Enphase Energy Careers - Senior Penetration Tester – IoT & Embedded Devices

JobviteBangalore, IndiaSenior
Active

Job description

Enphase Energy Careers { "@context": "http://schema.org", "@type": "JobPosting", "datePosted": "2026-06-21", "description": "

Enphase Energy is a global energy technology company and a leading provider of solar, battery, and electric vehicle charging products. Founded in 2006, our innovative microinverter technology revolutionized solar power, making it a safer, more reliable, and scalable energy source. Today, the Enphase Energy System enables users to make, use, save, and sell their own power. Enphase is also one of the most successful and innovative clean energy companies in the world, with more than 80 million products shipped across 160 countries. Join our dynamic teams designing and developing next-gen energy technologies and help drive a sustainable future!

This role at Enphase requires working onsite\u00A03 days a week, with plans to transition back to a full 5 day in office schedule over time.

Security Test Engineer

As a Security Test Engineer at Enphase Energy, you will help secure our applications, APIs, and AWS-based infrastructure that support millions of energy systems globally. Working closely with senior security engineers, you will perform security assessments, identify vulnerabilities, support remediation efforts, and contribute to offensive security initiatives.

This role is ideal for a security professional with a passion for penetration testing, application security, red teaming, and secure development practices.

What You Will Be Doing

  • Perform hands-on penetration testing of web applications, APIs, and backend services.
  • Conduct vulnerability assessments and security reviews of applications and AWS environments.
  • Use security testing tools such as Polaris, Black Duck (SCA), SonarQube, Burp Suite, and OWASP ZAP to identify and validate security issues.
  • Execute Static Application Security Testing (SAST), Software Composition Analysis (SCA), and Dynamic Application Security Testing (DAST) activities.
  • Validate security findings and work with engineering teams on remediation recommendations.
  • Assist in integrating security testing into CI/CD pipelines and support secure SDLC initiatives.
  • Perform AWS security assessments, including IAM reviews, privilege analysis, network security reviews, and configuration assessments.
  • Participate in threat modeling exercises and security architecture reviews.
  • Execute red team exercise and adversary emulation activities to identify real-world attack paths.
  • Develop scripts and automation using Python or Bash to improve security testing processes.
  • Research emerging threats, vulnerabilities, and attack techniques affecting web applications and cloud-native environments.
  • Track vulnerabilities through remediation and closure.


What You Bring

  • BE/BTech in Computer Science, Information Security, Electronics, or a related field.
  • 2-4 years of experience in Application Security, Penetration Testing, Security Testing, or Offensive Security.
  • Hands-on experience with Burp Suite,\u00A0OWASP ZAP,\u00A0Polaris,\u00A0Black Duck (SCA),\u00A0SonarQube
  • Strong understanding of:\u00A0OWASP Top 10, API Security Top 10, Secure Coding Practices, Vulnerability Assessment and Penetration Testing (VAPT)
  • Experience performing manual security testing of web applications and REST APIs.
  • Working knowledge of AWS security concepts, including IAM, security groups, VPCs, secrets management, and access controls.
  • Familiarity with SAST, DAST, and SCA methodologies.
  • Basic understanding of threat modeling and attack surface analysis.
  • Experience using Linux environments and security testing tools.
  • Proficiency in Python, Bash, or other scripting languages.
  • Strong analytical and problem-solving skills.


