Golonex

Security Operations

EDR · MDR · XDR Email Security SOC Monitoring & SIEM Continuous VAPT Security Awareness Training

IT & Governance

Configuration Management Backup & DR / BCP IT & Security Governance IS Audit Readiness Compliance Readiness

Advisory & AI

Fractional Leadership AI Automation Solutions Lab Staff Augmentation

Products

GOMA — Omnichannel Messaging gowin.tools All products

Company & Resources

About Our Work Industries Golonex Ready Blog Golonex Press ↗ Golonex Tools ↗ Hire with us → Book a Call →
🧪 QA Engineers

Hire Dedicated Security Testing / Pen Test QA Engineers — India, US, UK & Australia

Hire pre-vetted security testing and penetration testing QA engineers who probe your apps for vulnerabilities before attackers do. Golonex places dedicated India-based security testers with US, UK, Australian, and Indian teams — working in your timezone, under NDA, integrated within one week and with no lock-in.

The role

What a Security Testing / Pen Test QA does

A security testing / pen test QA engineer performs vulnerability assessments and penetration tests against web apps, APIs, and mobile apps, mapping findings to OWASP and providing clear remediation guidance. Our engineers combine manual exploitation with tooling to find issues like injection, broken auth, and misconfigurations automated scanners miss.

Core expertise

OWASP Top 10 Burp Suite OWASP ZAP Penetration testing Vulnerability assessment Web & API security testing SQL injection & XSS testing Authentication & session testing Nmap & Metasploit Static & dynamic analysis (SAST/DAST) Mobile app security testing Security misconfiguration review Threat modeling Remediation reporting
Outcomes

What a Golonex Security Testing / Pen Test QA builds for you

Penetration test reports with severity ratings
OWASP-mapped vulnerability assessments
API and web app security test suites
Authentication and access-control test cases
Remediation guidance and retest verification
Security regression checklists
Engagement

How it works

Engagement models

Full-time dedicated Part-time / hourly Remote Hybrid Onsite (US · UK · India)

Based in India, working in your timezone. Onsite options available across the US, UK, and India.

Category

🧪

QA Engineers

Demand: Medium demand
Why Golonex for Security Testing / Pen Test QAs

The Golonex difference

Named, pre-vetted engineers

Every Security Testing / Pen Test QA is screened for technical depth, communication, and reliability before you meet them — a sub-30% pass rate at the technical stage.

Integrated within 1 week

From enquiry to working team member in 5 business days. We handle onboarding, NDA, and access logistics.

Your timezone

India-based talent working overlapping hours with US, UK, and Australian teams. Daily standups and real-time collaboration, agreed upfront.

NDA-protected, no lock-in

Full IP and confidentiality protection as standard. Month-to-month engagements — scale up or down as your project evolves.

FAQ

Hiring a Security Testing / Pen Test QA — FAQs

How quickly can I hire a security testing engineer through Golonex? +

Typically within one week. We shortlist pre-vetted security testers matched to your stack and scope, you interview them, and the selected engineer is onboarded within 5 business days.

How do you vet security testing engineers? +

Every candidate passes a hands-on security assessment, a communication assessment, and reference checks before you meet them. Fewer than 30% of applicants clear our technical bar, and all work is performed under NDA.

What kind of security testing do they perform? +

Our engineers run vulnerability assessments and penetration tests on web apps, APIs, and mobile apps, mapping findings to the OWASP Top 10. They combine manual exploitation with tools like Burp Suite and ZAP to surface issues scanners miss.

Do they provide remediation guidance, not just findings? +

Yes. Each finding comes with severity, reproduction steps, and clear remediation advice, and our engineers retest fixes to confirm the vulnerability is closed. You get an actionable report, not just a raw scan dump.

Do your security testing engineers work in my timezone? +

Yes. Our India-based engineers work overlapping hours with US, UK, and Australian teams so they can coordinate test windows and walk through findings live. The overlap is agreed upfront.

Get started

Ready to hire a Security Testing / Pen Test QA?

Tell us the role, stack, and timeline. We'll match you with a named, pre-vetted engineer — integrated within 1 week.