Application Testing Engineer

Quess

Chennai District, Bengaluru, Pune District

On-site

INR 700,000 - 1,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Quess is seeking an Application Tester with strong DevSecOps experience in Chennai. The role focuses on building secure software through CI/CD, SAST/DAST, and vulnerability management.

You will collaborate with development and security teams to implement secure coding practices and tooling. Candidates should have BE/B.Tech or MCA and at least 3 years in SAST, SCA, DAST, and DevSecOps, with knowledge of Windows/Linux/UNIX environments and major security standards.

Qualifications

  • Experience with scripting languages like Python, PowerShell, Java, or Perl.
  • 16K Familiarity with dynamic web application vulnerability scanning tools and services.

Responsibilities

  • Execute large-scale application security programs.
  • 2

Skills

Scripting
Vulnerability scanning
CI/CD pipelines
DevSecOps
Git tooling
OWASP Top 10

Education

BE/B.Tech/ MCA

Tools

Acunetix
BurpSuite
HP WebInspect
HCL AppScan
CheckMarx
Snyk
Fortify
Veracode
GitHub
GitLab
Bitbucket

Job description

Role - Application tester

Experience with scripting / programming skills (e.g., Python, PowerShell, Java, Perl etc.) updated and familiarized with the latest exploits and security trends.

Familiarity with dynamic web application vulnerability scanning tools and services (Acunetix, HP WebInspect, HCL AppScan, BurpSuite)

Familiarity with static code analysis tools and services (CheckMarx, Snyk, Fortify Static Code Analysis tool, Veracode, Coverity, IBM AppScan Source)

Experience in developing a DevSecOps CI/CD pipeline completely using open source tools.

Experience with SCM tools like Github, Gitlab, Bitbucket and their ability to integrated with CI/CD pipelines by using webhooks, actions, etc.

Experience with implementing different phases of CI/CD like secret scanning, SAST, SCA, DAST, Infrastructure as code, compliance as code, vulnerability management.

Optimizing the pipeline to produce the best results and ability to plan a maturity model for the DevSecOps program.

Understanding of web-based application vulnerabilities (OWASP Top 10).

Experience with scripting / programming skills (e.g., Python or PowerShell or Java or Perl etc.).

To qualify for the role, you must have

BE/ B.Tech/ MCA.

Minimum of 3 years of full-time work experience in SAST, SCA, DAST and DevSecOps.

Knowledge of Windows, Linux, UNIX, any other major operating systems.

Strong Excel and PowerPoint skills.

Ideally, you will also have

Familiarity with programming languages such as Java, JavaScript, Python and Angular

Strong knowledge of relevant Security Standards (OWASP) and how to apply them to the software development lifecycle in a large agile environment.

Experience performing security analysis on web applications and APIs.

Experience working in an Agile environment.

Key Responsibilities

Expertise In executing large scale application security programs

Expertise in Shift left security concept and security in DevOps

Understanding of agile software development principles and security practices

Convey complex technical security concepts to technical and non-technical audiences including executives.

Strong knowledge of software supply chain vulnerabilities and the ability to effectively communicate methodologies and techniques with development teams

Provide technical leadership and advise to junior team members on application security engagements.

Develop automated solutions that mitigate risks throughout the organization.

Support policies and vulnerability analysis using application security testing infrastructure including (SAST, DAST, SCA, IAST, and API Security)

Ensure these tools deliver maximum value for both security and developer stakeholders.

Support integration and automation efforts to ensure that security testing is an integral and painless part of code development.

Partner with and train developers in how to deliver secure code.

Track, prioritize and drive remediation of code vulnerabilities.

Develop and foster effective working relationships within both Security and IT teams to ensure that projects are delivered securely and on-time.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Basebiz • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Application Security Engineer
Application Security Engineer

Basebiz • Chennai District

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

Basebiz • Pune District

On-site
INR 1,800,000 - 3,000,000
Application Security Testing Engineer
Application Security Testing Engineer

Infosys • Bengaluru

On-site
INR 900,000 - 1,200,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Application Security Manager
Application Security Manager

Coventine Digital • Chennai District, Bengaluru, Pune District

On-site
INR 3,000,000 - 6,000,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Application Security Engineer
Application Security Engineer

Cyberpwn • Bengaluru

On-site
INR 900,000 - 1,300,000
Security Testing Engineer
Security Testing Engineer

Infosys • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Group • Ahmedabad District

On-site
INR 2,800,000 - 4,200,000