Nice to Have

  • Hands-on experience with red team exercises or adversary simulation activities.
  • Exposure to MITRE ATT&CK framework.
  • Experience with container and Kubernetes security testing.
  • Knowledge of DevSecOps and CI/CD security practices.
  • Experience participating in bug bounty programs or CTF competitions.
  • Relevant certifications (Not Mandatory): OSCP & CEH
", "hiringOrganization": "Enphase Energy", "employmentType": "Full Time Employee (Experienced)", "industry": "Engineering", "identifier": "ob5nAfwX", "jobLocation": [ { "@type": "Place", "address": { "@type": "PostalAddress", "addressCountry": "India" } } ], "title": "Security Test Engineer", "baseSalary": { "@type": "MonetaryAmount", "currency": "", "value": { "@type": "QuantitativeValue", "minValue": "", "maxValue": "", "unitText": "" } } } Security Test Engineer Engineering Bangalore, India Apply Description Enphase Energy is a global energy technology company and a leading provider of solar, battery, and electric vehicle charging products. Founded in 2006, our innovative microinverter technology revolutionized solar power, making it a safer, more reliable, and scalable energy source. Today, the Enphase Energy System enables users to make, use, save, and sell their own power. Enphase is also one of the most successful and innovative clean energy companies in the world, with more than 80 million products shipped across 160 countries. Join our dynamic teams designing and developing next-gen energy technologies and help drive a sustainable future!This role at Enphase requires working onsite 3 days a week, with plans to transition back to a full 5 day in office schedule over time.Security Test EngineerAs a Security Test Engineer at Enphase Energy, you will help secure our applications, APIs, and AWS-based infrastructure that support millions of energy systems globally. Working closely with senior security engineers, you will perform security assessments, identify vulnerabilities, support remediation efforts, and contribute to offensive security initiatives.This role is ideal for a security professional with a passion for penetration testing, application security, red teaming, and secure development practices.What You Will Be DoingPerform hands-on penetration testing of web applications, APIs, and backend services.Conduct vulnerability assessments and security reviews of applications and AWS environments.Use security testing tools such as Polaris, Black Duck (SCA), SonarQube, Burp Suite, and OWASP ZAP to identify and validate security issues.Execute Static Application Security Testing (SAST), Software Composition Analysis (SCA), and Dynamic Application Security Testing (DAST) activities.Validate security findings and work with engineering teams on remediation recommendations.Assist in integrating security testing into CI/CD pipelines and support secure SDLC initiatives.Perform AWS security assessments, including IAM reviews, privilege analysis, network security reviews, and configuration assessments.Participate in threat modeling exercises and security architecture reviews.Execute red team exercise and adversary emulation activities to identify real-world attack paths.Develop scripts and automation using Python or Bash to improve security testing processes.Research emerging threats, vulnerabilities, and attack techniques affecting web applications and cloud-native environments.Track vulnerabilities through remediation and closure.What You BringBE/BTech in Computer Science, Information Security, Electronics, or a related field.2-4 years of experience in Application Security, Penetration Testing, Security Testing, or Offensive Security.Hands-on experience with Burp Suite, OWASP ZAP, Polaris, Black Duck (SCA), SonarQubeStrong understanding of: OWASP Top 10, API Security Top 10, Secure Coding Practices, Vulnerability Assessment and Penetration Testing (VAPT)Experience performing manual security testing of web applications and REST APIs.Working knowledge of AWS security concepts, including IAM, security groups, VPCs, secrets management, and access controls.Familiarity with SAST, DAST, and SCA methodologies.Basic understanding of threat modeling and attack surface analysis.Experience using Linux environments and security testing tools.Proficiency in Python, Bash, or other scripting languages.Strong analytical and problem-solving skills.Nice to HaveHands-on experience with red team exercises or adversary simulation activities.Exposure to MITRE ATT&CK framework.Experience with container and Kubernetes security testing.Knowledge of DevSecOps and CI/CD security practices.Experience participating in bug bounty programs or CTF competitions.Relevant certifications (Not Mandatory): OSCP & CEH Apply Apply Later ← Back to Current Openings Share lang: en_US Share LinkedIn Facebook Twitter Email Powered by Jobvite

Enphase Energy Careers { "@context": "http://schema.org", "@type": "JobPosting", "datePosted": "2026-06-21", "description": "

Enphase Energy is a global energy technology company and a leading provider of solar, battery, and electric vehicle charging products. Founded in 2006, our innovative microinverter technology revolutionized solar power, making it a safer, more reliable, and scalable energy source. Today, the Enphase Energy System enables users to make, use, save, and sell their own power. Enphase is also one of the most successful and innovative clean energy companies in the world, with more than 80 million products shipped across 160 countries. Join our dynamic teams designing and developing next-gen energy technologies and help drive a sustainable future!

This role at Enphase requires working onsite\u00A03 days a week, with plans to transition back to a full 5 day in office schedule over time.

Security Test Engineer

As a Security Test Engineer at Enphase Energy, you will help secure our applications, APIs, and AWS-based infrastructure that support millions of energy systems globally. Working closely with senior security engineers, you will perform security assessments, identify vulnerabilities, support remediation efforts, and contribute to offensive security initiatives.

