Enter a job title or keyword

Security Test Engineer

Enphase Energy


Job Location:

Bengaluru - India

Monthly Salary: Not provided by the employer
Posted: 10 August 2026 (19 days ago)
Application Deadline: 25 November 2026
Vacancies: 1 Vacancy

Department:

Engineering

Job Summary

Description

Enphase Energy is a global energy technology company and a leading provider of solar battery and electric vehicle charging products. Founded in 2006 our innovative microinverter technology revolutionized solar power making it a safer more reliable and scalable energy source. Today the Enphase Energy System enables users to make use save and sell their own power. Enphase is also one of the most successful and innovative clean energy companies in the world with more than 80 million products shipped across 160 countries. Join our dynamic teams designing and developing next-gen energy technologies and help drive a sustainable future!

This role at Enphase requires working onsite3 days a week with plans to transition back to a full 5 day in office schedule over time.

Security Test Engineer

As a Security Test Engineer at Enphase Energy you will help secure our applications APIs and AWS-based infrastructure that support millions of energy systems globally. Working closely with senior security engineers you will perform security assessments identify vulnerabilities support remediation efforts and contribute to offensive security initiatives.

This role is ideal for a security professional with a passion for penetration testing application security red teaming and secure development practices.

What You Will Be Doing

  • Perform hands-on penetration testing of web applications APIs and backend services.
  • Conduct vulnerability assessments and security reviews of applications and AWS environments.
  • Use security testing tools such as Polaris Black Duck (SCA) SonarQube Burp Suite and OWASP ZAP to identify and validate security issues.
  • Execute Static Application Security Testing (SAST) Software Composition Analysis (SCA) and Dynamic Application Security Testing (DAST) activities.
  • Validate security findings and work with engineering teams on remediation recommendations.
  • Assist in integrating security testing into CI/CD pipelines and support secure SDLC initiatives.
  • Perform AWS security assessments including IAM reviews privilege analysis network security reviews and configuration assessments.
  • Participate in threat modeling exercises and security architecture reviews.
  • Execute red team exercise and adversary emulation activities to identify real-world attack paths.
  • Develop scripts and automation using Python or Bash to improve security testing processes.
  • Research emerging threats vulnerabilities and attack techniques affecting web applications and cloud-native environments.
  • Track vulnerabilities through remediation and closure.


What You Bring

  • BE/BTech in Computer Science Information Security Electronics or a related field.
  • 2-4 years of experience in Application Security Penetration Testing Security Testing or Offensive Security.
  • Hands-on experience with Burp SuiteOWASP ZAPPolarisBlack Duck (SCA)SonarQube
  • Strong understanding of:OWASP Top 10 API Security Top 10 Secure Coding Practices Vulnerability Assessment and Penetration Testing (VAPT)
  • Experience performing manual security testing of web applications and REST APIs.
  • Working knowledge of AWS security concepts including IAM security groups VPCs secrets management and access controls.
  • Familiarity with SAST DAST and SCA methodologies.
  • Basic understanding of threat modeling and attack surface analysis.
  • Experience using Linux environments and security testing tools.
  • Proficiency in Python Bash or other scripting languages.
  • Strong analytical and problem-solving skills.


Nice to Have

  • Hands-on experience with red team exercises or adversary simulation activities.
  • Exposure to MITRE ATT&CK framework.
  • Experience with container and Kubernetes security testing.
  • Knowledge of DevSecOps and CI/CD security practices.
  • Experience participating in bug bounty programs or CTF competitions.
  • Relevant certifications (Not Mandatory): OSCP & CEH

Required Experience:

IC


About Company

Enphase is a global energy management technology company that provides residential and commercial solar plus storage solutions. We manufacture solutions spanning solar generation, energy storage, and web-based monitoring and control.

View Profile View Profile