freiberufler Senior Test Automation Engineer / Pentester / SDET - Web, API, Embedded & Security Testing auf freelance.de

Senior Test Automation Engineer / Pentester / SDET - Web, API, Embedded & Security Testing

zuletzt online vor wenigen Stunden
  • 80‐150€/Stunde
  • Vilnius
  • Europa
  • ro  |  en  |  it  |  de
  • 06.06.2026
  • Contract ready

Kurzvorstellung

Cybersecurity Senior SOC Analyst, Penetration Tester, and Engineer with an MSc in Cybersecurity and extensive remote project experience spanning enterprise IT and embedded automotive security.

Geschäftsdaten

 Freiberuflich
 Steuernummer bekannt
 Berufshaftpflichtversicherung aktiv

Qualifikationen

  • Cybersecurirty
  • Embedded Entwicklung / hardwarenahe Entwicklung
  • Penetrationstest
  • Quality Assurance Engineer
  • risk assesment
  • Software engineering / -technik
  • Software Quality
  • System Validation
  • vulnerability assessment

Projekt‐ & Berufserfahrung

Lead Security Test Engineer / Lead Pentester
University of Arts London, UK, London
5/2024 – 5/2026 (2 Jahre, 1 Monat)
Hochschulen und Forschungseinrichtungen
Tätigkeitszeitraum

5/2024 – 5/2026

Tätigkeitsbeschreibung

Owned and led the internal security testing and penetration testing function, establishing repeatable processes for test planning, vulnerability validation, risk-based prioritization, reporting, remediation coordination and retesting.
• Owned and led the internal penetration testing and security validation function across web applications, APIs, cloud assets and infrastructure.
• Defined pentest scope, test approach, tooling, evidence standards and reporting structure for security testing activities.
• Planned, scoped and executed penetration tests across multiple web applications, APIs, cloud assets and externally exposed services.
• Designed security test scenarios covering authentication, authorisation, input validation, exposed services, insecure configurations, outdated components and externally reachable attack paths.
• Combined automated scanning with manual pentesting techniques to validate exploitability, reduce false positives and produce actionable findings.
• Assessed close to 1,000 infrastructure components, identifying and validating vulnerabilities across servers, endpoints, services, cloud assets, network exposure and security controls.
• Used Burp Suite, OWASP ZAP, AppCheck, Pentera, Nuclei, OpenVAS/GVM, Nmap, Metasploit, Tenable and Tanium to discover, reproduce, validate and document security defects.
• Designed and built a risk scoring platform to calculate organization-specific risk scores for vulnerabilities identified through scans, penetration tests and manual validation.
• Converted raw vulnerability findings into risk-based remediation priorities using organizational context, asset criticality, exposure, exploitability and business impact.
• Managed the vulnerability lifecycle from discovery and validation through prioritization, remediation coordination, retesting and closure.
• Produced detailed pentest reports with reproduction steps, affected assets, proof-of-concept evidence, impact analysis, risk rating and remediation guidance.
• Coordinated with application, infrastructure and security teams to retest fixes, verify remediation effectiveness and reduce recurring security defects.
• Established repeatable workflows for scanning, manual validation, defect reporting, risk scoring, retesting and vulnerability closure.

Tools: AppCheck, Pentera, Burp Suite, OWASP ZAP, Nuclei, OpenVAS/GVM, Nmap, Metasploit, Amass, Tenable/Nessus, Tanium, CrowdStrike Falcon NG-SIEM/SOAR/XDR, Microsoft Defender, Azure, Entra ID, AWS, Varonis, Rubrik, BeyondTrust, Wireshark.

Eingesetzte Qualifikationen

Cyber Security Engineer

SDET / Test Automation & Security Testing Engineer May 2023 - May 2024
EveryoneTV, London, UK / Remote, London
5/2023 – 5/2024 (1 Jahr, 1 Monat)
Konsumgüterindustrie
Tätigkeitszeitraum

5/2023 – 5/2024

Tätigkeitsbeschreibung

SDET role focused on web, API, backend, device and security-aware testing for television and media platforms. Role based in London, with full remote working possible.
• Designed and executed automated tests for backend services, APIs, web applications and connected TV products.
• Automated API and backend validation using Postman, BlazeMeter and custom Python/JavaScript scripts.
• Tested REST and GraphQL services for reliability, responsiveness, regression behaviour and security weaknesses.
• Automated web application testing using Cypress, Selenium, Playwright and Puppeteer.
• Integrated automated checks into Jenkins and GCP-based workflows to support continuous validation.
• Conducted API and web application security testing using Burp Suite, OWASP ZAP, Postman and Wireshark.
• Identified vulnerabilities including authentication flaws, injection points, misconfigurations and insecure backend behaviours.
• Supported Splunk-based logging, dashboards and alerting to improve observability, troubleshooting and security monitoring.