This role is ideal for a security professional with a passion for penetration testing, application security, red teaming, and secure development practices.

What You Will Be Doing

  • Perform hands-on penetration testing of web applications, APIs, and backend services.
  • Conduct vulnerability assessments and security reviews of applications and AWS environments.
  • Use security testing tools such as Polaris, Black Duck (SCA), SonarQube, Burp Suite, and OWASP ZAP to identify and validate security issues.
  • Execute Static Application Security Testing (SAST), Software Composition Analysis (SCA), and Dynamic Application Security Testing (DAST) activities.
  • Validate security findings and work with engineering teams on remediation recommendations.
  • Assist in integrating security testing into CI/CD pipelines and support secure SDLC initiatives.
  • Perform AWS security assessments, including IAM reviews, privilege analysis, network security reviews, and configuration assessments.
  • Participate in threat modeling exercises and security architecture reviews.
  • Execute red team exercise and adversary emulation activities to identify real-world attack paths.
  • Develop scripts and automation using Python or Bash to improve security testing processes.
  • Research emerging threats, vulnerabilities, and attack techniques affecting web applications and cloud-native environments.
  • Track vulnerabilities through remediation and closure.


What You Bring

  • BE/BTech in Computer Science, Information Security, Electronics, or a related field.
  • 2-4 years of experience in Application Security, Penetration Testing, Security Testing, or Offensive Security.
  • Hands-on experience with Burp Suite,\u00A0OWASP ZAP,\u00A0Polaris,\u00A0Black Duck (SCA),\u00A0SonarQube
  • Strong understanding of:\u00A0OWASP Top 10, API Security Top 10, Secure Coding Practices, Vulnerability Assessment and Penetration Testing (VAPT)
  • Experience performing manual security testing of web applications and REST APIs.
  • Working knowledge of AWS security concepts, including IAM, security groups, VPCs, secrets management, and access controls.
  • Familiarity with SAST, DAST, and SCA methodologies.
  • Basic understanding of threat modeling and attack surface analysis.
  • Experience using Linux environments and security testing tools.
  • Proficiency in Python, Bash, or other scripting languages.
  • Strong analytical and problem-solving skills.


