Quality Engineer - Application Security - Costco Travel
📋 Role Overview & Responsibilities
Costco Travel IT is responsible for the technical future of Costco Wholesale, the third largest retailer in the world with wholesale operations in fourteen countries. Despite our size and explosive international expansion, we continue to provide a family, employee centric atmosphere in which our employees thrive and succeed. As proof, Costco ranks seventh in Forbes “World’s Best Employers”.
This is an environment unlike anything in the high-tech world and the secret of Costco’s success is its culture. The value Costco puts on its employees is well documented in articles from a variety of publishers including Bloomberg and Forbes. Our employees and our members come FIRST. Costco is well known for its generosity and community service and has won many awards for its philanthropy. The company joins with its employees to take an active role in volunteering by sponsoring many opportunities to help others.
Come join the Costco Travel IT family. Costco Travel IT is a dynamic, fast-paced environment, working through exciting transformation efforts. We are building the next generation retail environment where you will be surrounded by dedicated and highly professional employees.
Quality Engineers are core delivery team members responsible for the validation of functional and nonfunctional requirements implemented by a team. They are responsible for decomposing the functional and technical requirements created by Product Owners and Systems Analysts into test scripts. Quality Engineers raise defects as issues are identified and support the remediation process with teams.
The Quality Engineer - Application Security will work closely with stakeholders in Security, Engineering, Dev Ops, and other leaders within Costco Travel. The Engineer will be responsible for the overall security of our applications and services/APIs. This role has specific focuses on application security, vulnerability scanning, vulnerability scan outputs, and the tools and methodologies used.
The Quality Engineer will identify gaps and inefficiencies within the vulnerability management program and will work with the team to implement solutions. The Quality Engineer will ensure security best practices are enforced. They will mentor team members and provide consultative services to teams and stakeholders to ensure the security of our applications.
If you want to be a part of one of the worldwide BEST companies “to work for”, simply apply and let your career be reimagined.
ROLE
Defines the testing strategy and approach to validate new or enhanced functionality implemented by teams.Collaborates with team members to decompose functional and nonfunctional requirements into test scripts and scenarios.Determines test dependencies including QA test environment, QA tools, training, build and deployment plans, intra-team dependencies, and communication processes.Creates and executes manual and automated test scripts to validate the acceptance criteria defined within the epics and user stories implemented by team members.Develops manual test cases for all functional and non-functional requirements and collaborates with development team members to identify candidates for test case automation.Identifies risks impacting the timely delivery of a given product and collaborates with team members to prepare mitigation strategies.Executes smoke, functional, integration, and non-functional test scripts as part of the product/application delivery lifecycle.Collaborates with team members to investigate the root cause of failed manual or automated test scripts.Creates defects with detailed information pertaining to the failed test case / scenario with supporting documentation (screenshots, environment details, log files, etc.).Collaborates with team members to identify existing manual and automated test scripts that will be impacted through the development of new features and capabilities.Shares feedback with the team members pertaining to the quality of sprint deliverables during retrospectives.Manages the remediation of defects raised throughout the development lifecycle and creates supporting quality reports that are shared with stakeholders.Collaborates with product team members (e.g., Product Owners, System Analysts) to define the automating testing approach/strategy for a given product/application.Develops testing protocols and standards to improve end-to-end testing outcomes and shares and adopts best practices with the center of excellence (CoE) and other Quality Engineers.Creates test data to support the execution of functional and nonfunctional testing activities Develops and executes automated test scripts to accelerate team velocity through the reduction of manual testing efforts.Maintains the automated testing suite and accompanying framework for a given product.Collaborates with team members (e.g., DevOps Engineers, Systems Architects) to incorporate new automated test scripts into the continuous integration pipeline.Shares test automation practices with engineers to promote “shift left” testing disciplines and practices (incorporate testing earlier in development) within a team.Serves as a subject matter expert for application security, vulnerability management, and vulnerability scanning.Supports and consults with product and development teams in the area of application security.Assesses applications for vulnerabilities in web UIs and APIs.Provides manual application secure code reviews.Works analytically to solve both tactical and strategic problems within the vulnerability management program.Identifies attack surface reduction opportunities through vulnerability data analysis from enterprise custom and COTSapplications.Collaborates and communicates with Compliance, External auditors, and Business teams.Understands compliance requirements that may impact security, and effectively collaborates with business areas and project teams to develop security solutions that address requirements.Advocates for compliance and security measures, both internally and externally, to protect corporate applications andenvironments.Maintains current knowledge of industry trends and standards; proactively pursues professional growth in the areas of technology, business knowledge, and Costco policies and platforms.
