QA Tester- Vulnerability and Security Testing at NeoGenCode Technologies Pvt Ltd · Gurugram · 3 - 5 years · ₹5L - ₹6L / yr · Raised funding · Posted 27 Aug 2025

QA Tester- Vulnerability and Security Testing
Job Overview:
We are seeking a skilled QA Tester with a strong background in Vulnerability Testing to ensure the security, functionality, and reliability of our applications. The ideal candidate will have experience in penetration testing, security testing methodologies, load testing, automation, and working with compliance standards.
Key Responsibilities:
- Develop and execute test cases, scripts, and security test plans for applications and APIs.
- Perform vulnerability assessments and penetration testing on web, mobile, and cloud-based applications.
- Identify security loopholes, conduct risk analysis, and provide actionable remediation recommendations.
- Collaborate with development and DevOps teams to ensure secure coding practices.
- Automate security testing and integrate into CI/CD pipelines.
- Test applications against OWASP Top 10 vulnerabilities (e.g., SQL Injection, XSS, CSRF, SSRF).
- Utilize tools such as Burp Suite, OWASP ZAP, Metasploit, Kali Linux, Nessus, etc.
- Conduct API security testing and validate authentication & authorization mechanisms.
- Document security vulnerabilities and collaborate for timely remediation.
- Ensure compliance with industry standards like ISO 27001, GDPR, HIPAA, PCI-DSS, where applicable.
Required Skills & Qualifications:
- 3+ years of experience in Quality Assurance, with a strong focus on Security & Vulnerability Testing.
- In-depth knowledge of penetration testing tools and security frameworks.
- Experience with automated security testing in CI/CD environments (e.g., Jenkins, GitHub Actions, GitLab CI).
- Proficiency in manual and automated testing of web and mobile applications.
- Familiarity with scripting languages such as Python, Bash, or JavaScript for test automation.
- Experience working with cloud platforms like AWS, Azure, or GCP (preferred).
- Strong understanding of HTTP, APIs, and authentication protocols (OAuth, JWT, SAML).
- Good knowledge of network security, firewalls, and IDS/IPS systems.
- Certifications such as CEH, OSCP, CISSP, Security+ are a plus.

About NeoGenCode Technologies Pvt Ltd
About
Welcome to Neogencode Technologies, an IT services and consulting firm that provides innovative solutions to help businesses achieve their goals. Our team of experienced professionals is committed to providing tailored services to meet the specific needs of each client. Our comprehensive range of services includes software development, web design and development, mobile app development, cloud computing, cybersecurity, digital marketing, and skilled resource acquisition. We specialize in helping our clients find the right skilled resources to meet their unique business needs. At Neogencode Technologies, we prioritize communication and collaboration with our clients, striving to understand their unique challenges and provide customized solutions that exceed their expectations. We value long-term partnerships with our clients and are committed to delivering exceptional service at every stage of the engagement. Whether you are a small business looking to improve your processes or a large enterprise seeking to stay ahead of the competition, Neogencode Technologies has the expertise and experience to help you succeed. Contact us today to learn more about how we can support your business growth and provide skilled resources to meet your business needs.
Candid answers by the company
IT & Engineering Talent Staffing
- Provides full-time and contract-based hiring, delivering handpicked, pre‑screened developers across tech stacks—ranging from web, mobile, AI/ML, Web3/blockchain.
- Maintains a bench o vetted candidates, offering fast delivery of interview-ready profiles—often within 24 hours.
- Offers payroll management, handling compliance, tax, attendance, and documentation for both contractors and full-time employees.
2. End-to-End Project Delivery
- Delivers full-stack development solutions: web, mobile, cloud, AI/ML, Blockchain/Web3.
- Manages entire project lifecycle—requirements gathering, design (UI/UX), development, deployment, and ongoing support .
3. Additional Offerings
- Expands into cybersecurity consulting, digital marketing, and cloud platform services (like AWS, GCP, Azure) .
- Provides strategic IT consulting to align technology solutions with business objectives
Similar jobs (10)
Responsibilities
- Execute and support application vulnerability assessments (SAST, DAST, SCA, and manual code review), ensuring findings are accurate, actionable, and relevant to application risk.
- Validate scanner results, perform false-positive analysis, and track findings through remediation, including retesting to confirm effective fixes.