Nice to Have

  • Hands-on experience with red team exercises or adversary simulation activities.
  • Exposure to MITRE ATT&CK framework.
  • Experience with container and Kubernetes security testing.
  • Knowledge of DevSecOps and CI/CD security practices.
  • Experience participating in bug bounty programs or CTF competitions.
  • Relevant certifications (Not Mandatory): OSCP & CEH
", "hiringOrganization": "Enphase Energy", "employmentType": "Full Time Employee (Experienced)", "industry": "Engineering", "identifier": "ob5nAfwX", "jobLocation": [ { "@type": "Place", "address": { "@type": "PostalAddress", "addressCountry": "India" } } ], "title": "Security Test Engineer", "baseSalary": { "@type": "MonetaryAmount", "currency": "", "value": { "@type": "QuantitativeValue", "minValue": "", "maxValue": "", "unitText": "" } } } Security Test Engineer Engineering Bangalore, India Apply Description Enphase Energy is a global energy technology company and a leading provider of solar, battery, and electric vehicle charging products. Founded in 2006, our innovative microinverter technology revolutionized solar power, making it a safer, more reliable, and scalable energy source. Today, the Enphase Energy System enables users to make, use, save, and sell their own power. Enphase is also one of the most successful and innovative clean energy companies in the world, with more than 80 million products shipped across 160 countries. Join our dynamic teams designing and developing next-gen energy technologies and help drive a sustainable future!This role at Enphase requires working onsite 3 days a week, with plans to transition back to a full 5 day in office schedule over time.Security Test EngineerAs a Security Test Engineer at Enphase Energy, you will help secure our applications, APIs, and AWS-based infrastructure that support millions of energy systems globally. Working closely with senior security engineers, you will perform security assessments, identify vulnerabilities, support remediation efforts, and contribute to offensive security initiatives.This role is ideal for a security professional with a passion for penetration testing, application security, red teaming, and secure development practices.What You Will Be DoingPerform hands-on penetration testing of web applications, APIs, and backend services.Conduct vulnerability assessments and security reviews of applications and AWS environments.Use security testing tools such as Polaris, Black Duck (SCA), SonarQube, Burp Suite, and OWASP ZAP to identify and validate security issues.Execute Static Application Security Testing (SAST), Software Composition Analysis (SCA), and Dynamic Application Security Testing (DAST) activities.Validate security findings and work with engineering teams on remediation recommendations.Assist in integrating security testing into CI/CD pipelines and support secure SDLC initiatives.Perform AWS security assessments, including IAM reviews, privilege analysis, network security reviews, and configuration assessments.Participate in threat modeling exercises and security architecture reviews.Execute red team exercise and adversary emulation activities to identify real-world attack paths.Develop scripts and automation using Python or Bash to improve security testing processes.Research emerging threats, vulnerabilities, and attack techniques affecting web applications and cloud-native environments.Track vulnerabilities through remediation and closure.What You BringBE/BTech in Computer Science, Information Security, Electronics, or a related field.2-4 years of experience in Application Security, Penetration Testing, Security Testing, or Offensive Security.Hands-on experience with Burp Suite, OWASP ZAP, Polaris, Black Duck (SCA), SonarQubeStrong understanding of: OWASP Top 10, API Security Top 10, Secure Coding Practices, Vulnerability Assessment and Penetration Testing (VAPT)Experience performing manual security testing of web applications and REST APIs.Working knowledge of AWS security concepts, including IAM, security groups, VPCs, secrets management, and access controls.Familiarity with SAST, DAST, and SCA methodologies.Basic understanding of threat modeling and attack surface analysis.Experience using Linux environments and security testing tools.Proficiency in Python, Bash, or other scripting languages.Strong analytical and problem-solving skills.Nice to HaveHands-on experience with red team exercises or adversary simulation activities.Exposure to MITRE ATT&CK framework.Experience with container and Kubernetes security testing.Knowledge of DevSecOps and CI/CD security practices.Experience participating in bug bounty programs or CTF competitions.Relevant certifications (Not Mandatory): OSCP & CEH Apply Apply Later ← Back to Current Openings Share lang: en_US Share LinkedIn Facebook Twitter Email Powered by Jobvite

Enphase Energy Careers { "@context": "http://schema.org", "@type": "JobPosting", "datePosted": "2026-06-21", "description": "

Enphase Energy is a global energy technology company and a leading provider of solar, battery, and electric vehicle charging products. Founded in 2006, our innovative microinverter technology revolutionized solar power, making it a safer, more reliable, and scalable energy source. Today, the Enphase Energy System enables users to make, use, save, and sell their own power. Enphase is also one of the most successful and innovative clean energy companies in the world, with more than 80 million products shipped across 160 countries. Join our dynamic teams designing and developing next-gen energy technologies and help drive a sustainable future!

This role at Enphase requires working onsite\u00A03 days a week, with plans to transition back to a full 5 day in office schedule over time.

Security Test Engineer

As a Security Test Engineer at Enphase Energy, you will help secure our applications, APIs, and AWS-based infrastructure that support millions of energy systems globally. Working closely with senior security engineers, you will perform security assessments, identify vulnerabilities, support remediation efforts, and contribute to offensive security initiatives.

This role is ideal for a security professional with a passion for penetration testing, application security, red teaming, and secure development practices.

What You Will Be Doing

  • Perform hands-on penetration testing of web applications, APIs, and backend services.
  • Conduct vulnerability assessments and security reviews of applications and AWS environments.
  • Use security testing tools such as Polaris, Black Duck (SCA), SonarQube, Burp Suite, and OWASP ZAP to identify and validate security issues.
  • Execute Static Application Security Testing (SAST), Software Composition Analysis (SCA), and Dynamic Application Security Testing (DAST) activities.
  • Validate security findings and work with engineering teams on remediation recommendations.
  • Assist in integrating security testing into CI/CD pipelines and support secure SDLC initiatives.
  • Perform AWS security assessments, including IAM reviews, privilege analysis, network security reviews, and configuration assessments.
  • Participate in threat modeling exercises and security architecture reviews.
  • Execute red team exercise and adversary emulation activities to identify real-world attack paths.
  • Develop scripts and automation using Python or Bash to improve security testing processes.
  • Research emerging threats, vulnerabilities, and attack techniques affecting web applications and cloud-native environments.
  • Track vulnerabilities through remediation and closure.


