Exciting global company working with the global internet is seeking a (QA) Security Test Engineer with a strong background in security testing and automation, specializing in permissions and access control validation.
This role will focus on ensuring that our systems enforce correct user roles, access boundaries, and workflow rules across both low-code/no-code platforms and custom-built solutions via automated testing.
Additionally, this role will collaborate closely with business stakeholders, engineering teams, and Information Security to design, execute, and automate test plans that protect our applications from security and compliance risks.
Roles & Responsibilities
Develop, maintain, and execute test plans for access control, permissions, and workflow security.
Partner with Information Security, Product, and Engineering teams to define security testing requirements and acceptance criteria.
Perform manual and automated security testing of role-based access controls, authentication flows, and authorization rules.
Validate workflow-driven applications and low-code/no-code systems for correctness, escalation rules, and data leakage prevention.
Build and maintain automated test suites using tools such as Pytest (or similar frameworks).
Identify gaps in access policies, privilege escalation risks, and workflow misconfigurations.
Document test cases, defects, and results clearly for both technical and business audiences.
Advocate for secure development and testing practices throughout the engineering lifecycle.
From time to time, attend and participate in meetings in the Los Angeles office.
Required Knowledge, Skills & Abilities (KSAs)
4+ years of experience in QA engineering, with a focus on security testing and automation.
Strong understanding of permissions models, RBAC/ABAC, and access control testing.
Experience working with workflow automation, BPM, or low-code/no-code platforms (e.g., Appian, Salesforce, PowerApps).
Ability to collaborate with business teams, engineers, and security experts to translate requirements into effective tests.
Hands-on experience with test automation tools (preferred: Testim.io, Selenium, Pytest, Playwright).
Familiarity with CI/CD pipelines and integrating automated security/QA tests.
Strong problem-solving skills, attention to detail, and the ability to work independently.
Preferred Experience
Experience with threat modeling or penetration testing.
Knowledge of the OWASP Top 10 security risks.
Exposure to compliance frameworks (SOC2, ISO 27001, GDPR, etc.).
Programming or scripting background (JavaScript, Python, Java).
Language
Fluency in English, both written and spoken, is required.
Numbers & Facts
Location
Los Angeles, CA
Skills
Access Controlunmatched
Applications Securityunmatched
Authenticationunmatched
Automationunmatched
Business Process Managementunmatched
Computer Securityunmatched
Continuous Deployment/Deliveryunmatched
Continuous Integrationunmatched
Detail Orientedunmatched
English Languageunmatched
ISO (International Organization for Standardization)unmatched
Information/Data Security (InfoSec)unmatched
Javaunmatched
JavaScriptunmatched
Penetration Testingunmatched
Problem Solving Skillsunmatched
Product Engineeringunmatched
Pytestunmatched
Python Programming/Scripting Languageunmatched
Quality Assuranceunmatched
Quality Assurance Methodologyunmatched
Requirements Managementunmatched
Salesforce.comunmatched
Scripting (Scripting Languages)unmatched
Security Designunmatched
Seleniumunmatched
Team Playerunmatched
Test Automationunmatched
Test Caseunmatched
Test Plan/Scheduleunmatched
Test Requirementsunmatched
Test Suiteunmatched
Test Toolsunmatched
Testingunmatched
Threat Modelingunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.