
QA Staff Engineer
Barracuda Networks, Inc.2 hours ago
Bengaluru, IndiaStaff+
Responsibilities
- Design comprehensive test strategies and reference test architectures for WAF security rules, threat detection, attack mitigation, and enterprise deployment scenarios.
- Create and maintain automation frameworks and infrastructure for functional, security, performance, integration, regression, and WAF rule testing.
- Investigate customer-reported bugs, performance degradations, false positives and negatives, configuration issues, and production quality incidents.
- Work directly with enterprise customer security, QA, and DevOps teams to validate deployments, reproduce issues, and verify fixes.
- Design and execute security, network, protocol, attack-simulation, traffic-replay, load, and performance tests across Layer 3–7 scenarios.
- Develop tools for log analysis, metrics collection, test-data generation, traffic simulation, and automated security-event validation.
- Establish quality metrics, quality gates, release criteria, acceptance criteria, defect analysis, and root-cause investigation practices.
- Mentor QA engineers and developers, provide testability feedback in design reviews, and promote shift-left testing and test-driven development.
- Participate in customer war rooms and on-call rotations for critical enterprise quality issues.
Requirements
- At least 8 years of software quality assurance and test engineering experience, including at least 3 years in security-focused testing roles.
- At least 3 years testing WAFs, firewalls, CDNs, load balancers, reverse proxies, or similar security and networking products.
- Proven experience handling enterprise customer quality escalations, validating complex deployments, and designing automation frameworks for large-scale distributed systems.
- Strong customer-facing QA or enterprise product quality engineering experience.
- Deep knowledge of web application security, OWASP Top 10 validation, penetration-testing methodologies, vulnerability assessment, HTTP/HTTPS, TLS/SSL, network protocols, TCP/IP, DNS, and packet-level analysis.
- Experience with security testing tools, attack simulation, payload generation, injection attacks, XSS, CSRF, API security, performance testing, CI/CD test integration, cloud platforms, and containerized test environments.
- Strong programming skills in Python, Go, Java, or similar languages and experience with pytest, JUnit, TestNG, Robot Framework, or custom test frameworks.
- Experience with Postman, REST Assured, GraphQL testing, JMeter, Gatling, Locust, or k6 for API and performance testing.
- Experience using Wireshark, tcpdump, mitmproxy, or Charles Proxy for traffic inspection and debugging, plus distributed log analysis and performance profiling.
- Expertise in black-box, white-box, and grey-box testing; exploratory testing; regression strategy; test prioritization; test design techniques; and quality metrics.
- Preferred: chaos engineering, open-source testing contributions, CISSP, CEH, OSCP, GWAPT, ISTQB Advanced or Expert certification, compliance testing, penetration testing, red-team operations, security research, machine-learning testing, threat modeling, and Fortune 500 or Global 2000 experience.
Benefits
- Competitive compensation, equity, and benefits package.
- Opportunity to work on quality challenges protecting critical web applications and billions of requests daily.
- Direct impact on enterprise customer success through quality excellence.
- Collaborative, quality-focused culture with opportunities for deep technical work and close enterprise customer engagement.
- The role includes customer war-room support and on-call rotations for critical enterprise quality issues.
Tech Stack
Apache JMeterAWSAzureDockerGitHub ActionsGitLab CI/CDGoGoogle Cloud PlatformGraphQLgRPCJavaJenkinsJUnitKubernetesPostmanpytestPythonRobot FrameworkTestNG