Required
4+ years’ experience in security in an enterprise environment.2+ years’ experience with software development with Java or any other Object-Oriented LanguageKnowledgeable in remediation activities at the code or script level, including fixing vulnerabilities or defects.Demonstrated experience with Java programming, development practices, and common bug patterns.Familiar with application vulnerability/security frameworks and standards such as OWASP Top 10, SANS Top 20, CVE,CWE, CVSS, etc.Experience with vulnerability management processes including scanning, reporting, and remediation planning.Understanding of software development lifecycle and integrating application security into a CI/CD pipeline.Experience with revision control systems and the agile process using ADO, Git, or similar agile code system functions (Pull, Fetch, Push, Sync).Strong verbal and written communication skills.Ability to clearly communicate Information Security matters to executives, auditors, end users, analysts, peers, andengineers, using appropriate language, examples, and tone.Experience identifying and validating security requirements for software.Experience working with software development teams.Realistic outlook that understands security problems as a balance of both security and business needs.Demonstrated logical and structured approach to time management and task prioritization in support of team work goals.Strong analytical skills, documentation skills, and awareness of change management; ability to adapt to changing priorities.Strong collaborative mindset and able to function as a contributing member of the team.Ability to handle highly confidential information in a strictly professional manner.
Recommended
2+ years’ experience in working with DevOps engineers in an enterprise environment.Experience with one or more scripting or development languages.Experience coding, implementing custom software solutions, and supporting them in production environments.General cloud knowledge.Familiarity with agile continuous improvement methodologies.Experience developing and reporting enterprise level metrics.
Required Documents
Cover LetterResume
California applicants, please click here to review the Costco Applicant Privacy Notice.
Pay Ranges
Level 2 - $105,000 - $135,000
Level 3 - $130,000 - $160,000
We offer a comprehensive package of benefits including paid time off, health benefits - medical/dental/vision/hearing aid/pharmacy/behavioral health/employee assistance, health care reimbursement account, dependent care assistance plan, short-term disability and long-term disability insurance, AD&D insurance, life insurance, 401(k), stock purchase plan to eligible employees.
Costco is committed to a diverse and inclusive workplace. Costco is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or any other legally protected status. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to IT-Recruiting@costco.com
If hired, you will be required to provide proof of authorization to work in the United States. In some cases, applicants and employees for selected positions will not be sponsored for work authorization, including, but not limited to H1-B visas.
Frequently Asked Questions
How do I apply for the Quality Engineer - Application Security - Costco Travel position at Costco Wholesale? ▼
Click the “Apply for this Position” button on this page to submit your application directly to Costco Wholesale without recruitment intermediary fees.
Is this position eligible for remote work or visa sponsorship? ▼
This position is located in Seattle, WA with potential relocation and sponsorship assistance depending on candidate qualifications.
Are there any candidate fees on Hirely? ▼
No. Hirely is completely free for candidates. We never charge registration fees or placement fees.
Legitimate employers will never ask you to transfer funds, purchase equipment from unauthorized vendors, or pay application/visa fees. Hirely rigorously monitors listings, but always verify communication is from official corporate email domains.
Learn how to protect yourself against employment fraud →