Pooja Kaur
Senior QA Engineer - Security Testing Specialist · 7 years experience
Chandigarh, Punjab
[Your email] · [Your phone]
[Your LinkedIn URL] · [Your GitHub / Portfolio URL]
Professional Summary
- Expert QA Engineer with 7 years of experience in security testing and vulnerability assessment for web and mobile applications
- Proficient in automation testing using Selenium, Java, Python, and Playwright for comprehensive security validation
- Skilled in API testing, performance testing, and database security with SQL and DynamoDB
- Experienced in Agile environments, CI/CD integration with Jenkins and Azure DevOps, and REST Assured for secure API testing
- Knowledgeable in JavaScript, API automation, and test management for secure software development
- Familiar with regression testing, functional testing, and web services security validation
- Strong focus on quality assurance engineering, debugging, and secure application development practices
- Collaborative professional working with security teams to implement OWASP guidelines and compliance standards
Technical Skills
Work Experience
Senior QA Engineer - Security Testing Specialist
[Company name] · [Start date – End date]
7 years of specialized experience as a Security Tester and QA Engineer at cybersecurity firms in Chandigarh, focusing on web application security and compliance. Led security testing for 20+ projects, identifying and mitigating 500+ vulnerabilities, achieving 95% security compliance rate.
Responsibilities
- Design, develop, and execute comprehensive test plans and test cases for web, mobile, and API applications with security focus
- Develop and maintain automated test scripts using Selenium, Cypress, Playwright, and REST Assured for functional and security testing
- Perform manual testing including functional, regression, performance, and security testing to ensure software integrity
- Collaborate with cross-functional teams in Agile/Scrum environments to integrate security throughout the SDLC
- Integrate automated testing into CI/CD pipelines using Jenkins, GitHub Actions, and Azure DevOps
- Identify, document, and track defects and security vulnerabilities using JIRA, providing detailed analysis
- Conduct security testing using OWASP methodologies, Burp Suite, and other tools for vulnerability assessment
- Mentor junior QA engineers and lead knowledge sharing on security testing best practices
- Ensure compliance with QA methodologies, security standards, and regulatory requirements
- Work on specialized security testing for AI systems, mobile applications, and financial platforms
- Lead AI security testing: adversarial prompt injection red-teaming, OWASP LLM Top 10 compliance, LLM jailbreak testing, training data poisoning detection, AI supply chain security assessment, and model inversion attack testing using Garak and custom red-teaming frameworks
Project Experience
Healthcare Portal Security Assessment
Conducted comprehensive security testing for a patient management system, implementing OWASP guidelines and SAST/DAST scans. Identified and remediated critical vulnerabilities, ensuring HIPAA compliance and data protection. Technologies: Burp Suite, OWASP ZAP, Selenium, Python, Azure DevOps, SQL, REST Assured.
E-commerce Platform Security
Led security validation for an online marketplace handling payment processing, focusing on PCI DSS compliance and injection attack prevention. Integrated automated security tests into CI/CD pipelines. Technologies: JMeter, Java, Jenkins, AWS, Angular, Microservices, Penetration Testing Tools.
Fintech Mobile App Security
Performed security testing for a banking application, including mobile-specific threats and API security. Implemented threat modeling and automated security regression tests, reducing security incidents by 70%. Technologies: Playwright, Python, Pytest Framework, Azure DevOps, DynamoDB, Mobile Security Tools.
LLM Red-Teaming and OWASP LLM Top 10 Assessment
Led comprehensive security assessment of an enterprise LLM chatbot platform using Garak automated red-teaming tool, executing prompt injection attacks, jailbreak attempts, data exfiltration scenarios, and model inversion tests per OWASP LLM Top 10. Discovered 4 critical vulnerabilities including indirect prompt injection and training data leakage. Implemented automated AI security regression pipeline. Technologies: Garak, OWASP LLM Top 10, Prompt Injection Testing, LLM Red-Teaming, AI Jailbreak Testing, Adversarial ML Testing, Python, Burp Suite.
Education
B.Tech in Information Security from Punjab Engineering College, Chandigarh (2014-2018, 9.0 CGPA)
Certifications
Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), ISTQB Advanced Level - Security Testing, AWS Certified Security - Specialty
Achievements
Awarded "Security Excellence Award" for zero-breach record in healthcare project; Published research on "AI in Security Testing" at Cyber Security Conference; Led team that achieved SOC 2 Type II compliance