US Jobs US Jobs     UK Jobs UK Jobs     EU Jobs EU Jobs


Senior Engineer I, Software Test

Company Overview: Schneider Electric is a global leader in energy management and automation, committed to providing innovative solutions that ensure Life Is On everywhere, for everyone, and at every moment.

We are looking for a V&V Security Engineer to perform baseline security Verification & Validation of web applications and APIs.

The role sits between Security-focused QA and Application Security and is intended for someone who can independently perform structured security validation without requiring hardcore penetration testing expertise.

The engineer will work closely with QA, Development and Product Security teams to validate security controls, identify common security weaknesses, document findings and escalate advanced security issues when required.

Key Responsibilities

V&V Security Testing


* Perform security validation for application features and APIs as part of the V&V lifecycle.


* Understand feature functionality, user roles and expected security controls before testing.


* Validate security requirements across authentication, authorization, input validation, business logic, APIs, sessions, file handling and security headers.


* Verify security controls at the backend/API level, not only through the UI.


* Identify, reproduce and document security weaknesses.

Web & API Security Testing
Perform baseline testing for:


* Authentication: login, password reset, authentication enforcement and bypass scenarios.


* Authorization & Access Control: RBAC, horizontal/vertical access control, IDOR, object ownership, user/site/device/tenant access and restricted APIs.


* Input Validation: mandatory fields, null/empty values, datatype, length, boundaries, IDs, dates, enums and unexpected parameters.


* Business Logic: workflow bypass, date/quantity restrictions, duplicate requests, invalid state transitions and frontend-only restrictions.


* Session Management: logout, expiry, token/session reuse and privilege changes.


* REST APIs: request/response validation, HTTP methods, headers, JSON bodies, authorization and parameter manipulation.


* File Security: upload/download validation, file types, MIME types, size restrictions and access control.


* Security Headers: CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and other project-required headers.


* Error Handling & Information Disclosure: stack traces, internal paths, sensitive data, tokens, credentials and other unintended information exposure.

Reporting & Collaboration


* Create clear and reproducible security findings.


* Capture request/response evidence and screenshots.


* Explain security/business impact and remediation.


* Assign severity/CVSS where required.


* Track findings through Jira or equivalent systems.


* Perform security retesting after fixes.


* Work with developers and QA to explain security issues clearly.

Qualifications & Required skills:

Required Technical S...




Share Job