What You Bring

  • BE/BTech in Computer Science, Information Security, Electronics, or a related field.
  • 2-4 years of experience in Application Security, Penetration Testing, Security Testing, or Offensive Security.
  • Hands-on experience with Burp Suite,\u00A0OWASP ZAP,\u00A0Polaris,\u00A0Black Duck (SCA),\u00A0SonarQube
  • Strong understanding of:\u00A0OWASP Top 10, API Security Top 10, Secure Coding Practices, Vulnerability Assessment and Penetration Testing (VAPT)
  • Experience performing manual security testing of web applications and REST APIs.
  • Working knowledge of AWS security concepts, including IAM, security groups, VPCs, secrets management, and access controls.
  • Familiarity with SAST, DAST, and SCA methodologies.
  • Basic understanding of threat modeling and attack surface analysis.
  • Experience using Linux environments and security testing tools.
  • Proficiency in Python, Bash, or other scripting languages.
  • Strong analytical and problem-solving skills.


Nice to Have

  • Hands-on experience with red team exercises or adversary simulation activities.
  • Exposure to MITRE ATT&CK framework.
  • Experience with container and Kubernetes security testing.
  • Knowledge of DevSecOps and CI/CD security practices.
  • Experience participating in bug bounty programs or CTF competitions.
  • Relevant certifications (Not Mandatory): OSCP & CEH
", "hiringOrganization": "Enphase Energy", "employmentType": "Full Time Employee (Experienced)", "industry": "Engineering", "identifier": "ob5nAfwX", "jobLocation": [ { "@type": "Place", "address": { "@type": "PostalAddress", "addressCountry": "India" } } ], "title": "Security Test Engineer", "baseSalary": { "@type": "MonetaryAmount", "currency": "", "value": { "@type": "QuantitativeValue", "minValue": "", "maxValue": "", "unitText": "" } } } Security Test Engineer Engineering Bangalore, India Apply Description Enphase Energy is a global energy technology company and a leading provider of solar, battery, and electric vehicle charging products. Founded in 2006, our innovative microinverter technology revolutionized solar power, making it a safer, more reliable, and scalable energy source. Today, the Enphase Energy System enables users to make, use, save, and sell their own power. Enphase is also one of the most successful and innovative clean energy companies in the world, with more than 80 million products shipped across 160 countries. Join our dynamic teams designing and developing next-gen energy technologies and help drive a sustainable future!This role at Enphase requires working onsite 3 days a week, with plans to transition back to a full 5 day in office schedule over time.Security Test EngineerAs a Security Test Engineer at Enphase Energy, you will help secure our applications, APIs, and AWS-based infrastructure that support millions of energy systems globally. Working closely with senior security engineers, you will perform security assessments, identify vulnerabilities, support remediation efforts, and contribute to offensive security initiatives.This role is ideal for a security professional with a passion for penetration testing, application security, red teaming, and secure development practices.What You Will Be DoingPerform hands-on penetration testing of web applications, APIs, and backend services.Conduct vulnerability assessments and security reviews of applications and AWS environments.Use security testing tools such as Polaris, Black Duck (SCA), SonarQube, Burp Suite, and OWASP ZAP to identify and validate security issues.Execute Static Application Security Testing (SAST), Software Composition Analysis (SCA), and Dynamic Application Security Testing (DAST) activities.Validate security findings and work with engineering teams on remediation recommendations.Assist in integrating security testing into CI/CD pipelines and support secure SDLC initiatives.Perform AWS security assessments, including IAM reviews, privilege analysis, network security reviews, and configuration assessments.Participate in threat modeling exercises and security architecture reviews.Execute red team exercise and adversary emulation activities to identify real-world attack paths.Develop scripts and automation using Python or Bash to improve security testing processes.Research emerging threats, vulnerabilities, and attack techniques affecting web applications and cloud-native environments.Track vulnerabilities through remediation and closure.What You BringBE/BTech in Computer Science, Information Security, Electronics, or a related field.2-4 years of experience in Application Security, Penetration Testing, Security Testing, or Offensive Security.Hands-on experience with Burp Suite, OWASP ZAP, Polaris, Black Duck (SCA), SonarQubeStrong understanding of: OWASP Top 10, API Security Top 10, Secure Coding Practices, Vulnerability Assessment and Penetration Testing (VAPT)Experience performing manual security testing of web applications and REST APIs.Working knowledge of AWS security concepts, including IAM, security groups, VPCs, secrets management, and access controls.Familiarity with SAST, DAST, and SCA methodologies.Basic understanding of threat modeling and attack surface analysis.Experience using Linux environments and security testing tools.Proficiency in Python, Bash, or other scripting languages.Strong analytical and problem-solving skills.Nice to HaveHands-on experience with red team exercises or adversary simulation activities.Exposure to MITRE ATT&CK framework.Experience with container and Kubernetes security testing.Knowledge of DevSecOps and CI/CD security practices.Experience participating in bug bounty programs or CTF competitions.Relevant certifications (Not Mandatory): OSCP & CEH Apply Apply Later ← Back to Current Openings Share lang: en_US Share LinkedIn Facebook Twitter Email Powered by Jobvite