- Manage multiple application security initiatives concurrently while meeting strict timelines in a fast‑paced environment.
- Prioritize vulnerabilities based on business impact, exploitability, exposure, and likelihood, using industry best practices (e.g., CVSS scoring).
- Develop and maintain dashboards and reports tracking vulnerability metrics such as severity distribution, remediation SLAs, and mean time to remediation (MTTR).
- Support the integration of security scanning and vulnerability workflows into CI/CD pipelines, leveraging existing tooling and automation.
- Facilitate remediation planning by providing actionable recommendations and coordinating root cause analysis.
- Support threat modeling and application risk assessments, with a focus on discovering insecure design patterns.
- Participate in high‑severity or zero‑day vulnerability response activities, including impact analysis and coordinated remediation efforts, as needed.
- Provide input into policies and standards related to application and cloud security controls.
Qualifications and Education Requirements
- Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related discipline—or equivalent professional experience.
- 5-7 years of relevant experience in application security and/or vulnerability management.
- Solid understanding of common vulnerability classes (e.g., OWASP Top 10) and secure architecture principles.
- Proficiency in using Burp Suite for manual security testing of web applications and APIs, including validation of automated findings and identification of complex authentication, authorization, and business‑logic vulnerabilities.
- Hands-on experience with tools such as Burp Suite, Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and common network discovery tools (e.g., Nmap).
- Familiarity with NIST, MITRE ATT&CK, and CIS benchmarks.
- Programming/scripting proficiency in languages such as Python, Java, .NET, or similar.
- Excellent documentation, communication, and stakeholder engagement skills.
Desired Skills
- Professional certifications (e.g., Security+, SSCP, GWAPT, or pursuing CISSP, OSCP).
- Experience using the ServiceNow platform for vulnerability or incident tracking.
- Proficiency in Azure cloud and Azure DevOps environments.
- Experience using Power BI or similar tools to visualize vulnerability metrics and remediation trends for technical and non-technical stakeholders.
A BIT ABOUT US
Appknox is one of the top Mobile Application security companies recognized by Gartner and G2. A profitable B2B SaaS startup headquartered in Singapore & working from Bengaluru.
The primary goal of Appknox is to help businesses and mobile developers secure their mobile applications with a focus on delivery speed and high-quality security audits.
Appknox has helped secure mobile apps at Fortune 500 companies with major brands spread across regions like India, South-East Asia, Middle-East, US, and expanding rapidly. We have secured 300+ Enterprises globally.
We are a 65+ incredibly passionate team working to make an impact and helping some of the biggest companies globally. We work in a highly collaborative, very fast-paced work environment. If you have what it takes to be part of the team, we are excited and let’s speak further.
The Opportunity
To join the security team engaging with multiple clients, helping them with end to end security audits, also research about new topics and vulnerabilities to be added to the scanner, present it in conferences.
What An Ideal Candidate Would Look Like:
- Skills - Application Penetration Testing (Web, iOS and Android), experience with IoT testing, source code audits.
- Technology Stack: AWS, GCP, Objective C, Java, Python
- Responsibilities: Engage with clients for scoping call, perform security audits, remediation call with clients to patch the issues, research on new technologies/vulnerabilities
Minimum Requirements
- 2-4+ years of experience in application security and vulnerability research
- Strong foundation in mobile app security - Android or Ios
- Proven track record of discovering and disclosing CVEs in mobile platforms or popular applications (provide - github/bug bounty profiles)
- Strong understanding of exploit mitigations and proven ability to bypass them
- Should be able to architect automated detection logic for new vulnerabilities and integrate them into our security products
- Develop AI-driven agents to automate dynamic analysis
- Should be able to Leverage AI/LLMs to augment Pentesting efforts
- Ability to work independently in a fast-paced environment, balancing deep research with practical deliverables
Good to have Requirements
- Understanding of AI/ML security risks
Responsibilities
- Security assessment of web/mobile applications on various platforms
- Focusing on Mobile Application Security Research for new vulnerabilities
- Static and Dynamic Code Analysis
- Develop and interpret security standards and guides
- Automation of exploit development
- Understand and explain the results with impact on business and compliance status
- Continuously learning and training on latest tools and technique
Work Expectations
Within 1 month
Training on processes, security workflows and develop understanding on internal tools.
