# Pooja Kaur

Senior QA Engineer - Security Testing Specialist | 7 years experience | Chandigarh, Punjab

Sample resume with fictional details. Replace the content with your own experience and qualifications.

Email: [Your email] | Phone: [Your phone]
LinkedIn: [Your LinkedIn URL] | GitHub / Portfolio: [Your portfolio URL]

## Professional Summary

- Expert QA Engineer with 7 years of experience in security testing and vulnerability assessment for web and mobile applications
- Proficient in automation testing using Selenium, Java, Python, and Playwright for comprehensive security validation
- Skilled in API testing, performance testing, and database security with SQL and DynamoDB
- Experienced in Agile environments, CI/CD integration with Jenkins and Azure DevOps, and REST Assured for secure API testing
- Knowledgeable in JavaScript, API automation, and test management for secure software development
- Familiar with regression testing, functional testing, and web services security validation
- Strong focus on quality assurance engineering, debugging, and secure application development practices
- Collaborative professional working with security teams to implement OWASP guidelines and compliance standards

## Technical Skills

Automation Testing, Manual Testing, API Testing, Selenium, Java, Python, Cypress, Playwright, QA, Software Testing, Agile, CI/CD, JIRA, Git, REST Assured, Performance Testing, Test Automation, JavaScript, API Automation, Test Management, Regression Testing, Functional Testing, Web Services, Version Control, Scrum, Application Development, Test Cases, SDLC, Quality Assurance Engineering, Debugging, Artificial Intelligence, Test Design, Web Designing, Shopify Testing, Mobile Testing, Web Testing, Quality Assurance, OCS, OM, SQL, DynamoDB, AWS, Angular, SAAS, QA Lead, UI Automation, OMS Testing, Ecommerce Testing, WMS Testing, QA Methodologies, QA Process, Fintech, JMeter, PySpark, Databricks, Data Warehouse Testing, Azure DevOps, System Testing, Pytest Framework, Distribution System, Microservices, Locust, Continuous Integration, Automation Framework, Web Technologies, Test Scripts, Coding, OWASP, Burp Suite, Penetration Testing, SAST, DAST

## Work Experience

### Senior QA Engineer - Security Testing Specialist

[Company name] | [Start date - End date]

7 years of specialized experience as a Security Tester and QA Engineer at cybersecurity firms in Chandigarh, focusing on web application security and compliance. Led security testing for 20+ projects, identifying and mitigating 500+ vulnerabilities, achieving 95% security compliance rate.

### Responsibilities

- Design, develop, and execute comprehensive test plans and test cases for web, mobile, and API applications with security focus
- Develop and maintain automated test scripts using Selenium, Cypress, Playwright, and REST Assured for functional and security testing
- Perform manual testing including functional, regression, performance, and security testing to ensure software integrity
- Collaborate with cross-functional teams in Agile/Scrum environments to integrate security throughout the SDLC
- Integrate automated testing into CI/CD pipelines using Jenkins, GitHub Actions, and Azure DevOps
- Identify, document, and track defects and security vulnerabilities using JIRA, providing detailed analysis
- Conduct security testing using OWASP methodologies, Burp Suite, and other tools for vulnerability assessment
- Mentor junior QA engineers and lead knowledge sharing on security testing best practices
- Ensure compliance with QA methodologies, security standards, and regulatory requirements
- Work on specialized security testing for AI systems, mobile applications, and financial platforms
- Lead AI security testing: adversarial prompt injection red-teaming, OWASP LLM Top 10 compliance, LLM jailbreak testing, training data poisoning detection, AI supply chain security assessment, and model inversion attack testing using Garak and custom red-teaming frameworks

## Project Experience

### Healthcare Portal Security Assessment

Conducted comprehensive security testing for a patient management system, implementing OWASP guidelines and SAST/DAST scans. Identified and remediated critical vulnerabilities, ensuring HIPAA compliance and data protection. Technologies: Burp Suite, OWASP ZAP, Selenium, Python, Azure DevOps, SQL, REST Assured.

### E-commerce Platform Security

Led security validation for an online marketplace handling payment processing, focusing on PCI DSS compliance and injection attack prevention. Integrated automated security tests into CI/CD pipelines. Technologies: JMeter, Java, Jenkins, AWS, Angular, Microservices, Penetration Testing Tools.

### Fintech Mobile App Security

Performed security testing for a banking application, including mobile-specific threats and API security. Implemented threat modeling and automated security regression tests, reducing security incidents by 70%. Technologies: Playwright, Python, Pytest Framework, Azure DevOps, DynamoDB, Mobile Security Tools.

### LLM Red-Teaming and OWASP LLM Top 10 Assessment

Led comprehensive security assessment of an enterprise LLM chatbot platform using Garak automated red-teaming tool, executing prompt injection attacks, jailbreak attempts, data exfiltration scenarios, and model inversion tests per OWASP LLM Top 10. Discovered 4 critical vulnerabilities including indirect prompt injection and training data leakage. Implemented automated AI security regression pipeline. Technologies: Garak, OWASP LLM Top 10, Prompt Injection Testing, LLM Red-Teaming, AI Jailbreak Testing, Adversarial ML Testing, Python, Burp Suite.

## Education

B.Tech in Information Security from Punjab Engineering College, Chandigarh (2014-2018, 9.0 CGPA)

## Certifications

Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), ISTQB Advanced Level - Security Testing, AWS Certified Security - Specialty

## Achievements

Awarded "Security Excellence Award" for zero-breach record in healthcare project; Published research on "AI in Security Testing" at Cyber Security Conference; Led team that achieved SOC 2 Type II compliance
