Lumin Digital is a fintech company specializing in cloud native digital banking solutions.
Vulnerability Automation Engineer
Location
United States
Posted
24 days ago
Salary
$170K - $190K / year
Seniority
Senior
Job Description
Vulnerability Automation Engineer
Lumin Digital
• Design and implement end-to-end vulnerability automation pipelines that continuously discover assets, assess configurations, identify vulnerabilities, and execute or orchestrate remediation, without manual ticketing or human-in-the-loop coordination. • Build and maintain agentic AI workflows using tools such as Claude Code and MCP-based integrations to automate security engineering tasks, including code review for vulnerability patterns, configuration drift detection, and patch deployment across cloud-native environments. • Engineer new and enhance existing automated asset discovery and inventory systems that maintain a real-time, authoritative view of all infrastructure, services, and endpoints across environments, including ephemeral and containerized workloads. • Develop and operationalize automated configuration hardening pipelines that enforce security baselines (CIS Benchmarks, internal standards) as code, with drift detection and auto-remediation capabilities. • Create and maintain infrastructure-as-code templates, policy-as-code rules, and automated playbooks that embed security controls directly into deployment pipelines, preventing or resolving vulnerabilities at build time rather than discovering them post-deployment. • Build self-service remediation tooling and agentic support systems that empower development and infrastructure teams to resolve security findings autonomously, reducing cross-team dependencies and accelerating mean time to remediation. • Integrate vulnerability data sources (scanners, SCA tools, cloud-native security services, threat intelligence feeds) into unified automation platforms, normalizing and enriching findings to drive intelligent prioritization and automated response. • Develop metrics, dashboards, and automated reporting that provide real-time visibility into vulnerability posture, remediation velocity, and automation coverage, enabling leadership to measure program effectiveness without manual evidence gathering. • Collaborate with product, engineering, operations, and other risk teams to embed vulnerability automation into CI/CD pipelines, infrastructure provisioning workflows, and operational runbooks. • Perform other duties as assigned.
Job Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, Software Engineering, or a related field; or equivalent combination of education and demonstrated engineering experience in vulnerability lifecycle management and security automation.
- 5+ years of hands-on experience in security engineering, DevSecOps, vulnerability management, or infrastructure automation, with a strong emphasis on building automated systems rather than operating manual processes.
- Demonstrated experience building and shipping automation pipelines in production environments using Python, Go, Bash, or similar languages, with infrastructure-as-code tools such as Terraform.
- Proven track record of working in cloud-native environments with deep familiarity in containerized workloads, Kubernetes, serverless architectures, and CI/CD pipeline integration.
- Experience with vulnerability scanning and security assessment platforms (e.g., Tenable, Qualys, Wiz, Snyk, Trivy, Grype, or cloud-native equivalents) and the ability to integrate them programmatically into automated workflows.
- Deep understanding of vulnerability classes (OWASP Top 10, CWE, CVE/CVSS, EPSS) and modern prioritization frameworks that go beyond raw CVSS scores to factor exploitability, asset criticality, and business context.
- Proficiency with AI-assisted development tools (Claude Code, GitHub Copilot, or similar agentic coding assistants) and the ability to design, prompt-engineer, and orchestrate AI agents for security automation workflows.
- Strong software engineering fundamentals: version control (Git), code review, testing, CI/CD, API design, and the ability to write production-quality, maintainable code—not just scripts.
- Hands-on experience with cloud security tooling and APIs (AWS Config, GuardDuty, Inspector, Security Hub), container security.
- Familiarity with security data engineering concepts: API and database integration, data normalization, and building automated evidence-collection pipelines for compliance and audit support.
- Excellent written and verbal communication skills, with the ability to translate complex automation architectures into clear documentation, runbooks, and knowledge-transfer materials for cross-functional teams.
Related Guides
Related Categories
Related Job Pages
More QA Automation Engineer Jobs
Senior Automation Engineer
WorkBoardWorkBoard’s Strategy Execution Platform powers the digital operating rhythm for companies around the globe, providing organization-wide clarity, alignment, and insights for growth. AstraZeneca, Ford, 3M, Intel and many others rely on WorkBoard’s platform, playbook, and expertise to accelerate results by aligning OKRs, simplifying business reviews and scorecards, focusing weeklies on outcomes, and leveraging analytics – all with embedded AI. More than 15,000 people are certified in WorkBoard’s OKR coaching and Outcome Mindset Methodology™ which enables their organizations to quickly gain the agility OKRs can provide. Based in Silicon Valley and founded in 2013, WorkBoard investors include Andreessen Horowitz, SoftBank, GGV Capital, Workday Ventures, M12 (Microsoft), Intel Capital, Silicon Valley Bank, and Capital One.