Within 3 months
Actively contributing in exploit development and automation of it with the team.
Within 6 months
Expected to achieve Subject Matter Expert status on our core security products. We expect you to validate your findings against real-world conditions, with a strong emphasis on translating internal discoveries into actionable bug bounty submissions and earned CVEs to benchmark your impact against the external security community.
Within 1 Year
By the end of your first year, you will be expected to produce and submit a piece of novel, peer-reviewed security research. This deliverable must be of a quality suitable for top-tier industry conferences.
Personality traits we really admire
- A confident and dynamic working persona, which can bring fun to the team, and a sense of humour, is an added advantage.
- Great attitude to ask questions, learn and suggest process improvements.
- Has attention to details and helps identify edge cases.
- Highly motivated and coming up with fresh ideas and perspectives to help us move towards our goals faster.
- Follow timelines and absolute commitment to deadlines.
Interview Process - would be team specific
- Round 1- CTF round
- Round 2 -Profile Evaluation; HR
- Round 3 -Technical Interview with security team members
- Round 4 -Technical Interview with the Hiring Manager
- Round 5 -Technical round with CTO
- Round 6 -HR Round
Compensation
- As per Industry Standards
Why Join Us
- Freedom & Responsibility: If you are a person who enjoys challenging work & pushing your boundaries, then this is the right place for you. We appreciate new ideas & ownership as well as flexibility with working hours.
- Great Salary & Equity: We keep up with the market standards & provide pay packages considering updated standards. Also as Appknox continues to grow, you’ll have a great opportunity to earn more & grow with us. Moreover, we also provide equity options for our top performers.
- Holistic Growth: We foster a culture of continuous learning and take a much more holistic approach to train and develop our assets: the employees. We shall also support you all on that journey of yours.
- Transparency: Being a part of a start-up is an amazing experience, one of the reasons being open communication & transparency at multiple levels. Working with Appknox will give you the opportunity to experience it all first-hand.
QA Test Engineer – Manual & Automation
Location: Bangalore, India
Experience: 2–5 years
Employment Type: Full-time
Work Mode: On-site
About Juntrax
Juntrax is a B2B Cloud SaaS product company building business operations software for SMEs. Our platform helps businesses manage their day-to-day operations through streamlined digital workflows and tools.
We are looking for a QA Test Engineer who can ensure the quality, reliability, and usability of our product through a combination of manual and automated testing.
Key Responsibilities
- Design, develop, and execute manual and automated test cases for web-based SaaS applications.
- Perform functional, regression, integration, system, and API testing.
- Create and maintain automated test scripts for critical product workflows.
- Identify, document, track, and retest bugs using appropriate bug-tracking tools.
- Collaborate closely with developers, UI/UX designers, product teams, and other stakeholders to understand requirements and ensure product quality.
- Participate in requirement analysis and contribute to test planning and test strategy.
- Perform cross-browser and responsive testing to ensure a consistent user experience.
- Validate new features, enhancements, bug fixes, and product releases.
- Maintain clear documentation of test scenarios, test cases, defects, and test results.
- Help improve QA processes, automation coverage, and overall testing efficiency.
Required Skills & Qualifications
- 2–5 years of experience in Software Quality Assurance / Testing.
- Strong understanding of manual testing concepts and QA methodologies.
- Hands-on experience with automation testing using tools/frameworks such as Selenium, Playwright, Cypress, or similar.
- Experience with API testing using tools such as Postman or similar.
- Good understanding of SQL and database validation.
- Experience with regression, integration, functional, and end-to-end testing.
- Familiarity with Git/version control and basic CI/CD concepts.
- Ability to write clear and effective test cases and defect reports.
- Good analytical and problem-solving skills.
- Strong attention to detail and a quality-focused mindset.
Good to Have
- Experience testing B2B SaaS or cloud-based applications.
- Experience with JavaScript/TypeScript, Python, Java, or another programming language.
- Experience integrating automated tests into CI/CD pipelines.
- Familiarity with Agile/Scrum development environments.
- Experience with performance or security testing.
What We’re Looking For
- Someone who can think beyond the happy path and identify edge cases and potential failure points.
- A QA professional who is comfortable working independently as well as with cross-functional teams.
- Someone who takes ownership of product quality from requirement analysis through release.
