Company banner

R&D Engineer SW Quality 3

Job Description

Posted on: 

Please Note:

1. If you are a first time user, please create your candidate login account before you apply for a job. (Click Sign In > Create Account)

2. If you already have a Candidate Account, please Sign-In before you apply.

Job Description:

About the Role

The Brocade Switch and Networking (BSN) business unit of Broadcom is seeking a highly skilled Software QA Test Engineer – Brocade Switch & Networking (BSN) to test, verify, and automate the security validation of Brocade’s storage area network (SAN) based networked solutions. In this role, you will be an integral part of a high-performing test team responsible for verifying Brocade’s Fabric OS (FOS), associated hardware switching platforms, management APIs, and developing robust, automated security and functional test suites with focus on the lifecycle of the product line.

The ideal candidate possesses a solid foundation in software and hardware engineering principles, a deep understanding of system quality assurance, and a proven track record of designing, executing, and automating complex test plans. We are looking for a professional who can bridge the gap between QA automation engineering and offensive/defensive cybersecurity, with hands-on experience configuring, troubleshooting, and verifying enterprise network operating systems, AAA infrastructures, and cryptographic boundaries.

Primary Responsibilities

As a Software QA Test Engineer focused on Security and Test Automation, you will own the end-to-end quality assurance and automation processes for critical FOS security features. Your day-to-day responsibilities will include:

  • Security Test Strategy & Planning: Translate complex security technical specifications, regulatory standards, and break fix changes into comprehensive automated and manual test plans covering functional, integration, regression, performance, and security testing.
  • Automation Framework Development: Design, develop, and maintain robust test automation frameworks and scripts (primarily in Python) to automate CLI and API testing, improving testing efficiency, execution speed, and coverage.
  • Hardware & Software Backward Compatibility: Test security policy persistence, cryptographic boundary alignment, and config persistence during firmware migrations with mixed FOS versions (e.g., FOS v10.x, and v9.x).  Ensure seamless security enforcement on Gen 6 and Gen 7 hardware platforms alongside modern Gen 8 platforms.
  • SNMP: Design and execute test plans validating SNMP GET, GETNEXT, GETBULK, SET, and TRAP/INFORM operations against device MIBs. Verify custom and standard MIB objects (OIDs) return accurate, correctly typed values consistent with actual device/system state.  Test SNMP trap generation, timing, and content for fault, performance, and configuration-change events. Test SNMPv1/v3 support, including authentication and encryption. Perform interoperability testing with common NMS/monitoring tools to confirm real-world compatibility. Develop and maintain automated python test scripts to Test SNMP behavior across builds and regression cycles.  Identify, document, and track SNMP-related defects (incorrect OID values, missing traps, malformed responses, memory leaks under polling load) through resolution.
  • Authentication & Multi-Factor/Federated Authentication (MFA/FA): Verifying port-level authentication (DH-CHAP E-Port and F/N-Port, FCAP E-Port) and federated authentication (FA) utilizing OAuth 2.0 / JWT tokens with external Identity Providers (IDPs) such as Azure/Entra ID, including M2M (machine-to-machine) flows.
  • Network & Firewall Policy Validation: Test firewall policies, verifying INPUT and OUTPUT rulesets, ephemeral port restrictions, and default rate-limiting mechanisms.
  • Secure Shell & Secure File Transfers: Test SSH/SCP/SFTP basic functionality, client/server options, SSH rekeying, host key management and outbound secure file transfers.
  • Auditing & Event Messaging: Test secure syslog-ng, client authentication, security RAS logs, CLI history completeness, PII/CDA sanitization (GDPR compliance), and TLS/SSL failure records.
  • Cryptographic & Certificate Management: Verify classic and quantum-safe cryptographic parameters (such as TLSv1.3 ciphers, HTTPS Key Encapsulation Mechanisms - KEM, and post-quantum algorithms like ML-DSA and ML-KEM), certificate operations, CSR generation, SAN/CN validation, and path/revocation validation.
  • Defect Management & Advisory: Partner with development teams to identify, document, investigate, and track software defects and security vulnerabilities using industry-standard tools. Advise area leads on the overall quality status of assigned features.

Qualifications & Requirements (Must Have)

  • Education: Bachelor’s Degree in Engineering (Computer Science, Cyber Security, Electrical, or equivalent).
  • Experience: Minimum of 8 years of hands-on software testing experience, with a heavy focus on security testing and test automation.
  • Automation Scripting: High proficiency in Python for test automation, with hands-on experience automating APIs and CLI-based tools.
  • QA Methodologies: Robust understanding of software testing methodologies, including functional, negative, boundary, performance, scale, and longevity/stress/soak testing.
  • Networking & Protocols: Solid foundational knowledge of enterprise networking, routing, cryptography, and core communication protocols (TCP/IP, SSL/TLS, SSH, HTTPS, SFTP, SCP, and cryptographic handshake mechanics).
  • Operating Systems & Virtualization: Hands-on experience with the installation, configuration, usage, and troubleshooting of Linux, Windows, VMware environments, AAA infrastructure (LDAP, RSA, RADIUS, TACACS+), Federated IDP infrastructure (SAML, OIDC), PQC infrastructure, and vulnerability/intrusive scanner applications.
  • Storage Systems: Solid foundational knowledge of SAN/Storage technologies.
  • Professional Skills: Excellent analytical and problem-solving skills, exceptional written and verbal communication, and a proven ability to prioritize, multitask, and manage parallel projects in a fast-paced environment.
  • Active Cybersecurity Certifications (at least one required): OSCP (Offensive Security Certified Professional), GWAPT (GIAC Web Application Penetration Tester), GXPN (GIAC Exploit Researcher and Advanced Penetration Tester), CASE (Certified Application Security Engineer - Python), CSSLP (Certified Secure Software Lifecycle Professional), or CISSP (Certified Information Systems Security Professional).
  • Security Frameworks & Tooling: Familiarity with secure coding principles, threat modeling methodologies (e.g., STRIDE), and standard vulnerability ranking metrics (CVSS). Hands-on experience with scanners such as Qualys, Nessus, or Burp Suite.
  • Work Arrangement: This position requires 100% on-site attendance.

Highly Desired Skills & Experience

  • Standards & Compliance: Experience with pursuing product certification or compliance with regulatory bodies and standards such as FIPS (140-3), CC (Common Criteria / NDcPP), BSI, EUCC, NIST2, DORA, and CRA.
  • Storage Protocols: In-depth SAN protocol knowledge (Fibre Channel, FCIP, FICON).
  • Storage Systems: Solid foundational knowledge of SAN/Storage technologies.

Compensation and Benefits

The annual base salary range for this position is USD 91,100.00 To USD 146,000.00

As a valued member of our team, you'll be eligible for a discretionary annual bonus and the opportunity to receive not only a competitive new hire equity grant, but also annual equity awards, connecting your success directly to the company's growth. All subject to relevant plan documents and award agreements.

Broadcom offers a competitive and comprehensive benefits package: Medical, dental and vision plans, 401(K) participation including company matching, Employee Stock Purchase Program (ESPP), Employee Assistance Program (EAP), company paid holidays, paid sick leave and vacation time. The company follows all applicable laws for Paid Family Leave and other leaves of absence.

Broadcom is proud to be an equal opportunity employer.  We will consider qualified applicants without regard to race, color, creed, religion, sex, sexual orientation, national origin, citizenship, disability status, medical condition, pregnancy, protected veteran status or any other characteristic protected by federal, state, or local law.  We will also consider qualified applicants with arrest and conviction records consistent with local law.

If you are located outside USA, please be sure to fill out a home address as this will be used for future correspondence.

Apply now