Infosys
Security Testing Engineer
Bangalore, India
Apply through hirly
Upload your resume and get a version tailored to this job, plus a cover letter, in about thirty seconds — before you create an account.
Apply with hirlyhirly's read of this role
- Seniority
- Mid level
- Country
- IN
- Work mode
- On-site / unstated
- First seen by hirly
- 27 Sept 2026
Derived automatically from the posting. Sign up to see how the role scores against your own resume.
the posting
We are seeking a highly skilled Automation & Security Test Engineer with 3+ years of experience in test automation and application security testing. The ideal candidate should possess strong expertise in Selenium Automation using Java or C#, test framework development, CI/CD integration, and security testing methodologies including vulnerability assessment and DAST. Experience in secure application testing and quality engineering practices is highly desirable
Responsibilities
Key Responsibilities
Automation Testing
Design, develop, and maintain automation frameworks using Selenium WebDriver with Java or C#.
Develop and execute automated test scripts for Web, API, and Enterprise applications.
Build reusable automation libraries and utilities.
Integrate automation suites with CI/CD pipelines.
Perform regression, smoke, sanity, and functional testing using automated frameworks.
Analyze test results and provide detailed defect reports.
Collaborate with developers, business analysts, and QA teams to ensure quality deliverables.
Participate in test planning, estimation, and test strategy discussions.
Security Testing
Perform comprehensive Security Testing and Assessment activities across applications, APIs, cloud environments, and supporting infrastructure.
Execute Dynamic Application Security Testing (DAST), Vulnerability Assessments, and Security Validation activities using industry-standard tools and methodologies.
Conduct manual and automated security testing to identify vulnerabilities related to authentication, authorization, session management, encryption, access controls, and business logic flaws.
Assess applications against industry standards and frameworks such as OWASP Top 10, OWASP API Security Top 10, CWE, NIST, and SANS.
Identify, analyze, prioritize, and document security vulnerabilities with detailed risk ratings, business impact analysis, and remediation guidance.
Perform false-positive analysis, vulnerability validation, and retesting to verify remediation effectiveness.
Collaborate closely with Development, Architecture, QA, and DevSecOps teams to promote secure coding practices and integrate security into the Software Development Life Cycle (SDLC).
Perform security reviews, threat assessments, and risk-based security evaluations for new and existing applications.
Participate in vulnerability management activities including triage, tracking, risk acceptance reviews, and remediation validation.
Prepare detailed security assessment reports and effectively communicate findings, risks, and recommendations to technical and non-technical stakeholders.
Conduct false-positive analysis and provide remediation recommendations.
Validate authentication, authorization, session management, encryption, and access control mechanisms.
Support compliance initiatives and security governance requirements
Technical requirements
3+ years of experience in Application Security Testing, Vulnerability Assessment, and Security Validation.
Strong hands-on experience with DAST tools such as Burp Suite Pro, HCL AppScan, Acunetix, Netsparker, or equivalent.
Solid understanding of Web, API, and Cloud Security concepts.
Knowledge of OWASP Top 10, OWASP API Security Top 10, CVSS, CWE, and Secure SDLC practices.
Experience in vulnerability reporting, risk analysis, remediation validation, and stakeholder communication.
Understanding of authentication protocols such as OAuth 2.0, OpenID Connect (OIDC), SAML, JWT, and MFA.
Experience with Cloud Security (Azure/AWS/GCP) and container security assessments.
Exposure to SAST, SCA/OSS Security Testing, API Security Testing, and Threat Modeling methodologies.
Additional responsibilities
Preferred Skills
Experience in IAM Security Testing (Saviynt, SailPoint, Access Governance testing).
Exposure to Performance Testing tools such as JMeter or LoadRunner.
Experience working in DevSecOps environments.
Knowledge of container technologies such as Docker and Kubernetes.
Scripting knowledge in Python, PowerShell, or Shell scripting.
Education
Bachelor of Engineering
Similar jobs
- Testing EngineerIntertek Global · Bangalore, Karnataka, IndiaFirst seen today
- Testing Engineering AdvisorNTT America, Inc. · Bangalore, Karnataka, IndiaFirst seen today
- UAV Testing EngineerKITEMAPS AERIAL MAPPING SERVICES PRIVATE LIMITED · Bangalore, IndiaFirst seen 3d ago
- TESTING ENGINEERAbb · Bangalore, Karnataka, IndiaFirst seen 9d ago
- Controls Testing EngineerVertiv · Pune, IndiaFirst seen today
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job