSCP, GWAPT, CREST, or equivalent demonstrable experience.
- Solid Burp Suite Professional skills (Repeater, Intruder, Sequencer, Comparer, macros/session handling),
plus OWASP ZAP and ffuf/wfuzz.
- Experience with Playwright/Selenium, C#/Java/TypeScript and API automation using REST Assured/RestSharp.
- Experience with xUnit/NUnit/JUnit 5/TestNG and Page Object or equivalent frameworks.
- Automated email/passcode validation using MailHog, Mailtrap, smtp4dev, or provider APIs/IMAP.
- Performance testing using JMeter, k6, or Gatling, including correlation, parameterisation, think-time and volume-profile modelling.
- Accessibility testing using axe, WAVE/Lighthouse, NVDA/JAWS/VoiceOver, with strong WCAG 2.2 AA knowledge.
- Experience with Azure DevOps Test Plans, Xray, Zephyr, or TestRail, including requirements traceability and defect management.
- Scripting skills in Python or JavaScript/TypeScript, plus Bash or PowerShell.
- Strong knowledge of OWASP WSTG (ATHN/SESS), OWASP ASVS, and WCAG 2.2 AA.
📌 Sr. Security Test Engineer (India)
🏢 Cyber1Armor
📍 India