- 3–5 years of experience in manual QA testing, particularly for mobile (iOS/Android), backend, and API testing, including API tools (e.g. Postman) and SQL validation
- Hands-on experience or solid understanding of security testing, including vulnerability assessments, penetration testing, DAST methodologies, OWASP Top 10 vulnerabilities, and tools such as Burp Suite, Frida, or OWASP ZAP
- Basic knowledge of programming or scripting (e.g. Python, JavaScript), version control (GitHub/Azure DevOps), and authentication/authorization testing
- Experience or interest in test automation, CI/CD pipelines, performance testing tools (e.g. JMeter, k6, Locust), and mobile application security testing is a plus
- Security certifications, fintech experience, or familiarity with compliance frameworks (PCI DSS, ISO 27001, GDPR) are an advantage
- Strong analytical skills, attention to detail, and ability to collaborate with cross-functional teams