Tools: Python, JavaScript, Postman, BlazeMeter, Jenkins, GCP, REST, GraphQL, Cypress, Selenium, Playwright, Puppeteer, Burp Suite, OWASP ZAP, Wireshark, Splunk, Jira

Eingesetzte Qualifikationen

Test Automation, Test Management

Security Test Automation Engineer
Continental Automotive, Frankfurt
10/2022 – 10/2023 (1 Jahr, 1 Monat)
Automobilindustrie
Tätigkeitszeitraum

10/2022 – 10/2023

Tätigkeitsbeschreibung

Remote freelance engagement for end customer Continental Automotive, delivered via Valantic GmbH, focused on automated validation of embedded ECU security and flashing workflows.
• Analysed ECU security test requirements and translated them into structured, traceable test specifications.
• Authored detailed test case descriptions and maintained requirements traceability in IBM DOORS.
• Automated validation of ECU flashing and OTA update workflows using Python, Robot Framework and Lauterbach PRACTICE.
• Developed automated checks focused on secure flashing, update robustness, diagnostic behaviour and repeatable embedded validation.
• Used Vector CANoe, ODIS, Wireshark and Lauterbach Debugger to validate embedded system behaviour and diagnose defects.
• Managed test execution, defect evidence, result analysis and technical reporting.
• Supported Agile/Scrum delivery using Jira and Confluence in a distributed remote environment.

Tools: Python, Robot Framework, Lauterbach PRACTICE, Lauterbach Debugger, Vector CANoe, ODIS, Wireshark, IBM DOORS, Jira, Confluence, Agile/Scrum

Eingesetzte Qualifikationen

Cyber Security, Test Automation

Test Automation Engineer / SDET
Digital UK, London
1/2022 – 5/2023 (1 Jahr, 5 Monate)
High-Tech- und Elektroindustrie
Tätigkeitszeitraum

1/2022 – 5/2023

Tätigkeitsbeschreibung

Test automation role focused on enhanced parallelization of device, applications and services assessments. Role based in London, with full remote working possible.
• Designed and deployed a parallel automated test system capable of executing system-level tests across multiple physical devices.
• Built and commissioned a physical test rack supporting parallel validation of up to 16 devices.
• Integrated physical test equipment with supporting test services and applications, both on-premise and in cloud environments.
• Automated result collection, storage and reporting into TestRail and GCP.
• Reduced manual regression effort by up to 95% through automation of execution, data collection and reporting.
• Expanded automated test coverage by approximately 5x through new web, device, API, regression and security-aware test suites.
• Automated web application tests using Selenium, Cypress and Playwright.
• Conducted vulnerability and risk assessments on connected devices and cloud products using Nmap and Wireshark.

Tools: Python, JavaScript, Selenium, Cypress, Playwright, Postman, GCP, Jenkins, TestRail, Nmap, Wireshark, Jira, Confluence

Eingesetzte Qualifikationen

Test Automation

QA Automation Specialist
Freesat Ltd, London
4/2020 – 1/2022 (1 Jahr, 10 Monate)
High-Tech- und Elektroindustrie
Tätigkeitszeitraum

4/2020 – 1/2022

Tätigkeitsbeschreibung

QA automation role focused on consumer electronics, set-top-box testing, embedded applications and backend services validation, AV capture automation and performance testing. Hybrid role based from the London office.
• Automated system-level validation of set-top-box and media platforms by simulating end-user behaviour.
• Automated UI-level testing using AV capture processing, Python, Lua and the Test Wizard suite.
• Developed automated checks for consumer electronics user journeys, device responsiveness, stability and regression behaviour.
• Conducted backend service testing using Postman.
• Analysed network traffic using Wireshark to investigate communication issues and potential security concerns.
• Developed Python/OpenCV-based performance test scripts to measure responsiveness and detect regressions.
• Designed and executed stress, load and spike tests to validate system stability under demanding conditions.
• Automated storage and management of test results in GCP and TestRail.

Tools: Python, Lua, Test Wizard, AV capture tools, Postman, Wireshark, OpenCV, GCP, TestRail, Bash, Jira

Eingesetzte Qualifikationen

Qualitätsmanagement / QS / QA (IT), Test Automation

Software Test & Validation Engineer
Ford Motor Company, Dunton, Essex
4/2014 – 3/2020 (6 Jahre)
Automobilindustrie
Tätigkeitszeitraum

4/2014 – 3/2020

Tätigkeitsbeschreibung

Embedded automotive validation role focused on IC and mHEV powertrain systems, HiL testing, battery modelling, motor testing, automation, data analysis and reporting.
• Automated HiL test execution, data analysis and reporting for IC and mHEV powertrain systems.
• Used dSPACE, Python, Matlab/Simulink and Vector CANalyzer to validate real-time embedded automotive systems.
• Conducted manual and automated validation in HiL environments.
• Developed and maintained validation workflows for embedded control systems.
• Created scripts to automate execution, data processing and reporting of test results.
• Developed LiFePO4 battery models in Matlab/Simulink and validated model behaviour against real-world test data.
• Analysed starter motor test data to verify performance, reliability and compliance with expected behaviour.