- A continuous learner who is interested in increasing automation coverage and improving QA processes.
Why Join Juntrax?
- Work directly on a growing B2B SaaS product.
- Gain exposure to the complete software development and release lifecycle.
- Opportunity to contribute to both manual and automation QA practices.
- Work closely with engineering, product, and leadership teams.
- Be part of a fast-paced startup environment where your work has a direct impact on the product.
We are seeking a curious, detail-oriented, and quality-driven tester who is passionate about building great products within a startup culture. This role goes beyond traditional testing—you will be responsible for evaluating the entire product experience before it reaches the client.
Your primary responsibility will be testing across product functionality, UI, UX, and overall usability, while also having basic awareness of automation testing tools and concepts.
You will work closely with developers, designers, and product teams to ensure that what we ship is stable, intuitive, clean, and client-ready.
Key Responsibilities
1. Manual Testing (Primary Focus)
- Perform end-to-end manual testing of web and/or mobile applications.
- Test all product features to ensure they work as expected across different scenarios.
- Identify, document, and report bugs, edge cases, inconsistencies, and usability issues.
- Validate fixes and ensure issues are fully resolved before release.
- Test applications from a real user’s perspective, not just based on requirements.
2. Product-Level Testing
- Evaluate whether the product:
- Solves the intended problem
- Has all the required features
- Feels complete and production-ready
- Identify missing flows, broken logic, or confusing behaviors.
- Ensure the product delivers a good overall experience, not just correct functionality.
3. UI Testing
- Review the visual quality of the product:
- Layout consistency
- Alignment, spacing, typography, and colors
- Check if the UI is:
- Clean and intuitive
- Not overly complex or cluttered
- Easy for users to understand and navigate
- Report UI inconsistencies across screens, devices, or browsers.
4. UX Testing
- Analyze how smooth and logical the user journey is.
- Identify friction points in:
- Navigation
- User flows
- Interactions and feedback
- Ensure the product feels natural, fast, and easy to use.
- Suggest improvements to enhance usability and user satisfaction.
5. Automation Testing Awareness
- understanding of automation testing concepts.
- Familiarity with common automation tools such as
- Selenium
- Cypress
- Playwright
- Postman (for API testing)
- Ability to understand where automation fits into the testing lifecycle.
6. Code Awareness (Secondary)
- Have a basic understanding of code and system behavior.
- Ability to:
- Read logs or error messages
- Understand where issues might originate
- Direct code-level testing is not mandatory, but awareness is a plus.
What We’re Looking For
Skills & Traits
- Strong attention to detail and observation skills
- Ability to think like an end user
- Logical thinking and problem-solving mindset
- Curious to explore edge cases and unusual scenarios
- Clear communication when reporting issues
- willingness to learn and improve continuously
Mindset & Passion
- You genuinely care about product quality
- You enjoy finding bugs, gaps, and improvements
- You take ownership of the product before it reaches the client
- You aim for “client-ready and polished,” not just “working.”
Eligibility
- A background in Computer Science, IT, Engineering, or related fields is a plus
What You’ll Gain
- Hands-on experience testing real products
- Exposure to the full product lifecycle before client delivery
- Strong foundation in manual testing, UI/UX evaluation, and product thinking
- Mentorship from experienced developers and product teams
- Opportunity to grow into a full-time QA or Product Quality role
Assignment :
We are looking for a detail-oriented Software Tester to ensure the quality, reliability, and performance of software applications. The Software Tester will be responsible for identifying defects, executing test cases, documenting issues, and working closely with developers and other team members to deliver high-quality software products.
Key Responsibilities
- Review software requirements and understand application functionality.
- Create, maintain, and execute test cases and test scenarios.
- Perform functional, regression, integration, system, and user acceptance testing.
- Identify, document, and track software defects and inconsistencies.
- Re-test resolved defects and perform regression testing.
- Conduct manual testing of web, mobile, or desktop applications.
- Verify software functionality across different browsers, devices, and environments.
- Prepare test plans, test reports, and other QA documentation.
- Collaborate with developers, business analysts, product managers, and other stakeholders.
- Participate in Agile/Scrum activities such as sprint planning, daily stand-ups, and retrospectives.
- Help improve testing processes and overall product quality.