Role Description WorkBoard’s Strategy Execution Platform powers the digital operating rhythm for companies around the globe, providing organization-wide clarity, alignment, and insights for growth. - Experience using AI-assisted development tools such as Claude Code or Cursor to accelerate test automation and improve engineering productivity. - Strong expertise in test automation frameworks such as Cypress and Playwright, along with other modern industry tools. - Proven experience designing, building, maintaining, and continuously improving automated test coverage. - Ability to reduce manual testing through thoughtful automation strategies, while also executing targeted manual testing when needed. - Experience partnering with engineering squads to define comprehensive test plans that balance automated and manual testing. - Active participation in agile team processes such as sprint ceremonies, release cycles, and cross-functional planning. - Experience integrating automated tests into CI/CD pipelines to enable continuous quality checks in deployment workflows. - Strong documentation skills, including maintaining test cases and clearly reporting test results and quality insights. - Ability to lead by example and raise the team’s automation maturity through knowledge sharing, coaching, and training. Qualifications - Applying strong judgment across both manual and automated testing methodologies. - Collaborating cross-functionally with engineering, product, and other stakeholders to improve software quality. - Finding creative, practical ways to improve testing efficiency, reliability, and coverage. - Communicating test strategies, risks, and outcomes clearly to both technical and non-technical audiences. - Working effectively in CI/CD-driven environments. - Bringing a proactive mindset and a strong commitment to continuous learning and team improvement. Requirements - Hands-on experience with CI/CD tools and integrating testing into delivery pipelines. - Experience leading QA or automation efforts and mentoring others in automation best practices. - A software development background that strengthens your approach to test automation. - Certifications in quality assurance, test automation, or agile methodologies. Benefits - 25 days PTO. - Additional Health insurance w/ Bulstrad. - Quarterly All-Hands meetings. - And much more! Company Description We are proud to be an equal opportunity workplace committed to building a team culture that celebrates learning, diversity, and inclusion. If you’re hungry to grow your skills while growing a company, your sense of urgency matches the size of our market opportunity, and you value and enable team mates’ contributions, then come join us!
Role Description As a Middle (Strong Middle) QA Engineer on our team, you will play a key role in ensuring the quality, stability, and reliability of our platform across frontend and backend systems. You will be involved in the full product lifecycle - from requirement analysis and test design to sprint goals sign off. This role requires a hands-on professional who is strong in manual testing but also capable of contributing to test automation efforts. You will collaborate closely with BA, developers, and DevOps engineers to build a robust quality culture, improve testing processes, and ensure high standards across multiple brands and releases. Working on this project will expose you to complex product logic, integrations with external providers, and high-load systems in a fast-paced environment. You will join a team that values ownership, proactive communication, and continuous improvement, with real opportunities to influence product quality and engineering standards. Qualifications - 3+ years of experience in Manual QA (experience in test automation is a strong plus). - Strong experience in testing web applications, REST APIs, and complex business logic. - Hands-on experience with writing test documentation: test strategy, test plans, test cases. - Experience in end-to-end testing of web-based products. - Understanding of client-server architecture and API testing tools (Postman or similar). - Preferably basic or intermediate automation skills (e.g., Java + rest-assured, Selenium). - Experience working with defect tracking tools (Jira or similar). - Experience working in Agile environments (Scrum / Kanban). - Strong analytical and problem-solving skills. - Ability to prioritize testing efforts based on risk and business impact. - Upper-Intermediate English (written and spoken). - Strong interest in leveraging AI tools (e.g., ChatGPT, Copilot or similar) to improve testing efficiency. - Experience or willingness to use AI for generating test cases, exploratory testing ideas, documentation, and bug analysis. - Ability to use AI to optimize repetitive QA activities and reduce manual effort. - Critical mindset when working with AI-generated outputs - ability to validate and adapt results. - Openness to experimenting with AI-driven testing approaches and sharing best practices within the team. Requirements - Nice to have experience in online gambling, fintech, or other high-load systems. - Technical background or degree in Computer Science (is a plus). - Experience in performance or load testing (is a plus). Responsibilities - Work as a member of a cross-functional Scrum team. - Perform comprehensive manual testing of web and API functionality. - Design, create, maintain, and execute test cases aligned with sprint commitments. - Perform regression, sanity, and end-to-end testing. - Identify, document, and track defects with clear reproduction steps. - Define testing scope, dependencies, risks, and potential blockers. - Collaborate closely with developers, product managers, and other stakeholders. - Contribute to improving QA processes and quality standards across teams. - Participate in requirement analysis and provide early feedback from a QA perspective. - Contribute to automation efforts where possible (test scripts, test coverage improvements).