Tools: Python, dSPACE, Matlab/Simulink, Vector CANalyzer, HiL, data analysis tools, embedded automotive systems

Eingesetzte Qualifikationen

Softwaretester, Test Automation, Validierungsingenieur

Model-Based & Embedded Software Development Engineer
Continental Automotive, Iasi
8/2011 – 3/2014 (2 Jahre, 8 Monate)
Automobilindustrie
Tätigkeitszeitraum

8/2011 – 3/2014

Tätigkeitsbeschreibung

Embedded software and model-based development role with strong testing, validation and simulation responsibilities for automotive control software.
• Developed test scripts for multiple validation stages including MiL, SiL and PiL.
• Executed unit, module, integration and hardware-level tests for embedded automotive software.
• Used BTC Embedded Tester and TPT for model-based and embedded software validation.
• Managed software requirements and traceability using Rational DOORS.
• Adjusted TargetLink models to meet development and testing requirements.
• Generated embedded C code for target platforms and authored embedded C code based on functional specifications.
• Developed and maintained Vector CANoe rest-bus simulations and acted as an internal trainer for Vector CANoe.

Tools: Embedded C, TargetLink, Rational DOORS, BTC Embedded Tester, TPT, Vector CANoe, MiL, SiL, PiL, automotive embedded systems

Eingesetzte Qualifikationen

Softwareentwickler, Testdesign (IT)

Ausbildung

Cybersecurity
MSc
Northumbria University
2023
London

Über mich

Senior Test Automation Engineer / SDET with 10+ years of experience designing, building and maintaining automated validation solutions across web applications, APIs, backend services, embedded automotive systems, cloud-connected platforms and consumer electronics. Strong hands-on automation background with Python, JavaScript, Robot Framework, Selenium, Cypress, Playwright, Puppeteer, Postman, Jenkins, TestRail and automotive validation toolchains including Vector, dSPACE, Matlab/Simulink, Lauterbach and ODIS. Experienced in building test infrastructure from scratch, extending commercial automation platforms, enabling parallel execution across physical devices, automating result collection and integrating tests into CI/CD workflows. Recent cybersecurity experience adds strong capability in security-aware testing, API security validation, web application pentesting, infrastructure vulnerability assessment and risk-based test design. EU citizen, fluent in English, available immediately for fully remote freelance and contract roles across Europe.

Weitere Kenntnisse

CORE EXPERTISE
Test Automation Engineering / SDET
Security Test Engineering
Penetration Testing Leadership
Web Application Security Testing
API Security Testing
Vulnerability Validation
Web UI Automation
API and Backend Testing
Test Infrastructure Design
CI/CD Test Integration
Parallel Test Execution
Automated Reporting
Embedded and Automotive Validation
HiL / MiL / SiL / PiL Testing
Performance, Load, Stress and Spike Testing
Attack Surface Assessment
Remediation Verification & Retesting
Remote Agile Delivery

TECHNICAL SKILLS
Security Assessments and Penetration Testing: Pentera BAS, AppCheck, Burp Suite, OWASP ZAP, Nmap, Wireshark, Nuclei, Tenable (Nessus), OpenVAS/GVM, Metasploit, vulnerability validation
Test Automation: Python, JavaScript, TypeScript, Robot Framework, Selenium, Cypress, Playwright, Puppeteer, pytest, Test Wizard, Lua, Bash, PowerShell, custom scripting
API & Backend Testing: Postman, BlazeMeter, REST APIs, GraphQL, API security testing, OWASP API Top 10, backend validation
CI/CD & Reporting: Jenkins, GCP, TestRail, Jira, Confluence, automated result collection, test reporting, cloud-based validation workflows
Embedded & Automotive: Vector CANoe, CANalyzer, CANape, dSPACE, Matlab/Simulink, Lauterbach, ODIS, IBM DOORS, Rational DOORS, HiL, MiL, SiL, PiL, ECU flashing, OTA validation
Security Testing:
Cloud & Platforms: GCP, AWS, Azure, Linux, Windows, macOS
Development: Embedded C, C, C++, JavaScript, Python, Java, PHP, Kotlin, SQL, Bash, PowerShell

Persönliche Daten

Sprache
  • Rumänisch (Muttersprache)
  • Englisch (Fließend)
  • Italienisch (Gut)
  • Deutsch (Grundkenntnisse)
Reisebereitschaft
Europa
Arbeitserlaubnis
  • Europäische Union
Home-Office
bevorzugt
Profilaufrufe
1827
Berufserfahrung
14 Jahre und 10 Monate (seit 08/2011)

Kontaktdaten

Nur registrierte PREMIUM-Mitglieder von freelance.de können Kontaktdaten einsehen.

Jetzt Mitglied werden