{ "@context": "http://schema.org", "@type": "JobPosting", "datePosted": "2026-06-21", "description": "

Enphase Energy is a global energy technology company and a leading provider of solar, battery, and electric vehicle charging products. Founded in 2006, our innovative microinverter technology revolutionized solar power, making it a safer, more reliable, and scalable energy source. Today, the Enphase Energy System enables users to make, use, save, and sell their own power. Enphase is also one of the most successful and innovative clean energy companies in the world, with more than 80 million products shipped across 160 countries. Join our dynamic teams designing and developing next-gen energy technologies and help drive a sustainable future!

This role at Enphase requires working onsite\u00A03 days a week, with plans to transition back to a full 5 day in office schedule over time.

Security Test Engineer

As a Security Test Engineer at Enphase Energy, you will help secure our applications, APIs, and AWS-based infrastructure that support millions of energy systems globally. Working closely with senior security engineers, you will perform security assessments, identify vulnerabilities, support remediation efforts, and contribute to offensive security initiatives.

This role is ideal for a security professional with a passion for penetration testing, application security, red teaming, and secure development practices.

What You Will Be Doing

  • Perform hands-on penetration testing of web applications, APIs, and backend services.
  • Conduct vulnerability assessments and security reviews of applications and AWS environments.
  • Use security testing tools such as Polaris, Black Duck (SCA), SonarQube, Burp Suite, and OWASP ZAP to identify and validate security issues.
  • Execute Static Application Security Testing (SAST), Software Composition Analysis (SCA), and Dynamic Application Security Testing (DAST) activities.
  • Validate security findings and work with engineering teams on remediation recommendations.
  • Assist in integrating security testing into CI/CD pipelines and support secure SDLC initiatives.
  • Perform AWS security assessments, including IAM reviews, privilege analysis, network security reviews, and configuration assessments.
  • Participate in threat modeling exercises and security architecture reviews.
  • Execute red team exercise and adversary emulation activities to identify real-world attack paths.
  • Develop scripts and automation using Python or Bash to improve security testing processes.
  • Research emerging threats, vulnerabilities, and attack techniques affecting web applications and cloud-native environments.
  • Track vulnerabilities through remediation and closure.


What You Bring

  • BE/BTech in Computer Science, Information Security, Electronics, or a related field.
  • 2-4 years of experience in Application Security, Penetration Testing, Security Testing, or Offensive Security.
  • Hands-on experience with Burp Suite,\u00A0OWASP ZAP,\u00A0Polaris,\u00A0Black Duck (SCA),\u00A0SonarQube
  • Strong understanding of:\u00A0OWASP Top 10, API Security Top 10, Secure Coding Practices, Vulnerability Assessment and Penetration Testing (VAPT)
  • Experience performing manual security testing of web applications and REST APIs.
  • Working knowledge of AWS security concepts, including IAM, security groups, VPCs, secrets management, and access controls.
  • Familiarity with SAST, DAST, and SCA methodologies.
  • Basic understanding of threat modeling and attack surface analysis.
  • Experience using Linux environments and security testing tools.
  • Proficiency in Python, Bash, or other scripting languages.
  • Strong analytical and problem-solving skills.


