Senior Test Automation Engineer / Pentester / SDET - Web, API, Embedded & Security Testing
- Verfügbarkeit einsehen
- 0 Referenzen
- 80‐150€/Stunde
- Vilnius
- Europa
- ro | en | it | de
- 06.06.2026
- Contract ready
Kurzvorstellung
Geschäftsdaten
Qualifikationen
Projekt‐ & Berufserfahrung
5/2024 – 5/2026
Tätigkeitsbeschreibung
Owned and led the internal security testing and penetration testing function, establishing repeatable processes for test planning, vulnerability validation, risk-based prioritization, reporting, remediation coordination and retesting.
• Owned and led the internal penetration testing and security validation function across web applications, APIs, cloud assets and infrastructure.
• Defined pentest scope, test approach, tooling, evidence standards and reporting structure for security testing activities.
• Planned, scoped and executed penetration tests across multiple web applications, APIs, cloud assets and externally exposed services.
• Designed security test scenarios covering authentication, authorisation, input validation, exposed services, insecure configurations, outdated components and externally reachable attack paths.
• Combined automated scanning with manual pentesting techniques to validate exploitability, reduce false positives and produce actionable findings.
• Assessed close to 1,000 infrastructure components, identifying and validating vulnerabilities across servers, endpoints, services, cloud assets, network exposure and security controls.
• Used Burp Suite, OWASP ZAP, AppCheck, Pentera, Nuclei, OpenVAS/GVM, Nmap, Metasploit, Tenable and Tanium to discover, reproduce, validate and document security defects.
• Designed and built a risk scoring platform to calculate organization-specific risk scores for vulnerabilities identified through scans, penetration tests and manual validation.
• Converted raw vulnerability findings into risk-based remediation priorities using organizational context, asset criticality, exposure, exploitability and business impact.
• Managed the vulnerability lifecycle from discovery and validation through prioritization, remediation coordination, retesting and closure.
• Produced detailed pentest reports with reproduction steps, affected assets, proof-of-concept evidence, impact analysis, risk rating and remediation guidance.
• Coordinated with application, infrastructure and security teams to retest fixes, verify remediation effectiveness and reduce recurring security defects.
• Established repeatable workflows for scanning, manual validation, defect reporting, risk scoring, retesting and vulnerability closure.
Tools: AppCheck, Pentera, Burp Suite, OWASP ZAP, Nuclei, OpenVAS/GVM, Nmap, Metasploit, Amass, Tenable/Nessus, Tanium, CrowdStrike Falcon NG-SIEM/SOAR/XDR, Microsoft Defender, Azure, Entra ID, AWS, Varonis, Rubrik, BeyondTrust, Wireshark.
Cyber Security Engineer
5/2023 – 5/2024
Tätigkeitsbeschreibung
SDET role focused on web, API, backend, device and security-aware testing for television and media platforms. Role based in London, with full remote working possible.
• Designed and executed automated tests for backend services, APIs, web applications and connected TV products.
• Automated API and backend validation using Postman, BlazeMeter and custom Python/JavaScript scripts.
• Tested REST and GraphQL services for reliability, responsiveness, regression behaviour and security weaknesses.
• Automated web application testing using Cypress, Selenium, Playwright and Puppeteer.
• Integrated automated checks into Jenkins and GCP-based workflows to support continuous validation.
• Conducted API and web application security testing using Burp Suite, OWASP ZAP, Postman and Wireshark.
• Identified vulnerabilities including authentication flaws, injection points, misconfigurations and insecure backend behaviours.
• Supported Splunk-based logging, dashboards and alerting to improve observability, troubleshooting and security monitoring.
Tools: Python, JavaScript, Postman, BlazeMeter, Jenkins, GCP, REST, GraphQL, Cypress, Selenium, Playwright, Puppeteer, Burp Suite, OWASP ZAP, Wireshark, Splunk, Jira
Test Automation, Test Management
10/2022 – 10/2023
Tätigkeitsbeschreibung
Remote freelance engagement for end customer Continental Automotive, delivered via Valantic GmbH, focused on automated validation of embedded ECU security and flashing workflows.
• Analysed ECU security test requirements and translated them into structured, traceable test specifications.
• Authored detailed test case descriptions and maintained requirements traceability in IBM DOORS.
• Automated validation of ECU flashing and OTA update workflows using Python, Robot Framework and Lauterbach PRACTICE.
• Developed automated checks focused on secure flashing, update robustness, diagnostic behaviour and repeatable embedded validation.
• Used Vector CANoe, ODIS, Wireshark and Lauterbach Debugger to validate embedded system behaviour and diagnose defects.
• Managed test execution, defect evidence, result analysis and technical reporting.
• Supported Agile/Scrum delivery using Jira and Confluence in a distributed remote environment.
Tools: Python, Robot Framework, Lauterbach PRACTICE, Lauterbach Debugger, Vector CANoe, ODIS, Wireshark, IBM DOORS, Jira, Confluence, Agile/Scrum
Cyber Security, Test Automation
1/2022 – 5/2023
Tätigkeitsbeschreibung
Test automation role focused on enhanced parallelization of device, applications and services assessments. Role based in London, with full remote working possible.
• Designed and deployed a parallel automated test system capable of executing system-level tests across multiple physical devices.
• Built and commissioned a physical test rack supporting parallel validation of up to 16 devices.
• Integrated physical test equipment with supporting test services and applications, both on-premise and in cloud environments.
• Automated result collection, storage and reporting into TestRail and GCP.
• Reduced manual regression effort by up to 95% through automation of execution, data collection and reporting.
