Security Testing Engineer

Infosys

Bengaluru

On-site

INR 1,200,000 - 1,800,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Infosys Quality Engineering in Bengaluru seeks an experienced Application Security Tester to strengthen web, API, and cloud security across enterprise applications.

You will perform DAST/VA, implement secure SDLC practices, collaborate with DevSecOps, and help drive remediation through detailed risk reports.

A strong background in OWASP Top 10, OAuth/OpenID, and recent cloud security work is required, with 3+ years in security testing.

Qualifications

  • 3+ years of experience in Application Security Testing, Vulnerability Assessment, and Security Validation.
  • Hands-on experience with DAST tools such as Burp Suite Pro, HCL AppScan, Acunetix, Netsparker, or equivalent.
  • Strong understanding of Web, API, and Cloud Security concepts.
  • Knowledge of OWASP Top 10, OWASP API Security Top 10, CVSS, CWE, and Secure SDLC practices.
  • Experience with authentication protocols such as OAuth 2.0, OpenID Connect, SAML, JWT, and MFA.
  • Exposure to Cloud Security (Azure/AWS/GCP) and container security assessments.
  • Familiarity with SAST, SCA/OSS Security Testing, API Security Testing, and Threat Modeling methodologies.

Responsibilities

  • Automation Testing across Web, API, and Enterprise applications.
  • Design, develop, and maintain automation frameworks using Selenium WebDriver with Java or C#.
  • Develop and execute automated test scripts; build reusable automation libraries.
  • Integrate automation suites with CI/CD pipelines.
  • Perform regression, smoke, sanity, and functional testing using automated frameworks.
  • Analyze test results and provide defect reports.
  • Collaborate with Dev, QA, BI, and DevSecOps teams to ensure quality deliverables.
  • Conduct vulnerability assessments, remediation validation, and risk-based security evaluations.

Skills

Automation Testing
Security Testing
Test Planning
Collaboration
Vulnerability Analysis

Education

Bachelor of Engineering

Tools

Selenium WebDriver
Burp Suite Pro
HCL AppScan
Acunetix
Netsparker
OWASP Testing Tools

Job description

Educational Requirements

Bachelor of Engineering

Service Line

Infosys Quality Engineering

Responsibilities
  • Automation Testing
  • Design, develop, and maintain automation frameworks using Selenium WebDriver with Java or C#.
  • Develop and execute automated test scripts for Web, API, and Enterprise applications.
  • Build reusable automation libraries and utilities.
  • Integrate automation suites with CI/CD pipelines.
  • Perform regression, smoke, sanity, and functional testing using automated frameworks.
  • Analyze test results and provide detailed defect reports.
  • Collaborate with developers, business analysts, and QA teams to ensure quality deliverables.
  • Participate in test planning, estimation, and test strategy discussions.
  • Security Testing
  • Perform comprehensive Security Testing and Assessment activities across applications, APIs, cloud environments, and supporting infrastructure.
  • Execute Dynamic Application Security Testing (DAST), Vulnerability Assessments, and Security Validation activities using industry-standard tools and methodologies.
  • Conduct manual and automated security testing to identify vulnerabilities related to authentication, authorization, session management, encryption, access controls, and business logic flaws.
  • Assess applications against industry standards and frameworks such as OWASP Top 10, OWASP API Security Top 10, CWE, NIST, and SANS.
  • Identify, analyze, prioritize, and document security vulnerabilities with detailed risk ratings, business impact analysis, and remediation guidance.
  • Perform false-positive analysis, vulnerability validation, and retesting to verify remediation effectiveness.
  • Collaborate closely with Development, Architecture, QA, and DevSecOps teams to promote secure coding practices and integrate security into the Software Development Life Cycle (SDLC).
  • Perform security reviews, threat assessments, and risk-based security evaluations for new and existing applications.
  • Participate in vulnerability management activities including triage, tracking, risk acceptance reviews, and remediation validation.
  • Prepare detailed security assessment reports and effectively communicate findings, risks, and recommendations to technical and non-technical stakeholders.
  • Conduct false-positive analysis and provide remediation recommendations.
  • Validate authentication, authorization, session management, encryption, and access control mechanisms.
  • Support compliance initiatives and security governance requirements.
Additional Responsibilities
  • Preferred SkillsExperience in IAM Security Testing (Saviynt, SailPoint, Access Governance testing).
  • Exposure to Performance Testing tools such as JMeter or LoadRunner.
  • Experience working in DevSecOps environments.
  • Knowledge of container technologies such as Docker and Kubernetes.
  • Scripting knowledge in Python, PowerShell, or Shell scripting.
Technical and Professional Requirements
  • 3+ years of experience in Application Security Testing, Vulnerability Assessment, and Security Validation.
  • Strong hands‑on experience with DAST tools such as Burp Suite Pro, HCL AppScan, Acunetix, Netsparker, or equivalent.
  • Solid understanding of Web, API, and Cloud Security concepts.
  • Knowledge of OWASP Top 10, OWASP API Security Top 10, CVSS, CWE, and Secure SDLC practices.
  • Experience in vulnerability reporting, risk analysis, remediation validation, and stakeholder communication.
  • Understanding of authentication protocols such as OAuth 2.0, OpenID Connect (OIDC), SAML, JWT, and MFA.
  • Experience with Cloud Security (Azure/AWS/GCP) and container security assessments.
  • Exposure to SAST, SCA/OSS Security Testing, API Security Testing, and Threat Modeling methodologies.
Preferred Skills
  • Technology->Testing Technologyes->Test Automation Technology
  • Technology->Java->Core Java
  • Technology->Security Testing->Security Testing - ALL
  • Technology->Automated Testing->Selenium-Java
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Testing Engineer
Application Security Testing Engineer

Infosys • Bengaluru

On-site
INR 900,000 - 1,200,000
Application Testing Engineer
Application Testing Engineer

Quess • Chennai District, Bengaluru, Pune District

Hybrid
INR 700,000 - 1,500,000
Application Security Engineer (SAST & DAST, DevSecOps)
Application Security Engineer (SAST & DAST, DevSecOps)

2coms • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Application Security Engineer
Application Security Engineer

Basebiz • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Application Security Engineer
Application Security Engineer

Basebiz • Chennai District

On-site
INR 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

Basebiz • Pune District

On-site
INR 1,800,000 - 3,000,000
C Sharp Testing Consultant
C Sharp Testing Consultant

Infosys • Bengaluru

On-site
INR 800,000 - 1,500,000
Security Tester
Security Tester

Disprz • Chennai District

On-site
INR 1,800,000 - 3,600,000
security testing engineer
security testing engineer

VMC Soft Technologies, Inc • Bengaluru

On-site
INR 3,500,000 - 6,000,000
Penetration Testing Engineer / Application Security Testing Engineer
Penetration Testing Engineer / Application Security Testing Engineer

VMC Soft Technologies, Inc • Bengaluru Urban

On-site
INR 1,800,000 - 3,600,000