Lead AI Security Engineer
Tech Stack / Keywords
Firma i stanowisko
EPAM is a global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and startups. With over thirty years of expertise in custom software, product and platform engineering, they empower clients to become AI-Native enterprises.
Wymagania
- Bachelor's degree in Computer Science, Information Security, Engineering, or equivalent experience
- Hands-on application security experience across the software development lifecycle
- Strong understanding of common application vulnerabilities and mitigations including the OWASP Top 10
- Practical experience with application security tooling like SAST, DAST, SCA, and secrets scanning integrated into CI/CD
- Working knowledge of at least one programming language such as Python, Java, C#, JavaScript, TypeScript, or Go to read code and assess vulnerabilities
- Experience with threat modeling and secure design review methodologies
- Understanding of DevOps/DevSecOps practices, CI/CD pipelines, and secure-by-design principles
- Familiarity with cloud application security concepts on platforms such as Azure, AWS, or GCP
- Experience collaborating with developers, architects, QA, DevOps, product, and security teams
- Ability to follow and improve defined security processes
- Practical understanding of AI-assisted productivity and automation, including building or configuring AI agents, integrating LLMs with tools and workflows, prompt engineering, and secure AI tool usage
- Good communication skills to explain security risks and remediation plans to technical and non-technical stakeholders
Nice to have:
- Experience with application security tools like Snyk, Checkmarx, Veracode, SonarQube, Semgrep, GitHub Advanced Security, Burp Suite, OWASP ZAP
- Knowledge of software supply chain security including SBOM, SLSA, Sigstore
- Experience with Infrastructure as Code and policy-as-code tools such as Terraform, Bicep, ARM templates, OPA, Checkov, Trivy
- Container and Kubernetes security experience including image scanning and runtime protection
- Experience with API security, secrets management (e.g., HashiCorp Vault, Azure Key Vault), and microservice security
- Understanding of compliance or security frameworks such as ISO 27001, NIST, CIS Benchmarks, PCI DSS, HIPAA, SOC 2
- Integrating security findings with SIEM/SOAR, ticketing, and vulnerability management workflows
- Experience with AI/LLM platforms such as Azure OpenAI, Azure AI Foundry, Amazon Bedrock, Microsoft Copilot, LangChain, AutoGen
- Awareness of AI and LLM application security risks including prompt injection, model governance, and OWASP Top 10 for LLM Applications
- Security certifications like CSSLP, GWAPT, OSCP, CISSP, CISM, CCSP, AI-related certifications like AI-900, AI-102
Obowiązki
- Embed security into the full software development lifecycle and promote shift-left and secure-by-design practices
- Perform and facilitate threat modeling, architecture security reviews, and design reviews for applications, services, and APIs
- Conduct secure code reviews (manual and AI-assisted) and advise developers on secure coding patterns and remediation
- Operate application security tooling including SAST, DAST, IAST, SCA, secrets scanning, and IaC scanning integrated into CI/CD pipelines
- Triage, validate, prioritize, and reduce false positives in security findings; partner with development teams for remediation
- Define and maintain security gates and policies in CI/CD pipelines balancing risk and developer velocity
- Secure the software supply chain, including dependency and open-source risk management, SBOM generation, artifact integrity, and build pipeline hardening
- Support application penetration testing and validation of fixes
- Manage secrets, secure configuration, API security, container/image security, and microservice security
- Establish and run a security champions program; develop and deliver secure-coding training and reusable security patterns
- Define and maintain application security standards, baselines, and policy-as-code; contribute to vulnerability management
- Build and maintain AI-assisted automations and workflows for vulnerability triage, code review, threat modeling, and remediation
- Integrate AI agents and LLM-driven automations into SDLC and CI/CD pipelines
- Develop and maintain reusable prompts and prompt templates for application security tasks
- Implement retrieval over codebases and security standards for AI assistants to use authoritative internal context
- Build validation and human-in-the-loop checkpoints into AI-assisted workflows
- Implement security and privacy controls for AppSec AI usage including least-privilege access and auditability
- Design and operate security controls for AI- and LLM-powered application features aligned with OWASP Top 10 for LLM Applications
- Define and enforce guardrails for secure AI adoption in product engineering and advise development teams
Benefity
- Opportunity to work with top experts driving innovation in AI, cloud, and digital platform modernization
- Hybrid work mode with remote work option within Poland
- Chance to work abroad up to 60 days annually
- Business-driven relocation opportunities
- Career development programs and mentoring
- Certification programs (Anthropic, Gemini, GCP, Azure, AWS)
- English classes
- Stable pay
- Participation in Employee Stock Purchase Plan with 15% discount
- Benefits package including health insurance, multisport, shopping vouchers
- Referral bonuses up to $2,000
- Offices with entertainment zones, table tennis, football, free snacks, coffee
- Corporate, social, and well-being events
Inne informacje
Klikając w przycisk „Aplikuj” lub w inny sposób wysyłając zgłoszenie rekrutacyjne, zgadzasz się na przetwarzanie Twoich danych osobowych przez EPAM Systems (Poland) sp. z o.o. z siedzibą w: Fabryczna 1A, 31-553 Kraków (Pracodawca), jako administratora danych osobowych w celu przeprowadzenia rekrutacji na stanowisko wskazane w ogłoszeniu zgodnie Polityką Prywatności dostępną na stronie: https://www.epam.com/applicant-privacy-notice
EPAM Systems
873 aktywne oferty