๐ Weโre Hiring: Senior QA & Security Engineer (Manual Testing + Penetration Testing)
Argalon Technologies Pvt Ltd๐ Location: Remote โ Ukraine-based candidates are especially encouraged to apply
๐ผ Type: Full-Time
๐ Product: Web & Mobile Applications
We are looking for an experienced QA & Security Engineer to join our team and take ownership of the quality, reliability, and security testing of our web and mobile applications.
This is not just a role for executing predefined test cases. We are looking for someone who can think like a real user, identify unusual scenarios, actively try to break the product, discover security weaknesses, and work closely with our development team to ensure every release is stable and secure.
Key ResponsibilitiesManual & Functional Testing
- Perform comprehensive manual testing of web and mobile applications
- Test complete user journeys and business workflows
- Perform functional, regression, integration, usability, compatibility, and exploratory testing
- Identify edge cases that developers may overlook
- Test APIs, forms, authentication, permissions, uploads, notifications, payments, messaging, dashboards, and other application features
- Test across different browsers, devices, screen sizes, and operating systems
- Reproduce bugs consistently and document them clearly
- Verify fixes and perform regression testing before production releases
- Create and maintain detailed test cases, test plans, and testing checklists
Security & Penetration Testing
- Perform authorized penetration testing of our applications and APIs
- Identify vulnerabilities related to authentication, authorization, sessions, APIs, file uploads, input validation, and access controls
- Test against OWASP Top 10 and common web/API security vulnerabilities
- Perform security testing for issues such as IDOR/BOLA, XSS, SQL injection, CSRF, SSRF, privilege escalation, broken access control, rate-limit weaknesses, and business-logic vulnerabilities
- Review application security from both authenticated and unauthenticated perspectives
- Document vulnerabilities with severity, reproduction steps, evidence, impact, and recommended remediation
- Retest vulnerabilities after developers implement fixes
- Strong experience in manual QA testing
- Practical experience with web and API penetration testing
- Excellent understanding of HTTP/HTTPS, REST APIs, authentication, sessions, cookies, tokens, and application architecture
- Strong knowledge of OWASP Web Security Testing Guide, OWASP Top 10, and OWASP API Security
- Experience with tools such as Burp Suite, Postman, OWASP ZAP, browser developer tools, Jira or similar platforms
- Ability to investigate complex bugs rather than simply report that something โdoesn't workโ
- Strong attention to detail and analytical thinking
- Ability to communicate clearly with developers and product managers
- Comfortable working independently and taking ownership of application quality
- Experience testing high-traffic platforms or social/networking applications
- Mobile application security testing
- API automation/testing experience
- Performance and load testing
- Basic understanding of cloud infrastructure and application security
- Experience with CI/CD environments
- Security certifications such as OSCP, OSWE, eWPT/eWPTX, BSCP, CEH, or similar
We want someone whose mindset is:
โBefore our users find a bug, I want to find it. Before an attacker finds a vulnerability, I want to find it.โ
You will work directly with our product and development teams and will have significant responsibility for ensuring that our applications are reliable, secure, and ready for production.
Ukraine-based QA and application-security professionals are especially encouraged to apply.
#Hiring #QualityAssurance #QAEngineer #ManualTesting #PenetrationTesting #CyberSecurity #ApplicationSecurity #WebSecurity #UkraineJobs #RemoteJobs #SoftwareTesting