Overview
Who are we?
Checkmarx is the leader in application security and ensures that enterprises worldwide can secure their application development from code to cloud. Our consolidated platform and services address the needs of enterprises by improving security and reducing TCO, while simultaneously building trust between AppSec, developers, and CISOs. At Checkmarx, we believe it’s not just about finding risk but remediate it across the entire application footprint and software supply chain with one seamless process for all relevant stakeholders.
We are honored to serve more than 1,800 customers, which includes 40 percent of all Fortune 100 companies including Siemens, Airbus, SalesForce, Stellantis, Adidas, Wal-Mart and Sanofi.
We’re excited to expand our global presence with the opening of a new site in Pune, India—an innovation hub designed to attract top talent and fuel the future of application security. Joining our Pune team means working on cutting-edge technologies in cloud, DevSecOps, AI-driven security and being part of a high-impact engineering culture where your code helps secure the software that powers the world.
Role Overview
We are looking for a highly technical QA Analyst with strong programming skills and a deep understanding of application security. You will join the team responsible for ensuring the accuracy of Checkmarx's vulnerability detection—reducing false positives and false negatives across supported languages and frameworks.
This role requires you to analyze code samples, understand secure coding patterns, collaborate with developers, and create test cases that improve detection logic
Responsibilities
- Investigate customer-reported false positives/negatives.
- Understand and reproduce real-world code samples.
- Collaborate with developers to extend test coverage.
- Research sanitizers, frameworks, and edge cases.
- Create code examples that test query accuracy.
- Support automation and regression testing for SAST queries.
Requirements
- Strong programming background (Java, C#, JS, Python, etc.).
- Experience in QA and development
- Ability to read, analyze, and test complex code scenarios.
- Strong communication and teamwork skills.
Nice to Have
Solid understanding of application security (OWASP, data flow, sanitization).
- Experience in security testing.