StackNexus
Website:
stacknexus.io
Job details:
Job Description: Security QA Engineer – Application & Open-Source Security (Pune India)
Function: Security Engineering / DevSecOps
Business Unit: VSP 360 – Data Services Division
Position: 2
Experience: 5–8 Years
Location: India (Hybrid/Remote – based on business needs)
Role Overview
We are looking for a
Security QA Engineer with strong
handson experience in Software Composition Analysis (SCA) tools such as
Black Duck or similar to support application security initiatives within the
VSP 360 Data Services platform.
This role demands a blend of
security testing, vulnerability triage, OSS compliance, and security tooling operations, working closely with
Security Architects, DevSecOps, and Engineering teams in a cloudnative environment.
Key Responsibilities
Application & OSS Security Testing
- Perform Software Composition Analysis (SCA) using Black Duck (or tools like CodeDx, JFrog Xray, FOSSA).
- Identify opensource vulnerabilities, license risks, and dependency issues across applications.
- Support release readiness and security QA validation for product deliveries.
Vulnerability Triage & Remediation Support
- Analyze, triage, and categorize security findings based on severity, exploitability, and business risk.
- Work with Security Architecture teams to validate findings, eliminate false positives, and define remediation approaches.
- Track security findings to closure and support risk acceptance workflows where approved.
CI/CD & Tool Integration
- Integrate SCA tools into CI/CD pipelines (Any one of experience: GitHub, GitLab, Azure DevOps, Jenkins).
- Support configuration, tuning, and onboarding of new repositories and services into security tools.
- Troubleshoot issues related to scanning failures, pipeline integrations, and agent setup.
Reporting & Security Governance
- Generate security reports, dashboards, and metrics for internal stakeholders.
- Maintain evidence for audits, internal security reviews, and compliance requirements.
- Assist in improving security testing processes and standard operating procedures.
Collaboration & Enablement
- Work closely with developers, QA, and platform teams to promote secure coding and dependency hygiene.
- Provide guidance on vulnerability fixes and coordinate followups with engineering teams.
- Participate in security reviews and continuous improvement initiatives.
Mandatory Skills & Experience - 5+ years of experience in Application Security, Security QA, or Software Security.
- Strong handson experience with Black Duck, OSS SCA or equivalent SCA tools.
- Proven experience in:
- OSS vulnerability analysis and license compliance
- Vulnerability triage and remediation tracking
- Security reporting and metrics
- Good understanding of:
- Secure SDLC and DevSecOps practices
- CI/CD pipelines
- Cloud platforms (AWS, Azure, or GCP)
Good to Have
- Exposure to SAST/DAST tools (Fortify, Checkmarx, Veracode, SonarQube, etc.).
- Experience with container and image scanning or Kubernetes security.
- Familiarity with microservices and APIbased architectures.
- Security certifications such as CEH, CSSLP, GWAPT, or equivalent (preferred, not mandatory).
Soft Skills
- Strong analytical and problemsolving skills.
- Good communication skills to work effectively with crossfunctional teams.
- Ability to work independently and manage multiple security tasks.
Why Join Us
- Opportunity to work on enterprisescale cloud platforms
- Direct exposure to security architecture and DevSecOps practices
- Strong focus on handson learning, ownership, and impact
Role Fitment
This Role Is Ideal For Candidates Who
- Enjoy handson security testing and analysis
- Are comfortable working between security architecture and engineering teams
- Can independently manage security tooling and drive findings to closure
Business Hour
- Normal Business hours. The expectation would be to start early to cover PST timezone or start late to cover EST time. Exception subject to manager permission.
Job Type
- Hybrid Working: Minimum 2 days from office Tuesday and Thursday, but in case of business need and high demand, the manager may request to be present in the office on other days.
Location
- Pune – Maharashtra – India
Click on Apply to know more.