Role Description You will build and deploy a complete business automation system from scratch. The stack centres on: - n8n (self-hosted) - Airtable - Claude API - Chatwoot - WATI (WhatsApp Business API) - Wave Accounting - Google Workspace APIs The system spans five operational domains and includes approximately 35 automation workflows across three service tiers. Key Domains & Scope - Customer Communications: Inbound message handling, AI-assisted response drafting, and lead classification across WhatsApp, Facebook Messenger, Instagram DM, and email. - Job & Booking Operations: Quote generation support, follow-up sequences (Day 1 / 3 / 7), booking confirmations, job assignment to technicians, no-show reminders, and route optimisation. - Revenue & Finance: Auto-invoice generation via Wave API, payment reminder sequences, bookkeeping entries, and weekly/monthly financial summaries. - Reputation & Retention: Google review request automation, review reply drafting, customer retention sequences (90-day / 180-day), and WhatsApp broadcast campaigns. - Internal Operations: VA performance dashboards, client onboarding automation, QA monitoring alerts, and monthly billing to our own clients. What You Will Do Phase 1 — Infrastructure Setup (Days 1–2) - Provision and configure a VPS (Hetzner or DigitalOcean) with Docker. - Install and configure n8n self-hosted with authentication and HTTPS. - Deploy Chatwoot (self-hosted) and connect all communication channels. - Set up credential management and environment variables for all APIs. Phase 2 — Core Automations (Days 3–14) - Build the WhatsApp inbound handler with Chatwoot webhook integration. - Implement Claude API integration for message classification and AI draft generation. - Build the Airtable database schema (Clients, Customers, Jobs, Quotes, Technicians, Conversations). - Develop lead scoring, missed-lead recovery, and quote follow-up sequences. - Build job notification flows to technicians with confirmation logic. - Implement no-show reminder system (24hr and 2hr pre-job). Phase 3 — Revenue & Operations Automations (Days 15–21) - Integrate Wave Accounting API for invoice auto-generation. - Build payment reminder sequences (Day 0 / 3 / 7 / 14) with escalation logic. - Integrate Google Calendar API for scheduling and technician assignment. - Implement route optimisation via Google Routes API with daily technician briefings. - Generate weekly and monthly reports with Claude-written summaries. Phase 4 — Retention & Intelligence Automations (Days 22–30) - Google review monitoring via Places API and AI-drafted reply workflow. - Customer retention sequences (90-day, 180-day re-engagement). - WhatsApp broadcast campaign system with opt-out compliance. - Seasonal maintenance reminders and greeting campaigns. - Competitor pricing monitoring via Google Maps and Carousell. - Annual service contract management with auto-scheduling. Phase 5 — Internal Systems - VA performance dashboard with SLA monitoring and alert triggers. - Client onboarding automation (form → Airtable → system setup → VA assignment). - QA monitoring with sentiment detection and escalation alerts. - Monthly billing automation for FortePartner’s own client invoices. Ongoing (Post-Build) - Monitor system health and resolve workflow failures promptly. - Update AI prompts based on quality feedback from the VA team. - Onboard new clients into the automation system as the business scales. - Build additional automations as the business grows. Qualifications - Hands-on experience with n8n — workflow building, webhook handling, conditional logic, scheduled triggers, and error handling. - REST API integration — comfortable reading API docs and building HTTP request nodes independently. - Airtable API — able to read, create, and update records via API (not only UI). - LLM API integration — experience calling OpenAI/Claude (or similar) with structured prompts. - Linux VPS — set up Docker, manage services, configure HTTPS, and troubleshoot server issues. - WhatsApp Business API — experience with WATI, 360Dialog, or similar BSP. Requirements - Self-hosted deployment and inbox configuration experience with Chatwoot. - Familiarity with Google Workspace APIs — Calendar, Gmail, Places, Routes. - Experience with Wave Accounting API — invoice and transaction management. - Multi-tenant automation design — one workflow serving multiple clients with different configurations. - Prompt engineering — system prompt design for consistent AI output quality. Working Style - Comfortable working from detailed written specifications without