- Support automation testing activities where required.
Key responsibilities
- Design, develop, and maintain automated test scripts using Katalon Studio for web, API, mobile, and desktop applications.
- Create and execute detailed test plans, test cases, and test scripts based on business requirements and technical specifications.
- Perform functional, regression, smoke, integration, and end-to-end testing across multiple environments.
- Build and manage reusable test frameworks and keyword-driven test libraries within Katalon.
- Integrate automated tests into CI/CD pipelines using tools like Jenkins, GitLab CI, or Azure DevOps.
- Conduct API testing using Katalon's built-in API testing capabilities and tools like Postman or REST Assured.
- Log, track, and verify defects using bug tracking tools such as Jira; ensure timely closure of issues.
- Participate in sprint planning, daily standups, and retrospectives as part of an Agile team.
- Analyse test results, generate reports, and communicate quality metrics to stakeholders.
- Mentor junior QA team members and contribute to continuous improvement of QA processes.
Good to have
- Katalon certification or any ISTQB / CSTE quality assurance certification.
- Experience with Appium or mobile testing frameworks for Android and iOS.
- Knowledge of performance testing tools such as JMeter or Gatling.
- Familiarity with BDD frameworks like Cucumber and Gherkin syntax.
- Exposure to cloud-based testing platforms such as BrowserStack or Sauce Labs.
- Understanding of SQL for database validation and backend testing.
Required Skills:-
- 4+ years of experience in Software Testing (Manual & Automation).
- Strong experience with Selenium or Playwright.
- Hands-on experience in API Testing (Postman, REST Assured, Swagger, etc.).
- Experience with CI/CD pipelines (Jenkins, GitLab CI, Azure DevOps, GitHub Actions).
- Strong understanding of Functional, Regression, and Non-functional Testing.
- Excellent analytical and debugging skills.
AI-Specific Skills
- Hands-on experience in GenAI / AI Testing.
- Experience testing LLM-based applications.
- Strong understanding of prompt engineering and prompt validation.
- Knowledge of LLM behavior, model variability, and non-deterministic outputs.
- Experience validating AI outputs for accuracy, hallucinations, bias, and safety.
- Test data management for AI applications.
- Understanding of Responsible AI testing concepts.
Hi Folks, we are currently Hiring for Security Engineer.
Gemini said
Hiring: Security Engineer
Company : Pentabay Softwares
Location : Anna salai, Mount Road
Mode: Fulltime
Pentabay Softwares INC is looking for a proactive Security Engineer (2–7 Years Exp) to fortify our global digital solutions. As we scale our footprint in the Healthcare IT sector, you will play a critical role in safeguarding sensitive data (ePHI) and ensuring our cloud-native architectures are resilient against evolving threats.
The Mission
You will be the architect of our defense, bridging the gap between high-speed development and rigorous security standards. Your day-to-day will involve "shifting security left" by embedding DevSecOps practices into our CI/CD pipelines and leading our compliance efforts for SOC 2, ISO 27001, and HIPAA.
Key Responsibilities
Defense & Architecture: Design and maintain secure cloud (AWS/Azure/GCP) and on-prem environments. Implement IAM policies, Zero Trust frameworks, and robust secrets management.
Offensive Testing: Conduct regular vulnerability assessments (VAPT), penetration testing, and code reviews using tools like Burp Suite and Nessus.
DevSecOps & Automation: Integrate SAST/DAST/SCA scanning into engineering workflows. Automate security tasks using Python or Bash.
Incident Response: Monitor SIEM tools (Splunk/CrowdStrike), respond to threats, and develop risk mitigation strategies.
Healthcare Compliance (Plus): Ensure data integrity for HL7/FHIR APIs and maintain HIPAA/HITECH audit readiness for healthcare clients.
What You Bring
Experience: 2–7 years in Information/Application Security with a strong grasp of the OWASP Top 10 and threat modeling (STRIDE).
Technical Depth: Proficiency in network/endpoint security, PKI, encryption standards (TLS/SSL), and container security (Docker/Kubernetes).
Compliance Knowledge: Familiarity with NIST, GDPR, and SOC 2 frameworks.
Tools: Hands-on experience with Metasploit, Wireshark, and Infrastructure-as-Code (Terraform).