Nice to Have

  • Hands-on experience with red team exercises or adversary simulation activities.
  • Exposure to MITRE ATT&CK framework.
  • Experience with container and Kubernetes security testing.
  • Knowledge of DevSecOps and CI/CD security practices.
  • Experience participating in bug bounty programs or CTF competitions.
  • Relevant certifications (Not Mandatory): OSCP & CEH
", "hiringOrganization": "Enphase Energy", "employmentType": "Full Time Employee (Experienced)", "industry": "Engineering", "identifier": "ob5nAfwX", "jobLocation": [ { "@type": "Place", "address": { "@type": "PostalAddress", "addressCountry": "India" } } ], "title": "Security Test Engineer", "baseSalary": { "@type": "MonetaryAmount", "currency": "", "value": { "@type": "QuantitativeValue", "minValue": "", "maxValue": "", "unitText": "" } } } Security Test Engineer Engineering Bangalore, India Apply Description Enphase Energy is a global energy technology company and a leading provider of solar, battery, and electric vehicle charging products. Founded in 2006, our innovative microinverter technology revolutionized solar power, making it a safer, more reliable, and scalable energy source. Today, the Enphase Energy System enables users to make, use, save, and sell their own power. Enphase is also one of the most successful and innovative clean energy companies in the world, with more than 80 million products shipped across 160 countries. Join our dynamic teams designing and developing next-gen energy technologies and help drive a sustainable future!This role at Enphase requires working onsite 3 days a week, with plans to transition back to a full 5 day in office schedule over time.Security Test EngineerAs a Security Test Engineer at Enphase Energy, you will help secure our applications, APIs, and AWS-based infrastructure that support millions of energy systems globally. Working closely with senior security engineers, you will perform security assessments, identify vulnerabilities, support remediation efforts, and contribute to offensive security initiatives.This role is ideal for a security professional with a passion for penetration testing, application security, red teaming, and secure development practices.What You Will Be DoingPerform hands-on penetration testing of web applications, APIs, and backend services.Conduct vulnerability assessments and security reviews of applications and AWS environments.Use security testing tools such as Polaris, Black Duck (SCA), SonarQube, Burp Suite, and OWASP ZAP to identify and validate security issues.Execute Static Application Security Testing (SAST), Software Composition Analysis (SCA), and Dynamic Application Security Testing (DAST) activities.Validate security findings and work with engineering teams on remediation recommendations.Assist in integrating security testing into CI/CD pipelines and support secure SDLC initiatives.Perform AWS security assessments, including IAM reviews, privilege analysis, network security reviews, and configuration assessments.Participate in threat modeling exercises and security architecture reviews.Execute red team exercise and adversary emulation activities to identify real-world attack paths.Develop scripts and automation using Python or Bash to improve security testing processes.Research emerging threats, vulnerabilities, and attack techniques affecting web applications and cloud-native environments.Track vulnerabilities through remediation and closure.What You BringBE/BTech in Computer Science, Information Security, Electronics, or a related field.2-4 years of experience in Application Security, Penetration Testing, Security Testing, or Offensive Security.Hands-on experience with Burp Suite, OWASP ZAP, Polaris, Black Duck (SCA), SonarQubeStrong understanding of: OWASP Top 10, API Security Top 10, Secure Coding Practices, Vulnerability Assessment and Penetration Testing (VAPT)Experience performing manual security testing of web applications and REST APIs.Working knowledge of AWS security concepts, including IAM, security groups, VPCs, secrets management, and access controls.Familiarity with SAST, DAST, and SCA methodologies.Basic understanding of threat modeling and attack surface analysis.Experience using Linux environments and security testing tools.Proficiency in Python, Bash, or other scripting languages.Strong analytical and problem-solving skills.Nice to HaveHands-on experience with red team exercises or adversary simulation activities.Exposure to MITRE ATT&CK framework.Experience with container and Kubernetes security testing.Knowledge of DevSecOps and CI/CD security practices.Experience participating in bug bounty programs or CTF competitions.Relevant certifications (Not Mandatory): OSCP & CEH Apply Apply Later ← Back to Current Openings Share lang: en_US Share LinkedIn Facebook Twitter Email

Security Test Engineer

Engineering Bangalore, India