Staff QA Engineer
Job description
About the Role
You are the owner of the safety net for our edge security products, responsible for defining the test strategy that protects our users and infrastructure. You will coordinate closely with development and automation teams to ensure quality is built into every release, acting as the final gatekeeper before products reach production. The role demands a mindset that questions every assumption and challenges how other organizations approach testing, pushing the boundaries of conventional QA practices. You will innovate within the testing space, challenging established norms and exploring novel approaches to validate complex security features. This position requires a high level of ownership where you proactively identify risks and drive quality initiatives without waiting for direction. You will be instrumental in shaping the quality culture across the engineering organization through your actions and mentorship. The success of this role is measured by the robustness of the security validation suite and the confidence it provides to the release process.
Key Facts
-
Location: India
-
Engagement: Work-from-office / In-Office role
-
Compensation: Base salary of 225,000 USD per year
What you'll do
Design and execute automated validation suites specifically for Deep Packet Inspection (DPI) and secure traffic inspection across network layers two through seven, ensuring comprehensive coverage of protocol interactions. Execute real-world scenarios involving a complex mix of clients, routers, and cloud infrastructure to probe deep network interactions, protocol handling nuances, and edge case behaviors. Verify the accuracy of TLS/SSL inspection mechanisms and the correct classification of network traffic under varying conditions and loads. Craft detailed test patterns specifically designed to exercise the handling of malformed packets, evasive traffic tactics, and intricate intrusion detection mechanisms with precision. Simulate sophisticated security vulnerabilities such as DNS tunneling, spoofing attempts, and aggressive port scanning to rigorously measure the efficacy and reliability of our detection systems. Extend the utilization of DPI tools like nDPI, Suricata, and Zeek to build custom validation scenarios, expand test coverage, and explore undocumented features or edge behaviors. Collaborate extensively with firmware developers to verify and validate access control logic embedded within device firmware, ensuring seamless integration between hardware and security policies. Drive the development of regression suites and observability frameworks to ensure that fixes for security issues do not introduce regressions in performance, stability, or user experience. Analyze vast quantities of data from test runs, identifying trends, anomalies, and systemic issues that require attention from development or product teams. Serve as a subject matter expert for edge security testing, mentoring other team members and establishing best practices for the organization.
Requirements
Candidates must bring a minimum of 10+ years of hands-on experience as an SDET, Security QA Engineer, or a similar role intensely focused on networking security and product validation. Proven ability to script and automate tests using Python for complex protocols and edge device scenarios is a strict prerequisite for success in this position. A deep, comprehensive understanding of TCP/IP, UDP, DNS, TLS, HTTP/HTTPS, NAT, VPNs, and various tunneling protocols is mandatory and non-negotiable. Hands-on experience with packet sniffers like Wireshark and the analysis of PCAP files to diagnose intricate issues is absolutely essential for this role. A solid comprehension of firewall behavior, DPI concepts, SSL inspection techniques, and secure communication protocols is expected at an advanced level. The ideal candidate must possess the ability to spot subtle design flaws, elusive race conditions, and hidden performance bottlenecks within complex distributed architectures and microservices. You must possess the ability to creatively break software systems in controlled environments to uncover meaningful defects, risk patterns, and potential security exposures. A methodical approach to testing is required, with the discipline to reproduce bugs, isolate variables, and document findings with extreme clarity and detail. Strong written and verbal communication skills are necessary to articulate complex technical issues to both technical and non-technical stakeholders effectively. The ability to work independently with minimal supervision while managing multiple priorities and deadlines in a fast-paced environment is critical.
Nice to have
Experience with nDPI, Suricata, or commercial DPI stacks for test automation represents a significant advantage and will accelerate your contribution to the team. Backgrounds in MITM techniques and threat simulation frameworks are highly desirable for creating realistic attack scenarios and validation tests. Candidates who have tested IoT or Wi-Fi edge devices such as OpenWRT, OpenSync, or embedded Linux environments will find this role a strong fit and alignment with their expertise. A background in cybersecurity, network security, or traffic classification provides a solid foundation for understanding the nuances of the products. Experience testing cloud-native networking products and associated observability pipelines, including metrics, logs, and traces, is also valued for a holistic testing perspective.
Practical notes
This is a work-from-office role based in Hyderabad, India. Please ensure you can commit to the expected in-office schedule as this role requires close collaboration with hardware and firmware teams. The compensation reflects the seniority and impact of the role, recognizing the critical responsibility in safeguarding the platform. The listed experience requirements are strict bars for consideration, and deviations cannot be accommodated. This position is integral to the security product line, and the successful candidate will directly influence the reliability and trustworthiness of the platform.