• Expanded automated test coverage by approximately 5x through new web, device, API, regression and security-aware test suites.
• Automated web application tests using Selenium, Cypress and Playwright.
• Conducted vulnerability and risk assessments on connected devices and cloud products using Nmap and Wireshark.
Tools: Python, JavaScript, Selenium, Cypress, Playwright, Postman, GCP, Jenkins, TestRail, Nmap, Wireshark, Jira, Confluence
Test Automation
4/2020 – 1/2022
Tätigkeitsbeschreibung
QA automation role focused on consumer electronics, set-top-box testing, embedded applications and backend services validation, AV capture automation and performance testing. Hybrid role based from the London office.
• Automated system-level validation of set-top-box and media platforms by simulating end-user behaviour.
• Automated UI-level testing using AV capture processing, Python, Lua and the Test Wizard suite.
• Developed automated checks for consumer electronics user journeys, device responsiveness, stability and regression behaviour.
• Conducted backend service testing using Postman.
• Analysed network traffic using Wireshark to investigate communication issues and potential security concerns.
• Developed Python/OpenCV-based performance test scripts to measure responsiveness and detect regressions.
• Designed and executed stress, load and spike tests to validate system stability under demanding conditions.
• Automated storage and management of test results in GCP and TestRail.
Tools: Python, Lua, Test Wizard, AV capture tools, Postman, Wireshark, OpenCV, GCP, TestRail, Bash, Jira
Qualitätsmanagement / QS / QA (IT), Test Automation
4/2014 – 3/2020
Tätigkeitsbeschreibung
Embedded automotive validation role focused on IC and mHEV powertrain systems, HiL testing, battery modelling, motor testing, automation, data analysis and reporting.
• Automated HiL test execution, data analysis and reporting for IC and mHEV powertrain systems.
• Used dSPACE, Python, Matlab/Simulink and Vector CANalyzer to validate real-time embedded automotive systems.
• Conducted manual and automated validation in HiL environments.
• Developed and maintained validation workflows for embedded control systems.
• Created scripts to automate execution, data processing and reporting of test results.
• Developed LiFePO4 battery models in Matlab/Simulink and validated model behaviour against real-world test data.
• Analysed starter motor test data to verify performance, reliability and compliance with expected behaviour.
Tools: Python, dSPACE, Matlab/Simulink, Vector CANalyzer, HiL, data analysis tools, embedded automotive systems
Softwaretester, Test Automation, Validierungsingenieur
8/2011 – 3/2014
Tätigkeitsbeschreibung
Embedded software and model-based development role with strong testing, validation and simulation responsibilities for automotive control software.
• Developed test scripts for multiple validation stages including MiL, SiL and PiL.
• Executed unit, module, integration and hardware-level tests for embedded automotive software.
• Used BTC Embedded Tester and TPT for model-based and embedded software validation.
• Managed software requirements and traceability using Rational DOORS.
• Adjusted TargetLink models to meet development and testing requirements.
• Generated embedded C code for target platforms and authored embedded C code based on functional specifications.
• Developed and maintained Vector CANoe rest-bus simulations and acted as an internal trainer for Vector CANoe.
Tools: Embedded C, TargetLink, Rational DOORS, BTC Embedded Tester, TPT, Vector CANoe, MiL, SiL, PiL, automotive embedded systems
Softwareentwickler, Testdesign (IT)
Ausbildung
Northumbria University
London
Über mich
Weitere Kenntnisse
Test Automation Engineering / SDET
Security Test Engineering
Penetration Testing Leadership
Web Application Security Testing
API Security Testing
Vulnerability Validation
Web UI Automation
API and Backend Testing
Test Infrastructure Design
CI/CD Test Integration
Parallel Test Execution
Automated Reporting
Embedded and Automotive Validation
HiL / MiL / SiL / PiL Testing
Performance, Load, Stress and Spike Testing
Attack Surface Assessment
Remediation Verification & Retesting
Remote Agile Delivery
TECHNICAL SKILLS
Security Assessments and Penetration Testing: Pentera BAS, AppCheck, Burp Suite, OWASP ZAP, Nmap, Wireshark, Nuclei, Tenable (Nessus), OpenVAS/GVM, Metasploit, vulnerability validation
Test Automation: Python, JavaScript, TypeScript, Robot Framework, Selenium, Cypress, Playwright, Puppeteer, pytest, Test Wizard, Lua, Bash, PowerShell, custom scripting
API & Backend Testing: Postman, BlazeMeter, REST APIs, GraphQL, API security testing, OWASP API Top 10, backend validation
CI/CD & Reporting: Jenkins, GCP, TestRail, Jira, Confluence, automated result collection, test reporting, cloud-based validation workflows
Embedded & Automotive: Vector CANoe, CANalyzer, CANape, dSPACE, Matlab/Simulink, Lauterbach, ODIS, IBM DOORS, Rational DOORS, HiL, MiL, SiL, PiL, ECU flashing, OTA validation
Security Testing:
Cloud & Platforms: GCP, AWS, Azure, Linux, Windows, macOS
Development: Embedded C, C, C++, JavaScript, Python, Java, PHP, Kotlin, SQL, Bash, PowerShell
Persönliche Daten
- Rumänisch (Muttersprache)
- Englisch (Fließend)
- Italienisch (Gut)
- Deutsch (Grundkenntnisse)
- Europäische Union
Kontaktdaten
Nur registrierte PREMIUM-Mitglieder von freelance.de können Kontaktdaten einsehen.
Jetzt Mitglied werden
