Software Staff Engineer

Engineering Bangalore , Karnataka,

We are seeking an exceptional Staff Software Engineer in Test to join our Web Application Firewall (WAF) team as a quality leader and technical architect. This critical role combines deep QA expertise with customer-facing responsibilities, serving as the quality champion for our enterprise customers and engineering teams. You will be the go-to expert for complex customer quality escalations, test architecture, and ensuring our WAF solutions meet the highest standards of reliability, security, and performance.

As a Staff QA Engineer on the WAF team, you'll work at the intersection of quality assurance, cybersecurity, and customer success. You'll design comprehensive test strategies for complex security scenarios, validate customer deployments, debug production quality issues, and ensure our enterprise customers can deploy our WAF with confidence. This role requires someone who can think strategically about quality architecture while being hands-on enough to write test code, analyze test results, and investigate customer-reported issues.


Responsibilities:

Quality Architecture & Test Strategy Leadership 

  • Design and architect comprehensive test strategies for WAF security rules, threat detection, and attack mitigation capabilities
  • Define quality standards, testing methodologies, and acceptance criteria for enterprise-grade WAF deployments
  • Create test frameworks and automation infrastructure for functional, security, performance, and integration testing
  • Develop reference test architectures for various deployment scenarios (cloud, on-premise, hybrid, multi-CDN)
  • Lead test strategy reviews and provide guidance on test coverage, regression testing, and quality metrics
  • Establish best practices for security testing, including OWASP Top 10 validation, false positive/negative testing, and attack simulation

 Enterprise Customer Quality Support & Escalations 

  • Serve as the primary quality escalation point for critical enterprise customer issues and deployment challenges
  • Conduct deep-dive investigations into customer-reported bugs, performance degradations, false positives/negatives, and configuration issues
  • Work directly with customer security, QA, and DevOps teams to validate WAF deployments, reproduce issues, and verify fixes
  • Design and execute customer-specific test scenarios to validate WAF configurations before production deployment
  • Provide technical QA expertise during customer war rooms, helping troubleshoot and validate fixes for security incidents
  • Build strong relationships with enterprise customers, becoming their trusted advisor for quality and testing practices

Security & Network Testing Expertise 

  • Design and execute comprehensive security test cases for OWASP Top 10, zero-day vulnerabilities, and emerging attack vectors
  • Validate WAF detection capabilities against real-world attack patterns, payloads, and evasion techniques
  • Develop test harnesses for complex networking scenarios across Layer 3-7, including TLS/SSL, HTTP/2, WebSockets, gRPC, and HTTP/3
  • Create automated tests for DDoS mitigation, bot detection, API security, and application-layer attack scenarios
  • Validate WAF performance under various load conditions, attack patterns, and traffic profiles
  • Test edge cases involving protocol violations, malformed requests, and RFC compliance
  • Collaborate with security research teams to translate threat intelligence into comprehensive test coverage

Test Automation & Tooling Development 

  • Build and maintain robust test automation frameworks for WAF rule testing, traffic replay, and attack simulation
  • Develop tools for log analysis, metrics collection, and automated validation of security events
  • Create performance testing infrastructure to validate WAF throughput, latency, and resource utilization at scale
  • Implement CI/CD test pipelines for continuous validation of WAF rules and detection capabilities
  • Design test data generation tools for creating realistic traffic patterns, attack payloads, and edge cases
  • Build customer environment simulation frameworks to reproduce production issues in test environments

Quality Leadership & Process Improvement 

  • Mentor QA engineers and developers on testing best practices, security testing, and quality methodologies
  • Drive quality metrics, defect analysis, and root cause investigations for production issues
  • Participate in design reviews to provide testability feedback and identify potential quality risks
  • Champion shift-left testing practices and test-driven development within the engineering team
  • Participate in on-call rotations for critical enterprise customer quality issues

Required Qualifications 

Experience 

  • 8+ years of software quality assurance and test engineering experience, with at least 3 years in security-focused testing roles
  • 3+ years testing WAF, firewalls, CDN, load balancers, reverse proxies, or similar security/networking products
  • Proven track record of handling enterprise customer quality escalations and validating complex deployments
  • Experience designing and implementing test automation frameworks for large-scale distributed systems
  • Strong background in customer-facing QA roles such as quality engineering for enterprise products, technical support, or solutions validation

Technical Skills 

Core Security & Networking Testing: 