hand-holding. - Proactive communicator — flags blockers early and asks the right questions. - Delivers working builds — tests flows end-to-end before marking tasks done. - Documents clearly so a non-technical team can understand the logic. - Available for a daily async check-in during the 30-day build phase. Good to Have - Prior work with home service businesses, field service management, or similar SMB verticals. - Experience building automations that support VA teams or BPO operations. - Familiarity with Singapore-specific tools (PayNow, Carousell, SingPass-connected services). - Make.com experience (as a fallback if self-hosted n8n is not feasible). - Basic frontend or form-builder skills for lightweight client-facing tools. Engagement Details - Phase 1 Deliverable: Full automation system live and tested within 30 days. - Ongoing Retainer: Monthly agreement for maintenance, new automations, and scaling support. - Communication: Async-first via WhatsApp or Slack; video calls for scoping and reviews. - Handover / IP & Confidentiality: All n8n workflow exports, Airtable schema docs, and setup notes required; NDA and IP assignment required before project commencement. - Payment Terms: Milestone-based for Phase 1; monthly for retainer. Ready to Make an Impact? Apply now at https://asiacruit.com or send your resume to careers@asiacruit.com with the subject line: “Freelance Automation Engineer – [Your Name]”
Senior API QA Automation Engineer
CAIWHEN YOU NEED TO MEET A HIGHER STANDARD® in US | ASIA | EUROPE | AUSTRALIA
Role Description We are seeking a QA Performance & API Automation Engineer to join our Quality Engineering team. This position will be full-time and remote. What You’ll Do: - Design, develop, and maintain automated API test suites using Postman and Newman - Validate RESTful APIs for functionality, reliability, and data integrity - Integrate API automation tests into CI/CD pipelines (Azure Pipelines preferred) - Analyze automation results and provide actionable insights to development teams - Design and execute performance, load, stress, soak, and scalability tests using Apache JMeter - Perform API performance testing to validate response times, throughput, and system behavior under load - Conduct UI performance testing to evaluate front-end responsiveness and end-user experience - Create realistic test scenarios using JMeter features such as parameterization, correlation, assertions, and listeners - Monitor system behavior during tests and identify performance bottlenecks - Analyze performance test results and identify root causes for performance issues - Produce clear, concise performance test reports with metrics, graphs, and recommendations - Collaborate with developers, architects, and DevOps teams to optimize application performance - Retest and validate performance fixes and improvements - Embed performance and automation testing into continuous testing pipelines - Support performance testing in cloud-based and microservices environments - Continuously improve test frameworks, performance strategies, and QA best practices Qualifications - 5+ years of experience in QA with strong focus on API automation and performance testing - Hands-on expertise with Apache JMeter for API and UI performance testing - Strong experience with Postman and Newman for API automation - Solid understanding of RESTful APIs, HTTP methods, status codes, and JSON - Experience with performance testing concepts: load, stress, endurance, spike testing - Knowledge of CI/CD tools and pipelines (Azure DevOps preferred, Jenkins, GitLab CI) - Experience analyzing application performance metrics and system behavior - Familiarity with SQL/database performance validation - Experience with Cloud Platforms (Azure preferred, AWS, GCP) Requirements - Experience with microservices architectures - Knowledge of monitoring and observability tools (Datadog preferred) - Basic scripting knowledge (Groovy, JavaScript, or similar) - Experience working with containerized environments (Docker/Kubernetes) Physical Demands - Ability to safely and successfully perform the essential job functions - Sedentary work that involves sitting or remaining stationary most of the time with occasional need to move around the office to attend meetings - Ability to conduct repetitive tasks on a computer, utilizing a mouse, keyboard, and monitor Reasonable Accommodation Statement If you require a reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employment selection process, please direct your inquiries to application.accommodations@cai.io or (888) 824 – 8111.