Bonus Points: Industry certifications like OSCP, CISSP, or CEH, and experience in Healthcare IT workflows.
Auditing space like ISO27001 , ISO9001 prefered
Why Pentabay?
At Pentabay, we offer more than just a job; we offer a security-first engineering culture.
Growth: A dedicated learning budget for certifications and conferences.
Impact: Work on cutting-edge Healthcare projects that demand the highest levels of data privacy.
Send resumes to : sandhiya.m at pentabay.com
We are hiring a Automation QA Tester for our travel Domain client to ensure the quality and reliability of our web and mobile travel applications.
The role involves creating and executing test cases, identifying bugs, and collaborating with developers to ensure seamless user experience.
Candidates should have 2–4 years of experience in Automation mobile Testing, strong understanding of SDLC/STLC, and good attention to detail.
Experience in testing booking/payment flows or travel domain applications will be an added advantage.
About the team
SecurITe’s mission is to build an Agentic‑AI driven security platform that protects critical infrastructure from modern cyber threats. Our focus is on delivering highly performant, resilient, and intelligent network security systems that help defenders stay ahead of adversaries.
About the Role
We’re looking for a seasoned Senior Quality Engineer to provide technical leadership and architectural oversight for our next‑generation cybersecurity AI platform. In this high-impact role, you will define the technical strategy for quality assurance, ensuring our agentic AI transforms cyber defense with unparalleled reliability.
You will be responsible for the end-to-end quality lifecycle, from architectural reviews to the deployment of scalable automation frameworks. Beyond technical execution, you will serve as a mentor to junior team members, fostering a culture of technical excellence and driving the strategy that ensures our solutions meet the rigorous demands of critical infrastructure protection.
What You’ll Do
● Defining and driving comprehensive QA strategies and roadmaps for the cybersecurity platform.
● Designing, developing, and executing test plans, test cases, and automated scripts to ensure software quality.
● Performing functional, regression, performance, scalability and security testing to identify bugs or defects.
● Collaborating with developers, product managers, and other stakeholders to understand product requirements and testing needs.
● Identifying, documenting, and tracking software defects, ensuring clear communication of issues and their resolutions.
● Leading deep-dive root-cause analysis for critical system defects and security vulnerabilities.
● Conducting thorough reviews of product specifications and software design to identify potential areas of concern before testing.
● Architecting and designing complex, scalable test automation frameworks to optimize CI/CD velocity.
● Ensuring the software meets customer and business requirements by validating the functionality and performance.
● Assisting in continuously improving QA processes, tools, and best practices to enhance software testing efficiency and effectiveness.
● Supporting user acceptance testing (UAT) and assisting clients with product validation.
● Mentoring junior and mid-level engineers, providing technical guidance and conducting architectural reviews.
Required Experience
● A Bachelor’s degree in Computer Science, Information Technology, Computer Engineering, or a related field.
● 8-10 years of proven experience in quality engineering, specifically within network cybersecurity, Identity Providers, or AI-integrated platforms.
● Expertise in manual and automated testing.
● Deep domain expertise in complex system validation and advanced automation practices at scale.
● Proficiency in programming languages like Python to build and run automated test scripts.
● "Strong knowledge of software testing methodologies, performance testing tools (e.g., JMeter, k6), and security traffic generation/simulation tools (e.g., Ixia BreakingPoint, Scapy, or Snort/Suricata traffic generators)."
● Understanding of continuous integration/continuous deployment (CI/CD) pipelines and version control systems like Git.
● Strong communication skills for documenting test results and interacting with cross-functional teams.
● Excellent analytical skills, attention to detail, and problem-solving ability.
● Ability to work independently as well as collaboratively in a team environment.
● A curious mindset with a willingness to quickly learn new technologies and testing tools.
Required Skills & Qualifications
● Familiarity with cloud-based testing environments (GCP, AWS, Azure).
● Experience with cybersecurity products or cloud services or IDP or Web UI
The Mindset
● Problem Solver: You thrive on complex, ambiguous challenges and engineer elegant solutions.
● Ownership‑Driven: You take initiative, move fast, and deliver outcomes without hand‑holding.
● Continuous Learner: You stay ahead of the curve in AI, ML, and emerging technologies.
● Startup DNA: You excel in fast‑moving environments where priorities evolve and impact is immediate.