  • Deep understanding of web application security testing including OWASP Top 10 validation, penetration testing methodologies, and vulnerability assessment
  • Expert-level knowledge of HTTP/HTTPS protocol testing, including header validation, state management, caching behavior, and RFC compliance testing
  • Strong understanding of TLS/SSL testing, including certificate validation, cipher suite testing, and security vulnerability verification
  • Proficiency with network protocol testing, TCP/IP validation, DNS testing, and packet-level analysis
  • Experience with security testing tools such as OWASP ZAP, Burp Suite, ModSecurity testing, vulnerability scanners, and fuzzing tools
  • Expertise in attack simulation and payload generation for injection attacks, XSS, CSRF, and other web vulnerabilities

Test Automation & Engineering: 

  • Strong programming skills in Python, Go, Java, or similar languages for test automation development
  • Experience building test frameworks using tools like pytest, JUnit, TestNG, Robot Framework, or custom solutions
  • Proficiency with API testing tools and frameworks (Postman, REST Assured, GraphQL testing)
  • Experience with performance testing tools (JMeter, Gatling, Locust, k6) and load generation at scale
  • Knowledge of CI/CD platforms (Jenkins, GitLab CI, GitHub Actions) and automated test integration
  • Familiarity with cloud platforms (AWS, Azure, GCP) and infrastructure-as-code for test environment provisioning
  • Experience with containerization (Docker, Kubernetes) for test environment management

Debugging & Analysis: 

  • Expertise using network analysis tools (Wireshark, tcpdump, mitmproxy, Charles Proxy) for traffic inspection and debugging
  • Proficiency with log analysis and correlation across distributed systems to investigate quality issues
  • Experience with performance profiling and identifying bottlenecks in high-throughput security systems
  • Ability to read and analyze network traces, application logs, and security events to reproduce and validate defects
  • Strong skills in test data analysis, metrics visualization, and quality reporting

QA Methodologies & Practices 

  • Expertise in black-box, white-box, and grey-box testing techniques
  • Strong understanding of exploratory testing, especially for security and edge case scenarios
  • Experience with regression testing strategies and test prioritization
  • Knowledge of test design techniques including boundary value analysis, equivalence partitioning, and state transition testing
  • Familiarity with quality metrics such as defect density, test coverage, escape rate, and mean time to detection

Soft Skills & Attributes 

  • Exceptional communication skills with the ability to explain quality issues and test results to both technical and non-technical audiences
  • Strong customer empathy and commitment to ensuring customer deployments meet quality standards
  • Detail-oriented with a passion for finding edge cases and potential failure scenarios
  • Calm under pressure during critical customer escalations and production quality incidents
  • Collaborative mindset with a track record of working effectively with development, security, and customer success teams
  • Self-directed with the ability to manage ambiguity and prioritize testing efforts effectively
  • Security-first mindset with a passion for protecting applications and ensuring security controls work as intended

Preferred Qualifications 

  • Experience with chaos engineering and resilience testing for distributed systems
  • Contributions to open-source testing tools or security testing frameworks
  • Relevant security certifications (CISSP, CEH, OSCP, GWAPT) or QA certifications (ISTQB Advanced/Expert)
  • Experience with compliance testing for PCI-DSS, SOC 2, HIPAA, GDPR and validating security controls
  • Background in penetration testing, red team operations, or security research
  • Experience with machine learning testing for security applications (bot detection, anomaly detection)
  • Understanding of API security testing patterns for REST, GraphQL, and gRPC protocols
  • Experience validating quality for Fortune 500 or Global 2000 enterprises 
  • Knowledge of threat modeling and using threat models to derive test scenarios

What You'll Work On 

  • Design comprehensive test strategies for WAF deployments protecting billions of requests daily
  • Validate and reproduce complex customer-reported security and performance issues
  • Build automated test suites for advanced rate limiting, bot mitigation, and API protection features
  • Develop performance test frameworks to validate WAF latency and throughput at enterprise scale
  • Create attack simulation tools to continuously validate WAF detection capabilities
  • Collaborate with product and engineering teams to improve testability and quality standards
  • Build test environments that accurately simulate customer production scenarios
  • Establish quality gates and release criteria for new WAF rules and features

Why Join Our Team 

  • Work on quality challenges at massive scale, ensuring world-class protection for critical web applications
  • Direct impact on customer success through quality excellence
  • Collaborative, quality-focused culture with opportunities for deep technical work
  • Opportunity to shape quality practices and work closely with enterprise customers
  • Competitive compensation, equity, and benefits package