Haystack
← Back to Jobs
Engineering
AT

Senior QA Verification Engineer – SAST/DAST & Automation

Aneka Talent SolutionsMalvern, PA🇺🇸United StatesPosted 28 Aug 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Malvern, PA, United States
Posted
19 hours ago

Job Description

Verification Engineer- Hybrid in Malvern PA

Team: AI Enablement — SDLC 2.0 Agentic Development
Reports To: [Manager/Director, AI Enablement / Quality & Risk]
Replaces / Absorbs: Manual QA authoring; the bulk of routine code-review load

 

SAST/DAST tooling- will need this testing experience. SonarQube, Semgrep, Checkmarx SASTf and CodeQA are SAST Tools. They will need experience with these and DAST Tools.

 This is a hybrid role and will require 2 days a week onsite.
 

Position Summary

The Verification Engineer owns the independent gates that catch what the building agent cannot see. Because a coding agent cannot be relied upon to grade its own work objectively, this role operates a separate, adversarial layer — distinct agents, distinct tests, and distinct judgment — whose sole purpose is to determine whether a build is actually correct, secure, and safe to ship.
This absorbs the majority of manual QA test authoring and routine human code review, replacing them with a structured, largely automated but independently-owned verification discipline.

Key Responsibilities

  • Operate the adversarial verification layer: separate QA and security agents, LLM-judge review, and held-out or composition tests that the building agent never sees during development.
  • Enforce deterministic gates — coverage floors (80% general / 90% security-critical, with a ratchet rule preventing regression), SAST/DAST/secret/dependency scans, test-edit detection, and dependency allowlists.
  • Run the tiered review model, routing irreversible or high-blast-radius changes to mandatory human architecture and security review rather than allowing them through automated gates alone.
  • Own and report escaped-defect and first-pass-accuracy metrics for the overall validation workstream.
  • Design and maintain held-out test suites and composition tests specifically so they remain unseen by the builder, preserving their diagnostic value.
  • Investigate gate failures to distinguish genuine defects from false positives, and feed systemic failure patterns back into the standards library.

Required Qualifications

  • 5+ years in QA engineering, test automation, or security engineering, including designing test strategy rather than only executing test cases.
  • Hands-on experience with SAST/DAST tooling, secret scanning, and dependency vulnerability scanning in a CI/CD context.
  • Understanding of code coverage tooling and how to set and enforce meaningful coverage thresholds.
  • Ability to design adversarial or held-out test scenarios that a builder (human or agent) would not have visibility into during development.
  • Working scripting ability to build and maintain automated gate checks.
  • Hands on experience with common RDBMS platforms and SQL queries
  • Familiarity AWS and container based architectures

Preferred Qualifications

  • Experience designing or operating LLM-judge or AI-assisted review pipelines.
  • Background in secure SDLC practices or participation in an architecture/security review board.
  • Familiarity with test-edit detection techniques (identifying when a builder has modified a test to pass rather than fixing the underlying code).

Success Metrics

  • Escaped-defect rate (defects found post-gate vs. pre-gate).
  • First-pass accuracy of builds arriving at verification.
  • Coverage floor compliance and ratchet adherence over time.
  • Percentage of high-blast-radius changes correctly routed to mandatory human review.

Similar jobs