{"schemaVersion":"jobsearcher.job.v1","id":"dba168cd4998ca95f2732736","url":"https://jobsearcher.com/jobs/dba168cd4998ca95f2732736","canonicalUrl":"https://jobsearcher.com/jobs/dba168cd4998ca95f2732736","title":"Security Testing Engineer","description":"Job Description\n\nAs a Security Engineer/Tester, you will be performing authorized security testing on some of the very complex, massive scale, and highly critical applications. You must be self-directed, able to work independently, as well as work in a team-oriented and fast paced environment. You need to be aware of a varied application security domains like authentication, authorization, identity management, cryptography, etc. As part of a shift left focus, you will be working part of the development team along with developers to proactively identify any security vulnerabilities (OWASP Top 10, SANS Top 25, CWE) at the earliest before they are discovered late in cycle by InfoSec teams or in production. You will be working as a liaison between the Infosec team and development teams, understanding the security issues reported by central InfoSec teams to development teams to help them understand and fix them. You require very good communication and presentation skills to be able to present your findings to Leadership/Management/Development teams to help them understand the Risk so that they can take informed decisions on mitigations, controls and residual risk. You need to be highly passionate in following the constantly changing threat landscape and familiarize with latest security vulnerabilities that impacts the teams.\n\nResponsibilities:\nConduct web application security testing on the applications and report the findings to Leadership / Management / Development teams\n\nUnderstand the security issues reported by InfoSec teams and work with development teams to make them understand and fix.\n\nEvangelize application security concepts within development community to help preventing the security vulnerabilities in first place.\n\nRequired Skills\n\nDeep understanding of different web application technologies, web protocols (HTTP, HTTPS, etc.), browser technologies, etc.\n\nIn depth domain understanding of application security in terms of Identity and Access Management (IAM), different authentication technologies (passwords, biometrics, OTP, digital certificates & PKI, device authentication, FIDO U2F/Passkeys, etc.\n\nProven expertise on different security testing tools (Proxy tools like Fiddler, Black box security testing tools like Burp, Static Security Code analysis tools,\n\nDeep understanding of different application security vulnerabilities such as OWASP Top 10, SANS Top 25, CWE, attack patterns (CAPEC), etc.\n\nBachelor's Degree in Computer Science or equivalent experience.\n\nMust be self-directed, able to work independently, as well as work in a team-oriented and fast paced environment\n\nDesired Skills:\nWorking experience on different security technologies and standards like Single Sign On (SSO) using SAML/OpenID, OAuth protocols, etc.\n\nGood understanding of Cryptographic algorithms and standards like Symmetric/Assymetric crypto techniques, digital signatures, JWS/JWE tokens, Hardware Security Modules (HSMs), etc.\n\nUnderstanding of Security vulnerabilities related to Cloud environments is an added advantage.\n\nWell known Security certifications is an added advantage\n\nUnderstanding of Threat Modelling concepts and Secure Development Life Cycle processes.\n\nMobile Application Security familiarity is desirable.","company":"Photon","rawCompany":"photon","city":"Denver","state":"CO","isRemote":false,"isActive":false,"createdAt":"2026-08-15T12:33:46.335Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.04","title":"Penetration Testers","slug":"penetration-testers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security Testing Engineer","description":"Job Description\n\nAs a Security Engineer/Tester, you will be performing authorized security testing on some of the very complex, massive scale, and highly critical applications. You must be self-directed, able to work independently, as well as work in a team-oriented and fast paced environment. You need to be aware of a varied application security domains like authentication, authorization, identity management, cryptography, etc. As part of a shift left focus, you will be working part of the development team along with developers to proactively identify any security vulnerabilities (OWASP Top 10, SANS Top 25, CWE) at the earliest before they are discovered late in cycle by InfoSec teams or in production. You will be working as a liaison between the Infosec team and development teams, understanding the security issues reported by central InfoSec teams to development teams to help them understand and fix them. You require very good communication and presentation skills to be able to present your findings to Leadership/Management/Development teams to help them understand the Risk so that they can take informed decisions on mitigations, controls and residual risk. You need to be highly passionate in following the constantly changing threat landscape and familiarize with latest security vulnerabilities that impacts the teams.\n\nResponsibilities:\nConduct web application security testing on the applications and report the findings to Leadership / Management / Development teams\n\nUnderstand the security issues reported by InfoSec teams and work with development teams to make them understand and fix.\n\nEvangelize application security concepts within development community to help preventing the security vulnerabilities in first place.\n\nRequired Skills\n\nDeep understanding of different web application technologies, web protocols (HTTP, HTTPS, etc.), browser technologies, etc.\n\nIn depth domain understanding of application security in terms of Identity and Access Management (IAM), different authentication technologies (passwords, biometrics, OTP, digital certificates & PKI, device authentication, FIDO U2F/Passkeys, etc.\n\nProven expertise on different security testing tools (Proxy tools like Fiddler, Black box security testing tools like Burp, Static Security Code analysis tools,\n\nDeep understanding of different application security vulnerabilities such as OWASP Top 10, SANS Top 25, CWE, attack patterns (CAPEC), etc.\n\nBachelor's Degree in Computer Science or equivalent experience.\n\nMust be self-directed, able to work independently, as well as work in a team-oriented and fast paced environment\n\nDesired Skills:\nWorking experience on different security technologies and standards like Single Sign On (SSO) using SAML/OpenID, OAuth protocols, etc.\n\nGood understanding of Cryptographic algorithms and standards like Symmetric/Assymetric crypto techniques, digital signatures, JWS/JWE tokens, Hardware Security Modules (HSMs), etc.\n\nUnderstanding of Security vulnerabilities related to Cloud environments is an added advantage.\n\nWell known Security certifications is an added advantage\n\nUnderstanding of Threat Modelling concepts and Secure Development Life Cycle processes.\n\nMobile Application Security familiarity is desirable.","datePosted":"2026-08-15T12:33:46.335Z","dateModified":"2026-08-15T12:33:46.335Z","hiringOrganization":{"@type":"Organization","name":"Photon","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Denver","addressRegion":"CO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"dba168cd4998ca95f2732736"},"url":"https://jobsearcher.com/jobs/dba168cd4998ca95f2732736"}}