Security Test Engineer
Emerson Ltd
Edinburgh, United Kingdom
2 days ago
Role details
Contract type
Permanent contract Employment type
Full-time (> 32 hours) Working hours
Regular working hours Languages
English Experience level
SeniorJob location
Edinburgh, United Kingdom
Tech stack
JavaScript
Microsoft Windows
Automation of Tests
Azure
Bash
Burp Suite
Computer Security
Linux
DNS
Firmware
Hypertext Transfer Protocols (HTTP)
Python
Key Management
Modbus
Network Protocols
NMap
Open Web Application Security
Powershell
Regression Testing
Fortify (Software)
TCP/IP
Wireshark
Scripting (Bash/Python/Go/Ruby)
Information Technology
Metasploit
Nessus
Checkmarx
Devsecops
Vulnerability Analysis
Job description
- Conduct risk analysis and define test strategies aligned with security objectives.
- Plan, implement, and report on security testing activities, including: Tool and technique selection, Security requirements testing, Threat mitigation testing, Vulnerability testing, Abuse case testing, Attack surface analysis, Regression testing and Test automation
- Analyse, report, and supervise security defects.
- Ensure compliance with internal processes and applicable standards (e.g., IEC 62443, ISO 27001).
- Support internal and external audits as required.
- Drive continuous improvement by staying updated on emerging threats, tools, and standard methodologies.
- Occasional travel may be required, such as training or customer support.
Who You Are:
You combine technical skills, curiosity, and a strong understanding of threat models and security tools to ensure applications and infrastructure are resilient against real-world attacks. A Security Test Engineer is a diligent, analytical, and ethically grounded professional who identifies and tests for vulnerabilities in systems before attackers can exploit them.
Requirements
- Proven ability with a minimum 5 years of experience in software and/or firmware testing
- Engineering degree or equivalent experience in Software, Computer Science, Cybersecurity, or equivalent proven knowledge.
- Proficiency with tools such as Burp Suite, OWASP ZAP, Nessus, Metasploit, Wireshark, Nmap, Fortify, Checkmarx.
- Knowledge of scripting languages such as Python, JavaScript, Bash, or PowerShell.
- Understanding of encryption algorithms, key management, and secure protocols (TLS, SSH, etc.)
- Detailed understanding of common vulnerabilities (e.g., OWASP Top 10, CWE/SANS Top 25).
- Familiarity with Linux, Windows, and network protocols (TCP/IP, DNS, HTTP/S).
- Understanding of industrial protocols (e.g., Serial, Modbus, HART).
- Proficiency in industry regulations including IEC 62443, ISO 27001, NIST, OWASP.
- Proficiency in incorporating DevSecOps strategies; Experience with Azure DevOps is a positive attribute.
- Self directed and motivated in a team orientated environment
Preferred Qualifications That Set You Apart:
- Experience implementing DevSecOps standard processes; Azure DevOps experience is a plus.
About the company
At Emerson, we prioritize a workplace where every employee is valued, respected, and empowered to grow. We foster an environment that encourages innovation, collaboration, and diverse perspectives-because we know that great ideas come from great teams. Our dedication to ongoing career development and growing an inclusive culture ensures you have the support to thrive! Whether through mentorship, training, or leadership opportunities, we invest in your success so you can make a lasting impact. We believe diverse teams, working together are key to driving growth and delivering business results.
We recognise the importance of employee well-being. We prioritise in providing competitive benefit plans, including Private Medical cover, Employee Assistance Program, Employee Resource Groups, recognition and much more.
Make this great opportunity yours