Senior QA Engineer - Upwind Security - AWS GCP AZURE Docker WebUI API

$$$

Cloud Security · Runtime Threat Detection · Java · Selenide · Kubernetes · Terraform · Multi-Cloud

Every bug you find is one an attacker doesn't get to use. At this level, every bug you prevent is worth ten of them.
 

The stakes

Upwind is a runtime-powered cloud security platform. Our customers hand us their production cloud environments — AWS, Azure, GCP — and trust us to catch what's wrong: vulnerabilities, misconfigurations, exposed identities, live attacks in progress.

When a dashboard renders empty while CVEs exist in the data, a customer believes they're clean when they're not. When onboarding silently half-fails, an account goes unmonitored. When a detection fires against the wrong resource, an incident responder chases the wrong host.

Those aren't cosmetic defects. That's the line between a security product and a security theater product. We're hiring someone senior enough to hold that line across the platform, not just inside one feature.
 

What you'll own

Test strategy across product areas — cloud onboarding, vulnerability and image scanning, CSPM and compliance, inventory and identity correctness, runtime threat detection. You decide what gets tested, at what depth, and where the real risk sits. You'll be the person other engineers ask before shipping.

Automation architecture, not just test cases. Own the design and direction of our Java + Selenide WebUI framework: structure, patterns, page object design, test data strategy, parallelization, reporting, CI integration. Decide what belongs in UI automation and what belongs at the API layer — and say no to UI tests that shouldn't exist.
 

Testability as an engineering problem. Drive standards into the product itself — stable data-testid conventions, deterministic test hooks, seedable environments — so that a frontend refactor stops invalidating hundreds of tests that found no defect. This means writing proposals, winning agreement from frontend and backend leads, and seeing adoption through.
 

Release quality gates. Define exit criteria and risk-based prioritization for releases. Run and sign off regression cycles. Make the call on whether something ships — and be able to defend it with evidence.
 

Deep infrastructure work. Onboard AWS accounts and organizations via CloudFormation and Terraform, Azure tenants, GCP projects — and verify off-boarding genuinely cleans up. Deploy the Upwind Operator on EKS via Helm and host agents on EC2. Design and generate QA workloads that exercise detection paths realistically.
 

Data integrity at the system level. Cross-check the UI against backing stores, exports and generated reports. Trace a discrepancy through the stack — frontend, API, pipeline, store — and arrive with a diagnosis, not a question.
 

Raising the people around you. Mentor less experienced QA engineers, review their test designs and automation code, and set the standard for what a bug report and a test plan look like here.
 

What we need from you
 

Must have

  • Substantial commercial QA experience with genuine depth in both manual testing and automation
  • Strong Java — you design and refactor test code, not just add to it; you understand why the framework is built the way it is and can argue for changing it
  • Proven ownership of a UI automation framework in production (Selenide, Selenium, or equivalent) — including stability, runtime, and maintenance cost as things you actively managed
  • Test strategy and risk-based prioritization at product-area scale, not just test-case level
  • Strong API testing skills and the ability to debug across frontend, backend, pipeline and data store
  • Real working experience with at least one major cloud provider: IAM, resource models, onboarding and permission flows
  • Kubernetes in practice — kubectl, Helm, reading pod logs, understanding what a broken deployment is telling you
  • CI/CD: suites running in a pipeline, and you own why they're green
  • Git, Jira, Confluence; confident written and spoken English in a distributed team
     

Strongly preferred

  • Terraform or CloudFormation, hands-on
  • Cybersecurity domain knowledge — CVEs and vulnerability management, CSPM, IAM, threat detection
  • SQL or OpenSearch for independent verification of what the UI claims
  • Experience in regulated or compliance-driven environments (FedRAMP, SOC 2)
  • Track record of mentoring QA engineers
     

Who does well here

Someone who can't leave a question alone, and who has enough experience to know which questions are worth the day. Who sets up their own environments, chases root cause through the stack, and follows a fix to verification.
 

Someone whose bug reports get picked up immediately because they arrive with a diagnosis attached — and whose test strategies mean fewer of those reports need writing at all.
 

How we work

Inside feature squads, next to the backend and frontend owners — Slack working groups, Figma, Confluence. Senior QA here has real influence on what gets built and how, not a gate at the end of the pipeline.
 

Let's talk.

Required skills experience

QA/QC 2 years
UI Testing 2 years
API Testing 2 years
GUI Testing 2 years
Software testing 2 years
AWS 6 months
GCP (Google Cloud Platform) 6 months
Azure 6 months
Cloud Security 6 months
cloud computing 6 months
Docker 6 months

Required domain experience

Security 1 year

Required languages

English B2 - Upper Intermediate
Published 10 September
7 views
·
0 applications
To apply for this and other jobs on Djinni login or signup.
Loading...