An automation engineer writes tests in a programming language, and the language follows what the product is written in. Java is named most, because the frameworks that grew up around Selenium are Java frameworks and because the banks' and logistics GCCs test Java systems. Python is close behind, and it leads at the security companies, the device and vehicle companies, and in embedded testing, where it is the language of the test lab. JavaScript and TypeScript are third, used with Playwright and Cypress, and C# appears where the product is .NET, with Groovy in a few older Jenkins setups. SQL is asked for in a fair share of job posts, because many tests end by checking that the right record landed in the database.
The largest family of tools drives a web application the way a user would, clicking, typing and checking what appears. Selenium is the most-named tool in the whole role, the long-standing standard, and it is named in most automation job posts. Playwright is the newer tool and is second, and it leads at the security and device companies and on the staffing platforms. Cypress is third and WebdriverIO and Protractor appear in a few older job posts. TestNG and JUnit are the Java frameworks that organise and run the tests, pytest and Robot Framework are the Python equivalents, and Mocha and Jest the JavaScript ones. BrowserStack, Sauce Labs and LambdaTest are the services that run the same tests across many browsers and devices in the cloud. Allure and ExtentReports turn the results into reports.
A fair share of job posts ask for behaviour-driven development, where tests are written first as plain sentences that a business user can read and then wired to code. Cucumber is the tool, Gherkin the language the sentences are written in, SpecFlow the .NET version and Behave the Python one. It is asked for most at the banks' and logistics GCCs and in client work, where the business signs off the tests.
Behind every screen is an API, and testing it directly is faster and more reliable than testing through the browser. REST Assured is the Java library for this and is named in a large share of job posts. Postman is the tool for trying an API by hand and then turning those tries into automated checks, with Newman running them in a pipeline. SoapUI tests the older SOAP services still found at banks and in enterprise software, and Karate combines API testing with Gherkin. Pact, WireMock and Mountebank stand in for a service that is not there yet, so one team can test against another's API before it is built. API testing is asked for most at the payment networks, where every transaction must be right, and at the GCCs.
Some job posts ask whether the software is fast enough and stays up when thousands of users arrive at once. JMeter is the tool named most, by a wide margin, and in the performance job posts it is named in most of them. LoadRunner is the older enterprise tool, still named at the banks and payment companies. Gatling, k6 and Locust are the newer, code-first tools, and BlazeMeter runs JMeter tests in the cloud. Performance testers also read the monitoring: Dynatrace, Grafana, AppDynamics, New Relic and Datadog appear in their job posts to see where the slowness is. Performance testing is asked for most at the payment networks and security companies, and in the logistics GCC.
Mobile testing drives a real app on a real device. Appium is the tool named most, the cross-platform standard, with Espresso for Android and XCUITest for iOS when the test is written natively, and Detox for React Native apps. BrowserStack and Sauce Labs provide the device farms, and ADB talks to a connected Android phone. Mobile testing is concentrated at the medical-device companies, the media GCCs, the food-delivery apps and the car-dashboard companies.
Embedded and systems testing is a different kind of career, closer to hardware. The software under test runs on a car's dashboard, a medical device, a network appliance or an industrial machine, and the tests run on the real thing in a lab. Python is the language in nearly all of these job posts, with Robot Framework and pytest as the frameworks, and Wireshark for inspecting the traffic a device sends. Regulated industries require every requirement to be traced to a test, and IEC 62304, the standard for medical device software, appears in those job posts. Embedded testing is concentrated at the security companies with hardware products, the vehicle and industrial companies, the medical-device makers and the engineering services firms that serve them.
A fair share of job posts still describe testing by hand: designing test cases from the requirements, running them, exploring the product for things nobody thought to specify, and logging what breaks. The tools here are for managing the tests rather than running them. TestRail, Zephyr, Xray and Micro Focus ALM hold the test cases and results, Bugzilla tracks defects, and Tricentis Tosca and Katalon are the low-code tools that let a manual tester automate without programming. Manual testing is concentrated at the large services firms and the testing specialists, and at the healthcare-claims software companies, where it is a large part of the work. SQL is its one technical ask.
The point of automated tests is that they run on every change, and putting them in the build pipeline is the most common extra ask in the whole role, on most job posts. Jenkins is the pipeline named most, with Azure DevOps, GitHub Actions and GitLab CI/CD behind it, and CircleCI in a few job posts. Docker appears where the tests run in containers so they behave the same everywhere, and Kubernetes where the test environment itself is a cluster. This is asked for most at the security and device companies, the GCCs and the staffing platforms, and least at the large services firms.
Cloud and containers are asked for in a fair share of job posts, and in most at the security companies, where the product being tested runs in the cloud. AWS leads, with Azure and GCP behind it, and Terraform appears in a few job posts where the tester builds the test environment as code. Database testing is tagged on a fair share, most at the GCCs, and it means SQL against Oracle, SQL Server, PostgreSQL, MySQL or MongoDB to check the data behind the screen. Security testing, probing for weaknesses with tools such as OWASP ZAP and Burp Suite, appears in a small share, almost all at the security companies.
Underneath all of it sits the ordinary craft of working in a software team: Git for source control, pull requests and reviews, issue tracking, and an agile rhythm where tests are written alongside the features they check. Job posts count these as given and rarely list them as skills.
A test engineer who writes Java or Python, drives a browser with Selenium and Playwright, tests an API with REST Assured or Postman, organises tests with TestNG or pytest, writes them in Cucumber where the business wants to read them, checks the data with SQL, and runs it all in a Jenkins or GitHub Actions pipeline, meets the core of nearly every job post. The variations belong to the employer. The security, payment and medical-device companies want the most code, in Python, with Playwright, JMeter, Docker and the cloud, and testing holds up best there. The vehicle and industrial companies want embedded testing beside automation, with Robot Framework and Azure DevOps. The logistics and banks' GCCs want Selenium in Java with REST Assured, Cucumber, JMeter and the most SQL. The services firms and testing specialists still carry most of the manual work, with Selenium and Java where it is automated. The staffing platforms want automation engineers with Selenium, Playwright, REST Assured and GitLab CI/CD for remote work. Across all of them, the tester who codes is the one every surviving job post describes.