Skip to main content
Posted 03 August, 2026

Security Test Engineer

Enphase Energy
India Full Time
Reference: 62_162348_ob5nAfwX

Enphase Energy is a global energy technology company and a leading provider of solar, battery, and electric vehicle charging products. Founded in 2006, our innovative microinverter technology revolutionized solar power, making it a safer, more reliable, and scalable energy source. Today, the Enphase Energy System enables users to make, use, save, and sell their own power. Enphase is also one of the most successful and innovative clean energy companies in the world, with more than 80 million products shipped across 160 countries. Join our dynamic teams designing and developing next-gen energy technologies and help drive a sustainable future!

This role at Enphase requires working onsite3 days a week, with plans to transition back to a full 5 day in office schedule over time.

Security Test Engineer

As a Security Test Engineer at Enphase Energy, you will help secure our applications, APIs, and AWS-based infrastructure that support millions of energy systems globally. Working closely with senior security engineers, you will perform security assessments, identify vulnerabilities, support remediation efforts, and contribute to offensive security initiatives.

This role is ideal for a security professional with a passion for penetration testing, application security, red teaming, and secure development practices.

What You Will Be Doing

  • Perform hands-on penetration testing of web applications, APIs, and backend services.
  • Conduct vulnerability assessments and security reviews of applications and AWS environments.
  • Use security testing tools such as Polaris, Black Duck (SCA), SonarQube, Burp Suite, and OWASP ZAP to identify and validate security issues.
  • Execute Static Application Security Testing (SAST), Software Composition Analysis (SCA), and Dynamic Application Security Testing (DAST) activities.
  • Validate security findings and work with engineering teams on remediation recommendations.
  • Assist in integrating security testing into CI/CD pipelines and support secure SDLC initiatives.
  • Perform AWS security assessments, including IAM reviews, privilege analysis, network security reviews, and configuration assessments.
  • Participate in threat modeling exercises and security architecture reviews.
  • Execute red team exercise and adversary emulation activities to identify real-world attack paths.
  • Develop scripts and automation using Python or Bash to improve security testing processes.
  • Research emerging threats, vulnerabilities, and attack techniques affecting web applications and cloud-native environments.
  • Track vulnerabilities through remediation and closure.


What You Bring

  • BE/BTech in Computer Science, Information Security, Electronics, or a related field.
  • 2-4 years of experience in Application Security, Penetration Testing, Security Testing, or Offensive Security.
  • Hands-on experience with Burp Suite,OWASP ZAP,Polaris,Black Duck (SCA),SonarQube
  • Strong understanding of:OWASP Top 10, API Security Top 10, Secure Coding Practices, Vulnerability Assessment and Penetration Testing (VAPT)
  • Experience performing manual security testing of web applications and REST APIs.
  • Working knowledge of AWS security concepts, including IAM, security groups, VPCs, secrets management, and access controls.
  • Familiarity with SAST, DAST, and SCA methodologies.
  • Basic understanding of threat modeling and attack surface analysis.
  • Experience using Linux environments and security testing tools.
  • Proficiency in Python, Bash, or other scripting languages.
  • Strong analytical and problem-solving skills.


Nice to Have

  • Hands-on experience with red team exercises or adversary simulation activities.
  • Exposure to MITRE ATT&CK framework.
  • Experience with container and Kubernetes security testing.
  • Knowledge of DevSecOps and CI/CD security practices.
  • Experience participating in bug bounty programs or CTF competitions.
  • Relevant certifications (Not Mandatory): OSCP & CEH
Employment Type: Full Time Employee (Experienced)

Sign up for Job Alerts