CareerPlanGet AI match score →

Qa Security Testing

💼 Full-time🗓 2026-07-30

Core

QA Engineer specializing in validating web and API vulnerabilities for a cloud-based security testing product.

Role type

QA Security Testing Engineer

Builds

Cloud-based security testing product

Domain

Cybersecurity / Application Security

Deliverable

production ML models | product features

Required skills

Application security fundamentals, Web vulnerability analysis (SQLi, XSS, CSRF, SSRF), OWASP Top 10 knowledge, Vulnerability scanning tools (Burp Suite, Nmap, OWASP ZAP), Linux command-line, Python scripting, Test case design and execution, Regression and stress testing, Debugging and issue resolution

Preferred skills

Network protocols knowledge, API and database familiarity, Automated security testing (DAST), CI/CD and DevSecOps practices

Technologies

Burp Suite, Nmap, OWASP ZAP, Python, Linux

Responsibilities

Design and maintain test cases for web and API security features, Validate vulnerability findings and identify false positives/negatives, Perform functional, negative, regression, and stress testing, Analyze results and collaborate with developers on resolutions, Create test environments simulating attack scenarios, Support automated DAST workflows, Document test cases and security validation reports

Seniority

Mid-level, hands-on IC

Rewrite
## About the Role We are looking for a detail-oriented QA Engineer – Security Testing with strong application security fundamentals to support a cloud-based security testing product. The role involves validating web and API vulnerabilities, ensuring accurate vulnerability detection, improving automated security testing capabilities, and collaborating closely with engineering teams to deliver reliable and secure products. ## Key Responsibilities - Design, execute, and maintain test cases for web and API security testing features - Validate vulnerability findings, including identifying false positives and false negatives - Perform functional, negative, regression, and stress testing - Analyze test results, debug issues, and collaborate with developers for resolution - Create and maintain test environments simulating real-world attack scenarios - Support automated DAST and security testing workflows - Contribute to improving test coverage, automation, and product reliability - Document test cases, findings, and security validation reports ## Required Skills & Experience - 1–3 years of experience in application security, security testing, or penetration testing - Strong understanding of common web vulnerabilities including SQL Injection (SQLi), XSS, CSRF, SSRF, etc. - Good knowledge of OWASP Top 10 vulnerabilities and secure testing practices - Hands-on experience with tools such as Burp Suite, Nmap, OWASP ZAP, or similar vulnerability scanners - Basic scripting knowledge (preferably Python) - Familiarity with Linux environments and command-line tools - Strong analytical, debugging, and problem-solving skills - Good communication and collaboration abilities ## Nice to Have - Knowledge of network protocols, APIs, and databases - Experience with automated security testing or DAST tools - Familiarity with CI/CD pipelines and DevSecOps practices - Security certifications such as CEH, OSCP, Security+, or equivalent ## What We Offer - Opportunity to work on cutting-edge security testing products - Collaborative and learning-focused environment - Exposure to modern cloud and security technologies - Career growth in cybersecurity and product quality engineering
Sourced via wellfound · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on Wellfound ↗