{"id":1223692,"url":"https://alion.io/job/infosys-security-testing-engineer","title":"Security Testing Engineer","company":{"id":223,"name":"Infosys","domain":"infosys.com","url":"https://alion.io/company/infosys","size_band":"5000+","is_staffing_agency":false,"employer_type":"services","is_intermediary":false,"listed_via":null,"ats_vendor":"Career site","truth_index":{"grade":"B","score":75,"open_postings":372,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-09-30T05:45:00Z"}},"role":"QA","role_family":"QA","seniority":"middle","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Bengaluru, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":10000,"max_usd":26000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":9},"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"C#","optional":false},{"name":"CI/CD","optional":false},{"name":"Java","optional":false},{"name":"Selenium","optional":false},{"name":"Acunetix","optional":true},{"name":"AWS","optional":true},{"name":"Azure","optional":true},{"name":"Burp Suite","optional":true},{"name":"CVSS","optional":true},{"name":"CWE","optional":true},{"name":"Docker","optional":true},{"name":"GCP","optional":true},{"name":"IAM","optional":true},{"name":"JMeter","optional":true},{"name":"Kubernetes","optional":true},{"name":"OWASP","optional":true},{"name":"OWASP Top 10","optional":true},{"name":"PowerShell","optional":true},{"name":"Python","optional":true},{"name":"Threat Modeling","optional":true}],"status":"live","first_seen_at":"2026-08-10T07:05:06Z","employer_posted_date":"2026-09-25","last_verified_at":"2026-09-29T17:24:37Z","board_verified":true,"closed_at":null,"days_open":51,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":51},"description":"We are seeking a highly skilled Automation & Security Test Engineer with 3+ years of experience in test automation and application security testing. The ideal candidate should possess strong expertise in Selenium Automation using Java or C#, test framework development, CI/CD integration, and security testing methodologies including vulnerability assessment and DAST. Experience in secure application testing and quality engineering practices is highly desirable\nResponsibilities\nKey Responsibilities\nAutomation Testing\nDesign, develop, and maintain automation frameworks using Selenium WebDriver with Java or C#.\nDevelop and execute automated test scripts for Web, API, and Enterprise applications.\nBuild reusable automation libraries and utilities.\nIntegrate automation suites with CI/CD pipelines.\nPerform regression, smoke, sanity, and functional testing using automated frameworks.\nAnalyze test results and provide detailed defect reports.\nCollaborate with developers, business analysts, and QA teams to ensure quality deliverables.\nParticipate in test planning, estimation, and test strategy discussions.\nSecurity Testing\nPerform comprehensive Security Testing and Assessment activities across applications, APIs, cloud environments, and supporting infrastructure.\nExecute Dynamic Application Security Testing (DAST), Vulnerability Assessments, and Security Validation activities using industry-standard tools and methodologies.\nConduct manual and automated security testing to identify vulnerabilities related to authentication, authorization, session management, encryption, access controls, and business logic flaws.\nAssess applications against industry standards and frameworks such as OWASP Top 10, OWASP API Security Top 10, CWE, NIST, and SANS.\nIdentify, analyze, prioritize, and document security vulnerabilities with detailed risk ratings, business impact analysis, and remediation guidance.\nPerform false-positive analysis, vulnerability validation, and retesting to verify remediation effectiveness.\nCollaborate closely with Development, Architecture, QA, and DevSecOps teams to promote secure coding practices and integrate security into the Software Development Life Cycle (SDLC).\nPerform security reviews, threat assessments, and risk-based security evaluations for new and existing applications.\nParticipate in vulnerability management activities including triage, tracking, risk acceptance reviews, and remediation validation.\nPrepare detailed security assessment reports and effectively communicate findings, risks, and recommendations to technical and non-technical stakeholders.\nConduct false-positive analysis and provide remediation recommendations.\nValidate authentication, authorization, session management, encryption, and access control mechanisms.\nSupport compliance initiatives and security governance requirements\nTechnical requirements\n3+ years of experience in Application Security Testing, Vulnerability Assessment, and Security Validation.\nStrong hands-on experience with DAST tools such as Burp Suite Pro, HCL AppScan, Acunetix, Netsparker, or equivalent.\nSolid understanding of Web, API, and Cloud Security concepts.\nKnowledge of OWASP Top 10, OWASP API Security Top 10, CVSS, CWE, and Secure SDLC practices.\nExperience in vulnerability reporting, risk analysis, remediation validation, and stakeholder communication.\nUnderstanding of authentication protocols such as OAuth 2.0, OpenID Connect (OIDC), SAML, JWT, and MFA.\nExperience with Cloud Security (Azure/AWS/GCP) and container security assessments.\nExposure to SAST, SCA/OSS Security Testing, API Security Testing, and Threat Modeling methodologies.\nAdditional responsibilities\nPreferred Skills\nExperience in IAM Security Testing (Saviynt, SailPoint, Access Governance testing).\nExposure to Performance Testing tools such as JMeter or LoadRunner.\nExperience working in DevSecOps environments.\nKnowledge of container technologies such as Docker and Kubernetes.\nScripting knowledge in Python, PowerShell, or Shell scripting.\nPreferred skills\nTechnology->Security Testing->Security Testing - ALL,Technology->Testing Technologyes->Test Automation Technology,Technology->Java->Core Java,Technology->Automated Testing->Selenium-Java\nEducation\nBachelor of Engineering","description_format":"text","description_chars":4257,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","IT Consulting & Digital Transformation","IT Outsourcing & Dedicated Teams"],"lifecycle":[{"event":"open","at":"2026-09-25T13:04:21Z"}],"liveness":{"score":11,"band":"cold","label":"Long shot","p_open":1,"p_active":0.407,"p_room":0.28,"age_days":50,"expected_fill_days":18,"reasons":["conf:12","stale_co","velocity","win:tail","crowd:brand"],"computed_at":"2026-09-30T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/infosys-security-testing-engineer","json_url":"https://alion.io/job/infosys-security-testing-engineer.json","meta":{"generated_at":"2026-10-01T00:16:23Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":341,"day_limit":5000,"remaining_today":4659,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}