Senior Engineer I, Software Test

Schneider Electric

Location: Gurgaon, HR , IN
Employment Type: FULL_TIME
Industry: Advertising and Public Relations
Occupational Category: 13-0000.00 – Business and Financial Operations
Posted: Tuesday, 25 August 2026
Valid Through: Thursday, 24 September 2026

Job Description

Schneider Electric is hiring a Senior Engineer I, Software Test in Gurgaon, HR. This is a full-time position.

Company Overview: Schneider Electric is a global leader in energy management and automation, committed to providing innovative solutions that ensure Life Is On everywhere, for everyone, and at every moment. We are looking for a V& V Security Engineer to perform baseline security Verification & Validation of web applications and APIs. The role sits between Security-focused QA and Application Security and is intended for someone who can independently perform structured security validation without requiring hardcore penetration testing expertise. The engineer will work closely with QA, Development and Product Security teams to validate security controls, identify common security weaknesses, document findings and escalate advanced security issues when required.

Key Responsibilities
  • V& V Security Testing
    • Perform security validation for application features and APIs as part of the V& V lifecycle.
    • Understand feature functionality, user roles and expected security controls before testing.
    • Validate security requirements across authentication, authorization, input validation, business logic, APIs, sessions, file handling and security headers.
    • Verify security controls at the backend/API level, not only through the UI.
    • Identify, reproduce and document security weaknesses.

  • Web & API Security Testing

  • Perform baseline testing for:
    • Authentication: login, password reset, authentication enforcement and bypass scenarios.
    • Authorization & Access Control: RBAC, horizontal/vertical access control, IDOR, object ownership, user/site/device/tenant access and restricted APIs.
    • Input Validation: mandatory fields, null/empty values, datatype, length, boundaries, IDs, dates, enums and unexpected parameters.
    • Business Logic: workflow bypass, date/quantity restrictions, duplicate requests, invalid state transitions and frontend-only restrictions.
    • Session Management: logout, expiry, token/session reuse and privilege changes.
    • REST APIs: request/response validation, HTTP methods, headers, JSON bodies, authorization and parameter manipulation.
    • File Security: upload/download validation, file types, MIME types, size restrictions and access control.
    • Security Headers: CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and other project-required headers.
    • Error Handling & Information Disclosure: stack traces, internal paths, sensitive data, tokens, credentials and other unintended information exposure.

  • Reporting & Collaboration
    • Create clear and reproducible security findings.
    • Capture request/response evidence and screenshots.
    • Explain security/business impact and remediation.
    • Assign severity/CVSS where required.
    • Track findings through Jira or equivalent systems.
    • Perform security retesting after fixes.
    • Work with developers and QA to explain security issues clearly.
    Qualifications & Required skills:

    Required Technical Skills

    Application Security

    Understanding of:
    • OWASP fundamentals
    • Authentication & Authorization
    • Broken Access Control / IDOR
    • Input Validation
    • XSS
    • SQL Injection fundamentals
    • Path Traversal
    • CSRF/CORS fundamentals
    • Session Management
    • Business Logic vulnerabilities
    • File Upload/Download security
    • Security Headers
    • Information Disclosure


    API Security
    • REST APIs
    • HTTP methods and status codes
    • JSON request/response structures
    • Headers and cookies
    • Bearer tokens
    • JWT fundamentals
    • API authentication and authorization
    • Backend validation


    Tools

    Burp Suite
    • Proxy
    • HTTP History
    • Repeater
    • Decoder
    • Request/response analysis
    • Basic request manipulation


    Experience

    Typically, 5-7 years in:
    • Application Security
    • Security V& V
    • Web/API Security Testing


    Education

    Bachelor's degree in:
    • Computer Science


    Key Competencies

    The ideal candidate demonstrates:
    • Strong application-security fundamentals.
    • Good QA/testing mindset.
    • Analytical and curious approach.
    • Ability to understand application workflows.
    • Strong API/request analysis skills.
    • Ability to distinguish functional bugs from security vulnerabilities.
    Rewards designed for you

    Our Total Rewards is our way of saying: We see you and we value you. It's more than just pay and benefits-it's a meaningful investment in you. It is designed to help you perform, grow, feel safe, and elevate your potential. The package helps you care for yourself and your family, plan your future, grow your skills and career, collaborate in an inclusive workplace, and contribute to your community. At Schneider Electric, we're here for what matters most to you. Discover more at our Career Page.

    * Country-specific programs and initiatives may be available.

    Looking to make an IMPACT with your career?

    When you are thinking about joining a new team, culture matters. At Schneider Electric, our values and behaviors are the foundation for creating a great culture to support business success. We believe that our IMPACT values - Inclusion, Mastery, Purpose, Action, Curiosity, Teamwork - starts with us.

    IMPACT is also your invitation to join Schneider Electric where you can contribute to turning sustainability ambition into actions, no matter what role you play. It is a call to connect your career with the ambition of achieving a more resilient, efficient, and sustainable world.

    We are looking for IMPACT Makers; exceptional people who turn sustainability ambitions into actions at the intersection of automation, electrification, and digitization. We celebrate IMPACT Makers and believe everyone has the potential to be one.

    Become an IMPACT Maker with Schneider Electric - apply today!

    €40 billion global revenue
    +9% organic growth
    150 000+ employees in 100+ countries

    You must submit an online application to be considered for any position with us. This position will be posted until filled.

    Schneider Electric aspires to be the most inclusive and caring company in the world, by providing equitable opportunities to everyone, everywhere, and ensuring all employees feel uniquely valued and safe to contribute their best. We mirror the diversity of the communities in which we operate, and 'inclusion' is one of our core values. We believe our differences make us stronger as a company and as individuals and we are committed to championing inclusivity in everything we do.

    At Schneider Electric, we uphold the highest standards of ethics and compliance, and we believe that trust is a foundational value. Our Trust Charter is our Code of Conduct and demonstrates our commitment to ethics, safety, sustainability, quality and cybersecurity, underpinning every aspect of our business and our willingness to behave and respond respectfully and in good faith to all our stakeholders. You can find out more about our Trust Charter here

    Schneider Electric is an Equal Opportunity Employer. It is our policy to provide equal employment and advancement opportunities in the areas of recruiting, hiring, training, transferring, and promoting all qualified individuals regardless of race, religion, color, gender, disability, national origin, ancestry, age, military status, sexual orientation, marital status, or any other legally protected characteristic or conduct.

    Education Requirements

    high school

    Skills

    Please see the job description for required or recommended skills.

    Benefits

    Please see the job description for benefits.

    Apply Now

    Index requested: • Indexed: