What you will do:
- This position will be responsible for Manual Testing and Validation:
- Conduct in-depth manual testing to identify vulnerabilities not covered by automated tools.
- Validate the accuracy of automated findings and ensure comprehensive coverage for critical systems.
- Provide detailed remediation guidance to development teams based on manual findings.
- Conduct both automated and manual testing to uncover vulnerabilities:
- Static Analysis: Detect insecure coding patterns during development.
- Tools: GitHub Advanced Security (CodeQL), SonarCloud, Checkmarx CLI.
- Dynamic Application Security Testing (DAST): Identify runtime vulnerabilities such as XSS or SQL Injection.
- Tools: OWASP ZAP CLI Runner, Burp Suite Enterprise Edition.
- Fuzz Testing: Discover unknown vulnerabilities through randomized inputs.
- Tools: ClusterFuzzLite, libFuzzer.
- Dependency Analysis: Identify vulnerabilities in third-party libraries and components.
- Tools: Dependabot, Snyk CLI, OWASP Dependency-Check.
- Environment Simulation and Sandboxing: Test software in isolated environments to simulate real-world attacks.
- Tools: Docker, Minikube, Cuckoo Sandbox.
- Identify, prioritize, and track vulnerabilities from multiple sources, including automated tools, penetration testing, and external reports.
- Collaborate with development teams to ensure timely remediation of findings.
- Design, implement, and maintain automated security testing pipelines using GitHub Actions.
- Integrate security tools into CI/CD workflows to enable continuous testing.
- Enhance pipeline efficiency by automating vulnerability identification, tracking, and validation processes.
- Act as the primary security liaison for engineering teams, guiding secure coding practices and remediation strategies.
- Review and approve remediation actions to verify closure of identified vulnerabilities.
- Establish workflows for vulnerability triage, testing, and closure.
- Develop and monitor metrics to measure the effectiveness and efficiency of vulnerability management processes.
What we look for:
- Expertise in building and managing automated security testing pipelines in CI/CD workflows.
- Strong knowledge of static and dynamic application security testing tools and methodologies.
- Hands-on experience conducting manual security testing, including penetration testing and vulnerability validation.
- Proficiency in programming or scripting languages (e.g., Python, Ruby, Go, or Rust) for building and customising testing tools.
- Experience working with development teams to remediate vulnerabilities and ensure secure software delivery.
- Familiarity with secure coding practices and common vulnerabilities (e.g., OWASP Top 10, CWE/SANS Top 25).
- Knowledge of modern security frameworks such as MITRE ATT&CK and NIST CSF.
- Experience with Kubernetes and containerised application security.
- Proven ability to automate complex security testing workflows.
- Published tools or research related to security testing or vulnerability management.

0 applies
9 views
Other Jobs from Kong
Staff Product Manager- Konnect Platform
Senior Fullstack Software Engineer, Insomnia (Shanghai)
Senior Software Engineer, Gateway Enterprise - Shanghai
Site Reliability Engineer
Senior Solutions Engineer, Australia
Similar Jobs
Principal Site Reliability Engineer
Full Stack Engineer, Sora
Deputy Director: Principal DevOps Process & Metrics Architect
Senior Software Engineer, Full Stack
There are more than 50,000 engineering jobs:
Subscribe to membership and unlock all jobs
Engineering Jobs
60,000+ jobs from 4,500+ well-funded companies
Updated Daily
New jobs are added every day as companies post them
Refined Search
Use filters like skill, location, etc to narrow results
Become a member
🥳🥳🥳 452 happy customers and counting...
Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.
To try it out
For active job seekers
For those who are passive looking
Cancel anytime
Frequently Asked Questions
- We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
- We've got about 70,000 jobs from 5,000 vetted companies. No fake or sleazy jobs here!
- We aggregate jobs from 5,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
- We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
- Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
- Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
- Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅
What Fellow Engineers Say