QA Automation and Security Testing Careers in Bangladesh: A Roadmap
Bangladesh has a large software outsourcing industry, and almost every product company and agency here needs testers. Most testing jobs are still manual, though. Testers who can also write automation and think like an attacker are much harder to find, and that gap is a good place to build a career.
This is the path I'd recommend, based on nearly six years of testing web, mobile and API products in Dhaka for HRMS, fintech, healthcare, EdTech, e-commerce and transport companies.
Stage 1: get the testing fundamentals right
Automation and security both rest on good test design. If you can't decide what to test, writing it in code won't help.
- Test design techniques: boundary value analysis, equivalence partitioning, decision tables and state transitions.
- Writing clear test cases from SRS documents, user stories and Figma designs.
- Writing bug reports a developer can act on: steps, expected vs actual, severity vs priority, evidence.
- How testing fits into Agile / Scrum teams.
The ISTQB Foundation Level (CTFL) syllabus is a good structured way to cover this, and local employers recognize it. Training institutes such as BITM (BASIS Institute of Technology & Management) and People N Tech run SQA courses if you'd rather learn with a group.
Stage 2: learn one programming language well
Choose one language and stick with it until you're comfortable:
- Java is still very common in enterprise QA teams here (Selenium, TestNG, Rest Assured).
- JavaScript / TypeScript if you want Playwright or Cypress, which most new projects use.
- Python is good for Pytest and also very useful later for security scripting.
Learn basic SQL too. A lot of testing comes down to checking that the data in the database is correct.
Stage 3: build real automation
- UI: Selenium WebDriver or Playwright, with the Page Object Model.
- API: Postman and Newman first, then Rest Assured or Playwright's API testing.
- Mobile: Appium for Android and iOS. Mobile apps are a big part of the local market.
- CI: run your suite in GitHub Actions or Jenkins on every push. A framework that only runs on your laptop doesn't count for much.
- Performance: the basics of JMeter or k6.
Stage 4: add security testing
This is where you really stand out. QA engineers already understand how the application is supposed to work, which is exactly what you need to spot when it does something it shouldn't.
- Learn the OWASP Top 10 and OWASP API Security Top 10.
- Learn Burp Suite (the Community edition is free) and OWASP ZAP.
- Work through the free PortSwigger Web Security Academy labs, and practise on TryHackMe and HackTheBox.
- Start with the bugs that fit naturally into QA work: access control and IDOR (see my IDOR testing checklist), authentication and session flaws, XSS and SQL injection.
- Add the checks to your automation, as described in QA automation and security testing in one CI pipeline.
Practical certifications to work towards: eJPT for the basics, Burp Suite Certified Practitioner (BSCP) for web application security, and later OSCP. That's the order I'm following myself.
Always stay legal. Only test systems you own, systems you have written permission for, or bug bounty programmes whose scope includes the target. Testing someone else's system without permission is a crime in Bangladesh, as it is almost everywhere.
Stage 5: make your work visible
Recruiters, local and overseas, can't see what you did inside a private company project. Give them something they can see:
- A GitHub profile with one or two clean automation frameworks against public demo sites, running in CI.
- Write-ups of PortSwigger or TryHackMe labs that explain your reasoning, not only the answer.
- A simple portfolio website and an up-to-date LinkedIn profile that use the same job title.
- Short articles about problems you solved. Writing them forces you to understand the topic properly.
Working remotely from Bangladesh
Bangladesh is on UTC+6. Afternoons here overlap with European mornings, and mornings overlap with Australia and East Asia, which makes a remote QA role workable. Remote teams look for three things: strong written English in bug reports and updates, automation that runs in CI without supervision, and testers who work independently and say early when something is blocked.
Summary
- Learn the testing fundamentals (consider ISTQB CTFL).
- Learn one programming language plus SQL.
- Build UI, API and mobile automation that runs in CI.
- Learn the OWASP Top 10, Burp Suite and ZAP, and practise on legal labs.
- Make your work public on GitHub, in write-ups and on a portfolio.
If you're a tester in Bangladesh on this path and want to compare notes, my portfolio has my contact details.