Infosys
Infosys

Security Testing Engineer

RoleSecurity
LevelMid Level
LocationBangalore, India
WorkOn-site
TypeSenior Consultant
Posted1 month ago
Apply now

About the role

We are seeking a highly skilled Automation & Security Test Engineer with 3+ years of experience in test automation and application security testing. The ideal candidate should possess strong expertise in Selenium Automation using Java or C#, test framework development, CI/CD integration, and security testing methodologies including vulnerability assessment and DAST. Experience in secure application testing and quality engineering practices is highly desirable

Key Responsibilities:

  • Automation Testing

  • Design, develop, and maintain automation frameworks using Selenium Web Driver with Java or C#.

  • Develop and execute automated test scripts for Web, API, and Enterprise applications.

  • Build reusable automation libraries and utilities.

  • Integrate automation suites with CI/CD pipelines.

  • Perform regression, smoke, sanity, and functional testing using automated frameworks.

  • Analyze test results and provide detailed defect reports.

  • Collaborate with developers, business analysts, and QA teams to ensure quality deliverables.

  • Participate in test planning, estimation, and test strategy discussions.

  • Security Testing

  • Perform comprehensive Security Testing and Assessment activities across applications, APIs, cloud environments, and supporting infrastructure.

  • Execute Dynamic Application Security Testing (DAST), Vulnerability Assessments, and Security Validation activities using industry-standard tools and methodologies.

  • Conduct manual and automated security testing to identify vulnerabilities related to authentication, authorization, session management, encryption, access controls, and business logic flaws.

  • Assess applications against industry standards and frameworks such as OWASP Top 10, OWASP API Security Top 10, CWE, NIST, and SANS.

  • Identify, analyze, prioritize, and document security vulnerabilities with detailed risk ratings, business impact analysis, and remediation guidance.

  • Perform false-positive analysis, vulnerability validation, and retesting to verify remediation effectiveness.

  • Collaborate closely with Development, Architecture, QA, and Dev Sec Ops teams to promote secure coding practices and integrate security into the Software Development Life Cycle (SDLC).

  • Perform security reviews, threat assessments, and risk-based security evaluations for new and existing applications.

  • Participate in vulnerability management activities including triage, tracking, risk acceptance reviews, and remediation validation.

  • Prepare detailed security assessment reports and effectively communicate findings, risks, and recommendations to technical and non-technical stakeholders.

  • Conduct false-positive analysis and provide remediation recommendations.

  • Validate authentication, authorization, session management, encryption, and access control mechanisms.

  • Support compliance initiatives and security governance requirements

  • 3+ years of experience in Application Security Testing, Vulnerability Assessment, and Security Validation.

  • Strong hands-on experience with DAST tools such as Burp Suite Pro, HCL App Scan, Acunetix, Netsparker, or equivalent.

  • Solid understanding of Web, API, and Cloud Security concepts.

  • Knowledge of OWASP Top 10, OWASP API Security Top 10, CVSS, CWE, and Secure SDLC practices.

  • Experience in vulnerability reporting, risk analysis, remediation validation, and stakeholder communication.

  • Understanding of authentication protocols such as OAuth 2.0, OpenID Connect (OIDC), SAML, JWT, and MFA.

  • Experience with Cloud Security (Azure/AWS/GCP) and container security assessments.

  • Exposure to SAST, SCA/OSS Security Testing, API Security Testing, and Threat Modeling methodologies.

  • Preferred Skills

  • Experience in IAM Security Testing (Saviynt, Sail Point, Access Governance testing).

  • Exposure to Performance Testing tools such as JMeter or Load Runner.

  • Experience working in Dev Sec Ops environments.

  • Knowledge of container technologies such as Docker and Kubernetes.

  • Scripting knowledge in Python, PowerShell, or Shell scripting.

Education: Bachelor of Engineering

  • Preferred skills: Technology->Security Testing->Security Testing
  • ALL,Technology->Testing Technologyes->Test Automation Technology,Technology->Java->Core Java,Technology->Automated Testing->Selenium-Java

Benefits and perks

Learning Budget

Required skills

Cybersecurity

Risk management

Incident response

About Infosys

BANGALORE

Headquarters