2 hours ago
Bengaluru, IndiaStaff+

Responsibilities

  • Design comprehensive test strategies and reference test architectures for WAF security rules, threat detection, attack mitigation, and enterprise deployment scenarios.
  • Create and maintain automation frameworks and infrastructure for functional, security, performance, integration, regression, and WAF rule testing.
  • Investigate customer-reported bugs, performance degradations, false positives and negatives, configuration issues, and production quality incidents.
  • Work directly with enterprise customer security, QA, and DevOps teams to validate deployments, reproduce issues, and verify fixes.
  • Design and execute security, network, protocol, attack-simulation, traffic-replay, load, and performance tests across Layer 3–7 scenarios.
  • Develop tools for log analysis, metrics collection, test-data generation, traffic simulation, and automated security-event validation.
  • Establish quality metrics, quality gates, release criteria, acceptance criteria, defect analysis, and root-cause investigation practices.
  • Mentor QA engineers and developers, provide testability feedback in design reviews, and promote shift-left testing and test-driven development.
  • Participate in customer war rooms and on-call rotations for critical enterprise quality issues.

Requirements

  • At least 8 years of software quality assurance and test engineering experience, including at least 3 years in security-focused testing roles.
  • At least 3 years testing WAFs, firewalls, CDNs, load balancers, reverse proxies, or similar security and networking products.
  • Proven experience handling enterprise customer quality escalations, validating complex deployments, and designing automation frameworks for large-scale distributed systems.
  • Strong customer-facing QA or enterprise product quality engineering experience.
  • Deep knowledge of web application security, OWASP Top 10 validation, penetration-testing methodologies, vulnerability assessment, HTTP/HTTPS, TLS/SSL, network protocols, TCP/IP, DNS, and packet-level analysis.
  • Experience with security testing tools, attack simulation, payload generation, injection attacks, XSS, CSRF, API security, performance testing, CI/CD test integration, cloud platforms, and containerized test environments.
  • Strong programming skills in Python, Go, Java, or similar languages and experience with pytest, JUnit, TestNG, Robot Framework, or custom test frameworks.
  • Experience with Postman, REST Assured, GraphQL testing, JMeter, Gatling, Locust, or k6 for API and performance testing.
  • Experience using Wireshark, tcpdump, mitmproxy, or Charles Proxy for traffic inspection and debugging, plus distributed log analysis and performance profiling.
  • Expertise in black-box, white-box, and grey-box testing; exploratory testing; regression strategy; test prioritization; test design techniques; and quality metrics.
  • Preferred: chaos engineering, open-source testing contributions, CISSP, CEH, OSCP, GWAPT, ISTQB Advanced or Expert certification, compliance testing, penetration testing, red-team operations, security research, machine-learning testing, threat modeling, and Fortune 500 or Global 2000 experience.

Benefits

  • Competitive compensation, equity, and benefits package.
  • Opportunity to work on quality challenges protecting critical web applications and billions of requests daily.
  • Direct impact on enterprise customer success through quality excellence.
  • Collaborative, quality-focused culture with opportunities for deep technical work and close enterprise customer engagement.
  • The role includes customer war-room support and on-call rotations for critical enterprise quality issues.

Tech Stack

Apache JMeterAWSAzureDockerGitHub ActionsGitLab CI/CDGoGoogle Cloud PlatformGraphQLgRPCJavaJenkinsJUnitKubernetesPostmanpytestPythonRobot FrameworkTestNG

Categories

Barracuda Networks, Inc.

About Barracuda Networks, Inc.

1,001-5,000 employees
Contact me