Security Test Engineer
Enphase Energy- Location
- Bangalore, India
- Workplace
- —
- Employment
- Full Time
- Salary
- —
Posted 4d ago
Description
Enphase Energy is a global energy technology company and a leading provider of solar, battery, and electric vehicle charging products. Founded in 2006, our innovative microinverter technology revolutionized solar power, making it a safer, more reliable, and scalable energy source. Today, the Enphase Energy System enables users to make, use, save, and sell their own power. Enphase is also one of the most successful and innovative clean energy companies in the world, with more than 80 million products shipped across 160 countries. Join our dynamic teams designing and developing next-gen energy technologies and help drive a sustainable future!
This role at Enphase requires working onsite 3 days a week, with plans to transition back to a full 5 day in office schedule over time.
Security Test Engineer
As a Security Test Engineer at Enphase Energy, you will help secure our applications, APIs, and AWS-based infrastructure that support millions of energy systems globally. Working closely with senior security engineers, you will perform security assessments, identify vulnerabilities, support remediation efforts, and contribute to offensive security initiatives.
This role is ideal for a security professional with a passion for penetration testing, application security, red teaming, and secure development practices.
What You Will Be Doing
- Perform hands-on penetration testing of web applications, APIs, and backend services.
- Conduct vulnerability assessments and security reviews of applications and AWS environments.
- Use security testing tools such as Polaris, Black Duck (SCA), SonarQube, Burp Suite, and OWASP ZAP to identify and validate security issues.
- Execute Static Application Security Testing (SAST), Software Composition Analysis (SCA), and Dynamic Application Security Testing (DAST) activities.
- Validate security findings and work with engineering teams on remediation recommendations.
- Assist in integrating security testing into CI/CD pipelines and support secure SDLC initiatives.
- Perform AWS security assessments, including IAM reviews, privilege analysis, network security reviews, and configuration assessments.
- Participate in threat modeling exercises and security architecture reviews.
- Execute red team exercise and adversary emulation activities to identify real-world attack paths.
- Develop scripts and automation using Python or Bash to improve security testing processes.
- Research emerging threats, vulnerabilities, and attack techniques affecting web applications and cloud-native environments.
- Track vulnerabilities through remediation and closure.
What You Bring
- BE/BTech in Computer Science, Information Security, Electronics, or a related field.
- 2-4 years of experience in Application Security, Penetration Testing, Security Testing, or Offensive Security.
- Hands-on experience with Burp Suite, OWASP ZAP, Polaris, Black Duck (SCA), SonarQube
- Strong understanding of: OWASP Top 10, API Security Top 10, Secure Coding Practices, Vulnerability Assessment and Penetration Testing (VAPT)
- Experience performing manual security testing of web applications and REST APIs.
- Working knowledge of AWS security concepts, including IAM, security groups, VPCs, secrets management, and access controls.
- Familiarity with SAST, DAST, and SCA methodologies.
- Basic understanding of threat modeling and attack surface analysis.
- Experience using Linux environments and security testing tools.
- Proficiency in Python, Bash, or other scripting languages.
- Strong analytical and problem-solving skills.
Nice to Have
- Hands-on experience with red team exercises or adversary simulation activities.
- Exposure to MITRE ATT&CK framework.
- Experience with container and Kubernetes security testing.
- Knowledge of DevSecOps and CI/CD security practices.
- Experience participating in bug bounty programs or CTF competitions.
- Relevant certifications (Not Mandatory): OSCP & CEH
Skills
- AWS
- SCA
- SonarQube
- Burp Suite
- OWASP ZAP
- SAST
- DAST
- IAM
- Python
- Bash
- OWASP Top 10
- Linux
- Kubernetes
More jobs at Enphase Energy
All 46Product Security Architect
Enphase Energy · Fremont, California · yesterday
Sr. Reliability Test Engineer
Enphase Energy · Petaluma, California · USD 105,000–162,000/yr · 3d ago
Field Service Technician - NC (6 month Temporary Assignment)
Enphase Energy · United States · USD 23–36/hr · 5d ago
Field Service Technician - Chicago, IL
Enphase Energy · United States · USD 29–42/hr · 5d ago
Solid-State Transformer (SST) Product Management, Director to Senior Director
Enphase Energy · Austin, Texas · SF Bay Area, United States · United States · USD 180,000–253,800/yr · 6d ago
Similar roles
Staff Product Security Engineer, PSIRT
ServiceNow · Hyderabad, Telangana, India · today
Sr Staff Inbound Product Manager
ServiceNow · Hyderabad, Telangana, India · today
Sr Software Engineer - Cloud Platform—Kubernetes Development
ServiceNow · Hyderabad, India · today
Senior Software Engineer
Smiths Group · Bengaluru, KA, India · today
QA Engineer Contractual - 6 months
AbhiBus · Hyderabad, TS, India · today
Sr Staff Software Engineer
ServiceNow · Hyderabad, Telangana, India · today