Lead AI Security Engineer
Tech Stack / Keywords
Firma i stanowisko
EPAM is a global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and startups. The company has over thirty years of expertise in custom software, product, and platform engineering, focusing on empowering clients to become AI-Native enterprises.
Wymagania
- Bachelor's degree in Computer Science, Information Security, Engineering, or equivalent practical experience
- Hands-on application security experience across the software development lifecycle
- Strong understanding of common application vulnerabilities and mitigations including the OWASP Top 10, and secure coding principles
- Practical experience with application security tools such as SAST, DAST, SCA, and secrets scanning, integrated into CI/CD
- Working knowledge of at least one programming language such as Python, Java, C#, JavaScript, TypeScript, or Go sufficient to read code and assess vulnerabilities
- Experience with threat modeling and secure design review methodologies
- Understanding of DevOps/DevSecOps practices, CI/CD pipelines, and secure-by-design principles
- Familiarity with cloud application security concepts for major platforms like Azure, AWS, or GCP
- Experience participating in multiple production projects or engineering teams
- Ability to collaborate with developers, architects, QA, DevOps, product, and security teams and influence without owning codebase
- Ability to follow, maintain and improve defined security processes
- Practical understanding of AI-assisted productivity and automation beyond chatbot usage including building/configuring AI agents, integrating LLMs with tools, prompt engineering, creating runbooks, and secure AI tool usage
- Good communication skills explaining security risks, technical decisions, and remediation plans to technical and non-technical stakeholders
Nice to have:
- Experience with application security platforms like Snyk, Checkmarx, Veracode, SonarQube, Semgrep, GitHub Advanced Security, Burp Suite, OWASP ZAP
- Experience with software supply chain security including SBOM, SLSA, Sigstore, dependency and artifact integrity controls
- Experience with Infrastructure as Code and policy-as-code tools like Terraform, Bicep, ARM templates, OPA, Checkov, or Trivy
- Experience with container and Kubernetes security, image scanning, registries, runtime protection, and network policies
- Experience with API security, secrets management tools such as HashiCorp Vault, Azure Key Vault, and microservice security patterns
- Understanding of compliance/security frameworks like ISO 27001, NIST, CIS Benchmarks, PCI DSS, HIPAA, SOC 2, SOX
- Experience integrating security findings with SIEM/SOAR, ticketing, and vulnerability management workflows
- Experience with AI/LLM platforms/frameworks such as Azure OpenAI, Azure AI Foundry, Amazon Bedrock, Microsoft Copilot Studio, LangChain, AutoGen
- Understanding AI and LLM application security risks including prompt injection, insecure output handling, data leakage, excessive agency, insecure tool use, model governance, and AI supply chain risks
- Security certifications like CSSLP, GWAPT/GWEB, OSCP/OSWE, CISSP, CISM, CCSP, and AI-related certifications such as AI-900, AI-102
Obowiązki
- Embed security into the full software development lifecycle and drive shift-left and secure-by-design practices across engineering teams
- Perform and facilitate threat modeling, architecture security reviews, and design reviews for applications, services, and APIs
- Conduct secure code reviews (manual and AI-assisted) and advise developers on secure coding patterns and remediation
- Implement, configure, tune, and operate application security tooling, including SAST, DAST, IAST, SCA, secrets scanning, and IaC scanning, integrated into CI/CD pipelines
- Triage, validate, prioritize, and reduce false positives in security findings, partnering with development teams to track issues through remediation
- Define, implement, and maintain security gates and policies in CI/CD pipelines balancing risk reduction with developer velocity
- Secure the software supply chain including dependency and open-source risk management, SBOM generation, artifact integrity, signing, and build pipeline hardening
- Support and coordinate application penetration testing and validate fixes for vulnerabilities
- Drive secrets management, secure configuration, API security, container and image security, and microservice security practices
- Establish and run a security champions program; develop and deliver secure-coding training, guidelines, and reusable security patterns
- Define and maintain application security standards, baselines, and policy-as-code; contribute to vulnerability management and risk acceptance
- Build, deploy, and maintain AI-assisted automations and agentic workflows to reduce manual effort in application security activities
- Build and integrate AI agents and LLM-backed automations into the SDLC and CI/CD pipelines using function calling, REST, and webhooks
- Develop reusable prompts, structured-prompting patterns, and templates for application security tasks and tune them for accuracy and safety
- Implement retrieval over codebases, security standards, and remediation guidance to inform AI assistants with authoritative internal context
- Build evaluation, validation, and human-in-the-loop checkpoints in AI-assisted workflows including output verification and approval gates
- Implement security and privacy controls for AppSec AI usage including least-privilege access, secrets handling, prompt-injection resistance, and auditability
- Design, implement, and operate security controls for AI- and LLM-powered application features aligned with the OWASP Top 10 for LLM Applications
- Define and enforce guardrails for secure AI adoption in product engineering, covering prompt security, model access, data protection, and human-in-the-loop processes
- Advise development teams on building AI features securely
Benefity
- Hybrid work mode with opportunity to work remotely within Poland
- Chance to work abroad for up to 60 days annually
- Business-driven relocation opportunities
- Career development programs including thought leadership, mentoring, soft skills, and well-being
- Certification programs (Anthropic, Gemini, GCP, Azure, AWS)
- English classes
- Stable pay
- Participation in Employee Stock Purchase Plan with 15% discount
- Benefits package including health insurance, multisport, shopping vouchers
- Referral bonuses up to $2,000
- Offices with entertainment and relaxation zones, table tennis and football
- Free snacks, coffee and more
- Corporate, social and well-being events
Inne informacje
Klikając w przycisk „Aplikuj” lub w inny sposób wysyłając zgłoszenie rekrutacyjne, zgadzasz się na przetwarzanie Twoich danych osobowych przez EPAM Systems (Poland) sp. z o.o. z siedzibą w: Fabryczna 1A, 31-553 Kraków (Pracodawca), jako administratora danych osobowych w celu przeprowadzenia rekrutacji na stanowisko wskazane w ogłoszeniu zgodnie Polityką Prywatności dostępną na stronie: https://www.epam.com/applicant-privacy-notice
EPAM Systems
873 aktywne oferty